////////////////////////////////////////////////////
xp
////////////////////////////////////////////////////
7C809E01 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936EF5
[tmp] = 00242000
[tmp] = 00000004
----------------------------------
7C809E01 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936EF5
[tmp] = 00243000
[tmp] = 00000004
----------------------------------
7C809E01 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936EF5
[tmp] = 00244000
[tmp] = 00000004
----------------------------------
7C809E01 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936EF5
[tmp] = 00245000
[tmp] = 00000004
----------------------------------
7C809E01 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936EF5
[tmp] = 00246000
[tmp] = 00000004
----------------------------------
7C809E3A Access violation in KERNEL32 ignored on request
7C809E01 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936F8E | ASCII "h["
[tmp] = 00245FF0
[tmp] = 00000010
----------------------------------
////////////////////////////////////////////////////
2003
////////////////////////////////////////////////////
7C82B267 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936EF5
[tmp] = 7C9BA000
[tmp] = 00000004
----------------------------------
7C82B267 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936EF5
[tmp] = 7C9BB000
[tmp] = 00000004
----------------------------------
7C82B267 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936EF5
[tmp] = 7C9BC000
[tmp] = 00000004
----------------------------------
7C82B267 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936EF5
[tmp] = 7C9BD000
[tmp] = 00000004
----------------------------------
7C82B267 Breakpoint at kernel32.IsBadReadPtr
----------------------------------
[tmp] = 00936EF5
7C9BC000这个是在ntdll里,00246000在exe前
2003里最后异常了,没显示后2个参数,也没继续下去,等知道themida想干吗后,再看看osc插件的问题
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课