我用PEID查了一下Themida/WinLicense V1.8.2.0 + -> Oreans Technologies [Overlay] *
然后用od载入...用okdodo的脚本跑到
(请问这是vc7的入口吗?我和别人的对比好像不是...是不是伪oep?我和别人对比的又好像不是)
本人超级菜...谢谢
008156EF 8DBD 410DE60A lea edi, dword ptr [ebp+AE60D41]
008156F5 AD lods dword ptr [esi]
008156F6 034424 28 add eax, dword ptr [esp+28]
008156FA AB stos dword ptr es:[edi]
008156FB 5E pop esi
008156FC C3 retn
008156FD 56 push esi
008156FE 8D9D 2E1AF70A lea ebx, dword ptr [ebp+AF71A2E]
00815704 FFD3 call ebx
00815706 ^ E9 A7FFFFFF jmp 008156B2
0081570B 83BD 1B1AFA0A 0>cmp dword ptr [ebp+AFA1A1B], 0 ;停在这里
00815712 0F84 08000000 je 00815720
00815718 8D85 D71AF70A lea eax, dword ptr [ebp+AF71AD7]
0081571E FFD0 call eax
00815720 68 00800000 push 8000
00815725 6A 00 push 0
00815727 FFB5 5D2AE60A push dword ptr [ebp+AE62A5D]
0081572D FF95 E92BE60A call dword ptr [ebp+AE62BE9]
00815733 68 00800000 push 8000
00815738 6A 00 push 0
0081573A FFB5 5D0FE60A push dword ptr [ebp+AE60F5D]
00815740 FF95 E92BE60A call dword ptr [ebp+AE62BE9]
00815746 68 00800000 push 8000
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课