软件是VC写的,用PEID显示为:Microsoft Visual C++ 7.0 Method2 [调试]
二话不说,直接到OD载入,然后输入假的激活码,很快就能找到关键点:
00401D6D . C74424 1C 00000>mov dword ptr ss:[esp+1C],0
00401D75 . E8 96E80100 call <jmp.&MFC71.#3761>
00401D7A . 51 push ecx
00401D7B . 8D5424 08 lea edx,dword ptr ss:[esp+8]
00401D7F . 8BCC mov ecx,esp
00401D81 . 896424 10 mov dword ptr ss:[esp+10],esp
00401D85 . 52 push edx
00401D86 . FF15 E4514200 call dword ptr ds:[<&MFC71.#297>] ; MFC71.7C14E575
00401D8C . 8B8E C8000000 mov ecx,dword ptr ds:[esi+C8]
00401D92 . FF15 30504200 call dword ptr ds:[<&Control.AVProxy::Reg>; Control.AVProxy::RegisteProduct