首页
社区
课程
招聘
[原创]x32dbg/x64dbg去除汇编多余|线的补丁
发表于: 2020-2-19 08:38 2056

[原创]x32dbg/x64dbg去除汇编多余|线的补丁

2020-2-19 08:38
2056

每次复制汇编代码,就会呈现下面的样子:
00007FF95FDF11E6 | CC | int3 |
00007FF95FDF11E7 | CC | int3 |
00007FF95FDF11E8 | CC | int3 |
00007FF95FDF11E9 | CC | int3 |
00007FF95FDF11EA | CC | int3 |
00007FF95FDF11EB | CC | int3 |
00007FF95FDF11EC | 48:895C24 10 | mov qword ptr ss:[rsp+10],rbx | rbx:PEB.InheritedAddressSpace
00007FF95FDF11F1 | 48:897424 18 | mov qword ptr ss:[rsp+18],rsi |
00007FF95FDF11F6 | 55 | push rbp |
00007FF95FDF11F7 | 57 | push rdi |
00007FF95FDF11F8 | 41:56 | push r14 | r14:"minkernel\ntdll\ldrinit.c"
十分的不爽,还得活人手动替换掉 |
这个补丁 就是为了解决这个问题而为。

 

打完补丁后的:
0016DD32 68 A00F0000 push 0xFA0
0016DD37 68 ECB03500 push wnconfig.35B0EC
0016DD3C E8 486D1000 call 0x274A89
0016DD41 83C4 0C add esp,0xC
0016DD44 68 40CC2A00 push wnconfig.2ACC40 2ACC40:L"kernel32.dll"
0016DD49 FF15 8CB72A00 call dword ptr ds:[<&GetModuleHandleW>]

 

https://www.lanzous.com/i9gynjg


[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

收藏
免费 0
支持
分享
最新回复 (7)
雪    币: 8729
活跃值: (5195)
能力值: ( LV4,RANK:50 )
在线值:
发帖
回帖
粉丝
2
有线不是挺好的嘛!
0000000001A01490 < | 4C:8BDC                  | MOV R11, RSP                                                 |
0000000001A01493   | 49:895B 18               | MOV QWORD PTR DS:[R11+0x18], RBX                             |
0000000001A01497   | 55                       | PUSH RBP                                                     |
0000000001A01498   | 57                       | PUSH RDI                                                     |
0000000001A01499   | 41:56                    | PUSH R14                                                     |
0000000001A0149B   | 48:83EC 60               | SUB RSP, 0x60                                                |
0000000001A0149F   | 41:8BF9                  | MOV EDI, R9D                                                 |
0000000001A014A2   | 49:8BD8                  | MOV RBX, R8                                                  |
0000000001A014A5   | 8BEA                     | MOV EBP, EDX                                                 |
0000000001A014A7   | 4C:8BF1                  | MOV R14, RCX                                                 |
0000000001A014AA   | 48:83F9 FF               | CMP RCX, 0xFFFFFFFFFFFFFFFF                                  |
0000000001A014AE   | 74 5C                    | JE 0x1A0150C                                                 |
0000000001A014B0   | 6548:8B0425 30000000     | MOV RAX, QWORD PTR GS:[0x30]                                 |
0000000001A014B9   | 49:8973 08               | MOV QWORD PTR DS:[R11+0x8], RSI                              |
0000000001A014BD   | 33F6                     | XOR ESI, ESI                                                 |
0000000001A014BF   | 4D:897B 10               | MOV QWORD PTR DS:[R11+0x10], R15                             |
0000000001A014C3   | 44:8B78 40               | MOV R15D, DWORD PTR DS:[RAX+0x40]                            |
0000000001A014C7   | 48:8B05 F0610000         | MOV RAX, QWORD PTR DS:[0x1A076BE]                            |
0000000001A014CE   | 33D2                     | XOR EDX, EDX                                                 |
0000000001A014D0   | 44:8D4E 30               | LEA R9D, QWORD PTR DS:[RSI+0x30]                             |
0000000001A014D4   | 4D:8D43 B8               | LEA R8, QWORD PTR DS:[R11-0x48]                              |
0000000001A014D8   | 49:8973 A8               | MOV QWORD PTR DS:[R11-0x58], RSI                             |
0000000001A014DC   | 48:85C0                  | TEST RAX, RAX                                                |
0000000001A014DF   | 74 04                    | JE 0x1A014E5                                                 |
0000000001A014E1   | FFD0                     | CALL RAX                                                     |
0000000001A014E3   | EB 06                    | JMP 0x1A014EB                                                |
0000000001A014E5   | FF15 8D2B0000            | CALL QWORD PTR DS:[<&NtQueryInformationProcess>]             |
0000000001A014EB   | 85C0                     | TEST EAX, EAX                                                |
0000000001A014ED   | 78 04                    | JS 0x1A014F3                                                 |
0000000001A014EF   | 8B7424 50                | MOV ESI, DWORD PTR SS:[RSP+0x50]                             |
0000000001A014F3   | 44:3BFE                  | CMP R15D, ESI                                                |
0000000001A014F6   | 4C:8BBC24 88000000       | MOV R15, QWORD PTR SS:[RSP+0x88]                             |
0000000001A014FE   | 48:8BB424 80000000       | MOV RSI, QWORD PTR SS:[RSP+0x80]                             |
0000000001A01506   | 0F85 1E010000            | JNE 0x1A0162A                                                |
0000000001A0150C   | 83FD 1D                  | CMP EBP, 0x1D                                                |
0000000001A0150F   | 75 70                    | JNE 0x1A01581                                                |
0000000001A01511   | 83FF 04                  | CMP EDI, 0x4                                                 |
0000000001A01514   | 74 16                    | JE 0x1A0152C                                                 |
0000000001A01516   | B8 040000C0              | MOV EAX, 0xC0000004                                          |
0000000001A0151B   | 48:8B9C24 90000000       | MOV RBX, QWORD PTR SS:[RSP+0x90]                             |
0000000001A01523   | 48:83C4 60               | ADD RSP, 0x60                                                |
0000000001A01527   | 41:5E                    | POP R14                                                      |
0000000001A01529   | 5F                       | POP RDI                                                      |
0000000001A0152A   | 5D                       | POP RBP                                                      |
0000000001A0152B   | C3                       | RET                                                          |

2020-2-19 10:53
0
雪    币: 35508
活跃值: (7155)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
3
sunsjw 有线不是挺好的嘛!0000000001A01490&nbsp;&lt;&nbsp;|&nbsp;4C:8BDC&nbsp;&nbsp;&nbsp ...
请教下,你用的是啥版本?前面为啥有个< 
2020-2-20 08:58
0
雪    币: 319
活跃值: (2439)
能力值: ( LV12,RANK:980 )
在线值:
发帖
回帖
粉丝
4
ninebell 请教下,你用的是啥版本?前面为啥有个<
CTRL+A后就有了
2020-2-20 12:12
0
雪    币: 35508
活跃值: (7155)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
5
csjwaman CTRL+A后就有了[em_1]
还是没有啊,亲 ~~

005B7C12 | 56             | push esi                                | esi:EntryPoint
005B7C13 | 00D8           | add al,bl                               |
005B7C15 | C2 5600        | ret 56                                  |
005B7C18 | 0000           | add byte ptr ds:[eax],al                |
005B7C1A | 0000           | add byte ptr ds:[eax],al                |
005B7C1C | 48             | dec eax                                 |
005B7C1D | 77 5B          | ja winhex自制汉化修正版.5B7C7A                 |
005B7C1F | 0055 8B        | add byte ptr ss:[ebp-75],dl             |
005B7C22 | EC             | in al,dx                                |
005B7C23 | 83C4 F0        | add esp,FFFFFFF0                        |
2020-2-21 08:26
0
雪    币: 319
活跃值: (2439)
能力值: ( LV12,RANK:980 )
在线值:
发帖
回帖
粉丝
6
ninebell 还是没有啊,亲 ~~ 005B7C12 | 56 | push esi | esi:EntryPoint ...
这个是标签的尖括号啊
2020-2-21 19:33
0
雪    币: 35508
活跃值: (7155)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
7
csjwaman 这个是标签的尖括号啊[em_1]
你用的哪个版本,粘出来的,没有这个啊,push段首 和 retn段尾看着很不舒服啊。
2020-2-22 09:26
0
雪    币: 319
活跃值: (2439)
能力值: ( LV12,RANK:980 )
在线值:
发帖
回帖
粉丝
8
ninebell 你用的哪个版本,粘出来的,没有这个啊,push段首 和 retn段尾看着很不舒服啊。
最新的版本:
00597474 < | 55                  | PUSH EBP                                   |
00597475   | 8BEC                | MOV EBP,ESP                                |
00597477   | 83C4 F0             | ADD ESP,0xFFFFFFF0                         |
0059747A   | B8 446F5900         | MOV EAX,<sub_596F44>                       | 596F44:L"¥"
0059747F   | E8 3801E7FF         | CALL <sub_4075BC>                          |
2020-2-22 13:43
0
游客
登录 | 注册 方可回帖
返回
//