好友
阅读权限10
听众
最后登录1970-1-1
|
楼主的分析很到位,学习了。另一个破解思路是这样的,供参考:
000000014000D1BF | 81FB E6030000 | cmp ebx,3E6 |==>mov al, 0x1
000000014000D1C5 | 75 1F | jne uninstalltool.14000D1E6 ||==>nop
000000014000D1C7 | 48:8D0D 8A3A2600 | lea rcx,qword ptr ds:[140270C58] | 0000000140270C58:L"Corporate License"
000000014000D1CE | E8 19E52100 | call uninstalltool.14022B6EC |
000000014000D1D3 | 48:8D15 7E3A2600 | lea rdx,qword ptr ds:[140270C58] | rdx:"H冹(杷\r", 0000000140270C58:L"Corporate License"
000000014000D1DA | 44:8BC0 | mov r8d,eax |
000000014000D1DD | 48:8D4D AF | lea rcx,qword ptr ss:[rbp-51] |
000000014000D1E1 | E8 96060000 | call uninstalltool.14000D87C |
000000014000D1E6 | 49:8BCF | mov rcx,r15 |
000000014000D1E9 | E8 8E290000 | call uninstalltool.14000FB7C |
000000014001A8CE | F0:0FC141 58 | lock xadd dword ptr ds:[rcx+58],eax | rcx+58:L"倀猍翼"
000000014001A8D3 | 85C0 | test eax,eax |
000000014001A8D5 | 74 0B | je uninstalltool.14001A8E2 |
000000014001A8D7 | E8 00040000 | call uninstalltool.14001ACDC |
000000014001A8DC | 83F8 03 | cmp eax,3 |
000000014001A8DF | 0F94C3 | sete bl |==>mov eax, 0x1
000000014001A8E2 | 8AC3 | mov al,bl |==>nop
000000014001A8E4 | 48:83C4 20 | add rsp,20 |
000000014001A8E8 | 5B | pop rbx |
000000014001A8E9 | C3 | ret | |
免费评分
-
查看全部评分
|