能力值:
( LV2,RANK:10 )
|
-
-
76 楼
看看先???????
|
能力值:
(RANK:215 )
|
-
-
77 楼
最初由 快雪时晴 发布
我试了antidebugdemo.exe,可以脱壳,但运行出错,是不是还要修复,如何修复?
可能到OEP了,如果不完全正确,请再单步走几下! ........
我这里运行不到生成脱壳文件就不动了。
我的系统是XP+SP2
|
能力值:
( LV2,RANK:10 )
|
-
-
78 楼
昨天的两个NotePad.exe不能正确处理,这是操作系统的问题,把文件随便改个名字就可以了.
|
能力值:
( LV2,RANK:10 )
|
-
-
79 楼
引用:最初由 dingshan 发布
特别是mydaj居然是个mm
最初由 mejy 发布
!哈哈~~晕下 呼唤源码,呵呵
可不是我一厢情愿的说法,水木清华的人说的,具体没证实~
|
能力值:
( LV2,RANK:10 )
|
-
-
80 楼
苏州视算就是Ltt开的公司,
楼主是公司的员工吧.
上次去过一次你们公司, 环境不错.
就是没有MM,呵呵
|
能力值:
( LV2,RANK:10 )
|
-
-
81 楼
最初由 gx_sz 发布 苏州视算就是Ltt开的公司, 楼主是公司的员工吧. 上次去过一次你们公司, 环境不错. 就是没有MM,呵呵
这不是小GE吗?呵呵
我是ZhangYL
|
能力值:
(RANK:215 )
|
-
-
82 楼
记录文件可不可以直接用TXT文本?
|
能力值:
( LV2,RANK:10 )
|
-
-
83 楼
0.18-0.19都存在问题:
MAKEPE后不能生成脱壳文件。就不动了
0.17没问题
2K-SP4
|
能力值:
( LV2,RANK:10 )
|
-
-
84 楼
最初由 liuyilin 发布 0.18-0.19都存在问题: MAKEPE后不能生成脱壳文件。就不动了 0.17没问题 2K-SP4
能否把带壳文件贴上来?或者通过QQ发给我看下.
|
能力值:
( LV2,RANK:10 )
|
-
-
85 楼
例如:
http://bbs.pediy.com/showthread.php?threadid=19248
图片:
|
能力值:
( LV2,RANK:10 )
|
-
-
86 楼
建议跑到OEP后勾选"遇到API暂停",然后继续GO!,停止后,用MAKEPE命令,后面加上OEP地址参数,如:MAKEPE 401000
这样一般会成功
|
能力值:
( LV2,RANK:10 )
|
-
-
87 楼
最初由 Kernel64 发布 建议跑到OEP后勾选"遇到API暂停",然后继续GO!,停止后,用MAKEPE命令,后面加上OEP地址参数,如:MAKEPE 401000
这样一般会成功
谢谢,可以了。
|
能力值:
( LV4,RANK:50 )
|
-
-
88 楼
Eip==0040E8C0
UPX 0.89.6 - 1.02 / 1.05 - 1.22 -> Markus & Lazlo
0040E8C0 60 PUSHAD
0040E8C1 BE15B04000 MOV ESI,40B015
0040E8C6 8DBEEB5FFFFF LEA EDI,DWORD PTR [ESI-0A015h]
0040E8CC 57 PUSH EDI
0040E8CD 83CDFF OR EBP,FF
0040E8D0 EB10 JMP 0040E8E2
0040E8E2 8B1E MOV EBX,DWORD PTR [ESI]
0040E8E4 83EEFC SUB ESI,FC
0040E8E7 11DB ADC EBX,EBX
0040E8E9 72ED JB 0040E8D8
0040E8D8 8A06 MOV AL,BYTE PTR [ESI]
0040E8DA 46 INC ESI
0040E8DB 8807 MOV BYTE PTR [EDI],AL
0040E8DD 47 INC EDI
0040E8DE 01DB ADD EBX,EBX
0040E8E0 7507 JNZ 0040E8E9
0040E8E9 72ED JB 0040E8D8
0040E8EB B801000000 MOV EAX,1
0040E8F0 01DB ADD EBX,EBX
0040E8F2 7507 JNZ 0040E8FB
0040E8FB 11C0 ADC EAX,EAX
0040E8FD 01DB ADD EBX,EBX
0040E8FF 73EF JNB 0040E8F0
0040E901 7509 JNZ 0040E90C
0040E90C 31C9 XOR ECX,ECX
0040E90E 83E803 SUB EAX,3
0040E911 720D JB 0040E920
0040E920 01DB ADD EBX,EBX
0040E922 7507 JNZ 0040E92B
0040E92B 11C9 ADC ECX,ECX
0040E92D 01DB ADD EBX,EBX
0040E92F 7507 JNZ 0040E938
0040E938 11C9 ADC ECX,ECX
0040E93A 7520 JNZ 0040E95C
0040E95C 81FD00F3FFFF CMP EBP,FFFFF300
0040E962 83D101 ADC ECX,1
0040E965 8D142F LEA EDX,DWORD PTR [EDI+EBP]
0040E968 83FDFC CMP EBP,FC
0040E96B 760F JNA 0040E97C
0040E96D 8A02 MOV AL,BYTE PTR [EDX]
0040E96F 42 INC EDX
0040E970 8807 MOV BYTE PTR [EDI],AL
0040E972 47 INC EDI
0040E973 49 DEC ECX
0040E974 75F7 JNZ 0040E96D
0040E96D 8A02 MOV AL,BYTE PTR [EDX]
0040E96F 42 INC EDX
0040E970 8807 MOV BYTE PTR [EDI],AL
0040E972 47 INC EDI
0040E973 49 DEC ECX
0040E974 75F7 JNZ 0040E96D
0040E96D 8A02 MOV AL,BYTE PTR [EDX]
0040E96F 42 INC EDX
0040E970 8807 MOV BYTE PTR [EDI],AL
0040E972 47 INC EDI
0040E973 49 DEC ECX
0040E974 75F7 JNZ 0040E96D
0040E976 E963FFFFFF JMP 0040E8DE
0040E8DE 01DB ADD EBX,EBX
0040E8E0 7507 JNZ 0040E8E9
0040E8E9 72ED JB 0040E8D8
0040E8D8 8A06 MOV AL,BYTE PTR [ESI]
0040E8DA 46 INC ESI
0037708A ***API: KERNEL32.DLL!LoadLibraryA
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!LoadLibraryA
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!LoadLibraryA
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!LoadLibraryA
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!LoadLibraryA
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!LoadLibraryA
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
0037708A ***API: KERNEL32.DLL!GetProcAddress
可能到OEP了,如果不完全正确,请再单步走几下!
0040EA0F E9B826FFFF JMP 004010CC <------//跨段跃,应该是OEP啦
可能到OEP了,如果不完全正确,请再单步走几下!
004010CC 55 PUSH EBP <------//程序入口
004010CD 8BEC MOV EBP,ESP
Command: MAKEPE 004010cc <------//下脱壳命令
Make PE now
Start:7C920000 End:7C9B4000
Start:7C800000 End:7C91C000
Start:77DA0000 End:77E49000
Start:77E50000 End:77EE1000
Start:76320000 End:76367000
Start:77F40000 End:77FB6000
Start:77EF0000 End:77F37000
Start:77D10000 End:77D9F000
Start:77BE0000 End:77C38000
Start:5D170000 End:5D207000
Start:7D590000 End:7DD82000
Start:76300000 End:7631D000
Start:62C20000 End:62C29000
Start:73FA0000 End:7400B000
Start:77180000 End:77282000
Start:10000000 End:100A2000
Start:73D30000 End:73E2E000
Start:61BE0000 End:61BED000
Start:77BD0000 End:77BD8000
Start:770F0000 End:7717C000
Start:76990000 End:76ACD000
Start:71A20000 End:71A37000
Start:71A10000 End:71A18000
HODULE=00400080
nSec=3
VirtualSize RVA PhysicalSize PhysicalOffset
p=00400178
a000 1000 0 0
p=004001A0
4000 b000 3c00 200
p=004001C8
1000 f000 e00 3e00
pStart=004062E4
pEnd=00406524
db6 10000 db6 10000
218 -> 1000
write object at 401000 len a000
Writing 401000 len a000
b000 -> b000
write object at 40b000 len 4000
Writing 40b000 len 4000
f000 -> f000
write object at 40f000 len 1000
Writing 40f000 len 1000
10000 -> 10000
Writing 378310 len db6
文件已保存到:E:\桌面的东西\壳\脱壳练习场\upx\2\ROR_Unpacked.exe
被调试程序已经终止
完美脱壳~~
|
能力值:
( LV4,RANK:50 )
|
-
-
89 楼
当调试一个程序正常结束,再调试其它的程序时,而第一个被调试的程序进程不会从内存中消失,关闭Ror也不行。当调试了N个程序以后,系统变得奇慢。。。
打开任务管理器看看,所有被调试过的进程都在,而且资源占用率惊人。手工结束后系统恢复正常。期待下一版中解决内存释放问题。
|
能力值:
( LV2,RANK:10 )
|
-
-
90 楼
最初由 playx 发布 当调试一个程序正常结束,再调试其它的程序时,而第一个被调试的程序进程不会从内存中消失,关闭Ror也不行。当调试了N个程序以后,系统变得奇慢。。。 打开任务管理器看看,所有被调试过的进程都在,而且资源占用率惊人。手工结束后系统恢复正常。期待下一版中解决内存释放问题。
目前只能手工结束,因为被调试程序跑起来后已经不在RORDbg的控制之下了,
这一点注意一下就可以了.
|
能力值:
( LV2,RANK:10 )
|
-
-
91 楼
凡是遇到MAKEPE不结束的情况,请下载V0.20
|
能力值:
( LV6,RANK:90 )
|
-
-
92 楼
抓个虫子
00528056 669D POPFW
00528057 9D POPFD
|
能力值:
( LV2,RANK:10 )
|
-
-
93 楼
最初由 aki 发布 抓个虫子 00528056 669D POPFW 00528057 9D POPFD 这个虫子抓的好啊~~~ Thx!
|
能力值:
( LV9,RANK:170 )
|
-
-
94 楼
支持版本不断升级完善
|
能力值:
( LV6,RANK:90 )
|
-
-
95 楼
最初由 Kernel64 发布
这个虫子抓的好啊~~~ Thx! 应该感谢老兄给大家带来这么好的东西才是.好久没见这么让人痛快的东东了,呵呵
|
能力值:
( LV9,RANK:410 )
|
-
-
96 楼
??其他版本都可以用,0。20好像出现BUG ,几步就不走了?
|
能力值:
( LV2,RANK:10 )
|
-
-
97 楼
最初由 hnhuqiong 发布 ??其他版本都可以用,0。20好像出现BUG ,几步就不走了?
是什么壳?最好提供log,便于我查找BUG.
|
能力值:
( LV12,RANK:220 )
|
-
-
98 楼
asprotect 2.x的版本好像都不行
|
能力值:
(RANK:215 )
|
-
-
99 楼
最初由 WiNrOOt 发布 asprotect 2.x的版本好像都不行
RT,你们那里还要人吗?俺想去给你打工。
|
能力值:
( LV2,RANK:10 )
|
-
-
100 楼
最初由 WiNrOOt 发布 asprotect 2.x的版本好像都不行
asprotect 2.x我测试过,没问题的,可以跑下来,不过,脱壳还不行。
即使脱了,也不能用的。
|
|
|