程序没有加壳,直接用OD载入!
输入假码有提示,可能通过查找参考字符或者难过堆栈返回找到关键CALL:
00404917 . 8>lea edi,dword ptr ds:[esi+64]
0040491A . 5>push eax
0040491B . 5>push ecx
0040491C . E>call Speed_Vi.0040E320
00404921 . 8>add esp,8
00404924 . 8>test al,al
00404926 . 7>jnz short Speed_Vi.00404944
00404928 . 6>push 40
0040492A . 6>push Speed_Vi.004233A4 ; ASCII "Sorry"
0040492F . 6>push Speed_Vi.00423378 ; ASCII "Invalid username or registration code "
00404934 . 8>mov ecx,esi
00404936 . E>call <jmp.&MFC42.#4224>
0040493B . C>mov byte ptr ds:[42484C],0
00404942 . E>jmp short Speed_Vi.0040499B
00404944 > 5>push edi
00404945 . 8>lea eax,dword ptr ss:[esp+C]
00404949 . 6>push Speed_Vi.0042336C ; ASCII "License to "