*UPolyX v0.5* written by Delikon/www.delikon.de ENTRYPOINT: 82b0 FILEENTRYPOINT: 26b0 [+] Checking for UPX [+] Yes this is packed with UPX! [+] Replace the section name UPX with jEtw [+] the second UPX section starts at 0x400 [+] the second UPX section is 0x2600 big [+] Found a 0x19c big space for the decryptor [+] using the xor/xor decryptor type 0 [+] Using for Register1 EBX [+] Using for Register2 ESI [+] using offset 1 [+] use 0x2d as manipulationByte [+] encrypt 150 bytes from address 0x4082b0 till address 0x408346 [+] Generated 0x33 byte decryptor [+] Generated 0x15a bytes of trash PRESS A KEY
脱壳:
OD加载后,往下翻:
……
004085E9 .^\E2 FB loopd short 004085E6
004085EB . 59 pop ecx
004085EC . 49 dec ecx
004085ED .^ 75 DE jnz short 004085CD
004085EF . FFE6 jmp esi //F4
004085F1 00 db 00
004085F2 00 db 00
004085F3 00 db 00