最初由 fly 发布
暂停后
BP GetProcAddress [ESP]<10000000
Shift+F9
Alt+F9
WinUpack 0.36 の 必?技
OllyDbg Load...
F12 暂停
命令行下命令 BP GetProcAddress
Shift+F9 然后取消断点
Alt+F9 到 004196AA
004196AA /74 1F je short WinUpack.004196CB
004196AC |51 push ecx
004196AD |56 push esi
004196AE |97 xchg eax,edi
004196AF |FFD1 call ecx
004196B1 |93 xchg eax,ebx
004196B2 |AC lods byte ptr ds:[esi]
004196B3 |84C0 test al,al
004196B5 ^|75 FB jnz short WinUpack.004196B2
004196B7 |3806 cmp byte ptr ds:[esi],al
004196B9 ^|74 EA je short WinUpack.004196A5
004196BB |8BC6 mov eax,esi
004196BD |79 05 jns short WinUpack.004196C4
004196BF |46 inc esi
004196C0 |33C0 xor eax,eax
004196C2 |66:AD lods word ptr ds:[esi]
004196C4 |50 push eax
004196C5 |53 push ebx
004196C6 |FFD5 call ebp
004196C8 |AB stos dword ptr es:[edi]
004196C9 ^|EB E7 jmp short WinUpack.004196B2
004196CB \C3 retn
直接在 004196CB retn 按下F4 再按一下F8 返回到 OEP -----> 0040A10E
?得新技能