先調整系統時間,讓軟體過期,下斷點 bpx getprivateprofilestringa, F12一下,
F10一下,到 :00416415
* Referenced by a CALL at Address:
|:004168FB
|
:004163F0 56
push esi
* Reference To: KERNEL32.GetPrivateProfileStringA, Ord:013Ah
|
:004163F1 8B358C314400 mov esi, dword
ptr [0044318C]
* Possible StringData Ref from Data Obj ->"HeroSHOW.INI"
|
:004163F7 6890604400 push 00446090
* Possible Reference to Menu: MenuID_0080
|
:004163FC 6880000000 push 00000080
:00416401 681CB64400 push 0044B61C<---使用者名稱
:00416406 6860AF4400 push 0044AF60
* Possible StringData Ref from Data Obj ->"USERNAME"
|
:0041640B 6854644400 push 00446454
* Possible StringData Ref from Data Obj ->"REGISTER"
|
:00416410 6848644400 push 00446448
:00416415 FFD6
call esi<---退出到這裡
* Possible StringData Ref from Data Obj ->"HeroSHOW.INI"
|
:00416417 6890604400 push 00446090
* Possible Reference to Menu: MenuID_0080
|
:0041641C 6880000000 push 00000080
:00416421 6818C14400 push 0044C118<---假註冊碼
:00416426 6860AF4400 push 0044AF60
* Possible StringData Ref from Data Obj ->"KEY"
|
:0041642B 6844644400 push 00446444
* Possible StringData Ref from Data Obj ->"REGISTER"
|
:00416430 6848644400 push 00446448
:00416435 FFD6
call esi
:00416437 5E
pop esi
:00416438 C3
ret<---退出到004168fb
=================================================================待續