fff000
³¬¼¶°æÖ÷
       
»ý·Ö 18503
·¢Ìû 2582
×¢²á 2006-5-27
״̬ ÀëÏß
|
 #1 ͵Ìì»»ÈÕ¡ª¡ª¹âÅ̰æÓÎÏ·ÍêÃÀת»»Ó²Å̰æ
͵Ìì»»ÈÕ¡ª¡ª¹âÅ̰æÓÎÏ·ÍêÃÀת»»Ó²Å̰æ
µçÄÔÓÎÏ·Íæ¼Ò¶¼Óöµ½¹ýÕâÑùµÄÎÊÌ⣬ºÜ¶àÓÎÏ·ÔÚÔËÐÐʱÈÔÐèÒª²åÈë¹âÅÌ(¡°ÍêÈ«°²×°¡±Çé¿öϾ¹È»Ò²ÊÇÈç´Ë£¡£¿)¡£Èç¹û¹âÅ̲»É÷ÒÅʧ»ò¹âÇý¹ÊÕÏ£¬Ãæ¶Ô°²×°ºÃµÄÓÎÏ·ÄãÊÇ·ñ¾ÍÎ޼ƿÉÊ©ÁËÄØ£¿Äã¿ÉÄÜ»áÑ¡Ôñ´ÓÍøÉÏÏÂÔØ¸ßÊÖÖÆ×÷µÄÃâCD²¹¶¡£¬¿ÉÊDz¢·Çÿ¸ö¹âÅ̰æÓÎÏ·¶¼ÄÜÕÒµ½»òÄÜÓÃÕâÑùµÄ²¹¶¡¡£±¾ÎľÍÒªÈÃÄã°çÑÝÒ»»Ø¸ßÊֵĽÇÉ«£¬×Ô¼ºÀ´´òÔìÍêÃÀµÄÓ²Å̰æÓÎÏ·¡£
ÌØ±ðÉùÃ÷:±¾ÎÄÄ¿µÄÖ»ÊÇΪÁËÈùºÂòÕý°æÓÎÏ·µÄÓû§Äܹ»ÔÚ²»Ä¥Ëð¹âÇýµÄÇé¿öÏ·½±ãµØ½øÐÐÓÎÏ·£¬ÒÔÏÂÐÞ¸ÄÀý×ÓÖнÔÒþÈ¥Á˲¿·ÖÓÎÏ·Ãû³Æ¡£
²¢²»ÊÇÿ¸ö¹âÅ̰æÓÎÏ·¶¼Äܹ»×ª»»ÎªÓ²Å̰棬ÒÔÏÂÁоÙÁËһЩ¿ÉÐ޸ĵÄÓÎÏ·ÀàÐͺÍÌØÕ÷£¬²¢¸ø³öʵ¼ÊÐ޸Ĺý³Ì¡£
ʵս1:È¥³ý¹âÅ̼ì²â
ÓÎÏ·ÌØÕ÷:ÓÎÏ·ËùÓÐÎļþ¾ùÒѰ²×°ÖÁÓ²ÅÌÖУ¬½öÔÚÓÎÏ·¿ªÊ¼Ê±³öÓÚ°æÈ¨±£»¤Ä¿µÄ¼ì²âÒ»´Î¹âÅÌ¡£
ÐÞ¸ÄÔÀí:ÔÚÓÎÏ·³ÌÐò¿ªÊ¼Î»ÖÃÓÐÒ»¶Î¼ì²â¹âÅ̵ĴúÂ룬×î¼òµ¥µÄ¼ì²â·½Ê½¾ÍÊÇ´Ó¹âÅÌÖжÁÈ¡ÌØ¶¨Îļþ£¬Ã»ÓжÁµ½Ôòµ¯³öÌáʾ¿ò²¢Ç¿ÖÆÍ˳öÓÎÏ·£¬Èç¹û¶Áµ½²¢È·ÈÏΪ¸ÃÓÎÏ·¹âÅÌ£¬Ôò³ÌÐòÌø×ªµ½ÓÎÏ·¿ªÊ¼´¦¡£
ÐÞ¸ÄÄѶÈ:¡ï¡ï¡ï
ËùÐ蹤¾ß:W32DASM(ÏÂÔØµØÖ·:http://www.pediy.com/tools/Disassemblers/W32Dasm/W32dsm8.93.rar)£¬RTA(ÏÂÔØµØÖ·:http://www.pediy.com/tools/Editors/RTA/rta.zip)¡£
µÚÒ»²½:ÏÂÔØW32DASM²¢½âѹ£¬ÔËÐнâѹĿ¼ÖеÄW32dsm8.93+.exe¡£Ñ¡ÔñW32DASMÖ÷½çÃæ²Ëµ¥¡°Disassembler¡úOpen File to Disassemble¡±(·´»ã±à¡ú´ò¿ªÐèÒª·´»ã±àµÄÎļþ)£¬ÔÚÎļþÑ¡Ôñ¿òÖÐÑ¡Ôñ´ò¿ª¡¶¡Á¡ÁÎïÓï¡·°²×°Ä¿Â¼ÏµÄzweipet.exe¡£
µÚ¶þ²½:Ñ¡Ôñ²Ëµ¥¡°Functions¡úImports¡±(º¯Êý¡úÊäÈë±í)£¬ÔÚµ¯³ö´°¿ÚÖÐÓÐÒ»¸öÁбí¿òÏêϸÁгöÁ˳ÌÐòÖÐÓõ½µÄAPIº¯Êý¡£ÔÚ´°¿ÚÉÏ·½Îı¾¿òÖÐÊäÈë¡°GetDriveType¡±(²»º¬ÒýºÅ)²¢µã»÷ÓҲࡰSearch¡±(ËÑË÷)°´Å¥£¬Ï·½Áбí¿òÖоÍÑ¡ÖÐÁ˸ú¯ÊýËùÔÚÐУ¬½Ó×ÅË«»÷Ëü(¼ûͼ1)¡£
ͼ1
СÌáʾ
APIÊdzÌÐòµ÷ÓÃϵͳ¹¦Äܵĺ¯Êý½Ó¿Ú£¬±ÈÈç³ÌÐòÒª¼ì²â¹âÅÌ£¬¾Í±ØÐëʹÓÃGetDriveTypeº¯ÊýÀ´»ñµÃÅÌ·ûµÄÉ豸ÀàÐÍ¡£Òò´ËÕÒµ½GetDriveTypeº¯ÊýÔÚ³ÌÐòÖеĵ÷ÓÃλÖ㬾ÍÒ»¶¨ÄÜÔÚ¸½½üÕÒµ½¹âÅ̼ì²â´úÂë¡£
µÚÈý²½:ÔÚW32DASMÖ÷½çÃæµÄ´úÂëÏÔʾ¿òÖоÍÒÔ¸ßÁÁ·½Ê½Ñ¡ÖÐÁËGetDriveTypeº¯ÊýµÄµ÷ÓÃλÖ㬽«´úÂë¿òÉÔ΢ÍùÏÂÀÒ»µã¾ÍÄÜ¿´µ½¹âÅ̼ì²â´úÂëÁË (¼ûͼ2)¡£´úÂë¿ò×î×ó²àµÄÀ¶É«Êý×ÖÊÇ´úÂëµÄλÖã¬Èç±¾ÎÄÖÐÔÚzweipet.exeÖÐÕÒµ½GetDriveTypeµÄλÖÃΪ0048843£¬¶ø¹âÅ̼ì²â´úÂëµÄλÖÃÔÚ004088BD´¦¡£ÒÔÏÂÊÇ´úÂë¼òҪעÊÍ:
ͼ2£ºÌáʾ¡°²åÈë¹âÅÌ¡±µÄ¹âÅ̼ì²â´úÂë
:004088BD mov eax,dword ptr[esp+14]
:004088C1 test eax, eax //¼ì²éÊÇ·ñÓйâÅÌ
:004088C3 jnz 004088DB //ÓйâÅÌÔòÌø×ªµ½004088DBλÖÃ(¼´ÓÎÏ·¿ªÊ¼Î»ÖÃ)£¬Ã»ÓйâÅÌÔò²»Ìø×ª
:004088C5 push 00000000
:004088C7 push 00428934
:004088CC push 00428919
:004088D1 push 00000000
:004088D3 call dword ptr[004233EC] //µ¯³öÒ»¸öÌáʾ´°¿Ú¡°Çë²åÈë¡Á¡ÁÎïÓïµÄÓÎÏ·¹âÅÌ¡±
:004088D9 jmp 00408933 //³ÌÐòתÏò´úÂë½áÊø²¿·Ö£¬Ò²¾ÍÊÇÇ¿ÖÆÍ˳öÓÎÏ·
(¼ûͼ3)
ͼ3£º004088D3λÖô¦µÄ´úÂëÖ´ÐÐʱ»áµ¯³ö´ËÌáʾ¿ò
µÚÈý²½:¿ÉÒÔ¿´µ½ÔÚ004088C3´¦¾ö¶¨Á˳ÌÐò×ßÏò(ÊǼÌÐøÏÂÒ»ÐдúÂ뻹ÊÇÌø×ªµ½004088DB´¦¿ªÊ¼ÓÎÏ·)£¬Èç¹ûÄÜÈóÌÐò²»¼ÓÅжÏÖ±½ÓÌø×ªµ½ 004088DB£¬¾ÍµÈÓÚÌø¹ýÁ˹âÅ̼ì²â¡£¹Ø±ÕW32DASM£¬´ò¿ª¸Õ²ÅÏÂÔØµÄRTA£¬Ñ¡Ôñ²Ëµ¥ÃüÁî¡°File¡úOpen File¡±(Îļþ¡ú´ò¿ªÎļþ)£¬Í¬ÑùÒ²ÊÇ´ò¿ªzweipet.exe¡£RTA½çÃæÁ¢¼´ÏÔʾ³özweipet.exeµÄ»ã±à³ÌÐò´úÂë¡£×î×ó²àµÄºìÉ«Êý×ÖΪ´úÂëλÖ㬱ßÉÏÀ¶É«Ê®Áù½øÖÆÊýΪ¸ÃÐдúÂëµÄ»úÆ÷Â룬ÓÒ²à»ÆÉ«ÎÄ×ÖÔòΪ»ã±à´úÂë¡£ÕÒµ½ÒªÐ޸ĵÄλÖÃ004088C3£¬¿ÉÕâ¾ä»ã±à´úÂëΪ¡°JNZ SHORT 4088DB¡±£¬½«ÆäÐÞ¸ÄΪ¡°JMP SHORT 4088DB¡±(²»º¬ÒýºÅ£¬»úÆ÷ÂëΪEB16)¡£
(ͼ4 ÐÞ¸Äǰ)
(ͼ5 Ð޸ĺó)
ÄãÖªµÀÂ𡪡ªJNZºÍJMPÊÇʲôÒâ˼£¿
JNZΪÓÐÌõ¼þ×ªÒÆÖ¸ÁÏȼì²âÒ»¸öÌõ¼þ£¬Èç¹ûÂú×ãÔòÌø×ª£¬·ñÔò¼ÌÐøÖ´ÐÐÏÂÒ»ÐдúÂë¡£¶øJMPÔòΪÎÞÌõ¼þ×ªÒÆÖ¸Á²»¼ì²âÈκÎÌõ¼þ¶øÖ±½ÓÌø×ªÖÁÐèÒª×ªÒÆµÄλÖá£
µÚËIJ½:Ñ¡Ôñ²Ëµ¥ÃüÁî¡°File¡úSave File¡±(Îļþ¡ú±£´
|

|
|