{"id":93,"date":"2009-05-24T16:31:39","date_gmt":"2009-05-24T16:31:39","guid":{"rendered":"http:\/\/kumouse.aafox.com\/?p=93"},"modified":"2009-05-24T16:31:39","modified_gmt":"2009-05-24T16:31:39","slug":"qqgame-2009-%e5%a4%9a%e5%bc%80-%e9%80%86%e5%90%91-%e6%ba%90%e7%a0%81-%e8%ae%b2%e8%a7%a3","status":"publish","type":"post","link":"https:\/\/www.kumouse.com\/?p=93","title":{"rendered":"QQGAME 2009 \u591a\u5f00 \u9006\u5411 \u6e90\u7801 \u8bb2\u89e3"},"content":{"rendered":"<p><![CDATA[\u7f51\u4e0a\u6709\u4e00\u4e9b\u8fd9\u6837\u7684\u8865\u4e01,\u4f46\u662f\u597d\u591a\u90fd\u6709\u75c5\u6bd2.\u4e5f\u6709\u4e00\u4e9b\u7834\u89e3\u7684\u6587\u7ae0,\u4f46\u662f\u6211\u4e2a\u4eba\u8ba4\u4e3a\u8bb2\u7684\u4e0d\u591f\u6e05\u695a,\u56e0\u4e3a\u7f51\u4e0a\u5927\u90e8\u5206\u6587\u7ae0\u5199\u7684\u662fQQ\u6e38\u620f2008\u7684,\u5373\u4f7f\u662f2009\u7684\u4e5f\u6ca1\u544a\u8bc9\u4f60\u5728\u54ea\u91cc\u4e0b\u65ad,\u4e0b\u65ad\u53ef\u662f\u7834\u89e3\u4e2d\u975e\u5e38\u5173\u952e\u7684\u73af\u8282,\u89e3\u4ee5\u6211\u4eca\u5929\u624d\u6253\u7b97\u5199\u8fd9\u6837\u4e00\u4e2a\u6587\u7ae0,\u4e3b\u8981\u662f\u65b9\u6cd5,\u5c31\u7b97QQ\u6e38\u620f\u518d\u5347\u7ea7,\u53ea\u8981\u6709\u65b9\u6cd5\u8fd8\u662f\u53ef\u4ee5\u7834\u89e3\u7684,\u5475\u5475!!!<br \/>\u4e0b\u9762\u6765\u8bf4\u8bf4\u5177\u4f53\u7684,\u51c6\u5907\u5de5\u5177ollyice<br \/>\u4e0b\u8f7d\u5730\u5740:<a href=\"http:\/\/www.kumouse.com\/article.asp?id=46\" title=\"http:\/\/www.kumouse.com\/article.asp?id=46\" target=\"_blank\">http:\/\/www.kumouse.com\/article.asp?id=46<\/a>\n\n\u9996\u5148\u6765\u8bb2\u4e00\u4e0b\u5e38\u7528\u7684\u9632\u591a\u5f00\u7684\u65b9\u6cd5:\n\n\u65b9\u6cd51: \u67e5\u627e\u7a97\u53e3\u6cd5,\u4f7f\u7528FindWindowA(W)\u6216GetWindowTextA(W)<br \/>\u65b9\u6cd52: \u4f7f\u7528\u4e92\u65a5\u5bf9\u8c61,\u7528\u5230CreateMutexA(W)<br \/>\u65b9\u6cd53: \u4f7f\u7528\u5171\u4eab\u533a\u5757\n\nQQ\u4f7f\u7528\u7684\u662f\u65b9\u6cd52,\u5177\u4f53\u7a0b\u5e8f\u8981\u5177\u4f53\u5206\u6790(\u7531\u4e8e\u6211\u6c34\u5e73\u6709\u9650\u8bb2\u89e3\u4e0d\u4e86)\u5982\u679c\u5206\u6790\u4e0d\u51fa\u6765\u53ef\u4ee5\u4e0agoogle\u67e5\u67e5,\u7f51\u4e0a\u6709\u5f88\u591a\u725b\u4eba\u7684.<br \/>\u5148\u6253\u5f00\u4e00\u4e2aQQ\u6e38\u620f\u7684\u7a97\u53e3\u7136\u540e(\u539f\u56e0\u770b\u4e0b\u8fb9),\u6211\u4eec\u7528ollyice\u6253\u5f00qqgame.exe\u6211\u7684\u6587\u4ef6\u7248\u672c\u662f2.3.103.9\u5927\u5c0f164808\u5b57\u8282,\u6e38\u620f\u7248\u672cQQGAME2009 beta3 sp3 \u6253\u5f00\u7a0b\u5e8f\u540e,\u7a0b\u5e8f\u4f1a\u505c\u5728\u8fd9\u91cc<br \/>\n\n<blockquote>00402150 &gt;\/$  55            push    ebp                              ;  (initial cpu selection)<br \/>00402151  |.  8BEC          mov     ebp, esp<br \/>00402153  |.  6A FF         push    -1<br \/>00402155  |.  68 38314000   push    00403138<br \/>0040215A  |.  68 D6224000   push    &lt;jmp.&#038;MSVCRT._except_handler3&gt;   ;  SE \u5904\u7406\u7a0b\u5e8f\u5b89\u88c5<br \/>0040215F  |.  64:A1 0000000&gt;mov     eax, dword ptr fs:[0]<br \/>00402165  |.  50            push    eax<br \/>00402166  |.  64:8925 00000&gt;mov     dword ptr fs:[0], esp<br \/><\/blockquote>\n\n\n\n00402150\u8fd9\u884c\u662f\u7a0b\u5e8f\u7684\u5f00\u59cb\u5904,\u6211\u4eec\u5728\u4e0b\u8fb9\u7684command\u5904\u8f93\u5165&quot;bp CreateMutexA&quot;\u8fd9\u53e5\u7684\u610f\u601d\u662f\u5728CreateMutexA\u8fd9\u4e2a\u51fd\u6570\u4e0b\u65ad,\u4e5f\u5c31\u662f\u65b9\u6cd52\u4e2d\u4f7f\u7528\u5230\u7684\u51fd\u6570.<br \/>\u7136\u540e\u6211\u4eec\u6309F9\u8fd0\u884c\u8fd9\u4e2a\u7a0b\u5e8f\u7a0b\u5e8f\u4f1a\u505c\u5728<br \/>\n\n<blockquote>7C80E9CF &gt;  8BFF            mov     edi, edi<br \/>7C80E9D1    55              push    ebp<br \/>7C80E9D2    8BEC            mov     ebp, esp<br \/>7C80E9D4    51              push    ecx<br \/>7C80E9D5    51              push    ecx<br \/>7C80E9D6    56              push    esi<br \/>7C80E9D7    33F6            xor     esi, esi<br \/>7C80E9D9    3975 10         cmp     dword ptr [ebp+10], esi<br \/>7C80E9DC    74 31           je      short 7C80EA0F<br \/><\/blockquote>\n\n\n\n7C80E9CF\u5c31\u662fCreateMutexA\u7684\u7b2c\u4e00\u884c,\u6211\u4eec\u8fd9\u65f6\u6309Alt+F9\u8fd4\u56de\u7528\u6237\u4ee3\u7801\u6765\u5230\n\n\n\n<blockquote>746824B0    FF75 08         push    dword ptr [ebp+8]<br \/>746824B3    FF15 88116874   call    dword ptr [74681188]             ; kernel32.CreateMutexA<br \/>746824B9    33C9            xor     ecx, ecx<br \/>746824BB    85C0            test    eax, eax<br \/>746824BD    0F95C1          setne   cl<br \/>746824C0    8906            mov     dword ptr [esi], eax<br \/>746824C2    5E              pop     esi<br \/>746824C3    8BC1            mov     eax, ecx<br \/>746824C5    5D              pop     ebp<br \/>746824C6    C2 0800         retn    8<br \/><\/blockquote>\n\n\n\n746824B9\u8fd9\u884c,\u770b\u770b\u4e0a\u4e00\u884c746824B3\u540e\u8fb9\u7684\u6ce8\u89e3\u5199\u7740\u4ec0\u4e48,kernel32.CreateMutexA\u4e5f\u5c31\u662f\u521a\u521a\u8c03\u7528\u4e86\u6700\u5173\u952e\u7684\u51fd\u6570,\u4f46\u662f\u8fd9\u4e2a\u51fd\u6570\u5728\u7a0b\u5e8f\u91cc\u8c03\u7528\u4e86\u5f88\u591a\u6b21,\u6211\u4eec\u600e\u4e48\u77e5\u9053\u54ea\u4e00\u6b21\u7684\u624d\u662f\u4e0d\u8ba9\u591a\u5f00\u7684\u4ee3\u7801\u5462?\u7b54\u6848\u5f88\u7b80\u5355,\u5c31\u662f\u8bd5,\u8bd5\u4e5f\u8981\u9760\u65b9\u6cd5\u7684,\u5bf9\u4e8eQQ\u6e38\u620f\u6765\u8bf4,\u6211\u4eec\u5f00\u6253\u5f00\u4e00\u4e2aQQ\u6e38\u620f\u7684\u767b\u9646\u7a97\u53e3,\u4e0d\u7528\u767b\u9646,\u7136\u540e\u518d\u6253\u5f00\u7b2c\u4e8c\u4e2a,\u53d1\u73b0\u4ec0\u4e48\u4e86?\u5bf9\u539f\u6765\u90a3\u4e2a\u7a97\u53e3\u5728\u95ea,\u884c\u4e86,\u6211\u4eec\u5c31\u901a\u8fc7\u5224\u65ad\u7a97\u53e3\u95ea,\u6765\u5f97\u5230\u5177\u4f53\u662f\u54ea\u4e00\u6b21\u8c03\u7528\u662f\u7981\u6b62\u6253\u5f00\u7b2c\u4e8c\u4e2a\u6e38\u620f\u7684\u4ee3\u7801.\u4e0b\u8fb9\u6211\u4eec\u6765\u8bd5,\u521a\u624d\u6309\u4e86\u4e00\u6b21F9\u548c\u4e00\u6b21Alt+F9,\u6211\u4eec\u7ee7\u7eed\u91cd\u590d\u521a\u624d\u7684\u5de5\u4f5c,\u76f4\u5230\u770b\u5230QQ\u7a97\u53e3\u95ea\u52a8,\u8bf4\u660e\u7981\u6b62\u53cc\u5f00\u7684\u4ee3\u7801\u4ee5\u7ecf\u88ab\u6267\u884c\u4e86,\u4e00\u5171\u6309\u4e86\u591a\u5c11\u6b21Alt+F9\u5462?17\u6b21,\u8bf4\u660e\u7b2c17\u6b21\u8c03\u7528\u624d\u662f\u771f\u6b63\u7684\u7981\u6b62\u53cc\u5f00.\n\n\u597d\u4e86,\u6211\u4eec\u8fd9\u65f6\u6309Ctrl+F2\u91cd\u65b0\u6253\u5f00\u7a0b\u5e8f,\u7a0b\u5e8f\u53c8\u505c\u5728\u4e8600402150\u5904,\u6211\u4eec\u6309Alt+b\u6253\u5f00\u65ad\u70b9\u7a97\u53e3\u770b\u5230\u6709\u4e00\u4e2a\u5730\u5740\u4e3a7C80E9CF\u7684\u65ad\u70b9,\u6211\u4eec\u7528\u9f20\u6807\u9009\u4e2d\u5b83,\u6309\u56de\u8f66,\u6765\u5230\u8fd9\u91cc\n\n\n\n<blockquote>7C80E9CF &gt;  8BFF            mov     edi, edi<br \/>7C80E9D1    55              push    ebp<br \/>7C80E9D2    8BEC            mov     ebp, esp<br \/>7C80E9D4    51              push    ecx<br \/>7C80E9D5    51              push    ecx<br \/>7C80E9D6    56              push    esi<br \/><\/blockquote>\n\n\n\n\u773c\u719f\u5417?\u8fd9\u91cc\u5c31\u662fCreateMutexA\u7684\u7b2c\u4e00\u884c,\u6211\u4eec\u9009\u4e2d7C80E9CF\u8fd9\u884c,\u6309Shift+F4\u8bbe\u7f6e\u4e00\u4e0b\u6761\u4ef6<br \/>\u6682\u505c\u7a0b\u5e8f\u90a3\u91cc\u9009\u62e9&quot;\u6309\u6761\u4ef6&quot;\u540e\u8fb9\u7684\u6761\u4ef6\u6ee1\u8db3\u6b21\u6570\u519916,\u4e3a\u4ec0\u4e48\u662f16\u5462?\u7b2c17\u6b21\u5c31\u4ee5\u7ecf\u7981\u6b62\u53cc\u5f00\u4e86,\u6211\u4eec\u8ba9\u4ed6\u505c\u5728\u7b2c16\u6b21\u8c03\u7528\u4e4b\u540e,\u597d\u770b\u770b\u5177\u4f53\u662f\u54ea\u4e2a\u8bed\u53e5\u7981\u6b62\u53cc\u5f00\u7684.<br \/>\u8bbe\u7f6e\u5b8c\u6210\u540e\u6309\u786e\u5b9a,\u518d\u6309F9\u8fd0\u884c\u7a0b\u5e8f.\u7a0b\u5e8f\u53c8\u505c\u5728\u4e867C80E9CF\u8fd9\u884c\u4e0a,\u4e0d\u8fc7\u8fd9\u6b21\u662f\u7b2c16\u6b21,\u6211\u4eec\u6309Alt+F9\u56de\u5230\u7528\u6237\u4ee3\u7801\u5904.\n\n\n\n<blockquote>10012886    85C0            test    eax, eax<br \/>10012888    8946 4C         mov     dword ptr [esi+4C], eax<br \/>1001288B    74 24           je      short 100128B1<br \/>1001288D    FF15 ACC00110   call    dword ptr [&lt;&#038;KERNEL32.GetLastErr&gt;; ntdll.RtlGetLastWin32Error<br \/>10012893    3D B7000000     cmp     eax, 0B7<br \/>10012898    8BCE            mov     ecx, esi<br \/>1001289A    75 07           jnz     short 100128A3<br \/>1001289C    E8 BE000000     call    1001295F<br \/>100128A1    EB 2A           jmp     short 100128CD<br \/>100128A3    E8 90010000     call    10012A38<br \/>100128A8    85C0            test    eax, eax<br \/>100128AA    74 21           je      short 100128CD<br \/><\/blockquote>\n\n<br \/>\u7a0b\u5e8f\u505c\u5728\u4e8610012886\u5904,\u6211\u4eec\u6309F8\u6b65\u8fc7.\u6267\u884c\u523010012893\u8fd9\u53e5\u65f6\u770b\u5230\u4fe1\u606f\u9762\u677f,\u4e5f\u5c31\u662f\u4ee3\u7801\u7a97\u53e3\u4e0b\u8fb9\u7684\u5c0f\u7a97\u53e3\u5199\u7740eax=000000B7,\u800c10012893\u8fd9\u53e5\u7684\u4ee3\u7801\u662fcmp eax,0B7 \u8fd9\u53e5\u7684\u610f\u601d\u5c31\u662f\u6bd4\u8f83eax\u548c0B7,\u63a5\u7740\u6267\u884c\u6309F8,\u5f53\u6765\u52301001289A\u8fd9\u884c\u65f6,\u6ce8\u610f\u4e86, jnz     short 100128A3\u7684\u610f\u601d\u662f\u8bf4,\u521a\u624d\u6bd4\u8f83\u7684eax\u548cB7\u5982\u679c\u8fd9\u4e24\u4e2a\u4e0d\u76f8\u7b49\u5219\u8df3\u8f6c\u5230100128A3,\u5426\u5219\u4e0d\u8df3,\u521a\u624deax=B7\u4e5f\u5c31\u662f\u76f8\u7b49,\u6240\u4ee5\u7a0b\u5e8f\u63a5\u7740\u6267\u884c,\u5e76\u4e0d\u8df3\u8f6c.\u63a5\u7740\u6309F8,\u6267\u884c\u5230100128A1\u8fd9\u884c,\u53d1\u73b0\u5148\u524d\u6253\u5f00\u7684QQ\u6e38\u620f\u7a97\u53e3\u95ea\u4e86,100128A1\u4e0a\u4e00\u884ccall    1001295F,\u8c03\u7528\u4e86\u8fd9\u4e2a\u5b50\u7a0b\u5e8f\u540eQQ\u6e38\u620f\u624d\u88ab\u7981\u6b62\u8fd0\u884c\u7684.\u8fd9\u662f\u5173\u952e\u7684\u90e8\u5206\u4e86.\n\n\u6211\u4eec\u5177\u4f53\u5206\u6790\u4e00\u4e0b\u8fd9\u6bb5\u4ee3\u7801\n\n\n\n<blockquote>10012893    3D B7000000     cmp     eax, 0B7<br \/>10012898    8BCE            mov     ecx, esi<br \/>1001289A    75 07           jnz     short 100128A3<br \/>1001289C    E8 BE000000     call    1001295F<br \/>100128A1    EB 2A           jmp     short 100128CD<br \/>100128A3    E8 90010000     call    10012A38<br \/>100128A8    85C0            test    eax, eax<br \/>100128AA    74 21           je      short 100128CD<br \/>100128AC    897D FC         mov     dword ptr [ebp-4], edi<br \/><\/blockquote>\n\n\n\n10012893\u8fd9\u53e5\u628aeax\u548cB7\u505a\u4e86\u6bd4\u8f83,1001289A\u8fd9\u53e5\u5224\u65adeax\u548cB7\u4e0d\u76f8\u7b49\u5219\u8df3\u8f6c\u5230100128A3,\u4f46\u5b9e\u9645\u60c5\u51b5\u662f\u76f8\u7b49,\u4e5f\u5c31\u662f\u4e0d\u8df3\u8f6c.\u5982\u679c\u6267\u884c\u4e861001289C\u8fd9\u884c\u7684\u5b50\u7a0b\u5e8f,\u5c31\u7981\u6b62\u53cc\u5f00\u4e86<br \/>\u6211\u4eec\u6765\u7b80\u5316\u4e00\u4e0b\u6d41\u7a0b<br \/>10012893    3D B7000000     cmp     eax, 0B7<br \/>1001289A    75 07           jnz     short 100128A3<br \/>1001289C    E8 BE000000     call    1001295F<br \/>100128A3    E8 90010000     call    10012A38<br \/>\u6839\u636e\u4e0a\u8fb9\u6240\u8bf4\u7684,\u6211\u4eec\u5982\u679c\u4e0d\u6267\u884c1001289C\u8fd9\u884c,\u5c31\u53ef\u4ee5\u53cc\u5f00,\u6700\u7b80\u5355\u7684\u529e\u6cd5\u6709\u4e24\u4e2a,\u53ef\u4ee5\u8df3\u8fc71001289C \u8fd9\u884c,\u4e00\u662f\u653910012893\u8fd9\u884c,\u628aeax\u548cB6\u6bd4,\u6216\u522b\u7684\u6570,\u53cd\u6b63\u4e0d\u662fB7\u5c31\u884c\u4e86.\u6539\u8fc7\u540e\u5f53\u6267\u884c\u52301001289A\u65f6,\u4f1a\u76f4\u63a5\u8df3\u5230100128A3\u53bb\u6267\u884c,1001289C\u6ca1\u6709\u88ab\u6267\u884c\u4e5f\u5c31\u662f\u53ef\u4ee5\u53cc\u5f00.\u4e8c\u662f\u628a1001289A\u8fd9\u53e5\u7684jnz\u6539\u6210je\u4e5f\u5c31\u662f\u628a\u539f\u6765\u7684eax\u548cB7\u4e0d\u76f8\u7b49\u5219\u8df3\u8f6c\u5230100128A3,\u53d8\u6210\u4e86\u76f8\u7b49\u5219\u8df3\u8f6c.\n\n\u6211\u4eec\u7528\u7b2c\u4e00\u79cd\u65b9\u6cd5\u8bd5\u8bd5.<br \/>\u9009\u4e2d10012893,\u4e5f\u5c31\u662fcmp eax,0B7\u8fd9\u53e5,\u6309F2,\u7136\u540e\u6309ALt+B\u628a\u521a\u624d\u76847C80E9CF\u90a3\u4e2a\u65ad\u70b9\u5220\u9664\u4e86,\u53ea\u5269\u4e0b10012893\u8fd9\u4e2a,\u7136\u540e\u6309ALT+C,\u518d\u6309Ctrl+F2\u91cd\u65b0\u8f7d\u5165\u7a0b\u5e8f,\u6309F9\u8fd0\u884c]]\n>\n<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4e0b\u9762\u6765\u8bf4\u8bf4\u5177\u4f53\u7684,\u51c6\u5907\u5de5\u5177ollyice\u4e0b\u8f7d\u5730\u5740:http:\/\/www.kumouse.com\/article [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-93","post","type-post","status-publish","format-standard","hentry","category-12"],"_links":{"self":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/posts\/93","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=93"}],"version-history":[{"count":0,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/posts\/93\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=93"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=93"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=93"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}