- UID
- 37730
注册时间2007-12-1
阅读权限10
最后登录1970-1-1
周游历练
TA的每日心情 | 开心 2017-8-17 14:13 |
---|
签到天数: 1 天 [LV.1]初来乍到
|
PEID V0.95 测为UPX 0.89.6 - 1.02 / 1.05 - 2.90 -> Markus & Laszlo [Overlay]
搞了一天了,还没搞定,请高手们指点
004A81E8 8B07 mov eax, dword ptr [edi]
004A81EA 8A5F 04 mov bl, byte ptr [edi+4]
004A81ED 66:C1E8 08 shr ax, 8
004A81F1 C1C0 10 rol eax, 10
004A81F4 86C4 xchg ah, al
004A81F6 29F8 sub eax, edi
004A81F8 80EB E8 sub bl, 0E8
004A81FB 01F0 add eax, esi
004A81FD 8907 mov dword ptr [edi], eax
004A81FF 83C7 05 add edi, 5
004A8202 88D8 mov al, bl
004A8204 ^ E2 D9 loopd short 004A81DF
004A8206 8DBE 00400A00 lea edi, dword ptr [esi+A4000]
004A820C 8B07 mov eax, dword ptr [edi]
004A820E 09C0 or eax, eax
004A8210 74 45 je short 004A8257
004A8212 8B5F 04 mov ebx, dword ptr [edi+4]
004A8215 8D8430 0C930A00 lea eax, dword ptr [eax+esi+A930C]
004A821C 01F3 add ebx, esi
004A821E 50 push eax
004A821F 83C7 08 add edi, 8
004A8222 FF96 60940A00 call dword ptr [esi+A9460]
004A8228 95 xchg eax, ebp
004A8229 8A07 mov al, byte ptr [edi]
004A822B 47 inc edi
004A822C 08C0 or al, al
004A822E ^ 74 DC je short 004A820C
004A8230 89F9 mov ecx, edi
004A8232 79 07 jns short 004A823B
004A8234 0FB707 movzx eax, word ptr [edi]
004A8237 47 inc edi
004A8238 50 push eax
004A8239 47 inc edi
004A823A B9 5748F2AE mov ecx, AEF24857
004A823F 55 push ebp
004A8240 FF96 64940A00 call dword ptr [esi+A9464]
004A8246 09C0 or eax, eax
004A8248 74 07 je short 004A8251
004A824A 8903 mov dword ptr [ebx], eax
004A824C 83C3 04 add ebx, 4
004A824F ^ EB D8 jmp short 004A8229
004A8251 FF96 74940A00 call dword ptr [esi+A9474]
004A8257 8BAE 68940A00 mov ebp, dword ptr [esi+A9468]
004A825D 8DBE 00F0FFFF lea edi, dword ptr [esi-1000]
004A8263 BB 00100000 mov ebx, 1000
004A8268 50 push eax
004A8269 54 push esp
004A826A 6A 04 push 4
004A826C 53 push ebx
004A826D 57 push edi ; bbx003.00400000
004A826E FFD5 call ebp
004A8270 8D87 17020000 lea eax, dword ptr [edi+217]
004A8276 8020 7F and byte ptr [eax], 7F
004A8279 8060 28 7F and byte ptr [eax+28], 7F
004A827D 58 pop eax
004A827E 50 push eax
004A827F 54 push esp
004A8280 50 push eax
004A8281 53 push ebx
004A8282 57 push edi
004A8283 FFD5 call ebp
004A8285 58 pop eax
004A8286 61 popad ------出壳
004A8287 8D4424 80 lea eax, dword ptr [esp-80]
004A828B 6A 00 push 0
004A828D 39C4 cmp esp, eax
004A828F ^ 75 FA jnz short 004A828B
004A8291 83EC 80 sub esp, -80
004A8294 - E9 D7F4F6FF jmp 00417770
004A8299 0000 add byte ptr [eax], al
004A829B 0000 add byte ptr [eax], al
我在向下我怎么也找不到oep |
本帖子中包含更多资源
您需要 登录 才可以下载或查看,没有账号?加入我们
x
|