在OD 里对WSASend或任何函数下CC 硬断 或内存断点,程序不执行不会出错,只要运行到下段的地方就会出错,感觉VEH派发异常的时候直接派发给了程序自身,程序是加壳的,用IDA怕是分析不了,脱壳后无法修复运行不了,HOOK列表里也看不出来什么,这种反断点挺普遍,我遇到好几个了,应该是用来同一款壳,一直搞不懂咋回事。
[PC Hunter Standard][MHClient-Connect.exe-->Ring3 Hook]: 106
挂钩对象 挂钩位置 钩子类型 挂钩处当前值 挂钩处原始值
G:\新世界墨\GodMxoNew\MHClient-Connect.exe 模块文件被替换,可能是模块升级后未重启程序导致的,也可能是被病毒劫持了
[*]len(1) ntdll.dll->DbgBreakPoint 0x0000000077E2000C->_ inline C3 CC
[*]len(5) ntdll.dll->DbgUiRemoteBreakin 0x0000000077EAF142->_ inline E9 80 9C FB FF 6A 08 68 30 BB
[*]len(1) ntdll.dll->DbgUserBreakPoint 0x0000000077E2000C->_ inline C3 CC
[*]len(7) kernel32.dll->K32EnumProcessModulesEx 0x00000000758590C4->_ inline E9 87 B7 5D FB CC CC 6A 0C 68 28 91 85 75
[*]len(5) kernel32.dll->K32GetMappedFileNameW 0x000000007585949F->_ inline E9 BC B3 5D FB 8B FF 55 8B EC
[*]len(5) kernel32.dll->K32GetModuleInformation 0x0000000075859149->_ inline E9 E2 B8 5D FB 68 90 00 00 00
[*]len(7) kernel32.dll->RegDeleteValueW 0x00000000757CEA5D->_ inline E9 7E 69 66 FB CC CC 6A 20 68 00 EB 7C 75
[*]len(7) kernel32.dll->RegQueryValueExW 0x00000000757B1EEE->_ inline E9 FD 34 68 FB CC CC 6A 2C 68 00 20 7B 75
[*]len(7) kernel32.dll->RegSetValueExA 0x00000000757C1409->_ inline E9 32 42 67 FB CC CC 6A 3C 68 30 15 7C 75
[*]len(7) kernel32.dll->RegSetValueExW 0x00000000757B5B85->_ inline E9 A6 FE 67 FB CC CC 6A 28 68 98 5C 7B 75
[*]len(5) KERNELBASE.dll->FreeLibrary 0x00000000765C2E7E->_ inline E9 ED 14 87 FA 8B FF 55 8B EC
[*]len(5) KERNELBASE.dll->GetModuleHandleExW 0x00000000765C1EFA->_ inline E9 81 27 87 FA 8B FF 55 8B EC
[*]len(5) KERNELBASE.dll->GetModuleHandleW 0x00000000765C1E4C->_ inline E9 1F 29 87 FA 8B FF 55 8B EC
[*]len(5) KERNELBASE.dll->LoadLibraryExW 0x00000000765C2BDC->_ inline E9 5F 1E 87 FA 8B FF 55 8B EC
[*]comctl32.dll[WinSxs]->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]ADVAPI32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
GDI32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]len(5) GDI32.dll->D3DKMTGetDisplayModeList 0x0000000075D6E773->_ inline E9 08 52 0C FB B8 6F 11 00 00
[*]len(5) GDI32.dll->D3DKMTQueryAdapterInfo 0x0000000075D6E9AD->_ inline E9 DE 4F 0C FB B8 81 11 00 00
[*]USER32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]len(5) USER32.dll->ChangeDisplaySettingsExW 0x0000000076830867->_ inline E9 54 2D 60 FA 8B FF 55 8B EC
[*]len(5) USER32.dll->CreateWindowExW 0x00000000767E8A29->_ inline E9 12 AE 64 FA 8B FF 55 8B EC
[*]len(5) USER32.dll->DisplayConfigGetDeviceInfo 0x0000000076847AF4->_ inline E9 D7 C7 5E FA 8B FF 55 8B EC
[*]len(5) USER32.dll->EnumDisplayDevicesA 0x00000000767F5645->_ inline E9 B6 EC 63 FA 8B FF 55 8B EC
[*]len(5) USER32.dll->EnumDisplayDevicesW 0x000000007680F61F->_ inline E9 3C 4D 62 FA 8B FF 55 8B EC
[*]USP10.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
SHLWAPI.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]len(5) ole32.dll->CoCreateInstance 0x0000000075B89C5B->_ inline E9 80 9A 2A FB 8B FF 55 8B EC
[*]len(5) ole32.dll->CoSetProxyBlanket 0x0000000075B55DD5->_ inline E9 26 DA 2D FB 8B FF 55 8B EC
OLEAUT32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
WINSPOOL.DRV->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]MPR.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
IMM32.DLL->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
MSCTF.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]nvinit.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
VERSION.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]nvd3d9wrap.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
SETUPAPI.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]CFGMGR32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
nvdxgiwrap.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]winmm.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]SoundLib.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]mss32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]MSVCR71.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]MSVCR71.dll->KERNEL32.dll:CreateProcessA 0x00000000757B1072->0x000000006DB1241B[C:\Windows\AppPatch\AcLayers.DLL] Iat 1B 24 B1 6D 72 10 7B 75
MSVCR71.dll->KERNEL32.dll:CreateProcessW 0x00000000757B103D->0x000000006DB1258F[C:\Windows\AppPatch\AcLayers.DLL] Iat 8F 25 B1 6D 3D 10 7B 75
[*]DINPUT8.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]WININET.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
urlmon.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
CRYPT32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]iertutil.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
opencc.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]FreeImage.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]srvcli.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]wkscli.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
CrashRpt1402.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]CrashRpt1402.dll->KERNEL32.dll:CreateProcessW 0x00000000757B103D->0x000000006DB1258F[C:\Windows\AppPatch\AcLayers.DLL] Iat 8F 25 B1 6D 3D 10 7B 75
liblz4.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
PocoFoundation.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]PocoFoundation.dll->KERNEL32.dll:CreateProcessW 0x00000000757B103D->0x000000006DB1258F[C:\Windows\AppPatch\AcLayers.DLL] Iat 8F 25 B1 6D 3D 10 7B 75
[*]ntmarta.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]WLDAP32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
WebviewEdge.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
G:\新世界墨\GodMxoNew\WebView2Loader.dll 模块文件被替换,可能是模块升级后未重启程序导致的,也可能是被病毒劫持了
UxTheme.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]gdiplus.dll[WinSxs]->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]OLEACC.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
fwpuclnt.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
dwmapi.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]SS3DRendererForMuk.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]d3d8.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]WINTRUST.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]nvumdshim.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
igdumdim32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]igdusc32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
BaseNetwork.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]comdlg32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]mssmp3.asi->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
mssvoice.asi->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]mssa3d.m3d->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]mssds3d.m3d->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]mssdx7.m3d->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]msseax.m3d->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
mssrsx.m3d->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]mssrsx.m3d->KERNEL32.dll:CreateProcessA 0x00000000757B1072->0x000000006DB1241B[C:\Windows\AppPatch\AcLayers.DLL] Iat 1B 24 B1 6D 72 10 7B 75
MSACM32.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
msssoft.m3d->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
mssdsp.flt->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
DSOUND.DLL->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]POWRPROF.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]CLBCatQ.DLL->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
MMDevApi.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
PROPSYS.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]AUDIOSES.DLL->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]NLAapi.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
napinsp.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]pnrpnsp.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
wshbth.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]SOGOUPY.IME->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
PicFace.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
PicFace.dll->KERNEL32.dll:CreateProcessW 0x00000000757B103D->0x000000006DB1258F[C:\Windows\AppPatch\AcLayers.DLL] Iat 8F 25 B1 6D 3D 10 7B 75
comctl32.dll[WinSxs]->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
rsaenh.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
bcrypt.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75
[*]bcryptprimitives.dll->KERNEL32.dll:GetProcAddress 0x00000000757B1222->0x000000007051FFF6[C:\Windows\syswow64\apphelp.dll] Iat F6 FF 51 70 22 12 7B 75