出来了
谢谢帮看看
005542FC 正常调用(指令数60165418): KERNEL32.DLL!GetProcAddress
005542FC 正常调用(指令数60165447): KERNEL32.DLL!GetProcAddress
005542FC 正常调用(指令数60165476): KERNEL32.DLL!GetProcAddress
00554295 正常调用(指令数60165508): KERNEL32.DLL!GetModuleHandleA
005542FC 正常调用(指令数60165535): KERNEL32.DLL!GetProcAddress
可能到OEP了,如果不完全正确,请再单步走几下!
005543B0 7508 JNZ 005543BA
可能到OEP了,如果不完全正确,请再单步走几下!
005543BA 6850254F00 PUSH 4F2550
005543BF C3 RET
可能到OEP了,如果不完全正确,请再单步走几下!
004F2550 55 PUSH EBP
Command: MAKEPE 4F2550
Make PE now
Start:7C920000 End:7C9B4000
Start:7C800000 End:7C91C000
Start:77D10000 End:77D9F000
Start:77EF0000 End:77F36000
Start:77DA0000 End:77E49000
Start:77E50000 End:77EE1000
Start:770F0000 End:7717C000
Start:77BE0000 End:77C38000
Start:76990000 End:76ACC000
Start:77BD0000 End:77BD8000
Start:5D170000 End:5D207000
Start:72F70000 End:72F96000
Start:773A0000 End:77B91000
Start:77F40000 End:77FB6000
Start:76680000 End:76722000
Start:765E0000 End:76672000
Start:76DB0000 End:76DC2000
Start:76300000 End:7631D000
Start:62C20000 End:62C29000
Start:73FA0000 End:7400B000
Start:10000000 End:1000C000
Start:77180000 End:77282000
Start:00F60000 End:01003000
Start:73D30000 End:73E2E000
Start:61BE0000 End:61BED000
Start:71A20000 End:71A37000
Start:71A10000 End:71A18000
Start:66000000 End:66152000
HODULE=00400100
nSec=10
VirtualSize RVA PhysicalSize PhysicalOffset
p=004001F8
f2000 1000 54400 400
p=00400220
3000 f3000 1200 54800
p=00400248
2000 f6000 0 0
p=00400270
3000 f8000 1000 55a00
p=00400298
1000 fb000 0 0
p=004002C0
1000 fc000 200 56a00
p=004002E8
e000 fd000 0 0
p=00400310
49000 10b000 22600 56c00
p=00400338
4000 154000 3a00 79200
p=00400360
1000 158000 0 0
卡在这里了