- UID
- 54436
注册时间2008-9-1
阅读权限8
最后登录1970-1-1
初入江湖

该用户从未签到
|
本人用了三种方法怎么脱出来,用PEiD查还是什么都查不到,估计还是没有脱?请高手帮忙看一下,代码在下面
004AF01A 57 push edi
004AF01B FFD5 call ebp
004AF01D 58 pop eax
004AF01E 61 popad
004AF01F 8D4424 80 lea eax,dword ptr ss:[esp-80] EPS定律法跟到这
004AF023 6A 00 push 0
004AF025 39C4 cmp esp,eax
004AF027 ^ 75 FA jnz short 定时关机.004AF023
004AF029 83EC 80 sub esp,-80
004AF02C - E9 EF84F6FF jmp 定时关机.00417520 跟到这里,再向下单步跟一下
00417515 B8 FF000000 mov eax,0FF
0041751A E8 16190000 call 定时关机.00418E35
0041751F C3 retn
00417520 E8 C4AF0000 call 定时关机.004224E9 到这个地方便脱壳了
00417525 ^ E9 79FEFFFF jmp 定时关机.004173A3
0041752A 8BFF mov edi,edi
0041752C 55 push ebp
0041752D 8BEC mov ebp,esp
0041752F 8BC1 mov eax,ecx
00417531 8B4D 08 mov ecx,dword ptr ss:[ebp+8]
00417534 C700 88DA4700 mov dword ptr ds:[eax],定时关机.0047DA88
0041753A 8B09 mov ecx,dword ptr ds:[ecx]
0041753C 8360 08 00 and dword ptr ds:[eax+8],0
00417540 8948 04 mov dword ptr ds:[eax+4],ecx
00417543 5D pop ebp
00417544 C2 0800 retn 8 |
|