我用peid查什么都没有,用fi查提示有UPX,但我看有调用彩虹的umhcontrol.ocx。脱壳后运行不了。脱壳后的程序用PEID查了一下使用了下面这些加密算法:MD5 :: 0026EF51 :: 0066EF51
The reference is above.
MD5 :: 0037857B :: 0077857B
The reference is above.
RIJNDAEL [S] [char] :: 002740A8 :: 006740A8
Referenced at 0066E473
Referenced at 0066E482
Referenced at 0066E491
Referenced at 0066E4A0
Referenced at 0066E4E6
Referenced at 0066E4F4
Referenced at 0066E501
Referenced at 0066E50E
Referenced at 00777D8B
RIJNDAEL [S] [char] :: 0037AA4A :: 0077AA4A
The reference is above.
RIJNDAEL [S-inv] [char] :: 002761A8 :: 006761A8
Referenced at 0066EBB4
Referenced at 0066EBC0
Referenced at 0066EBC6
Referenced at 0066EBD6
Referenced at 0066EBE3
Referenced at 0066EBF3
Referenced at 0066EBFF
Referenced at 0066EC0C
Referenced at 0066EC12
Referenced at 0066EC27
Referenced at 0066EC30
Referenced at 0066EC3D
Referenced at 0066EC4E
Referenced at 0066EC57
Referenced at 0066EC64
Referenced at 0066EC71
RIJNDAEL [S-inv] [char] :: 0037CB84 :: 0077CB84
The reference is above.
请问各位高手,如果是从系统领空中退出来的(比如ntdll,vb60.dll),那不能说明是程序带了自较验吧?因为我脱壳后的程序根本就不能运行,是从这段代码中退出的:
7C9585FA 8DA424 00000000 lea esp, dword ptr [esp]
7C958601 8DA424 00000000 lea esp, dword ptr [esp]
7C958608 > 8BD4 mov edx, esp
7C95860A 0F34 sysenter
7C95860C > C3 retn
在retn那里程序就停止了。我想如果有自较验那应当也是在程序领空里会有代码啊。我跟了半天就在ntdll和vb60.dll里转来转去,然后就退出了。
还请高手指点一二啊。