首页
社区
课程
招聘
tELock 0.98加的壳我找不到OEP了
发表于: 2005-6-17 19:39 4633

tELock 0.98加的壳我找不到OEP了

2005-6-17 19:39
4633
文件下载地址:mmm.rar
我是菜鸟,正在不断学习种
今天找了一个软件,用fi查telock 0.98加的壳, 于是按照论坛里的帖子试着脱,但到了找OEP的时候,老是刷一下代码窗口里什么都没了,试了好几次,好不容易眼疾手快的 抓住了,一看:
00475000  - E9 DE61FBFF    JMP mmm.00455000
00475005    0000            ADD BYTE PTR DS:[EAX],AL
00475007    0000            ADD BYTE PTR DS:[EAX],AL
00475009    0000            ADD BYTE PTR DS:[EAX],AL
0047500B    0000            ADD BYTE PTR DS:[EAX],AL
0047500D    0000            ADD BYTE PTR DS:[EAX],AL
0047500F    0000            ADD BYTE PTR DS:[EAX],AL

一看这个00455000的地址就不象是入口地址,哪里那么有零有整的。
结果一看节表

Memory map
Address    Size       Owner      Section         Contains      Type   Access    Initial   Mapped as

00400000   00001000   mmm                   PE header     Imag   RW        RWE
00401000   00054000   mmm   PELOCKnt                      Imag   RW        RWE
00455000   00078000   mmm   PELOCKnt        code          Imag   RW        RWE
004CD000   00003000   mmm   .rsrc           data,resourc  Imag   RW        RWE
004D0000   00003000   mmm   PELOCKnt        SFX,imports,  Imag   RW        RWE

这个不就是没脱壳的代码段么,又绕回来了。

另外找输入表那步我不知道怎么计算输入表的大小,教程里没说:

004D1991  77 F9 72 01 0C 98 33 C0 EB 01 B8 0B E4 75 01 EB  w?.?离?漉
004D19A1  EB 20 E8 BE 01 00 00 F9 72 02 CD 20 33 C5 F5 E8  ?杈..??3捧?
004D19B1  06 00 00 00 40 E9 06 00 00 00 1B C1 C3 48 8B C5  ...@?...撩H?
004D19C1  03 C7 E8 39 00 00 00 5B E8 00 00 00 00 00 00 00  氰9...[?......
004D19D1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D19E1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D19F1  00 00 00 00 00 66 AB FF E3 F0 B8 FA 20 13 F7 A4  .....f?沭跟 鳏
004D1A01  EB 02 CD 20 98 0B C0 60 E8 06 00 00 00 8B 64 24  ???类?...?$
004D1A11  08 EB 0D 2B FF 64 FF 37 64 89 27 F1 F7 F7 EB E8  ?+??d?聍麟?
004D1A21  85 E4 79 03 0F 91 42 1D 9B E3 22 2F 2B D2 64 8F  ?y??"/+忆?
004D1A31  02 5A EB 02 CD 20 0B C3 60 E8 06 00 00 00 8B 64  Z??绵?...?
004D1A41  24 08 EB 1A 64 67 FF 36 00 00 64 67 89 26 00 00  $?dg?..dg?..
004D1A51  9C 81 0C 24 00 01 00 00 9D F8 73 DC CD 20 64 67  ?.$...?s芡 dg
004D1A61  8F 06 00 00 58 61 EB 02 CD 20 13 C5 48 E8 00 00  ?..Xa??湃?.
004D1A71  00 00 0B E4 75 01 EB 13 C3 8B 1C 24 58 81 EB 6E  ..漉??$X?n
004D1A81  14 41 00 0B E4 75 01 EB F8 E8 0A 00 00 00 03 C6  A.漉滕?...?
004D1A91  E9 08 00 00 00 C1 D8 96 90 C3 1B C2 48 83 C8 5F  ?...霖??氯?_
004D1AA1  BE 50 0D AF 6F 81 F6 93 1E EE 6F EB 02 CD 20 03  拘.???铒??
004D1AB1  F3 68 2E 32 11 2D 5F 81 F7 23 32 11 2D F8 73 02  箬.2-_?#2-?
004D1AC1  0F 88 13 C7 98 68 9D 74 A3 51 5A EB 01 B8 33 C5  ??h?QZ???
004D1AD1  F9 6B D2 5D 31 16 D1 C2 F9 83 D2 27 46 46 46 46  ?逸1崖??FFFF
004D1AE1  85 E4 79 03 0F 91 42 1D 75 45 7F 53 4F F9 72 02  ?y?uESO?
004D1AF1  CD 20 03 C2 81 C2 7E 39 A1 04 EB 01 70 98 51 8B  ??漫9??p??
004D1B01  CF E3 03 59 EB CA 59 EB 02 CD 20 40 03 C6 61 F8  香Y胧Y??@漆?
004D1B11  73 02 0F 21 40 13 C5 C3 90 BA 85 9A 21 CE 99 A1  s!@琶??!??
004D1B21  1A FC A4 F0 29 4C 43 39 E7 2A 49 48 C6 1F 08 49  ??LC9?IH?I
004D1B31  2D D5 CB 73 3B BF 8C 9A 7C BA A9 C8 F3 27 5B 90  -账s;??憨润'[?
004D1B41  3D EE 4C FC 18 F9 DA 1E 2F 8C E5 4E B5 99 0F 88  =钐??/?N??
004D1B51  EB B2 BA BF 0B CB 4C 34 17 79 A0 C9 97 B7 4D 8F  氩嚎颂4y_?吠?
004D1B61  24 A9 FC 23 61 6C 18 C8 F9 65 DD 10 DC BC 8A 61  $?#al腮e?芗?
004D1B71  36 42 AA 64 A5 3C 2E CB 27 6A FE 89 70 DD 9F D1  6B??.?j?p??
004D1B81  D5 73 81 AE E6 3C 2B B4 2B C9 6A 20 60 97 96 3B  阵??+?申 `?;
004D1B91  B1 06 0B 17 57 6C A4 51 FF C5 C9 6B F3 F8 E2 A7  ?Wlぱ?呻篪猝
004D1BA1  74 AF 73 A9 D4 1A 18 8C 68 AF 4E 16 B6 F7 ED 9F  t?┰??恩?
004D1BB1  29 7D EE B7 B2 2E B5 8F 9F 3B AE 2C D9 D7 FC CF  )}罘????僮?
004D1BC1  8A 0B 11 E8 00 00 00 00 81 2C 24 37 02 00 00 FF  ??...?$7..?
004D1BD1  64 24 04 B5 00 E9 25 E4 FF FF 00 00 00 B4 BE 18  d$????..淳
004D1BE1  AE 1E 1C 0D 00 00 00 00 00 00 00 00 00 3E 1C 0D  ?..........>.
004D1BF1  00 2E 1C 0D 00 26 1C 0D 00 00 00 00 00 00 00 00  ....&.........
004D1C01  00 4B 1C 0D 00 36 1C 0D 00 00 00 00 00 00 00 00  .K..6.........
004D1C11  00 00 00 00 00 00 00 00 00 00 00 00 00 56 1C 0D  .............V.
004D1C21  00 00 00 00 00 69 1C 0D 00 00 00 00 00 D9 AC E7  .....i......佻?
004D1C31  77 00 00 00 00 24 E8 D6 77 00 00 00 00 6B 65 72  w....$柚w....ker
004D1C41  6E 65 6C 33 32 2E 64 6C 6C 00 75 73 65 72 33 32  nel32.dll.user32
004D1C51  2E 64 6C 6C 00 00 00 47 65 74 4D 6F 64 75 6C 65  .dll...GetModule
004D1C61  48 61 6E 64 6C 65 41 00 00 00 4D 65 73 73 61 67  HandleA...Messag
004D1C71  65 42 6F 78 41 00 00 00 00 00 00 00 00 00 00 00  eBoxA...........
004D1C81  00 08 00 00 00 00 00 BC 1D 0D 00 E2 1D 0D 00 F9  ......?..?..?
004D1C91  1D 0D 00 3C 1E 0D 00 57 1E 0D 00 7C 1E 0D 00 91  ..<..W..|..?
004D1CA1  1E 0D 00 0E 1F 0D 00 00 00 E6 77 24 00 00 00 0E  ......骥$...
004D1CB1  50 05 00 00 00 00 00 00 D0 0C 00 00 00 0D 00 00  P......?......
004D1CC1  00 40 00 00 00 40 00 00 00 00 00 00 00 00 00 00  .@...@..........
004D1CD1  00 00 00 D3 C4 6A 95 ED 43 0E C3 01 00 00 00 FF  ...幽j?C?...?
004D1CE1  AF FA FF 00 50 05 00 00 80 07 00 00 00 00 00 00  ??P..?......
004D1CF1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1D01  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1D11  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1D21  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1D31  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1D41  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1D51  00 00 00 00 00 00 00 00 00 00 00 61 67 E1 3C B2  ...........ag??
004D1D61  FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 FF 00 00 B2  ?.?..?..?..?
004D1D71  FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 FF 00 00 B2  ?.?..?..?..?
004D1D81  FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 FF 00 00 B2  ?.?..?..?..?
004D1D91  FF 00 00 B2 FF 00 00 B2 FF 00 00 B2 FF 00 00 00  ?.?..?..?...
004D1DA1  00 E6 77 F7 2B 5E 22 00 00 00 00 00 00 00 00 00  .骥?^".........
004D1DB1  00 00 00 E3 00 3A 00 36 50 45 00 54 65 74 72 69  ...?:.6PE.Tetri
004D1DC1  73 54 65 72 6D 69 6E 61 74 6F 72 2E 65 78 65 00  sTerminator.exe.
004D1DD1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1DE1  00 49 6E 74 65 72 6E 61 6C 20 4C 6F 61 64 65 72  .Internal Loader
004D1DF1  20 45 72 72 6F 72 21 00 54 68 69 73 20 50 72 6F   Error!.This Pro
004D1E01  67 72 61 6D 20 64 6F 65 73 20 6E 6F 74 20 72 75  gram does not ru
004D1E11  6E 20 6F 6E 20 6D 61 63 68 69 6E 65 73 20 77 69  n on machines wi
004D1E21  74 68 20 61 63 74 69 76 65 20 73 79 73 74 65 6D  th active system
004D1E31  20 64 65 62 75 67 67 65 72 21 00 45 72 72 6F 72   debugger!.Error
004D1E41  20 77 68 69 6C 65 20 6C 6F 61 64 69 6E 67 20 61   while loading a
004D1E51  20 44 4C 4C 21 00 45 72 72 6F 72 20 77 68 69 6C   DLL!.Error whil
004D1E61  65 20 6C 6F 63 61 74 69 6E 67 20 61 20 44 4C 4C  e locating a DLL
004D1E71  20 66 75 6E 63 74 69 6F 6E 21 00 44 65 63 6F 6D   function!.Decom
004D1E81  70 72 65 73 73 69 6F 6E 20 65 72 72 6F 72 21 00  pression error!.
004D1E91  43 52 43 20 65 72 72 6F 72 21 20 46 69 6C 65 20  CRC error! File
004D1EA1  63 6F 6E 74 65 6E 74 20 68 61 73 20 62 65 65 6E  content has been
004D1EB1  20 6D 6F 64 69 66 69 65 64 2E 20 49 66 20 79 6F   modified. If yo
004D1EC1  75 20 72 75 6E 20 61 20 73 79 73 74 65 6D 0D 0A  u run a system..
004D1ED1  64 65 62 75 67 67 65 72 2C 20 63 6C 65 61 72 20  debugger, clear
004D1EE1  61 6C 6C 20 62 72 65 61 6B 70 6F 69 6E 74 73 20  all breakpoints
004D1EF1  62 65 66 6F 72 65 20 72 75 6E 6E 69 6E 67 20 74  before running t
004D1F01  68 69 73 20 70 72 6F 67 72 61 6D 21 00 49 6E 74  his program!.Int
004D1F11  65 67 72 69 74 79 20 63 68 65 63 6B 20 66 61 69  egrity check fai
004D1F21  6C 65 64 21 20 54 68 69 73 20 46 69 6C 65 20 68  led! This File h
004D1F31  61 73 20 62 65 65 6E 20 6D 6F 64 69 66 69 65 64  as been modified
004D1F41  2E 0D 0A 52 65 61 73 6F 6E 20 6D 69 67 68 74 20  ...Reason might
004D1F51  62 65 20 61 20 70 6F 73 73 69 62 6C 65 20 76 69  be a possible vi
004D1F61  72 75 73 20 69 6E 66 65 63 74 69 6F 6E 21 00 A8  rus infection!.?
004D1F71  AB D1 A5 5A BD BF 78 1E F2 18 7A B2 A8 9E 9C 00  ?ペ娇x?z波?.
004D1F81  00 09 09 08 08 0A 00 00 00 00 00 00 00 00 00 00  ..............
004D1F91  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1FA1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1FB1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1FC1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1FD1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1FE1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D1FF1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2001  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2011  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2021  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2031  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2041  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2051  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2061  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2071  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2081  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2091  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D20A1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D20B1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D20C1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D20D1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D20E1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D20F1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2101  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2111  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2121  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2131  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2141  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2151  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2161  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2171  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2181  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D2191  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D21A1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D21B1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D21C1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D21D1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D21E1  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
004D21F1  00 00 00 00 00 00 00 78 69 78 69 68 65 68 65 00  .......xixihehe. 



[课程]Android-CTF解题方法汇总!

收藏
免费 0
支持
分享
最新回复 (10)
雪    币: 898
活跃值: (4039)
能力值: ( LV9,RANK:3410 )
在线值:
发帖
回帖
粉丝
2
Tetris Terminator
---------------------------
程序文件损坏,请重新安装!
---------------------------
确定   

另外:
要学脱壳先从简单的开始
2005-6-17 22:48
0
雪    币: 224
活跃值: (147)
能力值: ( LV9,RANK:970 )
在线值:
发帖
回帖
粉丝
3
还是先UPX开始吧~关于这个你可以按二哥的手动脱壳过程来

入门18篇,进阶13篇。。。
2005-6-17 22:51
0
雪    币: 224
活跃值: (147)
能力值: ( LV9,RANK:970 )
在线值:
发帖
回帖
粉丝
4
在动态代码情况下

要想翻看代码的话

就先一直按住ctrl+向上的箭头/向下的箭头
2005-6-17 22:52
0
雪    币: 202
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
二哥是谁啊,他的文章在哪里?thx
2005-6-17 23:39
0
雪    币: 224
活跃值: (147)
能力值: ( LV9,RANK:970 )
在线值:
发帖
回帖
粉丝
6
www.chinadfcg.com
搜索”二哥“
2005-6-18 00:03
0
雪    币: 108
活跃值: (42)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
7
不止一个壳啊
还有PELOCKnt
2005-6-18 00:11
0
雪    币: 817
活跃值: (1927)
能力值: ( LV12,RANK:2670 )
在线值:
发帖
回帖
粉丝
8
最初由 闪电狼 发布
不止一个壳啊
还有PELOCKnt


不是PELOCKnt,而是EncryptPE v1.2003.5.18!!!

这是脱掉tElock98的:

附件:Unpack_tElock98_mmm.rar

脱掉EncryptPE v1.2003.5.18后主程序为:Microsoft Visual C++ 7.0编译!

论坛附件大小限制,所以传不了脱掉tElock98 + EncryptPE v1.2003.5.18的完整脱壳文件。。。
2005-6-18 01:06
0
雪    币: 108
活跃值: (42)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
9
最初由 KuNgBiM 发布


不是PELOCKnt,而是EncryptPE v1.2003.5.18!!!

这是脱掉tElock98的:
........

  别激动..我没看软件 我只看区段了
2005-6-18 15:08
0
雪    币: 202
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
10
最初由 KuNgBiM 发布


不是PELOCKnt,而是EncryptPE v1.2003.5.18!!!

这是脱掉tElock98的:
........


崇拜你啊,老大,加我QQ啊 :63891284
2005-6-18 17:27
0
雪    币: 202
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
11
太tmd损了,加了两个壳子。。。。55555,我说我怎么找不到入口呢
2005-6-18 17:37
0
游客
登录 | 注册 方可回帖
返回
//