00402476 3BE8 cmp ebp,eax
00402478 74 03 je short jsy.0040247D
0040247A 83CE 02 or esi,2
0040247D 68 B4A54300 push jsy.0043A5B4 ; ASCII "WGSHELL.DLL"
00402482 E8 19460000 call jsy.00406AA0
00402487 394424 20 cmp dword ptr ss:[esp+20],eax
0040248B 74 03 je short jsy.00402490
0040248D 83CE 04 or esi,4
00402490 68 A8A54300 push jsy.0043A5A8 ; ASCII "BMPINFO.BIN"
00402495 E8 06460000 call jsy.00406AA0
0040249A 394424 18 cmp dword ptr ss:[esp+18],eax
0040249E 74 03 je short jsy.004024A3
004024A0 83CE 08 or esi,8
004024A3 68 9CA54300 push jsy.0043A59C ; ASCII "MAPINFO.BIN"
004024A8 E8 F3450000 call jsy.00406AA0
004024AD 394424 1C cmp dword ptr ss:[esp+1C],eax
004024B1 74 03 je short jsy.004024B6
004024B3 83CE 10 or esi,10
004024B6 85F6 test esi,esi
004024B8 0F84 98000000 je jsy.00402556 //如果在这里把je改成 jmp 让他跳就不会有“更新提示”了,但是不用点凳陆,一点就出错
004024BE 6A 44 push 44
004024C0 68 BCA44300 push jsy.0043A4BC
004024C5 68 7CA54300 push jsy.0043A57C
004024CA 8BCF mov ecx,edi
004024CC E8 25D30100 call jsy.0041F7F6
004024D1 83F8 06 cmp eax,6
源文件可以用的,脱壳后就不行了,可能是检查文件大小吧
还能在那个地方改不让他检查文件大小,
附件:jsy.rar
[培训]《安卓高级研修班(网课)》月薪三万计划,掌握调试、分析还原ollvm、vmp的方法,定制art虚拟机自动化脱壳的方法