|
ollydbg载放PECMD。EXE,右键查找所有参考文本字串,找到如下类似的信息,双击进入
"WinPE Commander (Modified By Lxl1638)"
"PECMD"
"%s - %s"
"2.8.262.1036"
双击后见到的信息为如下
0040564E |. 68 282D4100 PUSH PECMD.00412D28 ; UNICODE "EXPLORER.EXE"
00405653 |. E8 18140000 CALL PECMD.00406A70
00405658 |. 85C0 TEST EAX,EAX
0040565A |. 59 POP ECX
0040565B |. 75 03 JNZ SHORT PECMD.00405660
0040565D |. 40 INC EAX
0040565E |. EB 02 JMP SHORT PECMD.00405662
00405660 |> 33C0 XOR EAX,EAX
00405662 |> 8325 A0434100>AND DWORD PTR DS:[4143A0],0
00405669 |. 85C0 TEST EAX,EAX
0040566B 0F84 B4000000 JE PECMD.00405725 在反汇编这列上双击这行,把JE改为JMP
00405671 |. 8B35 24134000 MOV ESI,DWORD PTR DS:[<&USER32.wsprintfW>; USER32.wsprintfW
00405677 |. 68 302A4000 PUSH PECMD.00402A30 ; /<%s> = "WinPE Commander (Modified By Lxl1638)"
0040567C |. 68 7C2A4000 PUSH PECMD.00402A7C ; |<%s> = "PECMD"
00405681 |. 8D85 60FFFFFF LEA EAX,DWORD PTR SS:[EBP-A0] ; |
00405687 |. 68 882A4000 PUSH PECMD.00402A88 ; |Format = "%s - %s"
0040568C |. 50 PUSH EAX ; |s
0040568D |. FFD6 CALL NEAR ESI ; \wsprintfW
0040568F |. 68 502C4000 PUSH PECMD.00402C50 ; UNICODE "2.8.262.1036"
00405694 |. 8D85 60FFFFFF LEA EAX,DWORD PTR SS:[EBP-A0]
0040569A |. 50 PUSH EAX
0040569B |. 8D85 C0FEFFFF LEA EAX,DWORD PTR SS:[EBP-140]
004056A1 |. 68 6C2C4000 PUSH PECMD.00402C6C ; UNICODE "%s , V%s#0"
004056A6 |. 50 PUSH EAX
004056A7 |. FFD6 CALL NEAR ESI
004056A9 |. 6A 01 PUSH 1
004056AB |. E8 A4FEFFFF CALL PECMD.00405554
然后再在这行右键,复制到可执行文件,选择,在弹出的窗口中,关闭,会提示你保存为一个文件,将文件保存为pecmd.exe即可,这样就没有LOGO的版本信息了 |
|