$55, $8B, $EC, $6A, $FF, $68, $2A, $2C, $0A, $00, $68, $38, $90, $0D, $00, $64,
$A1, $00, $00, $00, $00, $50, $64, $89, $25, $00, $00, $00, $00, $58, $64, $A3,
$00, $00, $00, $00, $58, $58, $58, $58, $8B, $E8, $B8, $00, $10, $40, $00, $FF,
$E0, $90, $00, $00, $00, $00, $00, $00, $00, $00, $00, $00, $00, $00, $00, $00 呵呵,伪装的Microsoft Visual C++的外壳
入口花代码:
00463000 >55 PUSH EBP
00463001 8BEC MOV EBP,ESP
00463003 6A FF PUSH -1
00463005 68 2A2C0A00 PUSH 0A2C2A
0046300A 68 38900D00 PUSH 0D9038
0046300F 64:A1 00000000MOV EAX,DWORD PTR FS:
00463015 50 PUSH EAX
00463016 64:8925 0000000>MOV DWORD PTR FS:,ESP
0046301D 58 POP EAX
0046301E 64:A3 00000000MOV DWORD PTR FS:,EAX
00463024 58 POP EAX
00463025 58 POP EAX
00463026 58 POP EAX
00463027 58 POP EAX
00463028 8BE8 MOV EBP,EAX
0046302A B8 D4F44400 MOV EAX,Project1.0044F4D4
0046302F- FFE0 JMP EAX ; Project1.0044F4D4 VC的程序就不用伪装了吧... 恭喜病愈。。。。。。。。 支持了,不错的 东西 支持。好东西 好东西 支持一下! 先回帖子 在下软件 !!!!!!!!!!!!!!!!
页:
1
[2]