peid查为UPX 0.89.6 - 1.02 / 1.05 - 1.24 -> Markus & Laszlo [Overlay]
esp后先来到下面
0048D08F 8D4424 80 lea eax, dword ptr [esp-80]
0048D093 6A 00 push 0
0048D095 39C4 cmp esp, eax
0048D097 ^ 75 FA jnz short 0048D093
0048D099 83EC 80 sub esp, -80
0048D09C - E9 3D7BFCFF jmp 00454BDE
jmp 后来到下面
00454BDE E8 8EA50000 call 0045F171//入口点
00454BE3 ^ E9 16FEFFFF jmp 004549FE
00454BE8 C3 ret
00454BE9 B8 92FC4500 mov eax, 0045FC92
00454BEE A3 282D4700 mov dword ptr [472D28], eax
00454BF3 C705 2C2D4700 8>mov dword ptr [472D2C], 0045F38E
00454BFD C705 302D4700 4>mov dword ptr [472D30], 0045F34C
00454C07 C705 342D4700 8>mov dword ptr [472D34], 0045F380
00454C11 C705 382D4700 F>mov dword ptr [472D38], 0045F2F6
00454C1B A3 3C2D4700 mov dword ptr [472D3C], eax
00454C20 C705 402D4700 0>mov dword ptr [472D40], 0045FC0C
00454C2A C705 442D4700 0>mov dword ptr [472D44], 0045F30C
00454C34 C705 482D4700 7>mov dword ptr [472D48], 0045F276
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课