ASProtect 1.23 RC4 - 1.3.08.24 -> Alexey Solodovnikov [Overlay]
学了天草第20课两种方法“以自己的名字注册ASProtect加壳程序”根据第一种方法,
01BE6038 BB 00000000 mov ebx,0 在这里脱壳之后用AsprDbgr,发现AsprDbgr不能运行,估计程序有检测
之后我又用第二种方法
01BE603D 0BDB or ebx,ebx
01BE603F 75 07 jnz short 01BE6048 到了这里没有跳转
01BE6041 894424 1C mov dword ptr ss:[esp+1C],eax
01BE6045 61 popad
01BE6046 50 push eax
01BE6047 C3 retn
在这里返回 007E23A1 E8 A9470100 call CreakMe.007F6B4F f7进去
007F6B4F 55 push ebp
007F6B50 8BEC mov ebp,esp
007F6B52 83EC 10 sub esp,10
007F6B55 A1 00BD9200 mov eax,dword ptr ds:[92BD00]
007F6B5A 8365 F8 00 and dword ptr ss:[ebp-8],0
007F6B5E 8365 FC 00 and dword ptr ss:[ebp-4],0
007F6B62 53 push ebx
007F6B63 57 push edi
007F6B64 BF 4EE640BB mov edi,BB40E64E
007F6B69 3BC7 cmp eax,edi
007F6B6B BB 0000FFFF mov ebx,FFFF0000
007F6B70 74 0D je short CreakMe.007F6B7F
007F6B72 85C3 test ebx,eax
007F6B74 74 09 je short CreakMe.007F6B7F
007F6B76 F7D0 not eax
007F6B78 A3 04BD9200 mov dword ptr ds:[92BD04],eax
007F6B7D EB 60 jmp short CreakMe.007F6BDF
007F6B7F 56 push esi
007F6B80 8D45 F8 lea eax,dword ptr ss:[ebp-8]
007F6B83 50 push eax
007F6B84 FF15 7C418100 call dword ptr ds:[81417C]
007F6B8A 8B75 FC mov esi,dword ptr ss:[ebp-4]
007F6B8D 3375 F8 xor esi,dword ptr ss:[ebp-8]
007F6B90 FF15 44418100 call dword ptr ds:[814144]
007F6B96 33F0 xor esi,eax
007F6B98 FF15 40418100 call dword ptr ds:[814140]
007F6B9E 33F0 xor esi,eax
007F6BA0 FF15 70418100 call dword ptr ds:[814170]
007F6BA6 33F0 xor esi,eax
007F6BA8 8D45 F0 lea eax,dword ptr ss:[ebp-10]
007F6BAB 50 push eax
007F6BAC FF15 D0418100 call dword ptr ds:[8141D0]
007F6BB2 8B45 F4 mov eax,dword ptr ss:[ebp-C]
007F6BB5 3345 F0 xor eax,dword ptr ss:[ebp-10]
007F6BB8 33F0 xor esi,eax
007F6BBA 3BF7 cmp esi,edi
007F6BBC 75 07 jnz short CreakMe.007F6BC5
007F6BBE BE 4FE640BB mov esi,BB40E64F
007F6BC3 EB 0B jmp short CreakMe.007F6BD0
007F6BC5 85F3 test ebx,esi
007F6BC7 75 07 jnz short CreakMe.007F6BD0
007F6BC9 8BC6 mov eax,esi
007F6BCB C1E0 10 shl eax,10
007F6BCE 0BF0 or esi,eax
007F6BD0 8935 00BD9200 mov dword ptr ds:[92BD00],esi
007F6BD6 F7D6 not esi
007F6BD8 8935 04BD9200 mov dword ptr ds:[92BD04],esi
007F6BDE 5E pop esi
007F6BDF 5F pop edi
007F6BE0 5B pop ebx
007F6BE1 C9 leave
007F6BE2 C3 retn
之后就不知道怎么办了,请高手提示点
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课