此软件的壳深度扫描壳为ASPack 2.12 -> Alexey Solodovnikov [Overlay]
OD加载显示内存71496A49地址不易读取,请修改EIP或忽略所有异常,看不到代码,
SHIFT+F9跳过,代码就看到了。
入口如下:
007AB001 > 60 pushad
007AB002 E8 03000000 call 测试.007AB00A
007AB007 - E9 EB045D45 jmp 45D7B4F7
007AB00C 55 push ebp
007AB00D C3 retn
007AB00E E8 01000000 call 测试.007AB014
007AB013 EB 5D jmp short 测试.007AB072
007AB015 BB EDFFFFFF mov ebx, -13
007AB01A 03DD add ebx, ebp
007AB01C 81EB 00B03A00 sub ebx, 3AB000
007AB022 83BD 22040000 0>cmp dword ptr [ebp+422], 0
007AB029 899D 22040000 mov dword ptr [ebp+422], ebx
007AB02F 0F85 65030000 jnz 测试.007AB39A
007AB035 8D85 2E040000 lea eax, dword ptr [ebp+42E]
007AB03B 50 push eax
007AB03C FF95 4D0F0000 call dword ptr [ebp+F4D]
007AB042 8985 26040000 mov dword ptr [ebp+426], eax
007AB048 8BF8 mov edi, eax
007AB04A 8D5D 5E lea ebx, dword ptr [ebp+5E]
007AB04D 53 push ebx
007AB04E 50 push eax
007AB04F FF95 490F0000 call dword ptr [ebp+F49]
007AB055 8985 4D050000 mov dword ptr [ebp+54D], eax
007AB05B 8D5D 6B lea ebx, dword ptr [ebp+6B]
连接
http://d.namipan.com/d/f0af5b29522467f9e52b97a63d5b1648e1adbcd04a612500
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!