tElock 0.98b1 -> tE! [Overlay] 用脱壳机脱了后,不能运行应该要修复IAT表,有大哥们知道怎么修复的吗?小弟感谢了!!!!
用OD载入
00484724 > $ 55 PUSH EBP
00484725 . 8BEC MOV EBP,ESP
00484727 . B9 7A000000 MOV ECX,7A
0048472C > 6A 00 PUSH 0
0048472E . 6A 00 PUSH 0
00484730 . 49 DEC ECX
00484731 .^ 75 F9 JNZ SHORT PhoneCtl.0048472C
00484733 . 53 PUSH EBX
00484734 . 56 PUSH ESI
00484735 . 57 PUSH EDI
00484736 . B8 2C444800 MOV EAX,PhoneCtl.0048442C
0048473B . E8 DC21F8FF CALL PhoneCtl.0040691C
00484740 . 33C0 XOR EAX,EAX
00484742 . 55 PUSH EBP
00484743 . 68 5B714800 PUSH PhoneCtl.0048715B
00484748 . 64:FF30 PUSH DWORD PTR FS:[EAX]
0048474B . 64:8920 MOV DWORD PTR FS:[EAX],ESP
0048474E . A1 08694A00 MOV EAX,DWORD PTR DS:[4A6908]
00484753 . 8B00 MOV EAX,DWORD PTR DS:[EAX]
00484755 . E8 123EFDFF CALL PhoneCtl.0045856C
0048475A . A1 08694A00 MOV EAX,DWORD PTR DS:[4A6908]
0048475F . 8B00 MOV EAX,DWORD PTR DS:[EAX]
00484761 . E8 1E3EFDFF CALL PhoneCtl.00458584
00484766 . 8D55 E8 LEA EDX,DWORD PTR SS:[EBP-18]
00484769 . A1 08694A00 MOV EAX,DWORD PTR DS:[4A6908]
0048476E . 8B00 MOV EAX,DWORD PTR DS:[EAX]
00484770 . E8 6745FDFF CALL PhoneCtl.00458CDC
00484775 . 8B55 E8 MOV EDX,DWORD PTR SS:[EBP-18]
00484778 . B8 F47C4A00 MOV EAX,PhoneCtl.004A7CF4
0048477D . E8 9AFFF7FF CALL PhoneCtl.0040471C
00484782 . C605 887D4A00>MOV BYTE PTR DS:[4A7D88],0
00484789 . A1 F47C4A00 MOV EAX,DWORD PTR DS:[4A7CF4]
0048478E . E8 A9C1FFFF CALL PhoneCtl.0048093C
00484793 . A2 B8654A00 MOV BYTE PTR DS:[4A65B8],AL
00484798 . 803D B8654A00>CMP BYTE PTR DS:[4A65B8],1
0048479F . 0F85 21270000 JNZ PhoneCtl.00486EC6
004847A5 . 8D55 E0 LEA EDX,DWORD PTR SS:[EBP-20]
004847A8 . A1 F47C4A00 MOV EAX,DWORD PTR DS:[4A7CF4]
004847AD . E8 62C0FFFF CALL PhoneCtl.00480814
004847B2 . 8B45 E0 MOV EAX,DWORD PTR SS:[EBP-20]
004847B5 . 8D55 E4 LEA EDX,DWORD PTR SS:[EBP-1C]
004847B8 . E8 CFC5FFFF CALL PhoneCtl.00480D8C
004847BD . 8B55 E4 MOV EDX,DWORD PTR SS:[EBP-1C]
004847C0 . B8 CC7C4A00 MOV EAX,PhoneCtl.004A7CCC
004847C5 . E8 52FFF7FF CALL PhoneCtl.0040471C
004847CA . A1 F47C4A00 MOV EAX,DWORD PTR DS:[4A7CF4]
004847CF . E8 08BEFFFF CALL PhoneCtl.004805DC
004847D4 . 8BD8 MOV EBX,EAX
004847D6 . A1 CC7C4A00 MOV EAX,DWORD PTR DS:[4A7CCC]
004847DB . 8038 79 CMP BYTE PTR DS:[EAX],79
004847DE . 74 0A JE SHORT PhoneCtl.004847EA
004847E0 . A1 CC7C4A00 MOV EAX,DWORD PTR DS:[4A7CCC]
004847E5 . 8038 6F CMP BYTE PTR DS:[EAX],6F
004847E8 . 75 32 JNZ SHORT PhoneCtl.0048481C
004847EA > 33C9 XOR ECX,ECX
004847EC . B2 01 MOV DL,1
004847EE . A1 7CEA4700 MOV EAX,DWORD PTR DS:[47EA7C]
004847F3 . E8 4CB8FCFF CALL PhoneCtl.00450044
004847F8 . 8BF0 MOV ESI,EAX
004847FA . BA 78714800 MOV EDX,PhoneCtl.00487178 ; ASCII "EZIRIZ .NET Reactor!"
004847FF . 8BC6 MOV EAX,ESI
00484801 . E8 8EA4FFFF CALL PhoneCtl.0047EC94
00484806 . BA 98714800 MOV EDX,PhoneCtl.00487198 ; ASCII "This application is protected by an unregistered version of "EZIRIZ .NET Reactor"!"
0048480B . 8BC6 MOV EAX,ESI
0048480D . E8 0AA5FFFF CALL PhoneCtl.0047ED1C
00484812 . 8BC6 MOV EAX,ESI
00484814 . 8B10 MOV EDX,DWORD PTR DS:[EAX]
00484816 . FF92 F8000000 CALL DWORD PTR DS:[EDX+F8]
0048481C > A1 CC7C4A00 MOV EAX,DWORD PTR DS:[4A7CCC]
00484821 . 8038 6A CMP BYTE PTR DS:[EAX],6A
00484824 . 74 0A JE SHORT PhoneCtl.00484830
00484826 . A1 CC7C4A00 MOV EAX,DWORD PTR DS:[4A7CCC]
0048482B . 8038 79 CMP BYTE PTR DS:[EAX],79
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!