怎么脱了壳 PEid 报 Armadillo 1.xx - 2.xx -> Silicon Realms Toolworks
它上面是说公具吗,可以独立分出为编译器,真神奇
//入口是这个吧
00441C30 D>push ebp
00441C31 mov ebp,esp
00441C33 push -1
00441C35 push 4495D0
00441C3A push 4419CC ; SE handler installation
00441C3F mov eax,dword ptr fs:[0]
00441C45 push eax
00441C46 mov dword ptr fs:[0],esp
00441C4D sub esp,58
00441C50 push ebx
00441C51 push esi
00441C52 push edi
00441C53 mov dword ptr ss:[ebp-18],esp
00441C56 call dword ptr ds:[4791C8]
00441C5C xor edx,edx
00441C5E mov dl,ah
00441C60 mov dword ptr ds:[477418],edx
00441C66 mov ecx,eax
00441C68 and ecx,0FF
00441C6E mov dword ptr ds:[477414],ecx
00441C74 shl ecx,8
00441C77 add ecx,edx
00441C79 mov dword ptr ds:[477410],ecx
00441C7F shr eax,10
00441C82 mov dword ptr ds:[47740C],eax
00441C87 xor esi,esi
00441C89 push esi
00441C8A call 004443CC ; DUMPED.004443CC
00441C8F pop ecx
00441C90 test eax,eax
00441C92 jnz short 00441C9C ; DUMPED.00441C9C
00441C94 push 1C
00441C96 call 00441D4B ; DUMPED.00441D4B
00441C9B pop ecx
00441C9C mov dword ptr ss:[ebp-4],esi
00441C9F call 004440AC ; DUMPED.004440AC
00441CA4 call dword ptr ds:[4791CC] ; [GetCommandLineA
有上千个以上的 int3, 真够狠的,反正我又不会用, 向它先
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!