首页 电脑 电脑学堂 查看内容

魔兽世界启动器的分析

2006-7-21 04:07 482 0

摘要: 魔兽世界启动器 v0.1.4.7(7月3日更新[定时调用游戏|自动登录|插件、截图管理等])功能太强大了,自叹不如。。。 http://bbs.game.mop.com/viewthread.php...
关键词: nbsp dumped push 0050 eax call dword 0080 ptr mov

魔兽世界启动器 v0.1.4.7(7月3日更新[定时调用游戏|自动登录|插件、截图管理等])功能太强大了,自叹不如。。。 http://bbs.game.mop.com/viewthread.php?tid=1143103&extra=page%3D1功能:太多了,我就看重这个定时调用并自动登录游戏,有效防止采用键盘HOOK技术的木马盗取密码(启动器无法防止所有木马,它毕竟不是专业杀木马软件,作者只是尽力降低您中木马的危险而已,绝不是用了它您就可以高枕无忧)保护方法小小分析了一下,程序实在太大。。。我分析完了,IDA还在跑。。。本人分析纯属学习,请作者见谅,如有不妥,请联系我,我立刻删除保护1:随机生成窗口名0080DBCE |> \8B0F       mov ecx,dword ptr ds:[edi]0080DBD0 |. 8D45 EC     lea eax,dword ptr ss:[ebp-14]0080DBD3 |. BA 50DC8000   mov edx,dumped.0080DC500080DBD8 |. E8 FF7BBFFF   call dumped.004057DC0080DBDD |. 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080DBE0 |. E8 AB7DBFFF   call dumped.004059900080DBE5 |. 50         push eax                             ; /Text = "魔兽世界lllllllll"0080DBE6 |. 56         push esi                             ; |hWnd0080DBE7 |. E8 40B6BFFF   call <jmp.&user32.SetWindowTextA>             ; \SetWindowTextA0080DBEC |. E8 63B2BFFF   call <jmp.&user32.GetForegroundWindow>         ; [GetForegroundWindow0080DBF1 |. 3BF0       cmp esi,eax0080DBF3 |. 0F94C3       sete bl0080DBF6 |> 33C0       xor eax,eax0080DBF8 |. 5A         pop edx保护2:自动登陆0080E176   > \55         push ebp                             ; 自动登陆0080E177 > . E8 A0F9FFFF   call dumped.0080DB1C                     ; ->:TfrmMain.修改窗口名()0080E17C   . 59         pop ecx0080E17D   . 84C0       test al,al                           ; 这里判断当前窗口是不是WOW0080E17F   .^ 74 D0       je short dumped.0080E1510080E181   . 8D55 9C     lea edx,dword ptr ss:[ebp-64]               ; 解密后密码指针0080E184   . 8B45 F0     mov eax,dword ptr ss:[ebp-10]               ; 加密的密码0080E187   . E8 2CDACFFF   call dumped.0050BBB8                     ; 解密函数0080E18C   . 8B55 9C     mov edx,dword ptr ss:[ebp-64]               ; 解密后的密码0080E18F   . 8D45 F0     lea eax,dword ptr ss:[ebp-10]0080E192   . E8 A173BFFF   call dumped.004055380080E197   . 8B45 E8     mov eax,dword ptr ss:[ebp-18]0080E19A   . E8 69DACFFF   call dumped.0050BC080080E19F   . 8D55 94     lea edx,dword ptr ss:[ebp-6C]0080E1A2   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E1A5 > . 8B80 50040000 mov eax,dword ptr ds:[eax+450]               ; *cbbUser:TcxComboBox0080E1AB   . E8 507BC8FF   call dumped.00495D000080E1B0   . 8B45 94     mov eax,dword ptr ss:[ebp-6C]0080E1B3   . 8D55 98     lea edx,dword ptr ss:[ebp-68]0080E1B6   . E8 45C6BFFF   call dumped.0040A8000080E1BB   . 8B45 98     mov eax,dword ptr ss:[ebp-68]               ; 用户名0080E1BE   . E8 C1FCCFFF   call dumped.0050DE84                     ; 发送用户名0080E1C3   . EB 25       jmp short dumped.0080E1EA0080E1C5   > A1 F49D8300   mov eax,dword ptr ds:[839DF4]0080E1CA   . 8B00       mov eax,dword ptr ds:[eax]0080E1CC > . E8 1F5FCAFF   call dumped.004B40F0                     ; ->:TApplication._PROC_004B40F0()0080E1D1   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E1D4   . 80B8 F3040000 >cmp byte ptr ds:[eax+4F3],00080E1DB   . 74 0D       je short dumped.0080E1EA0080E1DD   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E1E0 > . E8 5322CAFF   call dumped.004B0438                     ; ->:TApplication._PROC_004B0438()0080E1E5   . E9 06010000   jmp dumped.0080E2F00080E1EA   > 55         push ebp0080E1EB > . E8 2CF9FFFF   call dumped.0080DB1C                     ; ->:TfrmMain.修改窗口名()0080E1F0   . 59         pop ecx0080E1F1   . 84C0       test al,al                           ; 这里判断当前窗口是不是WOW0080E1F3   .^ 74 D0       je short dumped.0080E1C50080E1F5   . B8 38E58000   mov eax,dumped.0080E538                   ; ASCII "vkTab"0080E1FA   . E8 85FCCFFF   call dumped.0050DE84                     ; 发送TAB健0080E1FF   . EB 25       jmp short dumped.0080E2260080E201   > A1 F49D8300   mov eax,dword ptr ds:[839DF4]0080E206   . 8B00       mov eax,dword ptr ds:[eax]0080E208 > . E8 E35ECAFF   call dumped.004B40F0                     ; ->:TApplication._PROC_004B40F0()0080E20D   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E210   . 80B8 F3040000 >cmp byte ptr ds:[eax+4F3],00080E217   . 74 0D       je short dumped.0080E2260080E219   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E21C > . E8 1722CAFF   call dumped.004B0438                     ; ->:TApplication._PROC_004B0438()0080E221   . E9 CA000000   jmp dumped.0080E2F00080E226   > 55         push ebp0080E227 > . E8 F0F8FFFF   call dumped.0080DB1C                     ; ->:TfrmMain.修改窗口名()0080E22C   . 59         pop ecx0080E22D   . 84C0       test al,al                           ; 这里判断当前窗口是不是WOW0080E22F   .^ 74 D0       je short dumped.0080E2010080E231   . 8B45 F0     mov eax,dword ptr ss:[ebp-10]               ; 密码0080E234   . E8 4BFCCFFF   call dumped.0050DE84                     ; 发送密码0080E239   . EB 25       jmp short dumped.0080E2600080E23B   > A1 F49D8300   mov eax,dword ptr ds:[839DF4]0080E240   . 8B00       mov eax,dword ptr ds:[eax]0080E242 > . E8 A95ECAFF   call dumped.004B40F0                     ; ->:TApplication._PROC_004B40F0()0080E247   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E24A   . 80B8 F3040000 >cmp byte ptr ds:[eax+4F3],00080E251   . 74 0D       je short dumped.0080E2600080E253   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E256 > . E8 DD21CAFF   call dumped.004B0438                     ; ->:TApplication._PROC_004B0438()0080E25B   . E9 90000000   jmp dumped.0080E2F00080E260   > 55         push ebp0080E261 > . E8 B6F8FFFF   call dumped.0080DB1C                     ; ->:TfrmMain.修改窗口名()0080E266   . 59         pop ecx0080E267   . 84C0       test al,al                           ; 这里判断当前窗口是不是WOW0080E269   .^ 74 D0       je short dumped.0080E23B0080E26B   . B8 48E58000   mov eax,dumped.0080E548                   ; ASCII "vkEnter"0080E270   . E8 0FFCCFFF   call dumped.0050DE84                     ; 发送ENTER登陆0080E275   . EB 22       jmp short dumped.0080E2990080E277   > A1 F49D8300   mov eax,dword ptr ds:[839DF4]0080E27C   . 8B00       mov eax,dword ptr ds:[eax]0080E27E > . E8 6D5ECAFF   call dumped.004B40F0                     ; ->:TApplication._PROC_004B40F0()0080E283   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E286   . 80B8 F3040000 >cmp byte ptr ds:[eax+4F3],00080E28D   . 74 0A       je short dumped.0080E2990080E28F   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E292 > . E8 A121CAFF   call dumped.004B0438                     ; ->:TApplication._PROC_004B0438()0080E297   . EB 57       jmp short dumped.0080E2F00080E299   > 55         push ebp0080E29A > . E8 7DF8FFFF   call dumped.0080DB1C                     ; ->:TfrmMain.修改窗口名()0080E29F   . 59         pop ecx0080E2A0   . 84C0       test al,al                           ; 这里判断当前窗口是不是WOW0080E2A2   .^ 74 D3       je short dumped.0080E2770080E2A4   . 8B45 E8     mov eax,dword ptr ss:[ebp-18]0080E2A7   . 0345 E4     add eax,dword ptr ss:[ebp-1C]0080E2AA   . E8 59D9CFFF   call dumped.0050BC08                     ; 等时间(自动登陆中的延迟)0080E2AF   . EB 22       jmp short dumped.0080E2D30080E2B1   > A1 F49D8300   mov eax,dword ptr ds:[839DF4]0080E2B6   . 8B00       mov eax,dword ptr ds:[eax]0080E2B8 > . E8 335ECAFF   call dumped.004B40F0                     ; ->:TApplication._PROC_004B40F0()0080E2BD   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E2C0   . 80B8 F3040000 >cmp byte ptr ds:[eax+4F3],00080E2C7   . 74 0A       je short dumped.0080E2D30080E2C9   . 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E2CC > . E8 6721CAFF   call dumped.004B0438                     ; ->:TApplication._PROC_004B0438()0080E2D1   . EB 1D       jmp short dumped.0080E2F00080E2D3   > 55         push ebp0080E2D4 > . E8 43F8FFFF   call dumped.0080DB1C                     ; ->:TfrmMain.修改窗口名()0080E2D9   . 59         pop ecx0080E2DA   . 84C0       test al,al                           ; 这里判断当前窗口是不是WOW0080E2DC   .^ 74 D3       je short dumped.0080E2B10080E2DE   . B8 48E58000   mov eax,dumped.0080E548                   ; ASCII "vkEnter"0080E2E3   . E8 9CFBCFFF   call dumped.0050DE84                     ; 发送回车,登陆人物,进游戏0080E2E8   > 8B45 EC     mov eax,dword ptr ss:[ebp-14]0080E2EB > . E8 4821CAFF   call dumped.004B0438                     ; ->:TApplication._PROC_004B0438()0080E2F0   > 33C0       xor eax,eax                           ; 自动登陆结束发送按键过程0050DEA4 |. 8BC3       mov eax,ebx                           ; 这里是要发送的字符串0050DEA6 |. BA 74E85000   mov edx,dumped.0050E874                   ; ASCII "vkTab"0050DEAB |. E8 2C7AEFFF   call dumped.004058DC0050DEB0 |. 75 2F       jnz short dumped.0050DEE10050DEB2 |. 6A 00       push 0                               ; /ExtraInfo = 00050DEB4 |. 6A 00       push 0                               ; |Flags = 00050DEB6 |. 6A 00       push 0                               ; |/Action = 00050DEB8 |. 6A 09       push 9                               ; ||Key = 90050DEBA |. E8 BDB1EFFF   call <jmp.&user32.MapVirtualKeyA>             ; |\MapVirtualKeyA0050DEBF |. 50         push eax                             ; |ScanCode0050DEC0 |. 6A 09       push 9                               ; |Key = VK_TAB0050DEC2 |. E8 0DB4EFFF   call <jmp.&user32.keybd_event>               ; \keybd_event0050DEC7 |. 6A 00       push 0                               ; /ExtraInfo = 00050DEC9 |. 6A 02       push 2                               ; |Flags = KEYEVENTF_KEYUP0050DECB |. 6A 00       push 0                               ; |/Action = 00050DECD |. 6A 09       push 9                               ; ||Key = 90050DECF |. E8 A8B1EFFF   call <jmp.&user32.MapVirtualKeyA>             ; |\MapVirtualKeyA0050DED4 |. 50         push eax                             ; |ScanCode0050DED5 |. 6A 09       push 9                               ; |Key = VK_TAB0050DED7 |. E8 F8B3EFFF   call <jmp.&user32.keybd_event>               ; \keybd_event。。。0050E1F0 |> \6A 00       |push 0                             ; /ExtraInfo = 0; Case 21 ('!') of switch 0050E0760050E1F2 |. 6A 00       |push 0                             ; |Flags = 00050E1F4 |. 6A 00       |push 0                             ; |/Action = 00050E1F6 |. 6A 10       |push 10                             ; ||Key = 100050E1F8 |. E8 7FAEEFFF   |call <jmp.&user32.MapVirtualKeyA>           ; |\MapVirtualKeyA0050E1FD |. 50         |push eax                             ; |ScanCode0050E1FE |. 6A 10       |push 10                             ; |Key = VK_SHIFT0050E200 |. E8 CFB0EFFF   |call <jmp.&user32.keybd_event>             ; \keybd_event0050E205 |. 6A 00       |push 0                             ; /ExtraInfo = 00050E207 |. 6A 00       |push 0                             ; |Flags = 00050E209 |. 6A 00       |push 0                             ; |ScanCode = 00050E20B |. 6A 31       |push 31                             ; |Key = 31 (Ƈ')0050E20D |. E8 C2B0EFFF   |call <jmp.&user32.keybd_event>             ; \keybd_event0050E212 |. 6A 00       |push 0                             ; /ExtraInfo = 00050E214 |. 6A 02       |push 2                             ; |Flags = KEYEVENTF_KEYUP0050E216 |. 6A 00       |push 0                             ; |ScanCode = 00050E218 |. 6A 31       |push 31                             ; |Key = 31 (Ƈ')0050E21A |. E8 B5B0EFFF   |call <jmp.&user32.keybd_event>             ; \keybd_event0050E21F |. 6A 00       |push 0                             ; /ExtraInfo = 00050E221 |. 6A 02       |push 2                             ; |Flags = KEYEVENTF_KEYUP0050E223 |. 6A 00       |push 0                             ; |/Action = 00050E225 |. 6A 10       |push 10                             ; ||Key = 100050E227 |. E8 50AEEFFF   |call <jmp.&user32.MapVirtualKeyA>           ; |\MapVirtualKeyA0050E22C |. 50         |push eax                             ; |ScanCode0050E22D |. 6A 10       |push 10                             ; |Key = VK_SHIFT0050E22F |. E8 A0B0EFFF   |call <jmp.&user32.keybd_event>             ; \keybd_event0050E234 |. E9 02060000   |jmp dumped.0050E83B。。。0050E7E3 |> \807C33 FF 3F   |cmp byte ptr ds:[ebx+esi-1],3F             ; Cases 2F ('/'),3F ('?') of switch 0050E0760050E7E8 |. 75 15       |jnz short dumped.0050E7FF0050E7EA |. 6A 00       |push 0                             ; /ExtraInfo = 00050E7EC |. 6A 00       |push 0                             ; |Flags = 00050E7EE |. 6A 00       |push 0                             ; |/Action = 00050E7F0 |. 6A 10       |push 10                             ; ||Key = 100050E7F2 |. E8 85A8EFFF   |call <jmp.&user32.MapVirtualKeyA>           ; |\MapVirtualKeyA0050E7F7 |. 50         |push eax                             ; |ScanCode0050E7F8 |. 6A 10       |push 10                             ; |Key = VK_SHIFT0050E7FA |. E8 D5AAEFFF   |call <jmp.&user32.keybd_event>             ; \keybd_event0050E7FF |> 6A 00       |push 0                             ; /ExtraInfo = 00050E801 |. 6A 00       |push 0                             ; |Flags = 00050E803 |. 6A 00       |push 0                             ; |ScanCode = 00050E805 |. 68 BF000000   |push 0BF                             ; |Key = BF0050E80A |. E8 C5AAEFFF   |call <jmp.&user32.keybd_event>             ; \keybd_event0050E80F |. 6A 00       |push 0                             ; /ExtraInfo = 00050E811 |. 6A 02       |push 2                             ; |Flags = KEYEVENTF_KEYUP0050E813 |. 6A 00       |push 0                             ; |ScanCode = 00050E815 |. 68 BF000000   |push 0BF                             ; |Key = BF0050E81A |. E8 B5AAEFFF   |call <jmp.&user32.keybd_event>             ; \keybd_event0050E81F |. 807C33 FF 3F   |cmp byte ptr ds:[ebx+esi-1],3F0050E824 |. 75 15       |jnz short dumped.0050E83B0050E826 |. 6A 00       |push 0                             ; /ExtraInfo = 00050E828 |. 6A 02       |push 2                             ; |Flags = KEYEVENTF_KEYUP0050E82A |. 6A 00       |push 0                             ; |/Action = 00050E82C |. 6A 10       |push 10                             ; ||Key = 100050E82E |. E8 49A8EFFF   |call <jmp.&user32.MapVirtualKeyA>           ; |\MapVirtualKeyA0050E833 |. 50         |push eax                             ; |ScanCode0050E834 |. 6A 10       |push 10                             ; |Key = VK_SHIFT0050E836 |. E8 99AAEFFF   |call <jmp.&user32.keybd_event>             ; \keybd_event0050E83B |> 46         |inc esi                             ; Default case of switch 0050E0760050E83C |. 4F         |dec edi0050E83D |.^ 0F85 32F7FFFF \jnz dumped.0050DF750050E843 |> 33C0       xor eax,eax                           ; 按键结束这个发送按键好像是用API模拟按键,会不会被键盘钩子截取呢?懂编程的能不能帮忙看看
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系 [邮箱地址] 删除

路过

雷人

握手

鲜花

鸡蛋

最新评论

返回顶部