新版的Asprotect的特征码有变化.
不是2.2版本的不能用83,C4,28,5D,5F,5E,5B,C3找OEP
to kmjyq : IAT输入表在数据窗口可以看到.
0046A150 00000000
0046A154 >7C96AE65 ntdll.RtlDeleteCriticalSection//开始部分
0046A158 >7C95F2FC ntdll.RtlLeaveCriticalSection
0046A15C >7C95F337 ntdll.RtlEnterCriticalSection
0046A160 >7C8284E0 kernel32.InitializeCriticalSection
0046A164 >7C828CFC kernel32.VirtualFree
0046A168 >7C82BEC9 kernel32.VirtualAlloc
0046A16C >7C82BC09 kernel32.LocalFree
0046A170 >7C82BB92 kernel32.LocalAlloc
0046A174 >7C82C07F kernel32.GetVersion
0046A178 >7C82BC6D kernel32.GetCurrentThreadId
0046A17C >7C82B44F kernel32.InterlockedDecrement
0046A180 >7C82B43B kernel32.InterlockedIncrement
0046A184 >7C818EA7 kernel32.VirtualQuery
0046A188 >7C82DC10 kernel32.WideCharToMultiByte
0046A18C >7C82BC7C kernel32.MultiByteToWideChar
0046A190 >7C82EF08 kernel32.lstrlenA
0046A194 >7C817702 kernel32.lstrcpynA
0046A198 >7C801E38 kernel32.LoadLibraryExA
0046A19C >7C82E15F kernel32.GetThreadLocale
0046A1A0 >7C801FF6 kernel32.GetStartupInfoA
0046A1A4 >7C82BFC1 kernel32.GetProcAddress
0046A1A8 >7C8263DC kernel32.GetModuleHandleA
0046A1AC >7C825F78 kernel32.GetModuleFileNameA
0046A1B0 >7C826DD9 kernel32.GetLocaleInfoA
0046A1B4 >7C814A34 kernel32.GetCommandLineA
0046A1B8 >7C827B48 kernel32.FreeLibrary
0046A1BC >7C806194 kernel32.FindFirstFileA
0046A1C0 >7C82AC2D kernel32.FindClose
0046A1C4 >7C813039 kernel32.ExitProcess
0046A1C8 >7C82F3FE kernel32.WriteFile
0046A1CC >7C85951C kernel32.UnhandledExceptionFilter
0046A1D0 >7C944119 ntdll.RtlUnwind
0046A1D4 >7C815DAE kernel32.RaiseException
0046A1D8 >7C82076F kernel32.GetStdHandle
0046A1DC 00000000
0046A1E0 >77E2DFC5 user32.GetKeyboardType
0046A1E4 >77E182EC user32.LoadStringA
0046A1E8 >77E4D8DE user32.MessageBoxA
0046A1EC >77E1A7C7 user32.CharNextA //结束
0046A1F0 00000000
0046A1F4 >00000000
0046A1F8 >00000000
0046A1FC >00000000
0046A200 00000000