请问如何脱ASProtect 1.2x - 1.3x [Registered] -> Alexey Solodovnikov的壳?
1\我先PEID V0.95查为ASProtect 1.2x - 1.3x [Registered] -> Alexey Solodovnikov
2\后用插件VeiA 0.15查为Version: [ Unknown! ], Signature: [ 9BCBD2C6 ]无法查到!
3\用PEID的外部扫描后得出:ASProtect v1.2x (New Strain) *
4\OD载入后用如下脚本:Aspr2.XX_unpacker_v1.0E.osc/Aspr2.XX_unpacker_v1.0SC.osc/Aspr2.XX_unpacker_v1.14aSC.osc/Aspr2.XX_unpacker_v1.15E.osc等在运行到如下代码时均出现提示:
04860000 60 pushad
04860001 9C pushfd
04860002 68 00004000 push 400000 ; ASCII "MZP"
04860007 68 00009A05 push 59A0000
0486000C 68 00009905 push 5990000
04860011 E8 EAFF1401 call 059B0000
04860016 8305 04018604 04 add dword ptr ds:[4860104],4
0486001D C605 7A008604 2D mov byte ptr ds:[486007A],2D
04860024 C705 00018604 0400>mov dword ptr ds:[4860100],59C0004
0486002E 68 00004000 push 400000 ; ASCII "MZP"
04860033 68 04009A05 push 59A0004
04860038 68 04009905 push 5990004
0486003D E8 BEFF1401 call 059B0000
04860042 EB 5C jmp short 048600A0
04860044 90 nop
04860045 90 nop
04860046 0000 add byte ptr ds:[eax],al
04860048 0000 add byte ptr ds:[eax],al
0486004A 0000 add byte ptr ds:[eax],al
0486004C 0000 add byte ptr ds:[eax],al
0486004E 0000 add byte ptr ds:[eax],al
04860050 8B15 00018604 mov edx,dword ptr ds:[4860100]
04860056 8B12 mov edx,dword ptr ds:[edx]
04860058 90 nop
04860059 90 nop
0486005A 8305 00018604 08 add dword ptr ds:[4860100],8
04860061 - E9 C2011501 jmp 059B0228
04860066 0000 add byte ptr ds:[eax],al
04860068 0000 add byte ptr ds:[eax],al
0486006A 0000 add byte ptr ds:[eax],al
0486006C 0000 add byte ptr ds:[eax],al
0486006E 90 nop
0486006F 90 nop
04860070 53 push ebx
04860071 8B1D 04018604 mov ebx,dword ptr ds:[4860104]
04860077 8913 mov dword ptr ds:[ebx],edx
04860079 8305 04018604 08 add dword ptr ds:[4860104],8
04860080 5B pop ebx
04860081 90 nop
04860082 90 nop
04860083 64:FF35 00000000 push dword ptr fs:[0]
0486008A - E9 D5001501 jmp 059B0164
0486008F 90 nop
换过多个OD均无效!
本人是菜鸟!还请各位高人指教帮助脱下此壳!
软件下载地址:
http://u.115.com/file/f26a94440b
CRS.rar-----(提取码:f26a94440b)
[培训]《安卓高级研修班(网课)》月薪三万计划,掌握调试、分析还原ollvm、vmp的方法,定制art虚拟机自动化脱壳的方法