脱壳工具 OD
平台 WINXP+SP2
DLL 名称是test.dll
下面是跟踪到的 花了好长时间
请各位大侠指教一下 这里是不是OEP 现在想要运行到这的话直接输入 g 10001000 即转到下面
10001000 > /6A FF push -1
10001002 . |68 D5740010 push test.100074D5 ; SE 处理程序安装
10001007 . |64:A1 0000000>mov eax,dword ptr fs:[0]
1000100D . |50 push eax
1000100E . |64:8925 00000>mov dword ptr fs:[0],esp
10001015 . |51 push ecx
10001016 . |56 push esi
10001017 . |8BF1 mov esi,ecx
10001019 . |897424 04 mov dword ptr ss:[esp+4],esi
1000101D . |8D4E 0C lea ecx,dword ptr ds:[esi+C]
10001020 . |E8 BB180000 call test.100028E0
10001025 . |8D8E C8010000 lea ecx,dword ptr ds:[esi+1C8]
1000102B . |C74424 10 000>mov dword ptr ss:[esp+10],0
10001033 . |E8 984B0000 call test.10005BD0
10001038 . |8D8E 74030000 lea ecx,dword ptr ds:[esi+374]
1000103E . |C64424 10 01 mov byte ptr ss:[esp+10],1
10001043 . |E8 28570000 call test.10006770
10001048 . |8D8E A8060000 lea ecx,dword ptr ds:[esi+6A8]
1000104E . |C64424 10 02 mov byte ptr ss:[esp+10],2
10001053 . |E8 285A0000 call test.10006A80
10001058 . |8D8E B8060000 lea ecx,dword ptr ds:[esi+6B8]
1000105E . |C64424 10 03 mov byte ptr ss:[esp+10],3
10001063 . |E8 584F0000 call test.10005FC0
10001068 . |8B4C24 08 mov ecx,dword ptr ss:[esp+8]
1000106C . |C706 F0820010 mov dword ptr ds:[esi],test.100082F0
10001072 . |C746 04 00000>mov dword ptr ds:[esi+4],0
10001079 . |C746 08 00000>mov dword ptr ds:[esi+8],0
10001080 . |8BC6 mov eax,esi
10001082 . |5E pop esi
10001083 . |64:890D 00000>mov dword ptr fs:[0],ecx
1000108A . |83C4 10 add esp,10
1000108D . |C3 ret
谢谢
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课