大家好!
在xp下脱了个壳在xp下能运行,在win7下不能运行,在win7下脱,xp用不了,iat都一样就是后面的数字不一样,大家帮我分析分析,谢谢!下面是个例子
这个是xp下面的iat
FThunk: 00173000 函数数: 00000012
1 00173000 advapi32.dll 01D3 RegDeleteKeyA
1 00173004 advapi32.dll 01E6 RegOpenKeyExA
1 00173008 advapi32.dll 00B1 DeleteService
1 0017300C advapi32.dll 01AF OpenServiceA
1 00173010 advapi32.dll 0242 StartServiceA
1 00173014 advapi32.dll 0044 ControlService
1 00173018 advapi32.dll 01C3 QueryServiceStatus
1 0017301C advapi32.dll 0066 CreateServiceA
1 00173020 advapi32.dll 01DA RegEnumKeyExA
1 00173024 advapi32.dll 01CC RegCloseKey
1 00173028 advapi32.dll 01CF RegCreateKeyA
1 0017302C advapi32.dll 01AD OpenSCManagerA
1 00173030 advapi32.dll 0040 CloseServiceHandle
1 00173034 advapi32.dll 01D0 RegCreateKeyExA
1 00173038 advapi32.dll 01D5 RegDeleteValueA
1 0017303C advapi32.dll 01FD RegSetValueExA
1 00173040 advapi32.dll 01E5 RegOpenKeyA
1 00173044 advapi32.dll 01F0 RegQueryValueExA
这个是win7下面的
FThunk: 00173000 NbFunc: 00000012
1 00173000 advapi32.dll 0626 RegDeleteKeyA
1 00173004 advapi32.dll 0649 RegOpenKeyExA
1 00173008 advapi32.dll 04C4 DeleteService
1 0017300C advapi32.dll 05E3 OpenServiceA
1 00173010 advapi32.dll 06AF StartServiceA
1 00173014 advapi32.dll 0446 ControlService
1 00173018 advapi32.dll 0611 QueryServiceStatus
1 0017301C advapi32.dll 046A CreateServiceA
1 00173020 advapi32.dll 0637 RegEnumKeyExA
1 00173024 advapi32.dll 0619 RegCloseKey
1 00173028 advapi32.dll 0620 RegCreateKeyA
1 0017302C advapi32.dll 05E1 OpenSCManagerA
1 00173030 advapi32.dll 0441 CloseServiceHandle
1 00173034 advapi32.dll 0621 RegCreateKeyExA
1 00173038 advapi32.dll 0630 RegDeleteValueA
1 0017303C advapi32.dll 0666 RegSetValueExA
1 00173040 advapi32.dll 0648 RegOpenKeyA
1 00173044 advapi32.dll 0656 RegQueryValueExA
[课程]Android-CTF解题方法汇总!