IAT的加密的手动查找
2009-06-05 16:55:22 来源:WEB开发网0101C925 |68 047C0201 push UnpackMe.01027C04 ; ASCII "oleaout32.dll"
0101C92A |8B55 F4 mov edx,dword ptr ss:[ebp-C]
0101C92D |52 push edx
0101C92E |E8 FD010000 call UnpackMe.0101CB30
0101C933 8BE5 mov esp,ebp
0101C935 5D pop ebp
0101C936 C3 retn=============在此继续F2下断
F9运行中断后,取消断点,F7进入:
010162CB 8B4D EC mov ecx,dword ptr ss:[ebp-14] ; UnpackMe.0100739D
010162CE 894D 08 mov dword ptr ss:[ebp+8],ecx
010162D1 833D B4C90201 00 cmp dword ptr ds:[102C9B4],0
010162D8 74 13 je short UnpackMe.010162ED
010162DA 6A 00 push 0
010162DC 6A 00 push 0
010162DE 6A 00 push 0
010162E0 8B15 B4C90201 mov edx,dword ptr ds:[102C9B4]
010162E6 52 push edx
010162E7 FF15 B8870201 call dword ptr ds:[10287B8] ; user32.PostMessageA
更多精彩
赞助商链接