Last article address: http://www.bkjia.com/Article/200801/23546.html
I wrote an article about vbprogram cracking last time. This time I found that this method is not generic, so I wrote a new article. in fact, these two articles are not specifically used to crack programs detected at startup. I just want to talk about a method that uses events in VB, so I can easily find the key to the program, if you are interested, please follow up. It's very easy. run VB6, create a project, add a module, double-click the module, delete the Form, and enter:
Sub Main
MsgBox ("test! ")
End
End Sub
Then compile the cost machine code. In this case, the method I mentioned previously is useless. Please come with me.
Or load TRW, and then follow it here.
......
0187: 6600DE5B FF1518110066 CALL 'kernel32! Getstartupinfoa'
0187: 6600DE61 0FB745D0 movzx eax, WORD [EBP-30]
0187: 6600DE65 A3D8F71066 MOV [6610F7D8], EAX
0187: 6600DE6A FF35CCF61066 push dword [6610F6CC]
0187: 6600DE70 56 PUSH ESI
0187: 6600DE71 be70f000066 mov esi, 6610F470
0187: 6600DE76 8BCE mov ecx, ESI
0187: 6600DE78 E860000000 CALL 6600 DEDD // enter
......
(Omitted process)
......
0187: ******** FF9694000000 call near [ESI + 94] // return the program's airspace when F8 is entered, we successfully stopped at the beginning of the VB code.
0187: ******** 8D45D4 lea eax, [EBP-2C]
0187: ******** 50 PUSH EAX
0187: ******** E807030000 CALL 66014710
0187: ********* 6A01 push byte + 01
0187: ********* 58 POP EAX
0187: ********* 5F POP EDI
0187: ********* 5E POP ESI
0187: ******** C9 LEAVE
0187: ******** C20400 RET 04
......
0187: 00401628 6A00 push byte + 00
0187: 0040162A 50 PUSH EAX
0187: 0040162B FF151C104000 CALL 'msvbvm60! RtcMsgBox '// This is MsgBox
0187: 00401631 8D4DB0 lea ecx, [EBP-50]
0187: 00401634 8D55C0 lea edx, [EBP-40]
0187: 00401637 51 PUSH ECX
0187: 00401638 8D45D0 lea eax, [EBP-30]
0187: 0040163B 52 PUSH EDX
0187: 0040163C 8D4DE0 lea ecx, [EBP-20]
0187: 0040163F 50 PUSH EAX
0187: 00401640 51 PUSH ECX
0187: 00401641 6A04 push byte + 04
0187: 00401643 FF1508104000 CALL 'msvbvm60! _ Vbafreevarlist'
0187: 00401649 83C414 add esp, BYTE + 14
0187: 0040164C FF150C104000 CALL 'msvbvm60! _ VbaEnd '// then the program End
0187: 00401652 6876164000 push dword 00401676
0187: 00401657 EB1C jmp short 00401675
Postscript:
Another case is that a Crackme is written in VB6. I have used either of the two methods to break it down (in fact, the author is not playing the cards by common sense ). create a new project and compile it as the local code. Try again. Can you use the above methods to break it down? That is to say, when the program starts (or before the verification code) There is no event, it is really a funny thing, such a program, tracking will only be in Msvbvm60.dll, then use ShowWindow to display the window. That is to say, the program does not detect it at startup (or does not generate any event during detection? Is it possible ?).
In my opinion, as long as an event or module is used in the vbprogram, whether the program is just started or running, as long as the TRW is used to break the breakpoint at the two points, you can easily find the key points of the program. if you have any comments or comments, please correct them.