编写语言:Micorsoft Visual C++ 7.0 Method2
OD插件之超级字串参考(查找ASCII)
地址 反汇编 文本字串
00404125 MOV ECX,我成功啦.00477590 羰g
00404194 MOV ECX,我成功啦.00477590 羰g
004041E6 MOV ECX,我成功啦.00477590 羰g
004115A9 MOV EDI,我成功啦.0045DA9C unknown security failure detected!
004115AE MOV DWORD PTR SS:[EBP-128],我成功啦.0045 a security error of unknown cause has been detected which has\ncorrupted the program's internal state. the program cannot safely\ncontinue execution and must now be terminated.\n
004115BF MOV EDI,我成功啦.0045D9C8 buffer overrun detected!
004115C4 MOV DWORD PTR SS:[EBP-128],我成功啦.0045 a buffer overrun has been detected which has corrupted the program's\ninternal state. the program cannot safely continue execution and must\nnow be terminated.\n
004115ED PUSH 我成功啦.0045D910 <program name unknown>
0041162E PUSH 我成功啦.0045D90C ...
0041165E MOV EDI,我成功啦.0045D908 \n\n
0041166A PUSH 我成功啦.0045D8FC program:
00411694 PUSH 我成功啦.0045D8D4 microsoft visual c++ runtime library
004120D7 PUSH 我成功啦.0045E314 mscoree.dll
004120E6 PUSH 我成功啦.0045E304 corexitprocess
0041587B PUSH 我成功啦.0045EA34 tz
00416361 PUSH 我成功啦.00474CA5 %x
004163EC PUSH 我成功啦.00478B18 %x,%x,%08x,%08x,%x,%x
0041647D PUSH 我成功啦.0047DB84 %10d,%x,%08x,%10d,%08x
00416A14 PUSH 我成功啦.0045E0DC kernel32.dll
00416A23 PUSH 我成功啦.0045E0B4 initializecriticalsectionandspincount
00419679 PUSH 我成功啦.0045E78C kernel32.dll
00419690 PUSH 我成功啦.0045E780 flsalloc
00419698 PUSH 我成功啦.0045E774 flsgetvalue
004196A5 PUSH 我成功啦.0045E768 flssetvalue
004196B2 PUSH 我成功啦.0045E760 flsfree
0041D8E2 PUSH 我成功啦.0045E9DC am/pm
0041D94C PUSH 我成功啦.0045E9D8 a/p
0041EBEE PUSH 60 (初始 cpu 选择)
0042974B PUSH 我成功啦.0045E71C <program name unknown>
0042977E PUSH 我成功啦.0045E718 ...
004297B2 PUSH 我成功啦.0045E6FC runtime error!\n\nprogram:
004297C4 PUSH 我成功啦.0045E6F8 \n\n
004297E0 PUSH 我成功啦.0045E6D0 microsoft visual c++ runtime library
0042A275 PUSH 我成功啦.0045DB90 user32.dll
0042A290 PUSH 我成功啦.0045DB84 messageboxa
0042A2A1 PUSH 我成功啦.0045DB74 getactivewindow
0042A2A9 PUSH 我成功啦.0045DB60 getlastactivepopup
0042A2C4 PUSH 我成功啦.0045DB44 getuserobjectinformationa
0042A2D5 PUSH 我成功啦.0045DB2C getprocesswindowstation
00439C63 DB BA because redirected dll name %wz does not include a slash\n
00454113 PUSH 我成功啦.00478B18 %x,%x,%08x,%08x,%x,%x
004544F8 PUSH 我成功啦.0047DB84 %10d,%x,%08x,%10d,%08x
OD插件之超级字串参考(查找unicode)
地址 反汇编 文本字串
00404125 MOV ECX,我成功啦.00477590 羰g
00404194 MOV ECX,我成功啦.00477590 羰g
004041E6 MOV ECX,我成功啦.00477590 羰g
004115A9 MOV EDI,我成功啦.0045DA9C unknown security failure detected!
004115AE MOV DWORD PTR SS:[EBP-128],我成功啦.0045 a security error of unknown cause has been detected which has\ncorrupted the program's internal state. the program cannot safely\ncontinue execution and must now be terminated.\n
004115BF MOV EDI,我成功啦.0045D9C8 buffer overrun detected!
004115C4 MOV DWORD PTR SS:[EBP-128],我成功啦.0045 a buffer overrun has been detected which has corrupted the program's\ninternal state. the program cannot safely continue execution and must\nnow be terminated.\nbuffer overrun detected!
004115ED PUSH 我成功啦.0045D910 <program name unknown>
0041162E PUSH 我成功啦.0045D90C ...<program name unknown>
0041165E MOV EDI,我成功啦.0045D908 \n\n
0041166A PUSH 我成功啦.0045D8FC program:
00411694 PUSH 我成功啦.0045D8D4 microsoft visual c++ runtime library
004120E6 PUSH 我成功啦.0045E304 corexitprocess
0041587B PUSH 我成功啦.0045EA34 tz
00416361 PUSH 我成功啦.00474CA5 %x
004163EC PUSH 我成功啦.00478B18 %x,%x,%08x,%08x,%x,%x
0041647D PUSH 我成功啦.0047DB84 %10d,%x,%08x,%10d,%08x
00416A14 PUSH 我成功啦.0045E0DC kernel32.dll
00416A23 PUSH 我成功啦.0045E0B4 initializecriticalsectionandspincount
00419679 PUSH 我成功啦.0045E78C kernel32.dll
00419690 PUSH 我成功啦.0045E780 flsalloc
00419698 PUSH 我成功啦.0045E774 flsgetvalueflsalloc
004196A5 PUSH 我成功啦.0045E768 flssetvalueflsgetvalueflsalloc
004196B2 PUSH 我成功啦.0045E760 flsfreeflssetvalueflsgetvalueflsalloc
0041D8E2 PUSH 我成功啦.0045E9DC am/pm
0041D94C PUSH 我成功啦.0045E9D8 a/pam/pm
0041EBEE PUSH 60 (初始 cpu 选择)
0042974B PUSH 我成功啦.0045E71C <program name unknown>
0042977E PUSH 我成功啦.0045E718 ...<program name unknown>
004297B2 PUSH 我成功啦.0045E6FC runtime error!\n\nprogram:
004297C4 PUSH 我成功啦.0045E6F8 \n\n
004297E0 PUSH 我成功啦.0045E6D0 microsoft visual c++ runtime library
0042A275 PUSH 我成功啦.0045DB90 user32.dll
0042A290 PUSH 我成功啦.0045DB84 messageboxauser32.dll
0042A2A1 PUSH 我成功啦.0045DB74 getactivewindowmessageboxauser32.dll
0042A2A9 PUSH 我成功啦.0045DB60 getlastactivepopup
0042A2C4 PUSH 我成功啦.0045DB44 getuserobjectinformationa
0042A2D5 PUSH 我成功啦.0045DB2C getprocesswindowstationgetuserobjectinformationa
00439C63 DB BA because redirected dll name %wz does not include a slash\n
00454113 PUSH 我成功啦.00478B18 %x,%x,%08x,%08x,%x,%x
004544F8 PUSH 我成功啦.0047DB84 %10d,%x,%08x,%10d,%08x
【更详细的关于此文件的sandboxie信息详见下面】
[ 本帖最后由 ranguangning 于 2008-7-20 22:31 编辑 ] |