脱壳,帮帮我,谢谢谢谢

来源:百度知道 编辑:UC知道 时间:2024/05/16 10:08:46
ASProtect 2.1x SKE -> Alexey Solodovnikov
以上的壳谁会脱?
会的帮帮忙

一、避开加密,得到完整IAT
OD忽略除INT3外的所有异常(注意同时忽略以下所有异常前面不要选),过两次异常后在CODE段下内存断点,到这里:

代码:--------------------------------------------------------------------------------004B09F0 55 PUSH EBP
004B09F1 8BEC MOV EBP,ESP
004B09F3 83C4 F0 ADD ESP,-10
004B09F6 B8 40074B00 MOV EAX,ssc_serv.004B0740
004B09FB E8 7C5CF5FF CALL ssc_serv.0040667C
004B0A00 A1 70744B00 MOV EAX,DWORD PTR DS:[4B7470]
004B0A05 8B00 MOV EAX,DWORD PTR DS:[EAX]
004B0A07 E8 D43FFBFF CALL ssc_serv.004649E0
004B0A0C A1 70744B00 MOV EAX,DWORD PTR DS:[4B7470]
004B0A11 8B00 MOV EAX,DWORD PTR DS:[EAX]
004B0A13 BA 800A4B00 MOV EDX,ssc_serv.004B0A80 ; ASCII "SSC Service Utility"
004B0A18 E8 BB3BFBFF CALL ssc_serv.004645D8
004B0A1D 8B0D C0754B00 MOV ECX,DWORD PTR DS:[4B75C0] ; ssc_serv.004BC344
004B0