- UID
- 53913
注册时间2008-6-10
阅读权限10
最后登录1970-1-1
周游历练
该用户从未签到
|
小弟初学~~请高手勿笑呵~~我这一程序用PE查壳提示"什么也没发现",PE自带的算法分析插件显示的是CRC32,不知道是没有加壳还是加了壳没查到~~
OD载入程序停在这里:
005228F1 > 8B0424 mov eax, dword ptr [esp] ; kernel32.7C816FD7
005228F4 25 0000FFFF and eax, FFFF0000
005228F9 8138 4D5A9000 cmp dword ptr [eax], 905A4D
005228FF 74 07 je short 00522908
00522901 2D 00100000 sub eax, 1000
00522906 ^ EB F1 jmp short 005228F9
00522908 55 push ebp
00522909 53 push ebx
0052290A 56 push esi
0052290B 57 push edi
0052290C 8BE8 mov ebp, eax
0052290E 0340 3C add eax, dword ptr [eax+3C]
00522911 8B78 78 mov edi, dword ptr [eax+78]
00522914 03FD add edi, ebp
00522916 8B77 20 mov esi, dword ptr [edi+20]
00522919 03F5 add esi, ebp
0052291B 33D2 xor edx, edx
0052291D 8B06 mov eax, dword ptr [esi]
0052291F 03C5 add eax, ebp
00522921 8138 47657450 cmp dword ptr [eax], 50746547
00522927 75 32 jnz short 0052295B
00522929 8178 04 726F634>cmp dword ptr [eax+4], 41636F72
00522930 75 29 jnz short 0052295B
请大哥人帮忙看看~~谢谢 |
|