有一个软件!用peid查无壳!
用od在入后提示有“压缩”等等!
看各位高手的脱壳发的帖子,试着用ESP定律
单步F8运行,ESP=0012ffc0
下断点HR 0012ffc0,F9运行!可就是断不下来!
请各位指点一下!
004023D0 >/$ 55 push ebp ; (initial cpu selection)
004023D1 |. 8BEC mov ebp, esp ;esp=0012ffc0
004023D3 |. 81EC 80000000 sub esp, 80
004023D9 |. 56 push esi
004023DA |. C745 D0 05AA8>mov dword ptr [ebp-30], 289AA05
004023E1 |. A1 FC7E5900 mov eax, dword ptr [<&KERNEL32.GetMo>
004023E6 |. 8945 F4 mov dword ptr [ebp-C], eax
004023E9 |. 8B0D 007F5900 mov ecx, dword ptr [<&KERNEL32.Virtu>; kernel32.VirtualQuery
004023EF |. 894D F8 mov dword ptr [ebp-8], ecx
004023F2 |. 8B15 047F5900 mov edx, dword ptr [<&KERNEL32.Virtu>; kernel32.VirtualProtect
004023F8 |. 8955 F0 mov dword ptr [ebp-10], edx
004023FB |. A1 087F5900 mov eax, dword ptr [<&KERNEL32.Globa>
00402400 |. 8945 A0 mov dword ptr [ebp-60], eax
00402403 |. 8B0D 0C7F5900 mov ecx, dword ptr [<&KERNEL32.Globa>; kernel32.GlobalLock
00402409 |. 894D FC mov dword ptr [ebp-4], ecx
0040240C |. 8B15 107F5900 mov edx, dword ptr [<&KERNEL32.Globa>; kernel32.GlobalUnlock
00402412 |. 8955 C4 mov dword ptr [ebp-3C], edx
00402415 |. A1 147F5900 mov eax, dword ptr [<&KERNEL32.Globa>
0040241A |. 8945 E4 mov dword ptr [ebp-1C], eax
0040241D |. 6A 00 push 0
0040241F |. FF55 F4 call dword ptr [ebp-C]
00402422 |. 8945 A4 mov dword ptr [ebp-5C], eax
00402425 |. 8B4D A4 mov ecx, dword ptr [ebp-5C]
00402428 |. 8B55 A4 mov edx, dword ptr [ebp-5C]
0040242B |. 0351 3C add edx, dword ptr [ecx+3C]
0040242E |. 8955 DC mov dword ptr [ebp-24], edx
00402431 |. 8B45 DC mov eax, dword ptr [ebp-24]
00402434 |. 8138 50450000 cmp dword ptr [eax], 4550
0040243A |. 75 11 jnz short 0040244D
0040243C |. 8B4D DC mov ecx, dword ptr [ebp-24]
0040243F |. 33D2 xor edx, edx
00402441 |. 66:8B51 04 mov dx, word ptr [ecx+4]
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!