各位大哥,本人刚到论坛学习,用dede反编译得到以下代码,请指点一个这个函数的写法。谢谢了。
begin
{
64FC94B8 55 push ebp
64FC94B9 8BEC mov ebp, esp
64FC94BB 83C4B4 add esp, -$4C
64FC94BE B87894FC64 mov eax, $64FC9478
|
64FC94C3 E83CBAFFFF call 64FC4F04
64FC94C8 33C0 xor eax, eax
64FC94CA 55 push ebp
* Possible String Reference to: '镠?滕桢??
|
64FC94CB 68FB94FC64 push $64FC94FB
***** TRY
|
64FC94D0 64FF30 push dword ptr fs:[eax]
64FC94D3 648920 mov fs:[eax], esp
64FC94D6 A1C0A2FC64 mov eax, dword ptr [$64FCA2C0]
64FC94DB 8B00 mov eax, [eax]
* Reference to GlobalVar_64FCB60C
|
64FC94DD A30CB6FC64 mov dword ptr [$64FCB60C], eax
64FC94E2 A1C0A2FC64 mov eax, dword ptr [$64FCA2C0]
64FC94E7 C7000894FC64 mov dword ptr [eax], $64FC9408
64FC94ED 33C0 xor eax, eax
64FC94EF 5A pop edx
64FC94F0 59 pop ecx
64FC94F1 59 pop ecx
64FC94F2 648910 mov fs:[eax], edx
****** FINALLY
|
* Possible String Reference to: '桢??
|
64FC94F5 680295FC64 push $64FC9502
64FC94FA C3 ret
|
64FC94FB E94897FFFF jmp 64FC2C48
64FC9500 EBF8 jmp 64FC94FA
|
64FC9502 E8E59BFFFF call 64FC30EC
64FC9507 90 nop
64FC9508 0000 add [eax], al
}
end.
[培训]《安卓高级研修班(网课)》月薪三万计划,掌握调试、分析还原ollvm、vmp的方法,定制art虚拟机自动化脱壳的方法