½ÔáÁÄé©àµêܹñÌÅAൽ© êÎRg��½¾¯êΤêµï¿½ï¿½Å·
WGAÍá@Rs[ÌWindows��áÈ���}Æðؾ·é�}ÆÅAMicrosoft Download Center�NæÑMicrsoft UpdateÌTCgªï¿½ï¿½ÀȵÉpÅ«éæ¤ÈéÆ��¤àÌÅ·
ÅÍÀÅƵÄCÓŵ½ªA7ÉMicrosoft DownloadAMicrosoft Update̼TCgÉÄK{ÆÈèܵ½
µ©µx[^ÌiK©ç�}êðjéñðôª»êÄ�NèA»ÝlªmFÅ«½Æ�}ëÅÍ©Èè½³ñÌû@ª èÜ·
ñðû@ÍKÈÉf¦µÄ�N«Ü·
1.GenuineCheck.exeÌR[h��p
x[^ÌiK©çmF³êÄ��½û@Å·
Microsoft DownloadÌTCgÅÍAActiveXÉæéFØÌÙ©ÉGenuineCheck.exeÆÄÎêéMicrosoftÌc[ðÀsµA¾çê½R[hðDownloadTCgÌYÉ\èt¯ÄNðNbNµÄFس¹éû@ª èÜ·
�}ÌGenuineCheck.exeð³KWindowsÅÀsµA¾çê½R[hðá@Rs[ÌWindowsÅp·é�}ÆÅAC¯ÅWindowsÅÌDownload CenterÌpªs¦éæ¤ÉÈèÜ·
lªmFÅ«½îñ³ÍAHackingSpiritsÆÄÎêéO[vÌWordhL gÅ·
½¾µUpdateTCgÅÍGenuineCheck.exeÌû@ªg¦È��½ßAÉÐî³êéû@ðp·é�}ÆÉÈèÜ·
2.JavaScriptðp
WGA³K^pJnúÉbèÉÈÁ½û@Å·
îñ³ÍBoing BoingÆ��¤BlogÌ728úÌL"Microsoft "Genuine Advantage" cracked in 24h"Å·
»ï¿½}ÉÐî³êÄ��éA`FbNÉp³êéêÌ@\ð³øÉ·éJavaScriptêsÌR[hðAAhXÉy[XgµÄÀsµÄ©ç`FbNsöªsíêéy[WÉiÞ·é�}ÆÉæèA`FbN©Ìð³øÆ·éàÌÅ·
3.GenuineCheck.exeÌÝ·[hÀs
ãLÌGenuineCheck.exeÌvpeBð\¦µAÝ·[hÌWindows2000ÉÝèµ½ãÅÀsµÄÝéàÌÅ·
�}êÉæèoͳêéR[hÍA½Æ¦GenuineCheck.exeðC¯ÅWindowsÅÀsµÄ��ÄàFØðÊÁĵܤæ¤Å·
�}�}à728útÅû@ðöJµÄ��ܷ
�}Ìû@àUpdateTCgÅÍpÅ«È��æ¤Å·
mFµ½Æ�}ëUpdateTCgÅÍGenuineCheck.exeðp·éû@ªñ³êÄ��È��æ¤Å·
4.AhI̳ø
Microsoft UpdateÅWGAÌ\tgEFAðCXg[·éÆAIEÌAhIƵÄ"Windows Genuine Advantage"Æ��¤Ìªo^³êÜ·
t@C¼ÍLegitCheckControl.dllÆ��¤àÌÈñÅ·ªA�}êð³øÉ·éû@ª èÜ·
IEÌj [©ç[c[][AhIÌÇ]ÆNbNµÄ��«A\¦³ê½XgÌÌ»ÌDLLðNbNµ½¤¦Å��ºÌ"³ø"ðIðð·é¾¯ÌìÆÅ·
XgÉYACeªÈ��êÍAãÌ\¦Æ��¤v_E©ç"Internet ExplorerÅgp³ê½AhI"ÉØèÖ¦êÎ\¦³êé©àµêܹñ
UpdateTCgÅàg¦ÄµÜ¤æ¤Å·
�N»çÅàÈPÅÀpIÈû@ŵå¤
5.`FbNÉp��çêéDLLÌü��
ãLÌLegitCheckControl.dllðoCiGfB^ÅJ«Aê𫷦ĵܤÆ��¤û@Å·
�}êÍêÅAVFAEFAÈÇÌ\tgEFAðàȵÅs³ÉpÅ«éæ¤É·éÈÇA³Ü�LÜÈ�~Hðs¤½ßÌû@ƵÄægíêÄ��éàÌÅ·
AhX0002BE98Ì8Bð33A0002BE99Ì45ðC0A0002BE9AÌD8ð90É«·¦Ä㫷龯ŷ
îñ³Í"LegitCheckControl.dll Hex"ÁÄõ·êÎ��ÁÏ��oÄ«Ü·
¿ÈÝÉHexÁÄ��¤ÌÍoCiÌÓ¡Å·
6.FØɺ¤t@CÌ����
"C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage\data"ÌfBNgÌàÉdata.datÆ��¤t@Cðì��µAvpeB©çÇÝæèêpÉÏX·éçµï¿½ï¿½Å·
��ØÅ·ªA൳KÅWindowsÅFصÄì��³ê½data.datðC¯ÅÉRs[·éÆ`FbNðñðūĵܤÌÅÍÈ��©Æ�NàÁÄ��ܷ
1`3Ì»ê¼êÌû@ªmF³ê½Æ«ÉÍCnet©çLªoÄ��ܷ
1."}CN\tgÌuWindows Genuine Advantagevɲ¯¹"
2."}CN\tgÌá@Rs[ÎôAàâèɼÊ"
3."uWindows Genuine AdvantagevÉܽàâñðô"
QlÉÈéLΩèÈÌÅA ÜèîñðWßÄ��ȩÁ½lÍ©ÄÝé�~«Å·
�}�}ÉÐîµ½ÌÍÇêàÈPÈû@Å·
ê®êà«pµÈ��æ¤ï¿½Nè��µÜ·
0002BFE5 8B --> 33
0002BFE6 45 --> C0
0002BFE7 D8 --> 90
ÅÍãLÌAhXª©Â©çÈ��æ¤Å·B
Æo[WÅÍ«·¦ðsÁÄ
MicrosoftUpdateÍpÅ«éæ¤Å·ªA
ÁTðÂÊÉDL·é�}ÆÍoÈ��æ¤Å·B
ájDirectX 9.0c
ÅàÅ«Ü·
0002C5C: 8B --> 33
0002C5B: 45 --> C0
0002C5E: D8 --> 90
çµï¿½ï¿½B
"C7 45 D8 06 00 00 00 8B 45 D8"
ÌÀÑð©Â¯Ä»ÌÅãÌ3ÂðÏXµÄ
"C7 45 D8 06 00 00 00 33 C0 90"
Æ·êÎæ��çµï¿½ï¿½B
Æ�}Ìo[W¾ÆA_E[hZ^[
ÅàDL Å«»¤B
Å»¤ÆµÜµ½ªEEE
0002C5C: 8B --> 33
0002C5B: 45 --> C0
OK
0002C5E: D8 --> 90
�}ÌÏX·ï¿½~«D8ªï¿½ï¿½È��EEE
"C7 45 D8 06 00 00 00 8B 45 D8"
"C7 45 D8 06 00 00 00 33 C0 90"
�}êàOK
ãLì©ç@·éÉi½¾ÌªÅ·ªj
0002C5E: D8 --> 90
ÍAhXªá¤æ¤È«ªµÜ·ªEE
0002DBDC: 8B �N33
0002DBDD: 45 �NC0
0002DBDE: D8 �N90
0000181: B0 �N A6
002ECEE: 8B �N 90
002ECEF: 85 �N 90
002ECF0: 60 �N 6A
002ECF1: FF �N 00
002ECF2: FF �N 58
002ECF3: FF �N 90
-> 2006/3/2tRgÌàeÅOK
õµ½¯ÇAܾîñª©½çÈ��BB
¿áñÆÊèܵ½
002F384: 8B �N 90
002F385: 85 �N 90
002F386: 60 �N 6A
002F387: FF �N 00
002F388: FF �N 58
002F389: FF �N 90
orz³ñÌÅÊèܵ½@ èªÆ¤I
�LÓI�LI
000303BA: 8B �N 90
000303BB: 85 �N 90
000303BC: 60 �N 6A
000303BD: FF �N 00
000303BE: FF �N 58
000303BF: FF �N 90
530@ÌÉ@8B 85 60 FF FF FF Ìt[Yª
3ÓLèÜ·B
Í3ÓÆà@90 90 6A 00 58 90 É«·¦ÄOKŵ½B
1. IE7-WindowsXP-x86-enu.exeðð
2. update\iecustom.dllðoCiGfB^ÅJ
3. 000012C0ð0F 95©ç0F 94ÖÏX
4. Û��µÄAupdate.exeðÀs
1. wmp11-windowsxp-x86-ja-jp.exeðð
2. legitlib.dllðoCiGfB^ÅJ
3. 00019923:8B�N33
00019924:45�NC0
00019925:D8�N90
4. Û��µÄAsetup_wm.exeðÀs
>1. IE7-WindowsXP-x86-enu.exeðð
ªÔá��ŷorz
�~IE7-WindowsXP-x86-enu.exe
IE7BETA2-WindowsXP-x86-jpn.exe
1. WindowsDefender.exe{ÌðoCiGfB^ÅJ
2. 00521B2E: 8B�N33
00521B2F: 45�NC0
00521B30: D8�N90
4. Û��µÄAWindowsDefender.exeðÀs
³¤Ü��«Üµ½B èªÆ¤²ï¿½L��ܵ½B
Æ�}ëÅWindowsDefenderÌWGAñðÅ·ªÆ·OÉGenuineCheck.exeÅG[ªEEE
Windows2000[hɵÄà¾ßQÄP|
1. IE7-WindowsXP-x86-enu.exeðð
2. update\iecustom.dllðoCiGfB^ÅJ
3. 000012C0ð0F 95©ç0F 94ÖÏX
@ 000012C0ð0F 6Að94@žß
@ 000012C0ð00 95ð94@žß
4. Û��µÄAupdate.exeðÀs
@©®N®µÄ��ܷB@
@Ç�}ðϦ½ç����ŷ©HH
1. IE7BETA2-WindowsXP-x86-jpn.exeðð
2. update\iecustom.dllðoCiGfB^ÅJ
3. 000012C0: 95�N94ÖÏX
4. Û��µÄAupdate.exeðÀs
1. IE7BETA2-WindowsXP-x86-jpn.exeðð
2. update\iecustom.dllðoCiGfB^ÅJ
3. 000012C0: 95�N94ÖÏX
4. Û��µÄAupdate.exeðÀs
hZbgAbvG[
t@Cª³µ èܹñh
IE7-À2 ¼É«·¦éêÍH
000303BA:
000303BB:
000303BC:
000303BD:
000303BE:
000303BF:
�}êçÌAhXªGfB^ũ©çÈ��ÌÍȺH
LegitCheckControl.dllÌo[W
1.5.530.0
000303BA: 8B �N 90
000303BB: 85 �N 90
000303BC: 60 �N 6A
000303BD: FF �N 00
000303BE: FF �N 58
000303BF: FF �N 90
Ånjŵ½B
VerÍÁÄ��é͸ÈÌÉccB
WXgMÁÄAWindowsUpdateÅà¤êñWGA(530)CXR³¹éæ¤ÉµÄAdll«·¦½çÊèܵ½B
dllMéOÉFØmFµ½Ìªï¿½Lö¾Á½Ì©àµêܹñB
2003ServerpÌsvWXgíðµ½ç½Ì©»¤ÈÁÄB
å³Í«Ì
ttp://briefcase.yahoo.co.jp/bc/nak265/lst?.dir=/KEYGEN&.order=&.view=l&.src=bc&.done=http%3a//briefcase.yahoo.co.jp/
2003ServerpÌsvWXgíðµ½ç½Ì©»¤ÈÁÄB
å³Í«Ì
ttp://briefcase.yahoo.co.jp/kirakiraicco
000303BB:
000303BC:
000303BD:
000303BE:
000303BF
ðoCiGfB^ÅÒWµæ¤ÆÇÝÝܵ½ªAS�}êçÌà̪©Â©èܹñBo[WªÏíÁ½Ìŵ天B²¯o·û@ð�N³¦¾³ï¿½ï¿½B
000303BA:
000303BB:
000303BC:
000303BD:
000303BE:
000303BF:
ðÒWµæ¤ÆÇÝÝܵ½ªAS�}êçÌà̪©Â©èܹñB�}ÌtßÌàÌÍ
000303A0:
000303B0:
000303C0:
000303D0:
000303E0:
000303F0:
ŵ½BOSÍWinXP@ProÅ·B
o[WªÏíÁ½Ìŵ天BFØñðû@ð�N³¦¾³ï¿½ï¿½B
ÌGfB^ũ©çÈ©Á½çAè®Å530(Microsoft©ç)ƵÄÄCXRàèÅÍB
èªÆ¤²ï¿½L��ܵ½B
ðÅ«È��ÈçÞè¾ï¿½~@
1. IE7BETA2-WindowsXP-x86-jpn.exeðð
ðû@ð�Nµ¦Ä¾³ï¿½ï¿½Ü¹B
ÅÅ«é
êñAÄN®³¹½ãÉà¤êxGfB^ÅJÌÍH
>>
000303BA:
000303BB:
000303BC:
000303BD:
000303BE:
000303BF:
ðÒWµæ¤ÆÇÝÝܵ½ªAS�}êçÌà̪©Â©èܹñB
GfB^Ìg��ûðæÇñÅÝľ³ï¿½ï¿½B
0 1 2 3 4 5 6 7 8 9 A B C D E F
000303B 8B 85 66 FF FF FF
GfB^ãÌ\¦ð��½ÂàèÈñÅ·ªAXy[Xª³³êÄܵ½B
ªÌÍÅB
�}êª1.5.540.0
8B 85 60 FF FF FF -> 90 90 6A 00 58 90
Å��¯»¤¾
¡ÌÆ�}ëWindowsUpdateÉÍe¿È��¯Ç
»Ì¤¿ï¿½ï¿½ÉÈéÌ©ÈH
>8B 85 60 FF FF FF -> 90 90 6A 00 58 90
>Å��¯»¤¾
âÁÄݽ¯ÇAÊÚŵ½B
DLL¾¯ü��1.5.530.0Éßµ½çWindowsUpdateÍÊèܵ½B
ÊçÈ��©Æ
ñsÉܽªÁÄé©ç©¦É��¯Ç
ÅÄéWGAÌUpdateªsÂÉÈèÜ·
>ÊçÈ��©Æ
OJ«·¦½¯ÇAÊÚŵ½B
N®É¤é³ï¿½ï¿½bZ[Wªoéæ¤ÉÈÁ½ÌÅAVXe̳Å1.5.530.0ÌóÔÉßµ¿áÁ½B
X^[g�Nt@C¼ðwèµÄÀsÅ@Regsvr32 %Windir%\system32\LegitCheckControl.dll /u@ðRsyµÄÀs
WXgGfB^Å
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\ CurrentVersion\Winlogon\Notify\WgaLogon@Æ@HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows \CurrentVersion\removeremove\WgaNotify
@ðíµÄ¾³ï¿½ï¿½BiºÍ³ï¿½ï¿½PCà èÜ·j
ÄN®ãUpdateðµÄ¾³ï¿½ï¿½Aíè·ï¿½ï¿½½ï¿½NðÄû¾µÄêÜ·B
à¤êxÄN®µÄ¾³ï¿½ï¿½A�}êÅWGAÌUpdateª³Èé͸ŷB