| 关键词: nbsp dumped push 0050 eax call dword 0080 ptr mov |
魔兽世界启动器 v0.1.4.7(7月3日更新[定时调用游戏|自动登录|插件、截图管理等])功能太强大了,自叹不如。。。 http://bbs.game.mop.com/viewthread.php?tid=1143103&extra=page%3D1功能:太多了,我就看重这个定时调用并自动登录游戏,有效防止采用键盘HOOK技术的木马盗取密码(启动器无法防止所有木马,它毕竟不是专业杀木马软件,作者只是尽力降低您中木马的危险而已,绝不是用了它您就可以高枕无忧)保护方法小小分析了一下,程序实在太大。。。我分析完了,IDA还在跑。。。本人分析纯属学习,请作者见谅,如有不妥,请联系我,我立刻删除保护1:随机生成窗口名0080DBCE |> \8B0F mov ecx,dword ptr ds:[edi]0080DBD0 |. 8D45 EC lea eax,dword ptr ss:[ebp-14]0080DBD3 |. BA 50DC8000 mov edx,dumped.0080DC500080DBD8 |. E8 FF7BBFFF call dumped.004057DC0080DBDD |. 8B45 EC mov eax,dword ptr ss:[ebp-14]0080DBE0 |. E8 AB7DBFFF call dumped.004059900080DBE5 |. 50 push eax ; /Text = "魔兽世界lllllllll"0080DBE6 |. 56 push esi ; |hWnd0080DBE7 |. E8 40B6BFFF call <jmp.&user32.SetWindowTextA> ; \SetWindowTextA0080DBEC |. E8 63B2BFFF call <jmp.&user32.GetForegroundWindow> ; [GetForegroundWindow0080DBF1 |. 3BF0 cmp esi,eax0080DBF3 |. 0F94C3 sete bl0080DBF6 |> 33C0 xor eax,eax0080DBF8 |. 5A pop edx保护2:自动登陆0080E176 > \55 push ebp ; 自动登陆0080E177 > . E8 A0F9FFFF call dumped.0080DB1C ; ->:TfrmMain.修改窗口名()0080E17C . 59 pop ecx0080E17D . 84C0 test al,al ; 这里判断当前窗口是不是WOW0080E17F .^ 74 D0 je short dumped.0080E1510080E181 . 8D55 9C lea edx,dword ptr ss:[ebp-64] ; 解密后密码指针0080E184 . 8B45 F0 mov eax,dword ptr ss:[ebp-10] ; 加密的密码0080E187 . E8 2CDACFFF call dumped.0050BBB8 ; 解密函数0080E18C . 8B55 9C mov edx,dword ptr ss:[ebp-64] ; 解密后的密码0080E18F . 8D45 F0 lea eax,dword ptr ss:[ebp-10]0080E192 . E8 A173BFFF call dumped.004055380080E197 . 8B45 E8 mov eax,dword ptr ss:[ebp-18]0080E19A . E8 69DACFFF call dumped.0050BC080080E19F . 8D55 94 lea edx,dword ptr ss:[ebp-6C]0080E1A2 . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E1A5 > . 8B80 50040000 mov eax,dword ptr ds:[eax+450] ; *cbbUser:TcxComboBox0080E1AB . E8 507BC8FF call dumped.00495D000080E1B0 . 8B45 94 mov eax,dword ptr ss:[ebp-6C]0080E1B3 . 8D55 98 lea edx,dword ptr ss:[ebp-68]0080E1B6 . E8 45C6BFFF call dumped.0040A8000080E1BB . 8B45 98 mov eax,dword ptr ss:[ebp-68] ; 用户名0080E1BE . E8 C1FCCFFF call dumped.0050DE84 ; 发送用户名0080E1C3 . EB 25 jmp short dumped.0080E1EA0080E1C5 > A1 F49D8300 mov eax,dword ptr ds:[839DF4]0080E1CA . 8B00 mov eax,dword ptr ds:[eax]0080E1CC > . E8 1F5FCAFF call dumped.004B40F0 ; ->:TApplication._PROC_004B40F0()0080E1D1 . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E1D4 . 80B8 F3040000 >cmp byte ptr ds:[eax+4F3],00080E1DB . 74 0D je short dumped.0080E1EA0080E1DD . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E1E0 > . E8 5322CAFF call dumped.004B0438 ; ->:TApplication._PROC_004B0438()0080E1E5 . E9 06010000 jmp dumped.0080E2F00080E1EA > 55 push ebp0080E1EB > . E8 2CF9FFFF call dumped.0080DB1C ; ->:TfrmMain.修改窗口名()0080E1F0 . 59 pop ecx0080E1F1 . 84C0 test al,al ; 这里判断当前窗口是不是WOW0080E1F3 .^ 74 D0 je short dumped.0080E1C50080E1F5 . B8 38E58000 mov eax,dumped.0080E538 ; ASCII "vkTab"0080E1FA . E8 85FCCFFF call dumped.0050DE84 ; 发送TAB健0080E1FF . EB 25 jmp short dumped.0080E2260080E201 > A1 F49D8300 mov eax,dword ptr ds:[839DF4]0080E206 . 8B00 mov eax,dword ptr ds:[eax]0080E208 > . E8 E35ECAFF call dumped.004B40F0 ; ->:TApplication._PROC_004B40F0()0080E20D . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E210 . 80B8 F3040000 >cmp byte ptr ds:[eax+4F3],00080E217 . 74 0D je short dumped.0080E2260080E219 . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E21C > . E8 1722CAFF call dumped.004B0438 ; ->:TApplication._PROC_004B0438()0080E221 . E9 CA000000 jmp dumped.0080E2F00080E226 > 55 push ebp0080E227 > . E8 F0F8FFFF call dumped.0080DB1C ; ->:TfrmMain.修改窗口名()0080E22C . 59 pop ecx0080E22D . 84C0 test al,al ; 这里判断当前窗口是不是WOW0080E22F .^ 74 D0 je short dumped.0080E2010080E231 . 8B45 F0 mov eax,dword ptr ss:[ebp-10] ; 密码0080E234 . E8 4BFCCFFF call dumped.0050DE84 ; 发送密码0080E239 . EB 25 jmp short dumped.0080E2600080E23B > A1 F49D8300 mov eax,dword ptr ds:[839DF4]0080E240 . 8B00 mov eax,dword ptr ds:[eax]0080E242 > . E8 A95ECAFF call dumped.004B40F0 ; ->:TApplication._PROC_004B40F0()0080E247 . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E24A . 80B8 F3040000 >cmp byte ptr ds:[eax+4F3],00080E251 . 74 0D je short dumped.0080E2600080E253 . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E256 > . E8 DD21CAFF call dumped.004B0438 ; ->:TApplication._PROC_004B0438()0080E25B . E9 90000000 jmp dumped.0080E2F00080E260 > 55 push ebp0080E261 > . E8 B6F8FFFF call dumped.0080DB1C ; ->:TfrmMain.修改窗口名()0080E266 . 59 pop ecx0080E267 . 84C0 test al,al ; 这里判断当前窗口是不是WOW0080E269 .^ 74 D0 je short dumped.0080E23B0080E26B . B8 48E58000 mov eax,dumped.0080E548 ; ASCII "vkEnter"0080E270 . E8 0FFCCFFF call dumped.0050DE84 ; 发送ENTER登陆0080E275 . EB 22 jmp short dumped.0080E2990080E277 > A1 F49D8300 mov eax,dword ptr ds:[839DF4]0080E27C . 8B00 mov eax,dword ptr ds:[eax]0080E27E > . E8 6D5ECAFF call dumped.004B40F0 ; ->:TApplication._PROC_004B40F0()0080E283 . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E286 . 80B8 F3040000 >cmp byte ptr ds:[eax+4F3],00080E28D . 74 0A je short dumped.0080E2990080E28F . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E292 > . E8 A121CAFF call dumped.004B0438 ; ->:TApplication._PROC_004B0438()0080E297 . EB 57 jmp short dumped.0080E2F00080E299 > 55 push ebp0080E29A > . E8 7DF8FFFF call dumped.0080DB1C ; ->:TfrmMain.修改窗口名()0080E29F . 59 pop ecx0080E2A0 . 84C0 test al,al ; 这里判断当前窗口是不是WOW0080E2A2 .^ 74 D3 je short dumped.0080E2770080E2A4 . 8B45 E8 mov eax,dword ptr ss:[ebp-18]0080E2A7 . 0345 E4 add eax,dword ptr ss:[ebp-1C]0080E2AA . E8 59D9CFFF call dumped.0050BC08 ; 等时间(自动登陆中的延迟)0080E2AF . EB 22 jmp short dumped.0080E2D30080E2B1 > A1 F49D8300 mov eax,dword ptr ds:[839DF4]0080E2B6 . 8B00 mov eax,dword ptr ds:[eax]0080E2B8 > . E8 335ECAFF call dumped.004B40F0 ; ->:TApplication._PROC_004B40F0()0080E2BD . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E2C0 . 80B8 F3040000 >cmp byte ptr ds:[eax+4F3],00080E2C7 . 74 0A je short dumped.0080E2D30080E2C9 . 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E2CC > . E8 6721CAFF call dumped.004B0438 ; ->:TApplication._PROC_004B0438()0080E2D1 . EB 1D jmp short dumped.0080E2F00080E2D3 > 55 push ebp0080E2D4 > . E8 43F8FFFF call dumped.0080DB1C ; ->:TfrmMain.修改窗口名()0080E2D9 . 59 pop ecx0080E2DA . 84C0 test al,al ; 这里判断当前窗口是不是WOW0080E2DC .^ 74 D3 je short dumped.0080E2B10080E2DE . B8 48E58000 mov eax,dumped.0080E548 ; ASCII "vkEnter"0080E2E3 . E8 9CFBCFFF call dumped.0050DE84 ; 发送回车,登陆人物,进游戏0080E2E8 > 8B45 EC mov eax,dword ptr ss:[ebp-14]0080E2EB > . E8 4821CAFF call dumped.004B0438 ; ->:TApplication._PROC_004B0438()0080E2F0 > 33C0 xor eax,eax ; 自动登陆结束发送按键过程0050DEA4 |. 8BC3 mov eax,ebx ; 这里是要发送的字符串0050DEA6 |. BA 74E85000 mov edx,dumped.0050E874 ; ASCII "vkTab"0050DEAB |. E8 2C7AEFFF call dumped.004058DC0050DEB0 |. 75 2F jnz short dumped.0050DEE10050DEB2 |. 6A 00 push 0 ; /ExtraInfo = 00050DEB4 |. 6A 00 push 0 ; |Flags = 00050DEB6 |. 6A 00 push 0 ; |/Action = 00050DEB8 |. 6A 09 push 9 ; ||Key = 90050DEBA |. E8 BDB1EFFF call <jmp.&user32.MapVirtualKeyA> ; |\MapVirtualKeyA0050DEBF |. 50 push eax ; |ScanCode0050DEC0 |. 6A 09 push 9 ; |Key = VK_TAB0050DEC2 |. E8 0DB4EFFF call <jmp.&user32.keybd_event> ; \keybd_event0050DEC7 |. 6A 00 push 0 ; /ExtraInfo = 00050DEC9 |. 6A 02 push 2 ; |Flags = KEYEVENTF_KEYUP0050DECB |. 6A 00 push 0 ; |/Action = 00050DECD |. 6A 09 push 9 ; ||Key = 90050DECF |. E8 A8B1EFFF call <jmp.&user32.MapVirtualKeyA> ; |\MapVirtualKeyA0050DED4 |. 50 push eax ; |ScanCode0050DED5 |. 6A 09 push 9 ; |Key = VK_TAB0050DED7 |. E8 F8B3EFFF call <jmp.&user32.keybd_event> ; \keybd_event。。。0050E1F0 |> \6A 00 |push 0 ; /ExtraInfo = 0; Case 21 ('!') of switch 0050E0760050E1F2 |. 6A 00 |push 0 ; |Flags = 00050E1F4 |. 6A 00 |push 0 ; |/Action = 00050E1F6 |. 6A 10 |push 10 ; ||Key = 100050E1F8 |. E8 7FAEEFFF |call <jmp.&user32.MapVirtualKeyA> ; |\MapVirtualKeyA0050E1FD |. 50 |push eax ; |ScanCode0050E1FE |. 6A 10 |push 10 ; |Key = VK_SHIFT0050E200 |. E8 CFB0EFFF |call <jmp.&user32.keybd_event> ; \keybd_event0050E205 |. 6A 00 |push 0 ; /ExtraInfo = 00050E207 |. 6A 00 |push 0 ; |Flags = 00050E209 |. 6A 00 |push 0 ; |ScanCode = 00050E20B |. 6A 31 |push 31 ; |Key = 31 (Ƈ')0050E20D |. E8 C2B0EFFF |call <jmp.&user32.keybd_event> ; \keybd_event0050E212 |. 6A 00 |push 0 ; /ExtraInfo = 00050E214 |. 6A 02 |push 2 ; |Flags = KEYEVENTF_KEYUP0050E216 |. 6A 00 |push 0 ; |ScanCode = 00050E218 |. 6A 31 |push 31 ; |Key = 31 (Ƈ')0050E21A |. E8 B5B0EFFF |call <jmp.&user32.keybd_event> ; \keybd_event0050E21F |. 6A 00 |push 0 ; /ExtraInfo = 00050E221 |. 6A 02 |push 2 ; |Flags = KEYEVENTF_KEYUP0050E223 |. 6A 00 |push 0 ; |/Action = 00050E225 |. 6A 10 |push 10 ; ||Key = 100050E227 |. E8 50AEEFFF |call <jmp.&user32.MapVirtualKeyA> ; |\MapVirtualKeyA0050E22C |. 50 |push eax ; |ScanCode0050E22D |. 6A 10 |push 10 ; |Key = VK_SHIFT0050E22F |. E8 A0B0EFFF |call <jmp.&user32.keybd_event> ; \keybd_event0050E234 |. E9 02060000 |jmp dumped.0050E83B。。。0050E7E3 |> \807C33 FF 3F |cmp byte ptr ds:[ebx+esi-1],3F ; Cases 2F ('/'),3F ('?') of switch 0050E0760050E7E8 |. 75 15 |jnz short dumped.0050E7FF0050E7EA |. 6A 00 |push 0 ; /ExtraInfo = 00050E7EC |. 6A 00 |push 0 ; |Flags = 00050E7EE |. 6A 00 |push 0 ; |/Action = 00050E7F0 |. 6A 10 |push 10 ; ||Key = 100050E7F2 |. E8 85A8EFFF |call <jmp.&user32.MapVirtualKeyA> ; |\MapVirtualKeyA0050E7F7 |. 50 |push eax ; |ScanCode0050E7F8 |. 6A 10 |push 10 ; |Key = VK_SHIFT0050E7FA |. E8 D5AAEFFF |call <jmp.&user32.keybd_event> ; \keybd_event0050E7FF |> 6A 00 |push 0 ; /ExtraInfo = 00050E801 |. 6A 00 |push 0 ; |Flags = 00050E803 |. 6A 00 |push 0 ; |ScanCode = 00050E805 |. 68 BF000000 |push 0BF ; |Key = BF0050E80A |. E8 C5AAEFFF |call <jmp.&user32.keybd_event> ; \keybd_event0050E80F |. 6A 00 |push 0 ; /ExtraInfo = 00050E811 |. 6A 02 |push 2 ; |Flags = KEYEVENTF_KEYUP0050E813 |. 6A 00 |push 0 ; |ScanCode = 00050E815 |. 68 BF000000 |push 0BF ; |Key = BF0050E81A |. E8 B5AAEFFF |call <jmp.&user32.keybd_event> ; \keybd_event0050E81F |. 807C33 FF 3F |cmp byte ptr ds:[ebx+esi-1],3F0050E824 |. 75 15 |jnz short dumped.0050E83B0050E826 |. 6A 00 |push 0 ; /ExtraInfo = 00050E828 |. 6A 02 |push 2 ; |Flags = KEYEVENTF_KEYUP0050E82A |. 6A 00 |push 0 ; |/Action = 00050E82C |. 6A 10 |push 10 ; ||Key = 100050E82E |. E8 49A8EFFF |call <jmp.&user32.MapVirtualKeyA> ; |\MapVirtualKeyA0050E833 |. 50 |push eax ; |ScanCode0050E834 |. 6A 10 |push 10 ; |Key = VK_SHIFT0050E836 |. E8 99AAEFFF |call <jmp.&user32.keybd_event> ; \keybd_event0050E83B |> 46 |inc esi ; Default case of switch 0050E0760050E83C |. 4F |dec edi0050E83D |.^ 0F85 32F7FFFF \jnz dumped.0050DF750050E843 |> 33C0 xor eax,eax ; 按键结束这个发送按键好像是用API模拟按键,会不会被键盘钩子截取呢?懂编程的能不能帮忙看看 |
|
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系
[邮箱地址] 删除
|