当前位置:网站首页>Crack WinRAR to ad pop-up window
Crack WinRAR to ad pop-up window
2022-06-12 13:56:00 【HyperCall】
WinRAR Ads pop up every time you start , After analysis, I found that it was easy to go to advertising ….. For technical exchange only , Do not use it to crack propagation ~
1. The goal is :32 position WinRAR Go to the advertising pop-up window , A single file ko
2.OD Load find window related API Call found CreateWindowEx Call to , All down
3.F9 Run to record which call is responsible for creating the advertisement pop-up .
The record discovery window class is named SysListView32 Of call After calling, the main window appears
The window class name is RarHtmlClassName Of call After calling, the advertisement window will appear , After careful analysis, it is found that the window class name is RarHtmlClassName Of call The nearby codes are related to the advertising window , So you can find the code that calls this function directly , Call this function NOP transfer
4. test , The advertising window has become a blank window , Explain that there are related window creation call It's not solved , Continue the above tracking and find
The window class name is RarReminder Related calls to , After analyzing the nearby code, it is found that the same function as above is responsible for reading the string value in the resource file , Get the advertisement address after decoding , After careful analysis, it is found that the timer should be set to access this function every once in a while . The starting address of this function is 00DB4A00( This system is enabled ASLR)
5. So in WinRAR Search for all commands in (call 00DB4A00) obtain
6. All NOP transfer ! Get it done , Super easy ,64 I won't say more about you ~
边栏推荐
- one × Convolution kernel of 1
- Encryptor and client authenticate with each other
- Xcode debugging OpenGLES
- Chapter IV expression
- 280 weeks /2171 Take out the least number of magic beans
- Lua common built-in functions
- lua 常用内置函数
- 1414. minimum number of Fibonacci numbers with sum K
- Now you must know the pointer
- Return value of WaitForSingleObject
猜你喜欢
MySQL 查询 limit 1000,10 和 limit 10 速度一样快吗? 深度分页如何破解
[advanced MySQL] evolution of MySQL index data structure (IV)
After reading the question, you will point to offer 16 Integer power of numeric value
chrome://tracing Performance analysis artifact
阿里云开发板HaaS510解析串口JSON数据并发送属性
Single bus temperature sensor 18B20 data on cloud (Alibaba cloud)
通过loganalyzer展示数据库中的日志
CSDN博客积分规则
拆改廣告機---業餘解壓
Web3.0,「激发创造」的时代
随机推荐
969. pancake sorting
3. Hidden processes under the ring
阿里云开发板HaaS510解析串口JSON数据并发送属性
Relevant knowledge points of cocoapods
Go language functions as parameters of functions
Tree reconstruction (pre order + middle order or post order + middle order)
Behind the unsealing of Shanghai, this group of developers "cloud gathering" built an AI anti epidemic robot
SystemC common errors
English learning plan
上海解封背后,这群开发者“云聚会”造了个AI抗疫机器人
Codeforces 1637 C. Andrew and stones - simple thinking
Debug code to quickly locate the error location
CSDN博客积分规则
Codeforces 1637 A. sorting parts - simple thinking
[semidrive source code analysis] [x9 chip startup process] 25 - Introduction to mailbox inter core communication mechanism (code analysis) rpmsg-ipcc RTOS & QNX
注重点击,追求更多用户进入网站,可以选择什么出价策略?
Summary of virtual box usage problems
Interview question 17.14 Minimum number of K (almost double hundreds)
chapter19 Allocation
Knowledge of wireless card driver