字符串 bp GetDlgItemTextA(W) **** bp GetDlgItemInt bp GetWindowTextA(W) **** bp GetWindowWord bmsg XXXX wm_gettext
对话框 bp MessageBeep bp MessageBoxA(W) **** bp MessageBoxExA(W) bp DialogBoxParamA(W) bp GreateWindowExA(W) bp ShowWindow bp UpdateWindow bmsg XXXX wm_command
对于VB的程序用bp MessageBoxA是无法断下来的,bp rtcMsgBox
注册表相关 bp RegCreateKeyA(W) bp RegDeleteKeyA(W) bp RegQueryValueA(W) bp RegCloseKey bp RegOpenKeyA(W) ****
时间相关 bp GetLocalTime bp GetFileTime bp GetSystemtime
INI初始化文件相关 bp GetPrivateProfileStringA ****//xor eax,eax--->or eax,eax bp GetPrivateProfileInt bp WritePrivateProfileString bp WritePrivateProfileInt
文件访问相关 bp ReadFile bp WriteFile bp CreateFileA **** bp SetFilePointer bp GetSystemDirectory