首页
社区
课程
招聘
hmimys'packer脱壳[原创]
发表于: 2006-10-1 17:08 3216

hmimys'packer脱壳[原创]

fob 活跃值
5
2006-10-1 17:08
3216
hmimys'packer

FoBnN

fobcrackgp[at]163.com



OD+LOPE+xxxxxxxxxxxxx

XP+SP2

Fake Ninja 2.7 by Spirit





hmimys'packer



.

---------------------------------------------------------------------- --





bp VirtualFree F9 RUN

004A6404 > E8 BA000000 call Fake_Nin.004A64C3 EP

004A6409 0300 add eax,dword ptr ds:[eax]

004A640B 0000 add byte ptr ds:[eax],al

004A640D 0050 0A add byte ptr ds:[eax+A],dl

004A6410 0000 add byte ptr ds:[eax],al

004A6412 1040 00 adc byte ptr ds:[eax],al



7C809AE4 > 8BFF mov edi,edi ; Fake_Nin.004A6C1C ;

7C809AE6 55 push ebp

7C809AE7 8BEC mov ebp,esp

7C809AE9 FF75 10 push dword ptr ss:[ebp+10]

7C809AEC FF75 0C push dword ptr ss:[ebp+C]

7C809AEF FF75 08 push dword ptr ss:[ebp+8]

7C809AF2 6A FF push -1

7C809AF4 E8 09000000 call kernel32.VirtualFreeEx

7C809AF9 5D pop ebp

7C809AFA C2 0C00 retn 0C





004A6D44 85F6 test esi,esi

004A6D46 74 05 je short Fake_Nin.004A6D4D

004A6D48 6A 01 push 1

004A6D4A 58 pop eax

004A6D4B EB 13 jmp short Fake_Nin.004A6D60





004A64DD AD lods dword ptr ds:[esi]

004A64DE 8BDE mov ebx,esi

004A64E0 8BF0 mov esi,eax

004A64E2 83C3 44 add ebx,44

004A64E5 AD lods dword ptr ds:[esi]

004A64E6 85C0 test eax,eax

004A64E8 74 32 je short Fake_Nin.004A651C



004A6521 AD lods dword ptr ds:[esi]

004A6522 50 push eax

004A6523 C3 retn F2 .





F9

004A6523 C3 retn EAX=OEP

F7

00472D0C 55 push ebp OEP

00472D0D 8BEC mov ebp,esp

00472D0F 83C4 F0 add esp,-10

00472D12 B8 1C2B4700 mov eax,Fake_Nin.00472B1C

00472D17 E8 6C2FF9FF call Fake_Nin.00405C88

00472D1C A1 14BA4700 mov eax,dword ptr ds:[47BA14]

00472D21 8B00 mov eax,dword ptr ds:[eax]

00472D23 E8 C08EFEFF call Fake_Nin.0045BBE8

00472D28 8B0D 20B84700 mov ecx,dword ptr ds:[47B820] ; Fake_Nin.0047CBD8

00472D2E A1 14BA4700 mov eax,dword ptr ds:[47BA14]







DUMP FIX

!

----------------------------------------------------------------------

,.

----------------------------------------------------------------------


[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

收藏
免费 0
支持
分享
最新回复 (0)
游客
登录 | 注册 方可回帖
返回
//