pb 全系列破解教程
pb吧
全部回复
仅看楼主
level 15
风萧寒211 楼主
准备工具
1.OD (百度搜索上因为属于动态调试软件 可能会被杀毒软件误报 我不背这个骂名 不给出地址你们自己去下)
2.pb 12.5.2 当前版本号为 5550 只要掌握着一个方法 所有的版本 均能搞定
以下是步骤
1.打开od 软件 选择 文件 打开 选择我们的 PB125.EXE 就是我们 安装在哪就到哪找
2.载入之后 直接F9运行 因为我安装了有段时间 现在提示我还剩 9天了
3. 出现这个窗体 别 忙着 点击 关闭 切换 进入od 按下 F12 在按下 alt+k 进入 呼叫堆栈 我们看到 user32.dialogboxparamw 选择 右键显示程序 进入 77D247AB 地址 按F2下断点
4.此时我们 按ctrl+F2 重新载入程序 F9 运行 程序 在下图中箭头处按下回车 进入10B93102 地址
5.ctrl+a 分析一下 看到10B930D0 是入口头 此处点 F2 下断 继续 ctrl+F2 重新载入程序 F9 运行 程序
6. 此时 停在了 我们刚才 断下的10B930D0 处 继续看 右下角 如图箭头处 回车
2016年01月17日 01点01分 1
level 15
风萧寒211 楼主
7. 重复 5-6 步骤一次 我们来到了这里 直接 看下面汇编代码 不要看着眼花 其实很简单
C# code?
123456789101112
13141516171
81920212223242526272829303
13233343536
37383940414243444546474849505
15253545556
5758596061626364656667686970717273747576777879808
18283848586
878889909192939495969798991001011021031041051061071081091101111121
13114115116
1171
18119120121
122123124125126127128129
13013113213
3
13413513613
7138 1061349F CC int3106134A0 /$ 55 push ebp ; 邪恶的入口 重点都在这里106134A1 |. 8BEC mov ebp,esp106134A3 |. 81EC 4C040000 sub esp,44C106134A9 |. 53 push ebx106134AA |. 33DB xor ebx,ebx106134AC |. 56 push esi106134AD |. 57 push edi106134AE |. 68 027F0000 push 7F02 ; /RsrcName = IDC_WAIT106134B3 |. 53 push ebx ; |hInst => NULL106134B4 |. 895D D0 mov dword ptr ss:[ebp-30],ebx ; |106134B7 |. 895D D8 mov dword ptr ss:[ebp-28],ebx ; |106134BA |. 895D E8 mov dword ptr ss:[ebp-18],ebx ; |106134BD |. 895D F4 mov dword ptr ss:[ebp-C],ebx ; |106134C0 |. 895D CC mov dword ptr ss:[ebp-34],ebx ; |106134C3 |. 895D F8 mov dword ptr ss:[ebp-8],ebx ; |106134C6 |. 895D E0 mov dword ptr ss:[ebp-20],ebx ; |106134C9 |. 895D D4 mov dword ptr ss:[ebp-2C],ebx ; |106134CC |. FF15 ECBA6810 call dword ptr ds:[<&USER32.LoadCursorW>] ; \LoadCursorW106134D2 |. 50 push eax ; /hCursor106134D3 |. FF15 E8BA6810 call dword ptr ds:[<&USER32.SetCursor>] ; \SetCursor106134D9 |. 8B75 08 mov esi,dword ptr ss:[ebp+8]106134DC |. 8945 C4 mov dword ptr ss:[ebp-3C],eax106134DF |. 8D45 D4 lea eax,dword ptr ss:[ebp-2C]106134E2 |. 50 push eax ; /Arg9106134E3 |. 8D4D E0 lea ecx,dword ptr ss:[ebp-20] ; |106134E6 |. 51 push ecx ; |Arg8106134E7 |. 8D55 F8 lea edx,dword ptr ss:[ebp-8] ; |106134EA |. 52 push edx ; |Arg7106134EB |. 8D45 CC lea eax,dword ptr ss:[ebp-34] ; |106134EE |. 50 push eax ; |Arg6106134EF |. 8D4D F4 lea ecx,dword ptr ss:[ebp-C] ; |106134F2 |. 51 push ecx ; |Arg5106134F3 |. 8D55 E8 lea edx,dword ptr ss:[ebp-18] ; |106134F6 |. 52 push edx ; |Arg4106134F7 |. 8D45 D8 lea eax,dword ptr ss:[ebp-28] ; |106134FA |. 50 push eax ; |Arg3106134FB |. 8D4D D0 lea ecx,dword ptr ss:[ebp-30] ; |106134FE |. 51 push ecx ; |Arg2106134FF |. 56 push esi ; |Arg110613500 |. E8 EBEBFFFF call PBSYS125.106120F0 ; \PBSYS125.106120F010613505 |. 8B46 4C mov eax,dword ptr ds:[esi+4C]10613508 |. 83C4 24 add esp,241061350B |. F6C4 08 test ah,81061350E |. 75 03 jnz short PBSYS125.106
13513106135
10 |. 8B5D 14 mov ebx,dword ptr ss:[ebp+14]10613513 |> 56 push esi10613514 |. E8 870B0000 call PBSYS125.106140A010613519 |. 6A 01 push 11061351B |. E8 72130700 call <jmp.&PBSHR125.#1145>10613520 |. 83C4 08 add esp,810613523 |. 8BF8 mov edi,eax10613525 |. E8 E0130700 call <jmp.&PBSHR125.#1105>1061352A |. 8BCE mov ecx,esi1061352C |. 8946 4C mov dword ptr ds:[esi+4C],eax1061352F |. E8 BCE1FFFF call PBSYS125.106116F010613534 |. 85C0 test eax,eax10613536 |. 8945 08 mov dword ptr ss:[ebp+8],eax10613539 |. 0F84 ED010000 je PBSYS125.1061372C1061353F |. F646 4C 01 test byte ptr ds:[esi+4C],110613543 |. 74 0C je short PBSYS125.106
13551106135
45 |. 8B56 04 mov edx,dword ptr ds:[esi+4]10613548 |. 52 push edx ; /Arg110613549 |. E8 32BE0600 call PBSYS125.1067F380 ; \PBSYS125.1067F3801061354E |. 83C4 04 add esp,410613551 |> 53 push ebx ; /Arg110613552 |. E8 09D9FFFF call PBSYS125.10610E60 ; \PBSYS125.10610E6010613557 |. 83C4 04 add esp,41061355A |. 85C0 test eax,eax1061355C |. 8945 08 mov dword ptr ss:[ebp+8],eax1061355F |. 0F84 C7010000 je PBSYS125.1061372C10613565 |. 56 push esi ; /Arg110613566 |. E8 55DDFFFF call PBSYS125.106112C0 ; \PBSYS125.106112C01061356B |. 83C4 04 add esp,41061356E |. 85C0 test eax,eax10613570 |. 8945 08 mov dword ptr ss:[ebp+8],eax10613573 |. 0F84 B3010000 je PBSYS125.1061372C10613579 |. F646 4C 01 test byte ptr ds:[esi+4C],11061357D |. 74 22 je short PBSYS125.106135A11061357F |. 6A 01 push 1 ; /Arg4 = 0000000110613581 |. 68 40B36910 push PBSYS125.1069B340 ; |Arg3 = 1069B34010613586 |. 68 54B36910 push PBSYS125.1069B354 ; |Arg2 = 1069B3541061358B |. 56 push esi ; |Arg11061358C |. E8 0F5C0100 call PBSYS125.PB_UtilGetProfInt ; \PB_UtilGetProfInt10613591 |. 85C0 test eax,eax10613593 |. 74 0C je short PBSYS125.106135A110613595 |. 8B46 04 mov eax,dword ptr ds:[esi+4]10613598 |. 50 push eax10613599 |. E8 D2FB0400 call PBSYS125.106631701061359E |. 83C4 04 add esp,4106135A1 |> 8B46 4C mov eax,dword ptr ds:[esi+4C]106135A4 |. B3 31 mov bl,31106135A6 |. 84C3 test bl,al106135A8 |. 74 40 je short PBSYS125.106135EA106135AA |. 84C0 test al,al106135AC |. 78 3C js short PBSYS125.106135EA106135AE |. F6C4 08 test ah,8106135B1 |. 75 37 jnz short PBSYS125.106135EA106135B3 |. 56 push esi106135B4 |. E8 577A0500 call PBSYS125.1066B010106135B9 |. 8B56 04 mov edx,dword ptr ds:[esi+4] ; |106135BC |. 8D4D FC lea ecx,dword ptr ss:[ebp-4] ; |106135BF |. 51 push ecx ; |Arg2106135C0 |. 52 push edx ; |Arg1106135C1 |. E8 5AAC0500 call PBSYS125.1066E220 ; \PBSYS125.1066E220106135C6 |. 8B45 FC mov eax,dword ptr ss:[ebp-4]106135C9 |. 83C4 0C add esp,0C106135CC |. 85C0 test eax,eax106135CE |. 74 1A je short PBSYS125.106135EA106135D0 |. 8B4D D4 mov ecx,dword ptr ss:[ebp-2C]106135D3 |. 85C9 test ecx,ecx106135D5 |. 74 0D je short PBSYS125.106135E4106135D7 |. 8B55 D4 mov edx,dword ptr ss:[ebp-2C]106135DA |. 8B08 mov ecx,dword ptr ds:[eax]106135DC |. 52 push edx106135DD |. 50 push eax106135DE |. FF51 14 call dword ptr ds:[ecx+14]106135E1 |. 8B45 FC mov eax,dword ptr ss:[ebp-4]106135E4 |> 8B10 mov edx,dword ptr ds:[eax]106135E6 |. 50 push eax106135E7 |. FF52 08 call dword ptr ds:[edx+8]106135EA |> 8D45 FC lea eax,dword ptr ss:[ebp-4]106135ED |. 50 push eax106135EE |. E8 09120700 call <jmp.&PBSHR125.#1101>106135F3 |. 83C4 04 add esp,4106135F6 |. 85C0 test eax,eax106135F8 |. 7C 1C jl short PBSYS125.106
13616106135
FA |. 837D FC 14 cmp dword ptr ss:[ebp-4],14106135FE |. 7D 16 jge short PBSYS125.10613616 ; 判断是不是用了10天 开始对话框 提醒了吧10613600 |. 8B4E 28 mov ecx,dword ptr ds:[esi+28] ; 我目前还剩9天了 肯定是 不跳 执行这里了10613603 |. 51 push ecx ; /Arg210613604 |. 56 push esi ; |Arg110613605 |. E8 468CFFFF call PBSYS125.1060C250 ; \PBSYS125.1060C2501061360A |. 8B45 FC mov eax,dword ptr ss:[ebp-4]1061360D |. 83C4 08 add esp,810613610 |. 85C0 test eax,eax10613612 |. 7F 0B jg short PBSYS125.1061361F10613614 |. EB 07 jmp short PBSYS125.1061361D
2016年01月17日 01点01分 2
level 15
风萧寒211 楼主
8. F2 在106134A0 为了简化教程节约时间 我直接让软件过期不能用 好 我把时间调到2014-6-18
我们 停在 1061351B E8 72130700 call <jmp.&PBSHR125.#1145>
处 f7 步入 C/C++ code?
1234 10BC817D > \A1 EC93DC10 mov eax,dword ptr ds:[10DC93EC]10BC8182 . 85C0 test eax,eax10BC8184 0F85 D1010000 jnz PBSHR125.10BC835B ; 此处10BC818A . A1 0094DC10 mov eax,dword ptr ds:[10DC9400]
将jnz 改为 jmp 这样就达到了破解的目的
我们f9运行 看看效果 破解完成
9.现在 只是在 od 里 破解成功 如果脱离 od 也没问题呢 我们 ctrl+f2 重新载入 程序
继续来到10BC8184 把 jnz 改为 jmp 然后 右键 点击复制可执行文件 进入界面之后 继续右键保存文件 此时我们就可以 把PBSHR125.dll 修改的覆盖掉了 为了 安全起见 复制一份这个文件
好了 od 关闭 我们打开 pb 12.5 是不是正常了 运行了 把 电脑时间调回来吧
2016年01月17日 01点01分 3
level 2
这样以后所有的控件都可以完美使用吗
2016年04月06日 14点04分 4
level 1
顶,问题是PB的ORCA和动态编译还是用不了,这种破解只是去掉了日期判断,新的PB2019和PB2017 R3用这种方式没用,编译出来的EXE还是有时间限制
2019年03月22日 22点03分 5
level 1
大佬,没学过电脑,您这个第7步 真的给我看的一头雾水! 方便加个q聊么
2022年05月09日 11点05分 6
😃
2022年05月10日 05点05分
1