一DLL ,PEID显示 :CrypKey Stealth -> CrypKey Inc. [Overlay],FI 显示 :UNKNOWN 。
入口代码:
100592C8 833D 6A910510 00 CMP DWORD PTR DS:[1005916A],0
100592CF 75 34 JNZ SHORT 复件_(2).10059305
100592D1 68 80900510 PUSH 复件_(2).10059080 ; ASCII "KERNEL32.DLL"
100592D6 E8 BD020000 CALL 复件_(2).10059598
100592DB 83C4 04 ADD ESP,4
100592DE 8B4424 04 MOV EAX,DWORD PTR SS:[ESP+4]
100592E2 A3 6E910510 MOV DWORD PTR DS:[1005916E],EAX
100592E7 6A 00 PUSH 0
100592E9 6A 00 PUSH 0
100592EB 6A 00 PUSH 0
100592ED FF15 9E900510 CALL NEAR DWORD PTR DS:[1005909E] ; kernel32.CreateMutexA
100592F3 A3 6A910510 MOV DWORD PTR DS:[1005916A],EAX
100592F8 83F8 00 CMP EAX,0
100592FB 75 18 JNZ SHORT 复件_(2).10059315
100592FD B8 00000000 MOV EAX,0
10059302 C2 0C00 RETN 0C
10059305 A1 4C900510 MOV EAX,DWORD PTR DS:[1005904C]
1005930A 83F8 02 CMP EAX,2
1005930D 75 06 JNZ SHORT 复件_(2).10059315
1005930F - FF25 00900510 JMP NEAR DWORD PTR DS:[10059000] ; 复件_(2).1002D687
10059315 B8 01000000 MOV EAX,1
1005931A C2 0C00 RETN 0C
用OD加载无法停在入口,请问有什么方法,可以让它停下来? 打算按FLY的破文脱了它,就这问题让我无法入手了。
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课