我今天搞了下也挂了,不过是在虚拟机下的
请问楼主一下两个地方怎么找到的哦,今天就因为没找到所以偷了下懒就。。。
★下面这处千万别漏了,这个是点击格式化目录这个按钮时调用的,直接删你注册表的!!
--------------------------------------------------------------------------------
00564159 . 6A 02 push 2 ; /Origin = FILE_END
0056415B . 6A 00 push 0 ; |pOffsetHi = NULL
0056415D . 6A 00 push 0 ; |OffsetLo = 0
0056415F . 8B45 F0 mov eax, dword ptr ss:[ebp-10] ; |
00564162 . 50 push eax ; |hFile
00564163 . E8 CC28EAFF call <jmp.&kernel32.SetFilePointer> ; \SetFilePointer
00564168 . 3D 508D0F00 cmp eax, 0F8D50
0056416D . 90 nop
0056416E . E9 F7000000 jmp killit.0056426A
--------------------------------------------------------------------------------
和
去除脱壳校验:
代码:--------------------------------------------------------------------------------
0045A000 /$ 53 push ebx ; 计算校验值
0045A001 |. 89C3 mov ebx, eax
0045A003 |. B8 FFFFFFFF mov eax, -1
0045A008 |. 56 push esi
0045A009 |. 85D2 test edx, edx
0045A00B |. 74 16 je short SourceFo.0045A023
0045A00D |> 0FB633 /movzx esi, byte ptr ds:[ebx]
0045A010 |. 0FB6C8 |movzx ecx, al
0045A013 |. 31F1 |xor ecx, esi
0045A015 |. C1E8 08 |shr eax, 8
0045A018 |. 33048D C09B5700 |xor eax, dword ptr ds:[ecx*4+579BC0]
0045A01F |. 43 |inc ebx
0045A020 |. 4A |dec edx
0045A021 |.^ 75 EA \jnz short SourceFo.0045A00D
0045A023 |> 5E pop esi
0045A024 |. F7D0 not eax
0045A026 |. 5B pop ebx
0045A027 \. C3 retn
--------------------------------------------------------------------------------
还有楼主在试用中遇到其他限制或问题没有哦