按照视频教程里的OD设置好后,载入007,停在系统断点.
困惑一: 教程里没有nop
7C921231 C3 retn
7C921232 8BFF mov edi,edi
7C921234 90 nop
7C921235 90 nop
7C921236 90 nop
7C921237 90 nop
7C921238 90 nop
7C921239 > CC int3
7C92123A C3 retn
7C92123B 90 nop
7C92123C 8BFF mov edi,edi
7C92123E 90 nop
7C92123F 90 nop
7C921240 90 nop
7C921241 90 nop
7C921242 90 nop
7C921243 8B4424 04 mov eax,dword ptr ss:[esp+4]
7C921247 CC int3
7C921248 C2 0400 retn 4
困惑二.在内存PE头下断后,SHIFT+F9返回不到程序领空?,而是到了如下7C9416C8 66:8378 5C 01 cmp word ptr ds:[eax+5C],1
7C9416CD 74 10 je short ntdll.7C9416DF
7C9416CF 8B85 24FFFFFF mov eax,dword ptr ss:[ebp-DC]
7C9416D5 F640 0A 02 test byte ptr ds:[eax+A],2
7C9416D9 0F84 74020000 je ntdll.7C941953
7C9416DF FFB5 64FFFFFF push dword ptr ss:[ebp-9C]
7C9416E5 E8 271B0000 call ntdll.7C943211
7C9416EA 3C 01 cmp al,1
7C9416EC 0F84 E9490100 je ntdll.7C9560DB
7C9416F2 FFB5 64FFFFFF push dword ptr ss:[ebp-9C]
7C9416F8 E8 BF190000 call ntdll.7C9430BC
7C9416FD 3C 01 cmp al,1
7C9416FF 0F84 D6490100 je ntdll.7C9560DB
怎么回事啊,是OD设置不对吗?请教一下
例子地址 http://www.begin09.cn/showtopic-41-1.html
天草个人班之初级班 http://Down.Begin09.Com/Begin09/Low/12、脱壳2.rar
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课