100093AB 00 db 00
100093AC 00 db 00
100093AD 00 db 00
100093AE 00 db 00
100093AF 00 db 00
100093B0 00 db 00
100093B1 00 db 00
100093B2 00 db 00
100093B3 00 db 00
100093B4 00 db 00
100093B5 00 db 00
100093B6 00 db 00
100093B7 00 db 00
100093B8 00 db 00
100093B9 00 db 00
100093BA 00 db 00
100093BB 00 db 00
100093BC 00 db 00
100093BD 00 db 00
100093BE 00 db 00
100093BF 00 db 00
100093C0 00 db 00
100093C1 . 837D 0C 01 cmp dword ptr ss:[ebp+C],1
说明,OEP在100093AB到100093C1之间,前面被偷了若干指令。
你可以用我的ollyhelper,可以轻易地断在dll的ep(不是OEP!)处
我用peid 0.92查得是DBPE 2.x -> Ding Boy
不过它实际上并不是dbpe.