文件下载地址:mmm.rar
我是菜鸟,正在不断学习种
今天找了一个软件,用fi查telock 0.98加的壳, 于是按照论坛里的帖子试着脱,但到了找OEP的时候,老是刷一下代码窗口里什么都没了,试了好几次,好不容易眼疾手快的 抓住了,一看:
00475000 - E9 DE61FBFF JMP mmm.00455000
00475005 0000 ADD BYTE PTR DS:[EAX],AL
00475007 0000 ADD BYTE PTR DS:[EAX],AL
00475009 0000 ADD BYTE PTR DS:[EAX],AL
0047500B 0000 ADD BYTE PTR DS:[EAX],AL
0047500D 0000 ADD BYTE PTR DS:[EAX],AL
0047500F 0000 ADD BYTE PTR DS:[EAX],AL
一看这个00455000的地址就不象是入口地址,哪里那么有零有整的。
结果一看节表
Memory map
Address Size Owner Section Contains Type Access Initial Mapped as
00400000 00001000 mmm PE header Imag RW RWE
00401000 00054000 mmm PELOCKnt Imag RW RWE
00455000 00078000 mmm PELOCKnt code Imag RW RWE
004CD000 00003000 mmm .rsrc data,resourc Imag RW RWE
004D0000 00003000 mmm PELOCKnt SFX,imports, Imag RW RWE
这个不就是没脱壳的代码段么,又绕回来了。
另外找输入表那步我不知道怎么计算输入表的大小,教程里没说:
004D1991 77 F9 72 01 0C 98 33 C0 EB 01 B8 0B E4 75 01 EB w?.?离?漉
004D19A1 EB 20 E8 BE 01 00 00 F9 72 02 CD 20 33 C5 F5 E8 ?杈..??3捧?
004D19B1 06 00 00 00 40 E9 06 00 00 00 1B C1 C3 48 8B C5 ...@?...撩H?
004D19C1 03 C7 E8 39 00 00 00 5B E8 00 00 00 00 00 00 00 氰9...[?......
004D19D1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D19E1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D19F1 00 00 00 00 00 66 AB FF E3 F0 B8 FA 20 13 F7 A4 .....f?沭跟 鳏
004D1A01 EB 02 CD 20 98 0B C0 60 E8 06 00 00 00 8B 64 24 ???类?...?$
004D1A11 08 EB 0D 2B FF 64 FF 37 64 89 27 F1 F7 F7 EB E8 ?+??d?聍麟?
004D1A21 85 E4 79 03 0F 91 42 1D 9B E3 22 2F 2B D2 64 8F ?y??"/+忆?
004D1A31 02 5A EB 02 CD 20 0B C3 60 E8 06 00 00 00 8B 64 Z??绵?...?
004D1A41 24 08 EB 1A 64 67 FF 36 00 00 64 67 89 26 00 00 $?dg?..dg?..
004D1A51 9C 81 0C 24 00 01 00 00 9D F8 73 DC CD 20 64 67 ?.$...?s芡 dg
004D1A61 8F 06 00 00 58 61 EB 02 CD 20 13 C5 48 E8 00 00 ?..Xa??湃?.
004D1A71 00 00 0B E4 75 01 EB 13 C3 8B 1C 24 58 81 EB 6E ..漉??$X?n
004D1A81 14 41 00 0B E4 75 01 EB F8 E8 0A 00 00 00 03 C6 A.漉滕?...?
004D1A91 E9 08 00 00 00 C1 D8 96 90 C3 1B C2 48 83 C8 5F ?...霖??氯?_
004D1AA1 BE 50 0D AF 6F 81 F6 93 1E EE 6F EB 02 CD 20 03 拘.???铒??
004D1AB1 F3 68 2E 32 11 2D 5F 81 F7 23 32 11 2D F8 73 02 箬.2-_?#2-?
004D1AC1 0F 88 13 C7 98 68 9D 74 A3 51 5A EB 01 B8 33 C5 ??h?QZ???
004D1AD1 F9 6B D2 5D 31 16 D1 C2 F9 83 D2 27 46 46 46 46 ?逸1崖??FFFF
004D1AE1 85 E4 79 03 0F 91 42 1D 75 45 7F 53 4F F9 72 02 ?y?uESO?
004D1AF1 CD 20 03 C2 81 C2 7E 39 A1 04 EB 01 70 98 51 8B ??漫9??p??
004D1B01 CF E3 03 59 EB CA 59 EB 02 CD 20 40 03 C6 61 F8 香Y胧Y??@漆?
004D1B11 73 02 0F 21 40 13 C5 C3 90 BA 85 9A 21 CE 99 A1 s!@琶??!??
004D1B21 1A FC A4 F0 29 4C 43 39 E7 2A 49 48 C6 1F 08 49 ??LC9?IH?I
004D1B31 2D D5 CB 73 3B BF 8C 9A 7C BA A9 C8 F3 27 5B 90 -账s;??憨润'[?
004D1B41 3D EE 4C FC 18 F9 DA 1E 2F 8C E5 4E B5 99 0F 88 =钐??/?N??
004D1B51 EB B2 BA BF 0B CB 4C 34 17 79 A0 C9 97 B7 4D 8F 氩嚎颂4y_?吠?
004D1B61 24 A9 FC 23 61 6C 18 C8 F9 65 DD 10 DC BC 8A 61 $?#al腮e?芗?
004D1B71 36 42 AA 64 A5 3C 2E CB 27 6A FE 89 70 DD 9F D1 6B??.?j?p??
004D1B81 D5 73 81 AE E6 3C 2B B4 2B C9 6A 20 60 97 96 3B 阵??+?申 `?;
004D1B91 B1 06 0B 17 57 6C A4 51 FF C5 C9 6B F3 F8 E2 A7 ?Wlぱ?呻篪猝
004D1BA1 74 AF 73 A9 D4 1A 18 8C 68 AF 4E 16 B6 F7 ED 9F t?┰??恩?
004D1BB1 29 7D EE B7 B2 2E B5 8F 9F 3B AE 2C D9 D7 FC CF )}罘????僮?
004D1BC1 8A 0B 11 E8 00 00 00 00 81 2C 24 37 02 00 00 FF ??...?$7..?
004D1BD1 64 24 04 B5 00 E9 25 E4 FF FF 00 00 00 B4 BE 18 d$????..淳
004D1BE1 AE 1E 1C 0D 00 00 00 00 00 00 00 00 00 3E 1C 0D ?..........>.
004D1BF1 00 2E 1C 0D 00 26 1C 0D 00 00 00 00 00 00 00 00 ....&.........
004D1C01 00 4B 1C 0D 00 36 1C 0D 00 00 00 00 00 00 00 00 .K..6.........
004D1C11 00 00 00 00 00 00 00 00 00 00 00 00 00 56 1C 0D .............V.
004D1C21 00 00 00 00 00 69 1C 0D 00 00 00 00 00 D9 AC E7 .....i......佻?
004D1C31 77 00 00 00 00 24 E8 D6 77 00 00 00 00 6B 65 72 w....$柚w....ker
004D1C41 6E 65 6C 33 32 2E 64 6C 6C 00 75 73 65 72 33 32 nel32.dll.user32
004D1C51 2E 64 6C 6C 00 00 00 47 65 74 4D 6F 64 75 6C 65 .dll...GetModule
004D1C61 48 61 6E 64 6C 65 41 00 00 00 4D 65 73 73 61 67 HandleA...Messag
004D1C71 65 42 6F 78 41 00 00 00 00 00 00 00 00 00 00 00 eBoxA...........
004D1C81 00 08 00 00 00 00 00 BC 1D 0D 00 E2 1D 0D 00 F9 ......?..?..?
004D1C91 1D 0D 00 3C 1E 0D 00 57 1E 0D 00 7C 1E 0D 00 91 ..<..W..|..?
004D1CA1 1E 0D 00 0E 1F 0D 00 00 00 E6 77 24 00 00 00 0E ......骥$...
004D1CB1 50 05 00 00 00 00 00 00 D0 0C 00 00 00 0D 00 00 P......?......
004D1CC1 00 40 00 00 00 40 00 00 00 00 00 00 00 00 00 00 .@...@..........
004D1CD1 00 00 00 D3 C4 6A 95 ED 43 0E C3 01 00 00 00 FF ...幽j?C?...?
004D1CE1 AF FA FF 00 50 05 00 00 80 07 00 00 00 00 00 00 ??P..?......
004D1CF1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1D01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1D11 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1D21 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1D31 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1D41 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1D51 00 00 00 00 00 00 00 00 00 00 00 61 67 E1 3C B2 ...........ag??
004D1D61 FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 ?.?..?..?..?
004D1D71 FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 ?.?..?..?..?
004D1D81 FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 ?.?..?..?..?
004D1D91 FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 FF 00 00 00 ?.?..?..?...
004D1DA1 00 E6 77 F7 2B 5E 22 00 00 00 00 00 00 00 00 00 .骥?^".........
004D1DB1 00 00 00 E3 00 3A 00 36 50 45 00 54 65 74 72 69 ...?:.6PE.Tetri
004D1DC1 73 54 65 72 6D 69 6E 61 74 6F 72 2E 65 78 65 00 sTerminator.exe.
004D1DD1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1DE1 00 49 6E 74 65 72 6E 61 6C 20 4C 6F 61 64 65 72 .Internal Loader
004D1DF1 20 45 72 72 6F 72 21 00 54 68 69 73 20 50 72 6F Error!.This Pro
004D1E01 67 72 61 6D 20 64 6F 65 73 20 6E 6F 74 20 72 75 gram does not ru
004D1E11 6E 20 6F 6E 20 6D 61 63 68 69 6E 65 73 20 77 69 n on machines wi
004D1E21 74 68 20 61 63 74 69 76 65 20 73 79 73 74 65 6D th active system
004D1E31 20 64 65 62 75 67 67 65 72 21 00 45 72 72 6F 72 debugger!.Error
004D1E41 20 77 68 69 6C 65 20 6C 6F 61 64 69 6E 67 20 61 while loading a
004D1E51 20 44 4C 4C 21 00 45 72 72 6F 72 20 77 68 69 6C DLL!.Error whil
004D1E61 65 20 6C 6F 63 61 74 69 6E 67 20 61 20 44 4C 4C e locating a DLL
004D1E71 20 66 75 6E 63 74 69 6F 6E 21 00 44 65 63 6F 6D function!.Decom
004D1E81 70 72 65 73 73 69 6F 6E 20 65 72 72 6F 72 21 00 pression error!.
004D1E91 43 52 43 20 65 72 72 6F 72 21 20 46 69 6C 65 20 CRC error! File
004D1EA1 63 6F 6E 74 65 6E 74 20 68 61 73 20 62 65 65 6E content has been
004D1EB1 20 6D 6F 64 69 66 69 65 64 2E 20 49 66 20 79 6F modified. If yo
004D1EC1 75 20 72 75 6E 20 61 20 73 79 73 74 65 6D 0D 0A u run a system..
004D1ED1 64 65 62 75 67 67 65 72 2C 20 63 6C 65 61 72 20 debugger, clear
004D1EE1 61 6C 6C 20 62 72 65 61 6B 70 6F 69 6E 74 73 20 all breakpoints
004D1EF1 62 65 66 6F 72 65 20 72 75 6E 6E 69 6E 67 20 74 before running t
004D1F01 68 69 73 20 70 72 6F 67 72 61 6D 21 00 49 6E 74 his program!.Int
004D1F11 65 67 72 69 74 79 20 63 68 65 63 6B 20 66 61 69 egrity check fai
004D1F21 6C 65 64 21 20 54 68 69 73 20 46 69 6C 65 20 68 led! This File h
004D1F31 61 73 20 62 65 65 6E 20 6D 6F 64 69 66 69 65 64 as been modified
004D1F41 2E 0D 0A 52 65 61 73 6F 6E 20 6D 69 67 68 74 20 ...Reason might
004D1F51 62 65 20 61 20 70 6F 73 73 69 62 6C 65 20 76 69 be a possible vi
004D1F61 72 75 73 20 69 6E 66 65 63 74 69 6F 6E 21 00 A8 rus infection!.?
004D1F71 AB D1 A5 5A BD BF 78 1E F2 18 7A B2 A8 9E 9C 00 ?ペ娇x?z波?.
004D1F81 00 09 09 08 08 0A 00 00 00 00 00 00 00 00 00 00 ..............
004D1F91 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1FA1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1FB1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1FC1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1FD1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1FE1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D1FF1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2001 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2011 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2021 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2031 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2041 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2051 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2061 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2071 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2081 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2091 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D20A1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D20B1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D20C1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D20D1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D20E1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D20F1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2101 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2111 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2121 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2131 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2141 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2151 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2161 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2171 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2181 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D2191 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D21A1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D21B1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D21C1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D21D1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D21E1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
004D21F1 00 00 00 00 00 00 00 78 69 78 69 68 65 68 65 00 .......xixihehe.
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课