UPX 0.89.6 - 1.02 / 1.05 - 1.24 -> Markus & Laszlo---脱壳完成!
已经脱壳,大家看看,关于如何跳过窗口.
用OD载入后,F7 就跳到CALL.
大大帮忙看看,怎么弄~
004011C3 /73 6A jnb short 0040122F
004011C5 |57 push edi
004011C6 |53 push ebx
004011C7 ^|73 F7 jnb short <&MSVBVM60.__vbaNextEachCo>
004011C9 |3C 51 cmp al, 51
004011CB |73 68 jnb short 00401235
004011CD |72 52 jb short 00401221
004011CF ^|73 94 jnb short 00401165
004011D1 |9A 5073F773 527>call far 7352:73F77350
004011D8 > |17 pop ss
004011D9 |74 52 je short 0040122D
//我在这里JNZ 然后出现'无法定位序数29968 于动态链接库 MSVBVM60.DLL'004011DB ^|73 A2 jnb short 0040117F
004011DD |4B dec ebx
004011DE |52 push edx
004011DF ^|73 BB jnb short <&MSVBVM60.__vbaRefVarAry>
004011E1 |58 pop eax
004011E2 |51 push ecx
004011E3 |73 03 jnb short <&MSVBVM60.__vbaVarTstEq>
004011E5 |8A52 73 mov dl, byte ptr [edx+73]
004011E8 > |36:98 cwde
004011EA |54 push esp
004011EB |73 30 jnb short 0040121D
004011ED |4C dec esp
004011EE |52 push edx
004011EF ^|73 D9 jnb short 004011CA
004011F1 |4B dec ebx
004011F2 |52 push edx
004011F3 |73 6F jnb short <&MSVBVM60.__vbaVarMul>
004011F5 |BB 51736C05 mov ebx, 56C7351
004011FA |52 push edx
004011FB |73 69 jnb short 00401266
004011FD |4C dec esp
004011FE |52 push edx
004011FF |73 02 jnb short 00401203
00401201 |0F5273 8B rsqrtps xmm6, dqword ptr [ebx-75]
00401205 |BE 517319A0 mov esi, A0197351
0040120A |44 inc esp
0040120B ^|73 F2 jnb short 004011FF
0040120D |95 xchg eax, ebp
0040120E |54 push esp
0040120F |73 74 jnb short 00401285
00401211 |75 54 jnz short 00401267
00401213 |73 19 jnb short 0040122E
00401215 |FA cli
00401216 |51 push ecx
00401217 ^|73 E9 jnb short 00401202
00401219 |BA 5173FAB7 mov edx, B7FA7351
0040121E |51 push ecx
0040121F |73 76 jnb short 00401297
00401221 |FE ??? ; 未知命令
00401222 |52 push edx
00401223 |73 17 jnb short <&MSVBVM60.__vbaRecUniToAn>
00401225 |43 inc ebx
00401226 |52 push edx
00401227 |73 12 jnb short 0040123B
00401229 |49 dec ecx
0040122A |52 push edx
0040122B ^|73 85 jnb short 004011B2
0040122D |8A52 73 mov dl, byte ptr [edx+73]
00401230 > CB retf
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)