程序加了两层壳,第一层是ASPack 2.12 ,第二层没见过,不知是什么壳?入口点如下:
00662000 > 55 PUSH EBP
00662001 8BEC MOV EBP,ESP
00662003 6A FF PUSH -1
00662005 68 2A2C0A00 PUSH 0A2C2A
0066200A 68 38900D00 PUSH 0D9038
0066200F 64:A1 00000000 MOV EAX,DWORD PTR FS:[0]
00662015 50 PUSH EAX
00662016 64:8925 0000000>MOV DWORD PTR FS:[0],ESP
0066201D 83EC 68 SUB ESP,68
00662020 53 PUSH EBX
00662021 56 PUSH ESI
00662022 57 PUSH EDI
00662023 8965 FA MOV DWORD PTR SS:[EBP-6],ESP
00662026 33DB XOR EBX,EBX
00662028 895D F8 MOV DWORD PTR SS:[EBP-8],EBX
0066202B 6A 02 PUSH 2
0066202D EB 01 JMP SHORT RMtoVCD?00662030
0066202F F8 CLC
00662030 58 POP EAX
00662031 5F POP EDI
00662032 5E POP ESI
00662033 5B POP EBX
00662034 64:8B25 0000000>MOV ESP,DWORD PTR FS:[0]
0066203B 64:8F05 0000000>POP DWORD PTR FS:[0]
00662042 58 POP EAX
00662043 58 POP EAX
00662044 58 POP EAX
00662045 5D POP EBP
00662046 66:9C PUSHFW
00662048 E8 04000000 CALL RMtoVCD?00662051
0066204D 0010 ADD BYTE PTR DS:[EAX],DL
0066204F 40 INC EAX
00662050 0083 C404EB04 ADD BYTE PTR DS:[EBX+4EB04C4],AL
00662056 31C8 XOR EAX,ECX
00662058 3F AAS
00662059 00EB ADD BL,CH
0066205B 04 F0 ADD AL,0F0
0066205D 0F4000 CMOVO EAX,DWORD PTR DS:[EAX]
00662060 66:9D POPFW
00662062 E8 AA000000 CALL RMtoVCD?00662111
00662067 8F ??? ; 未知命令
00662068 2026 AND BYTE PTR DS:[ESI],AH
0066206A 0000 ADD BYTE PTR DS:[EAX],AL
0066206C 0000 ADD BYTE PTR DS:[EAX],AL
0066206E 0000 ADD BYTE PTR DS:[EAX],AL
00662070 0000 ADD BYTE PTR DS:[EAX],AL
00662072 009F 2026008F ADD BYTE PTR DS:[EDI+8F002620],BL
00662078 2026 AND BYTE PTR DS:[ESI],AH
0066207A 0000 ADD BYTE PTR DS:[EAX],AL
0066207C 0000 ADD BYTE PTR DS:[EAX],AL
0066207E 0000 ADD BYTE PTR DS:[EAX],AL
00662080 0000 ADD BYTE PTR DS:[EAX],AL
[注意]看雪招聘,专注安全领域的专业人才平台!