<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>火星信息安全研究院脱壳『Unpack』</title>
	<atom:link href="http://www.h4ck.org.cn/category/crackasm/unpacktk/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.h4ck.org.cn</link>
	<description>Hack-Crack  信息安全 【Institute Of Information Serurity From Mars】</description>
	<lastBuildDate>Wed, 08 Feb 2012 03:19:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>SQLiteMaestro v11.3.0.1 Crack Guide</title>
		<link>http://www.h4ck.org.cn/2011/12/sqlitemaestro-v11-3-0-1-crack-guide/</link>
		<comments>http://www.h4ck.org.cn/2011/12/sqlitemaestro-v11-3-0-1-crack-guide/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 10:12:16 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[破解/汇编『Crack/Asm』]]></category>
		<category><![CDATA[脱壳『Unpack』]]></category>
		<category><![CDATA[Crack]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=3522</guid>
		<description><![CDATA[SQLiteMaestro v11.3.0.1 ]]></description>
			<content:encoded><![CDATA[<p><img title="SqliteMaestro" src="http://www.h4ck.org.cn/wp-content/uploads//2011/12/SqliteMaestro1.png" alt="" width="579" height="534" /></p>
<p>其实这个东西也不算是破解掉了，因为外面的那个aspr的壳没有脱掉，于是借助工具创建了一个带壳的loader。其实东西如果脱壳了，那么破解就非常简单了。如果不知道怎么脱这个壳，<a href="http://www.h4ck.org.cn/2010/03/asprotect-1-23-rc4-1-3-08-24-alexey-solodovnikov-stolen-code/" target="_blank">参考这里</a>。如果已经脱掉壳了。那么破解也就非常简单了。这里就简单的贴几条代码，看懂了就看，看不懂就算了。为了兑现前面说的话，这里不再提供loader下载，大家去别的地方找吧。不好意思。<span id="more-3522"></span></p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
</pre></td><td class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">00407C8C</span> $<span style="color: #339933;">-</span> FF25 4CE3E600 <span style="color: #00007f; font-weight: bold;">jmp</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>E6E34C<span style="color: #009900; font-weight: bold;">&#93;</span> <span style="color: #666666; font-style: italic;">; (initial cpu selection)</span>
<span style="color: #adadad; font-style: italic;">00407C92</span> 8BC0 <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00407C94</span> $<span style="color: #339933;">-</span> FF25 48E3E600 <span style="color: #00007f; font-weight: bold;">jmp</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>E6E348<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00407C9A</span> 8BC0 <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00407C9C</span> $<span style="color: #339933;">-</span> FF25 44E3E600 <span style="color: #00007f; font-weight: bold;">jmp</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>E6E344<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00407CA2</span> 8BC0 <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00407CA4</span> $<span style="color: #339933;">-</span> FF25 40E3E600 <span style="color: #00007f; font-weight: bold;">jmp</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>E6E340<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00407CAA</span> 8BC0 <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">01BB00E1</span> <span style="color: #0000ff;">51</span> <span style="color: #00007f; font-weight: bold;">push</span> <span style="color: #00007f;">ecx</span> <span style="color: #666666; font-style: italic;">;he 01BB00E1</span>
<span style="color: #adadad; font-style: italic;">01BB00E2</span> <span style="color: #0000ff;">57</span> <span style="color: #00007f; font-weight: bold;">push</span> <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">01BB00E3</span> 9C <span style="color: #00007f; font-weight: bold;">pushfd</span>
<span style="color: #adadad; font-style: italic;">01BB00E4</span> FC <span style="color: #00007f; font-weight: bold;">cld</span>
<span style="color: #adadad; font-style: italic;">01BB00E5</span> BF 2201BB01 <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">edi</span><span style="color: #339933;">,</span> 1BB0122
<span style="color: #adadad; font-style: italic;">01BB00EA</span> B9 <span style="color: #0000ff;">5E140000</span> <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> 145E
<span style="color: #adadad; font-style: italic;">01BB00EF</span> F3<span style="color: #339933;">:</span>AA <span style="color: #00007f; font-weight: bold;">rep</span> <span style="color: #00007f; font-weight: bold;">stos</span> <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">es</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edi</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01BB00F1</span> 9D <span style="color: #00007f; font-weight: bold;">popfd</span>
<span style="color: #adadad; font-style: italic;">01BB00F2</span> <span style="color: #0000ff;">5F</span> <span style="color: #00007f; font-weight: bold;">pop</span> <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">01BB00F3</span> <span style="color: #0000ff;">59</span> <span style="color: #00007f; font-weight: bold;">pop</span> <span style="color: #00007f;">ecx</span>
&nbsp;
<span style="color: #adadad; font-style: italic;">00E414D8</span> <span style="color: #339933;">/</span><span style="color: #0000ff;">74</span> <span style="color: #0000ff;">07</span> <span style="color: #00007f; font-weight: bold;">je</span> <span style="color: #000000; font-weight: bold;">short</span> 00E414E1 <span style="color: #666666; font-style: italic;">; 跳过提示窗口</span>
<span style="color: #adadad; font-style: italic;">00A2B4D8</span> <span style="color: #339933;">/</span>0F85 8F000000 <span style="color: #00007f; font-weight: bold;">jnz</span> 00A2B56D <span style="color: #666666; font-style: italic;">; 跳转到注册</span>
<span style="color: #adadad; font-style: italic;">00A2DAFD</span> <span style="color: #339933;">/</span>0F85 <span style="color: #0000ff;">98000000</span> <span style="color: #00007f; font-weight: bold;">jnz</span> 00A2DB9B <span style="color: #666666; font-style: italic;">; 跳转到注册</span></pre></td></tr></table></div>

<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2011/04/cracklb-dvd-2011-full/" title="CRACKL@B DVD 2011 FULL" rel="bookmark inlinks">CRACKL@B DVD 2011 FULL</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/10/mylanviewer-4-3-3-cracked/" title="MyLanViewer 4.3.3 破解版" rel="bookmark inlinks">MyLanViewer 4.3.3 破解版</a><span class="count">( 2 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/09/iappmaster-1-0-nag-removed-cracked-by-obaby/" title="iAppMaster 1.0 Nag Removed [Cracked by obaby]" rel="bookmark inlinks">iAppMaster 1.0 Nag Removed [Cracked by obaby]</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/06/w32dasm-v10-and-imprec-v1-7c/" title="W32Dasm V10 And ImpREC.v1.7c" rel="bookmark inlinks">W32Dasm V10 And ImpREC.v1.7c</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/08/ada-zoo-crack/" title="阿达宠物园 破解分析" rel="bookmark inlinks">阿达宠物园 破解分析</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/08/hide-window-hotkey-crack/" title="Hide Window Hotkey 破解版" rel="bookmark inlinks">Hide Window Hotkey 破解版</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/09/cxjk/" title="程序监控专家 破解版" rel="bookmark inlinks">程序监控专家 破解版</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/08/super-turtle-crack/" title="Super turtle 内存清理    破解版" rel="bookmark inlinks">Super turtle 内存清理    破解版</a><span class="count">( 0 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2011/12/sqlitemaestro-v11-3-0-1-crack-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scylla v0.5a- x64/x86 Imports Reconstruction</title>
		<link>http://www.h4ck.org.cn/2011/11/scylla-v0-5a-x64x86-imports-reconstruction/</link>
		<comments>http://www.h4ck.org.cn/2011/11/scylla-v0-5a-x64x86-imports-reconstruction/#comments</comments>
		<pubDate>Sat, 19 Nov 2011 09:06:39 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[脱壳『Unpack』]]></category>
		<category><![CDATA[PETools]]></category>
		<category><![CDATA[Unpack]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=3398</guid>
		<description><![CDATA[Scylla v0.5a- x64/x86 Imports Reconstruction]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.h4ck.org.cn/wp-content/uploads//2011/11/Scylla.png" rel="lightbox" title="Scylla"><img title="Scylla" src="http://www.h4ck.org.cn/wp-content/uploads//2011/11/Scylla.png" alt="" width="593" height="645" /></a></p>
<p>Scylla &#8211; x64/x86 Imports Reconstruction<br />
=======================================</p>
<p>ImpREC, CHimpREC, Imports Fixer&#8230; this are all great tools to rebuild an import table,<br />
but they all have some major disadvantages, so I decided to create my own tool for this job.<br />
<span id="more-3398"></span><br />
Scylla&#8217;s key benefits are:</p>
<p>- x64 and x86 support<br />
- full unicode support (probably some russian or chinese will like this <img src='http://www.h4ck.org.cn/wp-content/plugins/smilies-themer/Julianus/20x20-big_smile.png' alt=':-)' class='wp-smiley' /> )<br />
- written in C/C++<br />
- plugin support<br />
- works great with Windows 7</p>
<p>This tool was designed to be used with Windows 7 x64, so it is recommend to use this operating system.<br />
But it may work with XP and Vista, too.</p>
<p>Source code is licensed under GNU GENERAL PUBLIC LICENSE v3.0</p>
<p>Known Bugs<br />
&#8212;&#8212;&#8212;-</p>
<p>### Only Windows XP x64:</p>
<p>Windows XP x64 has some API bugs. 100% correct imports reconstruction is impossible.<br />
If you still want to use XP x64, here are some hints:</p>
<p>* EncodePointer/DecodePointer exported by kernel32.dll have both the same VA.<br />
Scylla, CHimpREC and other tools cannot know which API is correct. You need to fix this manually.<br />
Your fixed dump will probably run fine on XP but crash on Vista/7.</p>
<p>### ImpREC plugin support:</p>
<p>Some ImpREC Plugins don&#8217;t work with Windows Vista/7 because they don&#8217;t “return 1&#8243; in the DllMain function.</p>
<p>Keyboard Shortcuts<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>- CTRL + D: [D]ump<br />
- CTRL + F: [F]ix Dump<br />
- CTRL + R: PE [R]ebuild<br />
- CTRL + O: L[o]ad Tree<br />
- CTRL + S: [S]ave Tree<br />
- CTRL + T: Auto[t]race<br />
- CTRL + G: [G]et Imports<br />
- CTRL + I: [I]AT Autosearch</p>
<p>Changelog<br />
&#8212;&#8212;&#8212;</p>
<p>Version 0.5a:</p>
<p>- fixed memory leak<br />
- improved IAT search</p>
<p>Version 0.5:</p>
<p>- added save/load import tree feature<br />
- multi-select in tree view<br />
- fixed black icons problem in tree view<br />
- added keyboard shortcuts<br />
- dll dump + dll dump fix now working<br />
- added support for scattered IATs<br />
- pre select target path in open file dialogs<br />
- improved import resolving engine with api scoring<br />
- api selection dialog<br />
- minor bug fixes and improvements</p>
<p>Version 0.4:</p>
<p>- GUI code improvements<br />
- bug fixes<br />
- imports by ordinal</p>
<p>Version 0.3a:</p>
<p>- Improved import resolving<br />
- fixed buffer overflow errors</p>
<p>Version 0.3:</p>
<p>- ImpREC plugin support<br />
- minor bug fix</p>
<p>Version 0.2a:</p>
<p>- improved disassembler dialog<br />
- improved iat search</p>
<p>Version 0.2:</p>
<p>- improved process detection<br />
- added some options<br />
- new options dialog<br />
- improved source code</p>
<p><a href="http://dl.dbank.com/c0wy9nhwhn" target="_blank">click here to download.</a><br />
<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2010/02/explorersuite-13-12-09/" title="ExplorerSuite.13.12.09" rel="bookmark inlinks">ExplorerSuite.13.12.09</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/03/armadillo-v6-x-minimum-protection-unpack/" title="Armadillo V6.X Minimum Protection 【脱壳】" rel="bookmark inlinks">Armadillo V6.X Minimum Protection 【脱壳】</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/08/packer-unpack/" title="普通壳的脱壳方法和脱壳技巧【转载】" rel="bookmark inlinks">普通壳的脱壳方法和脱壳技巧【转载】</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/02/ida-pro-5-6-demo/" title="IDA PRO 5.6 Demo" rel="bookmark inlinks">IDA PRO 5.6 Demo</a><span class="count">( 1 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/04/imp64/" title="imp64" rel="bookmark inlinks">imp64</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/01/fhash/" title="文件Hash计算工具（MD5/SHA1/SHA256/CRC32）" rel="bookmark inlinks">文件Hash计算工具（MD5/SHA1/SHA256/CRC32）</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/01/protection-id-v0-6-3-5-public-december-2009/" title="Protection ID v0.6.3.5 Public DECEMBER 2009    " rel="bookmark inlinks">Protection ID v0.6.3.5 Public DECEMBER 2009    </a><span class="count">( 5 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/01/cracklb-dvd-shell-2010/" title="CRACKL@B DvD SHELL 2010" rel="bookmark inlinks">CRACKL@B DvD SHELL 2010</a><span class="count">( 0 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2011/11/scylla-v0-5a-x64x86-imports-reconstruction/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DecomeAS -Asprotect killer</title>
		<link>http://www.h4ck.org.cn/2011/07/decomeas-asprotect-killer/</link>
		<comments>http://www.h4ck.org.cn/2011/07/decomeas-asprotect-killer/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 08:44:09 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[脱壳『Unpack』]]></category>
		<category><![CDATA[Packer]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=2927</guid>
		<description><![CDATA[DecomeAS -Asprotect killer ]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.h4ck.org.cn/wp-content/uploads//2011/07/ASPR-KILLER.png" rel="lightbox" title="ASPR KILLER"><img title="ASPR KILLER" src="http://www.h4ck.org.cn/wp-content/uploads//2011/07/ASPR-KILLER.png" alt="" width="526" height="424" /></a></p>
<p><a href="http://dl.dbank.com/s089tq0wrn" target="_blank">Click here to download the file!</a><br />
<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2010/01/vmprotect-1-70-4-%e7%a0%b4%e8%a7%a3%e7%89%88/" title="VMProtect 1.70.4 破解版" rel="bookmark inlinks">VMProtect 1.70.4 破解版</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/01/protection-id-v0-6-3-5-public-december-2009/" title="Protection ID v0.6.3.5 Public DECEMBER 2009    " rel="bookmark inlinks">Protection ID v0.6.3.5 Public DECEMBER 2009    </a><span class="count">( 5 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/09/zprotect-v1-4-1-carcked/" title="加密强壳ZProtect v1.4.1破解版" rel="bookmark inlinks">加密强壳ZProtect v1.4.1破解版</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/03/binder-2010/" title="南域剑盟文件捆绑器2010" rel="bookmark inlinks">南域剑盟文件捆绑器2010</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/11/obsidium-v1-3-6-4-%e3%80%90cracked%e3%80%91/" title="Obsidium v1.3.6.4 【Cracked】" rel="bookmark inlinks">Obsidium v1.3.6.4 【Cracked】</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/01/asprotect-ske-2-51/" title="ASProtect SKE 2.51" rel="bookmark inlinks">ASProtect SKE 2.51</a><span class="count">( 1 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/10/mew-11-1-2-northfoxhcc/" title="MEW 11 1.2 -> NorthFox/HCC 脱壳脚本” rel=”bookmark inlinks”>MEW 11 1.2 -> NorthFox/HCC 脱壳脚本</a><span class="count">( 0 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2011/07/decomeas-asprotect-killer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32Dasm V10 And ImpREC.v1.7c</title>
		<link>http://www.h4ck.org.cn/2010/06/w32dasm-v10-and-imprec-v1-7c/</link>
		<comments>http://www.h4ck.org.cn/2010/06/w32dasm-v10-and-imprec-v1-7c/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 04:45:34 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[破解/汇编『Crack/Asm』]]></category>
		<category><![CDATA[脱壳『Unpack』]]></category>
		<category><![CDATA[Crack]]></category>
		<category><![CDATA[PETools]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=1704</guid>
		<description><![CDATA[猛击此处下载W32Dasm V10。 猛击此处下载ImpREC.v1.7c 相关文章 DailyPIM 4.1 Cracked by Obaby [修改为Loader模式，功能无缺失]( 3 ) 优易代理 1.6 破解版( 0 ) Total Commander 8.0 public beta 10 (x64) Crack Log( 0 ) CRACKL@B DvD SHELL 2010( 0 ) 人文件保密专家 V8.65 白金版 &#124; 专业的文件和文件夹的加密工具 破解版( 0 ) Keygener Assistant V1.6( 0 ) 迅雷5.9.9.1118本地VIP补丁( 0 ) 《破解—不破不逆》( 6 )]]></description>
			<content:encoded><![CDATA[<p><a rel="lightbox" href="http://www.h4ck.org.cn/wp-content/uploads//2010/06/w32dasm10.png" title="w32dasm10"><img title="w32dasm10" src="http://www.h4ck.org.cn/wp-content/uploads//2010/06/w32dasm10.png" alt="" width="600" height="504" /></a></p>
<p><a href="http://d.namipan.com/d/201ee307b88234b6b3efa90feada13f04eb67f189ee40900" target="_blank">猛击此处下载W32Dasm V10。</a><br />
<span id="more-1704"></span><br />
<a rel="lightbox" href="http://www.h4ck.org.cn/wp-content/uploads//2010/06/imp1.7.png" title="imp1.7"><img title="imp1.7" src="http://www.h4ck.org.cn/wp-content/uploads//2010/06/imp1.7.png" alt="" width="600" height="575" /></a></p>
<p><a href="http://d.namipan.com/d/18fefeba54504b242cebbead43b44a0e9219e01858920800" target="_blank">猛击此处下载ImpREC.v1.7c</a><br />
<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2011/05/winhex-16-0-sr-2-%e3%80%90share%e3%80%91/" title="WinHex 16.0 SR-2 【share】" rel="bookmark inlinks">WinHex 16.0 SR-2 【share】</a><span class="count">( 1 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/01/immunity-debugger-1-80/" title="Immunity Debugger 1.80" rel="bookmark inlinks">Immunity Debugger 1.80</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/08/kelai-patch-fixed/" title="科来网络分析系统 2010 技术交流版 【破解补丁修正版】" rel="bookmark inlinks">科来网络分析系统 2010 技术交流版 【破解补丁修正版】</a><span class="count">( 4 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/12/qq-international-v1-01910-today-remover-new/" title="QQ International V1.0(1910) Today Remover [new]" rel="bookmark inlinks">QQ International V1.0(1910) Today Remover [new]</a><span class="count">( 15 )</span></li>
<li><a href="http://www.h4ck.org.cn/2012/02/apk-dex-reverse-toolkit/" title="APK+Dex文件反编译及回编译工具 v1.6.7c 正式版" rel="bookmark inlinks">APK+Dex文件反编译及回编译工具 v1.6.7c 正式版</a><span class="count">( 2 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/12/trial-reset-v4-0-b1/" title="Trial Reset v4.0.b1 " rel="bookmark inlinks">Trial Reset v4.0.b1 </a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/04/imp64/" title="imp64" rel="bookmark inlinks">imp64</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/06/cracker-editor/" title="破解专用记事本 【修正版】" rel="bookmark inlinks">破解专用记事本 【修正版】</a><span class="count">( 0 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2010/06/w32dasm-v10-and-imprec-v1-7c/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ASProtect 1.23 RC4 &#8211; 1.3.08.24 -&gt; Alexey Solodovnikov 脱壳Stolen code 修复</title>
		<link>http://www.h4ck.org.cn/2010/03/asprotect-1-23-rc4-1-3-08-24-alexey-solodovnikov-stolen-code/</link>
		<comments>http://www.h4ck.org.cn/2010/03/asprotect-1-23-rc4-1-3-08-24-alexey-solodovnikov-stolen-code/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 04:30:54 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[脱壳『Unpack』]]></category>
		<category><![CDATA[Unpack]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=1385</guid>
		<description><![CDATA[程序的壳子：ASProtect 1.23 RC4 &#8211; 1.3.08.24 -&#62; Alexey Solodovnikov 用od载入程序，忽略除内存以外的所有异常，如下图。 载入后od会停留在此处： 00401000 &#38;gt; 68 01804B00 push 004B8001 00401005 E8 01000000 call 0040100B 0040100A C3 retn 0040100B C3 retn 0040100C 9E sahf 0040100D 6D ins dword ptr es:&#91;edi&#93;, dx 0040100E 1963 CD sbb dword ptr &#91;ebx-33&#93;, esp 00401011 B1 4C mov cl, 4C 00401013 FF73 EB push [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="lightbox" href="http://www.h4ck.org.cn/wp-content/uploads//2010/03/peid.png" title="peid"><img title="peid" src="http://www.h4ck.org.cn/wp-content/uploads//2010/03/peid.png" alt="" width="592" height="237" /></a></p>
<p>程序的壳子：ASProtect 1.23 RC4 &#8211; 1.3.08.24 -&gt; Alexey Solodovnikov<br />
用od载入程序，忽略除内存以外的所有异常，如下图。</p>
<p><a rel="lightbox" href="http://www.h4ck.org.cn/wp-content/uploads//2010/03/1.png" title="1"><img title="1" src="http://www.h4ck.org.cn/wp-content/uploads//2010/03/1.png" alt="" width="478" height="370" /></a><br />
<span id="more-1385"></span><br />
载入后od会停留在此处：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">00401000</span> &amp;gt<span style="color: #666666; font-style: italic;">;  68 01804B00     push    004B8001</span>
<span style="color: #adadad; font-style: italic;">00401005</span>    E8 <span style="color: #0000ff;">01000000</span>     <span style="color: #00007f; font-weight: bold;">call</span>    0040100B
<span style="color: #adadad; font-style: italic;">0040100A</span>    C3              <span style="color: #00007f; font-weight: bold;">retn</span>
<span style="color: #adadad; font-style: italic;">0040100B</span>    C3              <span style="color: #00007f; font-weight: bold;">retn</span>
<span style="color: #adadad; font-style: italic;">0040100C</span>    9E              <span style="color: #00007f; font-weight: bold;">sahf</span>
<span style="color: #adadad; font-style: italic;">0040100D</span>    6D              <span style="color: #00007f; font-weight: bold;">ins</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">es</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edi</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">dx</span>
<span style="color: #adadad; font-style: italic;">0040100E</span>    <span style="color: #0000ff;">1963</span> CD         <span style="color: #00007f; font-weight: bold;">sbb</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebx</span><span style="color: #339933;">-</span><span style="color: #0000ff;">33</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">00401011</span>    B1 4C           <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">cl</span><span style="color: #339933;">,</span> 4C
<span style="color: #adadad; font-style: italic;">00401013</span>    FF73 EB         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebx</span><span style="color: #339933;">-</span><span style="color: #0000ff;">15</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00401016</span>    03D4            <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">00401018</span>    E7 <span style="color: #0000ff;">48</span>           <span style="color: #00007f; font-weight: bold;">out</span>     <span style="color: #0000ff;">48</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">0040101A</span>    DA11            <span style="color: #0000ff; font-weight: bold;">ficom</span>   <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">0040101C</span>    B3 E7           <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">bl</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">0E7</span>
<span style="color: #adadad; font-style: italic;">0040101E</span>    <span style="color: #0000ff;">66</span><span style="color: #339933;">:</span>339D 49B2BC9&amp;gt<span style="color: #666666; font-style: italic;">;xor     bx, word ptr [ebp+9EBCB249]</span>
<span style="color: #adadad; font-style: italic;">00401025</span>    A7              <span style="color: #00007f; font-weight: bold;">cmps</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">esi</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">es</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span>e&amp;gt<span style="color: #666666; font-style: italic;">;</span>
<span style="color: #adadad; font-style: italic;">00401026</span>    0B49 9E         <span style="color: #00007f; font-weight: bold;">or</span>      <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #339933;">-</span><span style="color: #0000ff;">62</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00401029</span>    <span style="color: #0000ff;">43</span>              <span style="color: #00007f; font-weight: bold;">inc</span>     <span style="color: #00007f;">ebx</span></pre></div></div>

<p>Hideod，否则程序会直接异常退出，不过有的插件隐藏之后会有问题，不知道什么原因。<br />
shift+F9直接运行，注意观察堆栈窗口，出现硬盘指纹（”oBb/DABgLOI=”）的时候就快到最</p>
<p>后一次异常了，当硬盘指纹消失的时候就到达最后一次异常了（据说是26次，不过不知道是</p>
<p>怎么数的我怎么感觉是27次？:)）。</p>
<p>0012FF04   0012FF0C  指向下一个 SEH 记录的指针<br />
0012FF08   00254307  SE处理程序<br />
0012FF0C   0012FFC4  指向下一个 SEH 记录的指针<br />
0012FF10   00254C49  SE处理程序<br />
0012FF14   0012FF58<br />
0012FF18   00240000<br />
0012FF1C   00200000<br />
0012FF20   00254138<br />
0012FF24   01AC4EF8  ASCII “oBb/DABgLOI=”<br />
0012FF28   00000001</p>
<p>最后一次异常会到达下面的地方，注意观察格式会发现类似于：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #00007f; font-weight: bold;">je</span> xxxxxxxxxx；
……
<span style="color: #00007f; font-weight: bold;">je</span> yyyyyyyyyy；
……
<span style="color: #00007f; font-weight: bold;">retn</span></pre></div></div>

<p>的这么一个东西，在最后的retn上下f2断点，shift+F9运行，中断后删掉那个F2断点。</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">002539EC</span>    <span style="color: #0000ff;">3100</span>            <span style="color: #00007f; font-weight: bold;">xor</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">002539EE</span>    <span style="color: #0000ff;">64</span><span style="color: #339933;">:</span>8F05 <span style="color: #0000ff;">0000000</span>&amp;gt<span style="color: #666666; font-style: italic;">;pop     dword ptr fs:[0]</span>
<span style="color: #adadad; font-style: italic;">002539F5</span>    <span style="color: #0000ff;">58</span>              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">002539F6</span>    833D B07E2500 <span style="color: #0000ff;">0</span>&amp;gt<span style="color: #666666; font-style: italic;">;cmp     dword ptr [257EB0], 0</span>
<span style="color: #adadad; font-style: italic;">002539FD</span>    <span style="color: #0000ff;">74</span> <span style="color: #0000ff;">14</span>           <span style="color: #00007f; font-weight: bold;">je</span>      <span style="color: #000000; font-weight: bold;">short</span> 00253A13
<span style="color: #adadad; font-style: italic;">002539FF</span>    6A 0C           <span style="color: #00007f; font-weight: bold;">push</span>    0C
<span style="color: #adadad; font-style: italic;">00253A01</span>    B9 B07E2500     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> 257EB0
<span style="color: #adadad; font-style: italic;">00253A06</span>    8D45 F8         <span style="color: #00007f; font-weight: bold;">lea</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00253A09</span>    BA <span style="color: #0000ff;">04000000</span>     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">4</span>
<span style="color: #adadad; font-style: italic;">00253A0E</span>    E8 2DD1FFFF     <span style="color: #00007f; font-weight: bold;">call</span>    00250B40
<span style="color: #adadad; font-style: italic;">00253A13</span>    FF75 FC         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">4</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00253A16</span>    FF75 F8         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00253A19</span>    8B45 F4         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #000000; font-weight: bold;">C</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00253A1C</span>    <span style="color: #0000ff;">8338</span> <span style="color: #0000ff;">00</span>         <span style="color: #00007f; font-weight: bold;">cmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">0</span>
<span style="color: #adadad; font-style: italic;">00253A1F</span>    <span style="color: #0000ff;">74</span> <span style="color: #0000ff;">02</span>           <span style="color: #00007f; font-weight: bold;">je</span>      <span style="color: #000000; font-weight: bold;">short</span> 00253A23
<span style="color: #adadad; font-style: italic;">00253A21</span>    FF30            <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00253A23</span>    FF75 F0         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">10</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00253A26</span>    FF75 EC         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">14</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00253A29</span>    C3              <span style="color: #00007f; font-weight: bold;">retn</span>	<span style="color: #666666; font-style: italic;">;此处F2断点，shift+F9中断后删除</span></pre></div></div>

<p>此时注意观察堆栈窗口：<br />
0012FF24   01AC7228<br />
0012FF28   00400000  iconmake.00400000<br />
0012FF2C   A7E1C923<br />
0012FF30   0012FF6C<br />
0012FF34   00240000<br />
0012FF38   00200000<br />
下硬件断点：hr 0012FF30 后直接F9运行会中断到如下的地址处：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">01AC7348</span>   <span style="color: #339933;">/</span>EB <span style="color: #0000ff;">44</span>           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC738E                   <span style="color: #666666; font-style: italic;">; F8单步</span>
<span style="color: #adadad; font-style: italic;">01AC734A</span>   |EB <span style="color: #0000ff;">01</span>           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC734D
<span style="color: #adadad; font-style: italic;">01AC734C</span>   |9A 51579CFC BF0&amp;gt<span style="color: #666666; font-style: italic;">;call    far 00BF:FC9C5751</span>
<span style="color: #adadad; font-style: italic;">01AC7353</span>   |<span style="color: #0000ff;">0000</span>            <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">al</span>
<span style="color: #adadad; font-style: italic;">01AC7355</span>   |00B9 <span style="color: #0000ff;">00000000</span>   <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">bh</span>
<span style="color: #adadad; font-style: italic;">01AC735B</span>   |F3<span style="color: #339933;">:</span>AA           <span style="color: #00007f; font-weight: bold;">rep</span>     <span style="color: #00007f; font-weight: bold;">stos</span> <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">es</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edi</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC735D</span>   |9D              <span style="color: #00007f; font-weight: bold;">popfd</span>
<span style="color: #adadad; font-style: italic;">01AC735E</span>   |<span style="color: #0000ff;">5F</span>              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">01AC735F</span>   |<span style="color: #0000ff;">59</span>              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">01AC7360</span>   |C3              <span style="color: #00007f; font-weight: bold;">retn</span>
<span style="color: #adadad; font-style: italic;">01AC7361</span>   |<span style="color: #0000ff;">55</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">01AC7362</span>   |8BEC            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ebp</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">01AC7364</span>   |<span style="color: #0000ff;">53</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">01AC7365</span>   |<span style="color: #0000ff;">56</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">esi</span>
<span style="color: #adadad; font-style: italic;">01AC7366</span>   |8B75 0C         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">esi</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #000000; font-weight: bold;">C</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC7369</span>   |8B5D <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ebx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC736C</span>   |EB <span style="color: #0000ff;">11</span>           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC737F
<span style="color: #adadad; font-style: italic;">01AC736E</span>   |0FB703          <span style="color: #00007f; font-weight: bold;">movzx</span>   <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">word</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebx</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC7371</span>   |03C6            <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esi</span>
<span style="color: #adadad; font-style: italic;">01AC7373</span>   |83C3 <span style="color: #0000ff;">02</span>         <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">ebx</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">2</span>
<span style="color: #adadad; font-style: italic;">01AC7376</span>   |8BD0            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">01AC7378</span>   |8BC6            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esi</span>
<span style="color: #adadad; font-style: italic;">01AC737A</span>   |E8 0C000000     <span style="color: #00007f; font-weight: bold;">call</span>    01AC738B
<span style="color: #adadad; font-style: italic;">01AC737F</span>   |<span style="color: #0000ff;">66</span><span style="color: #339933;">:</span>833B <span style="color: #0000ff;">00</span>      <span style="color: #00007f; font-weight: bold;">cmp</span>     <span style="color: #000000; font-weight: bold;">word</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebx</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">0</span>
<span style="color: #adadad; font-style: italic;">01AC7383</span>  ^|<span style="color: #0000ff;">75</span> E9           <span style="color: #00007f; font-weight: bold;">jnz</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC736E
<span style="color: #adadad; font-style: italic;">01AC7385</span>   |5E              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">esi</span>
<span style="color: #adadad; font-style: italic;">01AC7386</span>   |5B              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">01AC7387</span>   |5D              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">01AC7388</span>   |C2 <span style="color: #0000ff;">0800</span>         <span style="color: #00007f; font-weight: bold;">retn</span>    <span style="color: #0000ff;">8</span>
<span style="color: #adadad; font-style: italic;">01AC738B</span>   |<span style="color: #0000ff;">0102</span>            <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edx</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">01AC738D</span>   |C3              <span style="color: #00007f; font-weight: bold;">retn</span>
<span style="color: #adadad; font-style: italic;">01AC738E</span>   \03C3            <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ebx</span>                         <span style="color: #666666; font-style: italic;">; F8单步</span>
<span style="color: #adadad; font-style: italic;">01AC7390</span>    BB A9000000     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ebx</span><span style="color: #339933;">,</span> 0A9
<span style="color: #adadad; font-style: italic;">01AC7395</span>    0BDB            <span style="color: #00007f; font-weight: bold;">or</span>      <span style="color: #00007f;">ebx</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">01AC7397</span>    <span style="color: #0000ff;">75</span> <span style="color: #0000ff;">07</span>           <span style="color: #00007f; font-weight: bold;">jnz</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC73A0
<span style="color: #adadad; font-style: italic;">01AC7399</span>    <span style="color: #0000ff;">894424</span> 1C       <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">esp</span><span style="color: #339933;">+</span>1C<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">01AC739D</span>    <span style="color: #0000ff;">61</span>              <span style="color: #00007f; font-weight: bold;">popad</span>
<span style="color: #adadad; font-style: italic;">01AC739E</span>    <span style="color: #0000ff;">50</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">01AC739F</span>    C3              <span style="color: #00007f; font-weight: bold;">retn</span>
<span style="color: #adadad; font-style: italic;">01AC73A0</span>    E8 <span style="color: #0000ff;">00000000</span>     <span style="color: #00007f; font-weight: bold;">call</span>    01AC73A5
<span style="color: #adadad; font-style: italic;">01AC73A5</span>    5D              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">01AC73A6</span>    81ED 4DE14B00   <span style="color: #00007f; font-weight: bold;">sub</span>     <span style="color: #00007f;">ebp</span><span style="color: #339933;">,</span> 4BE14D
<span style="color: #adadad; font-style: italic;">01AC73AC</span>    8D85 F2E04B00   <span style="color: #00007f; font-weight: bold;">lea</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span>4BE0F2<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC73B2</span>    8D8D 94E14B00   <span style="color: #00007f; font-weight: bold;">lea</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span>4BE194<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC73B8</span>    03CB            <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">01AC73BA</span>    <span style="color: #0000ff;">8941</span> <span style="color: #0000ff;">01</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">1</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">01AC73BD</span>    8D85 36E14B00   <span style="color: #00007f; font-weight: bold;">lea</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span>4BE136<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC73C3</span>    8D8D FAE04B00   <span style="color: #00007f; font-weight: bold;">lea</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span>4BE0FA<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC73C9</span>    <span style="color: #0000ff;">8901</span>            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">01AC73CB</span>    B8 <span style="color: #0000ff;">5E140000</span>     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> 145E
<span style="color: #adadad; font-style: italic;">01AC73D0</span>    8D8D FFE04B00   <span style="color: #00007f; font-weight: bold;">lea</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span>4BE0FF<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC73D6</span>    <span style="color: #0000ff;">8901</span>            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">01AC73D8</span>    8D8D 94E14B00   <span style="color: #00007f; font-weight: bold;">lea</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span>4BE194<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC73DE</span>    8D85 94F34B00   <span style="color: #00007f; font-weight: bold;">lea</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span>4BF394<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC73E4</span>    <span style="color: #0000ff;">51</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">01AC73E5</span>    <span style="color: #0000ff;">50</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">01AC73E6</span>    E8 76FFFFFF     <span style="color: #00007f; font-weight: bold;">call</span>    01AC7361
<span style="color: #adadad; font-style: italic;">01AC73EB</span>    <span style="color: #0000ff;">61</span>              <span style="color: #00007f; font-weight: bold;">popad</span>
<span style="color: #adadad; font-style: italic;">01AC73EC</span>    EB <span style="color: #0000ff;">02</span>           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC73F0
<span style="color: #adadad; font-style: italic;">01AC73EE</span>    CD20 26EB02CD   vxdjump CD02EB26
<span style="color: #adadad; font-style: italic;">01AC73F4</span>    20EB            <span style="color: #00007f; font-weight: bold;">and</span>     <span style="color: #00007f;">bl</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ch</span>
<span style="color: #adadad; font-style: italic;">01AC73F6</span>    02CD            <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">cl</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ch</span>
<span style="color: #adadad; font-style: italic;">01AC73F8</span>    208D 6434DD2B   <span style="color: #00007f; font-weight: bold;">and</span>     <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span>2BDD3464<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">cl</span>
<span style="color: #adadad; font-style: italic;">01AC73FE</span>    E6 <span style="color: #0000ff;">83</span>           <span style="color: #00007f; font-weight: bold;">out</span>     <span style="color: #0000ff;">83</span><span style="color: #339933;">,</span> <span style="color: #00007f;">al</span>
<span style="color: #adadad; font-style: italic;">01AC7400</span>    C41F            <span style="color: #00007f; font-weight: bold;">les</span>     <span style="color: #00007f;">ebx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">fword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edi</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC7402</span>    F2<span style="color: #339933;">:</span>             prefix <span style="color: #00007f; font-weight: bold;">repne</span><span style="color: #339933;">:</span>                            <span style="color: #666666; font-style: italic;">; 此处F7跟</span>
&nbsp;
入
<span style="color: #adadad; font-style: italic;">01AC7403</span>    EB <span style="color: #0000ff;">01</span>           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC7406
<span style="color: #adadad; font-style: italic;">01AC7405</span>    <span style="color: #0000ff;">6989</span> <span style="color: #0000ff;">74240065</span> E&amp;gt<span style="color: #666666; font-style: italic;">;imul    ecx, dword ptr [ecx+65002474], 8&amp;gt;</span>
<span style="color: #adadad; font-style: italic;">01AC740F</span>    C6              ???                                      <span style="color: #666666; font-style: italic;">; 未知命令</span>
<span style="color: #adadad; font-style: italic;">01AC7410</span>    <span style="color: #0000ff;">14</span> FA           <span style="color: #00007f; font-weight: bold;">adc</span>     <span style="color: #00007f;">al</span><span style="color: #339933;">,</span> 0FA
<span style="color: #adadad; font-style: italic;">01AC7412</span>    <span style="color: #0000ff;">2869</span> F2         <span style="color: #00007f; font-weight: bold;">sub</span>     <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #339933;">-</span>E<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ch</span>
<span style="color: #adadad; font-style: italic;">01AC7415</span>    EB <span style="color: #0000ff;">01</span>           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC7418
<span style="color: #adadad; font-style: italic;">01AC7417</span>    E8 BE060000     <span style="color: #00007f; font-weight: bold;">call</span>    01AC7ADA</pre></div></div>

<p>直到出现下面的代码停止跟入：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">01AC744B</span>    <span style="color: #0000ff;">55</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">01AC744C</span>    8BEC            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ebp</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">01AC744E</span>    6A FF           <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #339933;">-</span><span style="color: #0000ff;">1</span>
<span style="color: #adadad; font-style: italic;">01AC7450</span>    <span style="color: #0000ff;">68</span> 881F4700     <span style="color: #00007f; font-weight: bold;">push</span>    471F88
<span style="color: #adadad; font-style: italic;">01AC7455</span>    <span style="color: #0000ff;">68</span> 8A624300     <span style="color: #00007f; font-weight: bold;">push</span>    43628A
<span style="color: #adadad; font-style: italic;">01AC745A</span>    <span style="color: #0000ff;">64</span><span style="color: #339933;">:</span>A1 <span style="color: #0000ff;">00000000</span>  <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">fs</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">0</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC7460</span>    EB <span style="color: #0000ff;">02</span>           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC7464
<span style="color: #adadad; font-style: italic;">01AC7462</span>    CD20 <span style="color: #0000ff;">50648925</span>   vxdcall <span style="color: #0000ff;">25896450</span>
<span style="color: #adadad; font-style: italic;">01AC7468</span>    <span style="color: #0000ff;">0000</span>            <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">al</span>
<span style="color: #adadad; font-style: italic;">01AC746A</span>    <span style="color: #0000ff;">0000</span>            <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">al</span>
<span style="color: #adadad; font-style: italic;">01AC746C</span>    83EC <span style="color: #0000ff;">68</span>         <span style="color: #00007f; font-weight: bold;">sub</span>     <span style="color: #00007f;">esp</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">68</span>
<span style="color: #adadad; font-style: italic;">01AC746F</span>    EB <span style="color: #0000ff;">02</span>           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC7473
<span style="color: #adadad; font-style: italic;">01AC7471</span>    CD20 53EB02CD   vxdjump CD02EB53
<span style="color: #adadad; font-style: italic;">01AC7477</span>    <span style="color: #0000ff;">2056</span> EB         <span style="color: #00007f; font-weight: bold;">and</span>     <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">esi</span><span style="color: #339933;">-</span><span style="color: #0000ff;">15</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">dl</span>
<span style="color: #adadad; font-style: italic;">01AC747A</span>    02CD            <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">cl</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ch</span>
<span style="color: #adadad; font-style: italic;">01AC747C</span>    <span style="color: #0000ff;">2057</span> <span style="color: #0000ff;">89</span>         <span style="color: #00007f; font-weight: bold;">and</span>     <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edi</span><span style="color: #339933;">-</span><span style="color: #0000ff;">77</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">dl</span>
<span style="color: #adadad; font-style: italic;">01AC747F</span>    <span style="color: #0000ff;">65</span><span style="color: #339933;">:</span>E8 33DB895D  <span style="color: #00007f; font-weight: bold;">call</span>    5F364FB8
<span style="color: #adadad; font-style: italic;">01AC7485</span>    FC              <span style="color: #00007f; font-weight: bold;">cld</span>
<span style="color: #adadad; font-style: italic;">01AC7486</span>    6A <span style="color: #0000ff;">02</span>           <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #0000ff;">2</span>
<span style="color: #adadad; font-style: italic;">01AC7488</span>    EB <span style="color: #0000ff;">02</span>           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> 01AC748C
<span style="color: #adadad; font-style: italic;">01AC748A</span>    CD20 F2EB010F   vxdjump F01EBF2
<span style="color: #adadad; font-style: italic;">01AC7490</span>    <span style="color: #0000ff;">68</span> 8F604300     <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #0000ff;">43608F</span>
<span style="color: #adadad; font-style: italic;">01AC7495</span>    <span style="color: #0000ff;">68</span> 4A73AC01     <span style="color: #00007f; font-weight: bold;">push</span>    1AC734A
<span style="color: #adadad; font-style: italic;">01AC749A</span>    C3              <span style="color: #00007f; font-weight: bold;">retn</span></pre></div></div>

<p>复制01AC7460    EB 02           jmp     short 01AC7464这一行上面的代码的2进制模</p>
<p>式，如下（stolencode的一部分）：</p>
<p>55 8B EC 6A FF 68 88 1F 47 00 68 8A 62 43 00 64 A1 00 00 00 00<br />
继续F7，复制下面代码到jmp跳转前的二进制模式：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">01AC7464</span>    <span style="color: #0000ff;">50</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">01AC7465</span>    <span style="color: #0000ff;">64</span><span style="color: #339933;">:</span><span style="color: #0000ff;">8925</span> <span style="color: #0000ff;">0000000</span>&amp;gt<span style="color: #666666; font-style: italic;">;mov     dword ptr fs:[0], esp</span>
<span style="color: #adadad; font-style: italic;">01AC746C</span>    83EC <span style="color: #0000ff;">68</span>         <span style="color: #00007f; font-weight: bold;">sub</span>     <span style="color: #00007f;">esp</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">68</span></pre></div></div>

<p>二进制：<br />
50 64 89 25 00 00 00 00 83 EC 68</p>
<p>重复上述操作：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">01AC7473</span>    <span style="color: #0000ff;">53</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ebx</span></pre></div></div>

<p>二进制：53</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">01AC7478</span>    <span style="color: #0000ff;">56</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">esi</span></pre></div></div>

<p>二进制：56<br />
继续F7，复制下面的代码：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">01AC747D</span>    <span style="color: #0000ff;">57</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">01AC747E</span>    <span style="color: #0000ff;">8965</span> E8         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">18</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">01AC7481</span>    33DB            <span style="color: #00007f; font-weight: bold;">xor</span>     <span style="color: #00007f;">ebx</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">01AC7483</span>    895D FC         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">4</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">01AC7486</span>    6A <span style="color: #0000ff;">02</span>           <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #0000ff;">2</span></pre></div></div>

<p>二进制：<br />
57 89 65 E8 33 DB 89 5D FC 6A 02<br />
最后F7到如下的代码处时，开始F8单步往下：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">01AC734D</span>    <span style="color: #0000ff;">51</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ecx</span><span style="color: #666666; font-style: italic;">;开始F8单步</span>
<span style="color: #adadad; font-style: italic;">01AC734E</span>    <span style="color: #0000ff;">57</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">01AC734F</span>    9C              <span style="color: #00007f; font-weight: bold;">pushfd</span>
<span style="color: #adadad; font-style: italic;">01AC7350</span>    FC              <span style="color: #00007f; font-weight: bold;">cld</span>
<span style="color: #adadad; font-style: italic;">01AC7351</span>    BF 8E73AC01     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edi</span><span style="color: #339933;">,</span> 1AC738E
<span style="color: #adadad; font-style: italic;">01AC7356</span>    B9 <span style="color: #0000ff;">5E140000</span>     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> 145E
<span style="color: #adadad; font-style: italic;">01AC735B</span>    F3<span style="color: #339933;">:</span>AA           <span style="color: #00007f; font-weight: bold;">rep</span>     <span style="color: #00007f; font-weight: bold;">stos</span> <span style="color: #000000; font-weight: bold;">byte</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">es</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edi</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">01AC735D</span>    9D              <span style="color: #00007f; font-weight: bold;">popfd</span>
<span style="color: #adadad; font-style: italic;">01AC735E</span>    <span style="color: #0000ff;">5F</span>              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">01AC735F</span>    <span style="color: #0000ff;">59</span>              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">01AC7360</span>    C3              <span style="color: #00007f; font-weight: bold;">retn</span></pre></div></div>

<p>一直往下知道跟踪到最近的一个call停止跟踪：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">0043608F</span>    FF15 7CD94600   <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>46D97C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; F8到此处</span>
&nbsp;
msvcrt<span style="color: #339933;">.</span>__set_app_type
<span style="color: #adadad; font-style: italic;">00436095</span>    <span style="color: #0000ff;">59</span>              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">00436096</span>    830D 90A84900 F&amp;gt<span style="color: #666666; font-style: italic;">;or      dword ptr [49A890], FFFFFFFF</span>
<span style="color: #adadad; font-style: italic;">0043609D</span>    830D 94A84900 F&amp;gt<span style="color: #666666; font-style: italic;">;or      dword ptr [49A894], FFFFFFFF</span>
<span style="color: #adadad; font-style: italic;">004360A4</span>    FF15 78D94600   <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>46D978<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; </span>
&nbsp;
msvcrt<span style="color: #339933;">.</span>__p__fmode</pre></div></div>

<p>此时网上找就会找到一片零区域，将上面的二进制代码结合到一块最后就是下面的形式：</p>
<p>55 8B EC 6A FF 68 88 1F 47 00 68 8A 62 43 00 64 A1 00 00 00 00 50 64 89 25 00 00</p>
<p>00 00 83 EC 68 53 56 57 89 65 E8 33 DB 89 5D FC 6A 02<br />
将代码以二进制形式粘贴，在代码开始处新建EIP</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">00436062</span>    <span style="color: #0000ff;">55</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ebp</span><span style="color: #666666; font-style: italic;">;此处新建EIP</span>
<span style="color: #adadad; font-style: italic;">00436063</span>    8BEC            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ebp</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">00436065</span>    6A FF           <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #339933;">-</span><span style="color: #0000ff;">1</span>
<span style="color: #adadad; font-style: italic;">00436067</span>    <span style="color: #0000ff;">68</span> 881F4700     <span style="color: #00007f; font-weight: bold;">push</span>    00471F88
<span style="color: #adadad; font-style: italic;">0043606C</span>    <span style="color: #0000ff;">68</span> 8A624300     <span style="color: #00007f; font-weight: bold;">push</span>    0043628A                         <span style="color: #666666; font-style: italic;">; jmp 到 </span>
&nbsp;
msvcrt<span style="color: #339933;">.</span>_except_handler3
<span style="color: #adadad; font-style: italic;">00436071</span>    <span style="color: #0000ff;">64</span><span style="color: #339933;">:</span>A1 <span style="color: #0000ff;">00000000</span>  <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">fs</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">0</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00436077</span>    <span style="color: #0000ff;">50</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00436078</span>    <span style="color: #0000ff;">64</span><span style="color: #339933;">:</span><span style="color: #0000ff;">8925</span> <span style="color: #0000ff;">0000000</span>&amp;gt<span style="color: #666666; font-style: italic;">;mov     dword ptr fs:[0], esp</span>
<span style="color: #adadad; font-style: italic;">0043607F</span>    83EC <span style="color: #0000ff;">68</span>         <span style="color: #00007f; font-weight: bold;">sub</span>     <span style="color: #00007f;">esp</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">68</span>
<span style="color: #adadad; font-style: italic;">00436082</span>    <span style="color: #0000ff;">53</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">00436083</span>    <span style="color: #0000ff;">56</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">esi</span>
<span style="color: #adadad; font-style: italic;">00436084</span>    <span style="color: #0000ff;">57</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">00436085</span>    <span style="color: #0000ff;">8965</span> E8         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">18</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">00436088</span>    33DB            <span style="color: #00007f; font-weight: bold;">xor</span>     <span style="color: #00007f;">ebx</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">0043608A</span>    895D FC         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">4</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">0043608D</span>    6A <span style="color: #0000ff;">00</span>           <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #0000ff;">0</span>
<span style="color: #adadad; font-style: italic;">0043608F</span>    FF15 7CD94600   <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>46D97C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; </span>
&nbsp;
msvcrt<span style="color: #339933;">.</span>__set_app_type
<span style="color: #adadad; font-style: italic;">00436095</span>    <span style="color: #0000ff;">59</span>              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">00436096</span>    830D 90A84900 F&amp;gt<span style="color: #666666; font-style: italic;">;or      dword ptr [49A890], FFFFFFFF</span>
<span style="color: #adadad; font-style: italic;">0043609D</span>    830D 94A84900 F&amp;gt<span style="color: #666666; font-style: italic;">;or      dword ptr [49A894], FFFFFFFF</span>
<span style="color: #adadad; font-style: italic;">004360A4</span>    FF15 78D94600   <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>46D978<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; </span>
&nbsp;
msvcrt<span style="color: #339933;">.</span>__p__fmode
<span style="color: #adadad; font-style: italic;">004360AA</span>    8B0D 64A54900   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>49A564<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">004360B0</span>    <span style="color: #0000ff;">8908</span>            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">004360B2</span>    FF15 74D94600   <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>46D974<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; </span>
&nbsp;
msvcrt<span style="color: #339933;">.</span>__p__commode</pre></div></div>

<p><a rel="lightbox" href="http://www.h4ck.org.cn/wp-content/uploads//2010/03/2.png" title="2"><img title="2" src="http://www.h4ck.org.cn/wp-content/uploads//2010/03/2-1024x382.png" alt="" width="614" height="229" /></a></p>
<p>最后剩下的就是修复工作了，脱壳最好在xp下进行，因为测试的时候在win7下虽然能够脱壳</p>
<p>，但是修复出来的文件是有问题的，不能正常晕新。～还是xp兼容性好啊！如果有不能识别</p>
<p>的api可以用ASProtect 1.22   插件进行修复，一般的用level 1就能修复了。<br />
<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2011/07/unpack-64bit-exe-via-ida-debug-plugin/" title="IDA + Debug 插件 实现64Bit Exe脱壳" rel="bookmark inlinks">IDA + Debug 插件 实现64Bit Exe脱壳</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/08/yodas-protector-1-3-ashkbiz-danehkar-unpack/" title="yoda's Protector 1.3 -> Ashkbiz Danehkar 手脱笔记” rel=”bookmark inlinks”>yoda&#8217;s Protector 1.3 -> Ashkbiz Danehkar 手脱笔记</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/11/scylla-v0-5a-x64x86-imports-reconstruction/" title="Scylla v0.5a- x64/x86 Imports Reconstruction" rel="bookmark inlinks">Scylla v0.5a- x64/x86 Imports Reconstruction</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/06/pecompact-2-x-jeremy-collake-overlay-unpack/" title="PECompact 2.x -> Jeremy Collake [Overlay] 脱壳” rel=”bookmark inlinks”>PECompact 2.x -> Jeremy Collake [Overlay] 脱壳</a><span class="count">( 2 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/03/armadillo-v6-x-minimum-protection-unpack/" title="Armadillo V6.X Minimum Protection 【脱壳】" rel="bookmark inlinks">Armadillo V6.X Minimum Protection 【脱壳】</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/04/imp64/" title="imp64" rel="bookmark inlinks">imp64</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/08/packer-unpack/" title="普通壳的脱壳方法和脱壳技巧【转载】" rel="bookmark inlinks">普通壳的脱壳方法和脱壳技巧【转载】</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/07/ida-pe6-dll-unpack/" title="实战IDA PE+ DLL脱壳" rel="bookmark inlinks">实战IDA PE+ DLL脱壳</a><span class="count">( 0 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2010/03/asprotect-1-23-rc4-1-3-08-24-alexey-solodovnikov-stolen-code/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Armadillo V6.X Minimum Protection 【脱壳】</title>
		<link>http://www.h4ck.org.cn/2010/03/armadillo-v6-x-minimum-protection-unpack/</link>
		<comments>http://www.h4ck.org.cn/2010/03/armadillo-v6-x-minimum-protection-unpack/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 06:49:03 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[脱壳『Unpack』]]></category>
		<category><![CDATA[Unpack]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=1291</guid>
		<description><![CDATA[话说这个东西是前天拿到的，但是当时在家，东西也不全。平直接感觉是加壳了。去peid官方下载了个没有更新特征库的报了个什么都没发现，晕死。 今天重新查壳发现是Armadillo V6.X Minimum Protection -&#62; Silicon Realms Toolworks * Sign.By.fly * 20081227 *，脱壳后发现程序是用bc++写的： 这个文章网上有的，这里只是做个类似笔记的东西，没别的用处（文章本身就是依样画葫芦。）。 1.用od载入程序后，od停在 00660AC2 &#38;gt; $ E8 833C0000 call 0066474A 00660AC7 .^ E9 16FEFFFF jmp 006608E2 00660ACC /$ 6A 0C push 0C 00660ACE &#124;. 68 18436800 push 00684318 00660AD3 &#124;. E8 641E0000 call 0066293C 00660AD8 &#124;. 8365 E4 00 and dword ptr [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="lightbox" href="http://www.h4ck.org.cn/wp-content/uploads//2010/03/samart1.png" title="samart1"><img title="samart1" src="http://www.h4ck.org.cn/wp-content/uploads//2010/03/samart1.png" alt="" width="610" height="244" /></a></p>
<p>话说这个东西是前天拿到的，但是当时在家，东西也不全。平直接感觉是加壳了。去peid官方下载了个没有更新特征库的报了个什么都没发现，晕死。</p>
<p>今天重新查壳发现是Armadillo V6.X Minimum Protection -&gt; Silicon Realms Toolworks * Sign.By.fly * 20081227 *，脱壳后发现程序是用bc++写的：</p>
<p><a rel="lightbox" href="http://www.h4ck.org.cn/wp-content/uploads//2010/03/smart2.png" title="smart2"><img title="smart2" src="http://www.h4ck.org.cn/wp-content/uploads//2010/03/smart2.png" alt="" width="599" height="241" /></a></p>
<p>这个文章网上有的，这里只是做个类似笔记的东西，没别的用处（文章本身就是依样画葫芦。）。<br />
<span id="more-1291"></span><br />
1.用od载入程序后，od停在</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">00660AC2</span> &amp;gt<span style="color: #666666; font-style: italic;">; $  E8 833C0000   call    0066474A</span>
<span style="color: #adadad; font-style: italic;">00660AC7</span>   <span style="color: #339933;">.</span>^ E9 16FEFFFF   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #0000ff;">006608E2</span>
<span style="color: #adadad; font-style: italic;">00660ACC</span>  <span style="color: #339933;">/</span>$  6A 0C         <span style="color: #00007f; font-weight: bold;">push</span>    0C
<span style="color: #adadad; font-style: italic;">00660ACE</span>  |<span style="color: #339933;">.</span>  <span style="color: #0000ff;">68</span> <span style="color: #0000ff;">18436800</span>   <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #0000ff;">00684318</span>
<span style="color: #adadad; font-style: italic;">00660AD3</span>  |<span style="color: #339933;">.</span>  E8 <span style="color: #0000ff;">641E0000</span>   <span style="color: #00007f; font-weight: bold;">call</span>    0066293C
<span style="color: #adadad; font-style: italic;">00660AD8</span>  |<span style="color: #339933;">.</span>  <span style="color: #0000ff;">8365</span> E4 <span style="color: #0000ff;">00</span>    <span style="color: #00007f; font-weight: bold;">and</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>1C<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">0</span>
<span style="color: #adadad; font-style: italic;">00660ADC</span>  |<span style="color: #339933;">.</span>  8B75 <span style="color: #0000ff;">08</span>       <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">esi</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00660ADF</span>  |<span style="color: #339933;">.</span>  3B35 <span style="color: #0000ff;">70746800</span> <span style="color: #00007f; font-weight: bold;">cmp</span>     <span style="color: #00007f;">esi</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">687470</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00660AE5</span>  |<span style="color: #339933;">.</span>  <span style="color: #0000ff;">77</span> <span style="color: #0000ff;">22</span>         <span style="color: #00007f; font-weight: bold;">ja</span>      <span style="color: #000000; font-weight: bold;">short</span> 00660B09
<span style="color: #adadad; font-style: italic;">00660AE7</span>  |<span style="color: #339933;">.</span>  6A <span style="color: #0000ff;">04</span>         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #0000ff;">4</span>
<span style="color: #adadad; font-style: italic;">00660AE9</span>  |<span style="color: #339933;">.</span>  E8 C31A0000   <span style="color: #00007f; font-weight: bold;">call</span>    006625B1
<span style="color: #adadad; font-style: italic;">00660AEE</span>  |<span style="color: #339933;">.</span>  <span style="color: #0000ff;">59</span>            <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">00660AEF</span>  |<span style="color: #339933;">.</span>  <span style="color: #0000ff;">8365</span> FC <span style="color: #0000ff;">00</span>    <span style="color: #00007f; font-weight: bold;">and</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">4</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">0</span>
<span style="color: #adadad; font-style: italic;">00660AF3</span>  |<span style="color: #339933;">.</span>  <span style="color: #0000ff;">56</span>            <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">esi</span>
<span style="color: #adadad; font-style: italic;">00660AF4</span>  |<span style="color: #339933;">.</span>  E8 <span style="color: #0000ff;">01450000</span>   <span style="color: #00007f; font-weight: bold;">call</span>    00664FFA
<span style="color: #adadad; font-style: italic;">00660AF9</span>  |<span style="color: #339933;">.</span>  <span style="color: #0000ff;">59</span>            <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">00660AFA</span>  |<span style="color: #339933;">.</span>  <span style="color: #0000ff;">8945</span> E4       <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>1C<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00660AFD</span>  |<span style="color: #339933;">.</span>  C745 FC FEFFF&amp;gt<span style="color: #666666; font-style: italic;">;mov     dword ptr [ebp-4], -2</span>
<span style="color: #adadad; font-style: italic;">00660B04</span>  |<span style="color: #339933;">.</span>  E8 <span style="color: #0000ff;">09000000</span>   <span style="color: #00007f; font-weight: bold;">call</span>    00660B12
<span style="color: #adadad; font-style: italic;">00660B09</span>  |&amp;gt<span style="color: #666666; font-style: italic;">;  8B45 E4       mov     eax, dword ptr [ebp-1C]</span>
<span style="color: #adadad; font-style: italic;">00660B0C</span>  |<span style="color: #339933;">.</span>  E8 <span style="color: #0000ff;">701E0000</span>   <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #0000ff;">00662981</span>
<span style="color: #adadad; font-style: italic;">00660B11</span>  \<span style="color: #339933;">.</span>  C3            <span style="color: #00007f; font-weight: bold;">retn</span></pre></div></div>

<p>然后利用插件hideod，否则后面的步骤没法执行，会直接弹出检测到调试器的错误提示。下第一个断点BP VirtualProtect，处理IAT加密，下好断点后Shift+F9，注意把握返回时机（缓冲比较大的）。</p>
<p>然后直接alt+F9返回，会跳转到类似下面的代码处：1</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">00F4D0CC</span>    8B8D C8D5FFFF   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>2A38<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F4D0D2</span>    <span style="color: #0000ff;">51</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">00F4D0D3</span>    8B95 C4D5FFFF   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>2A3C<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F4D0D9</span>    <span style="color: #0000ff;">52</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">edx</span>
<span style="color: #adadad; font-style: italic;">00F4D0DA</span>    8B85 74D8FFFF   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>278C<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F4D0E0</span>    <span style="color: #0000ff;">0385</span> C0D5FFFF   <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>2A40<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F4D0E6</span>    <span style="color: #0000ff;">50</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00F4D0E7</span>    E8 24EA0000     <span style="color: #00007f; font-weight: bold;">call</span>    00F5BB10
<span style="color: #adadad; font-style: italic;">00F4D0EC</span>    83C4 0C         <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">esp</span><span style="color: #339933;">,</span> 0C
<span style="color: #adadad; font-style: italic;">00F4D0EF</span>    8D8D D4D5FFFF   <span style="color: #00007f; font-weight: bold;">lea</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>2A2C<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F4D0F5</span>    <span style="color: #0000ff;">51</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">00F4D0F6</span>    8B95 D4D5FFFF   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>2A2C<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F4D0FC</span>    <span style="color: #0000ff;">52</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">edx</span>
<span style="color: #adadad; font-style: italic;">00F4D0FD</span>    8B85 C8D5FFFF   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>2A38<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F4D103</span>    <span style="color: #0000ff;">50</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00F4D104</span>    8B8D 74D8FFFF   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>278C<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F4D10A</span>    038D C0D5FFFF   <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>2A40<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F4D110</span>    <span style="color: #0000ff;">51</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">00F4D111</span>    FF15 2C31F700   <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F7312C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.VirtualProtect</span></pre></div></div>

<p>在此处搜索命令：push 100，选择整个区段。找到后网上查找push ebp，上面会有甚多的int3中断。类似下面的结构：11</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">00F0327B</span>    CC              int3
<span style="color: #adadad; font-style: italic;">00F0327C</span>    CC              int3
<span style="color: #adadad; font-style: italic;">00F0327D</span>    CC              int3
<span style="color: #adadad; font-style: italic;">00F0327E</span>    CC              int3
<span style="color: #adadad; font-style: italic;">00F0327F</span>    CC              int3
<span style="color: #adadad; font-style: italic;">00F03280</span>    <span style="color: #0000ff;">55</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">00F03281</span>    8BEC            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ebp</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">00F03283</span>    83EC 2C         <span style="color: #00007f; font-weight: bold;">sub</span>     <span style="color: #00007f;">esp</span><span style="color: #339933;">,</span> 2C
<span style="color: #adadad; font-style: italic;">00F03286</span>    833D 20F6F700 <span style="color: #0000ff;">0</span>&amp;gt<span style="color: #666666; font-style: italic;">;cmp     dword ptr [F7F620], 0</span>
<span style="color: #adadad; font-style: italic;">00F0328D</span>    <span style="color: #0000ff;">75</span> <span style="color: #0000ff;">59</span>           <span style="color: #00007f; font-weight: bold;">jnz</span>     <span style="color: #000000; font-weight: bold;">short</span> 00F032E8
<span style="color: #adadad; font-style: italic;">00F0328F</span>    C745 EC D125ACB&amp;gt<span style="color: #666666; font-style: italic;">;mov     dword ptr [ebp-14], BFAC25D1</span>
<span style="color: #adadad; font-style: italic;">00F03296</span>    <span style="color: #0000ff;">68</span> <span style="color: #0000ff;">00010000</span>     <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #0000ff;">100</span>
<span style="color: #adadad; font-style: italic;">00F0329B</span>    E8 F6850500     <span style="color: #00007f; font-weight: bold;">call</span>    00F5B896</pre></div></div>

<p>修改push ebp为retn，直接返回，然后删除第一个断点。到此第一步结束。<br />
2.下第二个断点BP CreateThread 查找程序OEP Shift+F9一次后会停在下面的代码处：1</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">7C8106C7</span> &amp;gt<span style="color: #666666; font-style: italic;">;  8BFF            mov     edi, edi</span>
<span style="color: #adadad; font-style: italic;">7C8106C9</span>    <span style="color: #0000ff;">55</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">7C8106CA</span>    8BEC            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ebp</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">7C8106CC</span>    FF75 1C         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span>1C<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">7C8106CF</span>    FF75 <span style="color: #0000ff;">18</span>         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">18</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">7C8106D2</span>    FF75 <span style="color: #0000ff;">14</span>         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">14</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">7C8106D5</span>    FF75 <span style="color: #0000ff;">10</span>         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">10</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">7C8106D8</span>    FF75 0C         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #000000; font-weight: bold;">C</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">7C8106DB</span>    FF75 <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">7C8106DE</span>    6A FF           <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #339933;">-</span><span style="color: #0000ff;">1</span>
<span style="color: #adadad; font-style: italic;">7C8106E0</span>    E8 D7FDFFFF     <span style="color: #00007f; font-weight: bold;">call</span>    CreateRemoteThread
<span style="color: #adadad; font-style: italic;">7C8106E5</span>    5D              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">7C8106E6</span>    C2 <span style="color: #0000ff;">1800</span>         <span style="color: #00007f; font-weight: bold;">retn</span>    <span style="color: #0000ff;">18</span></pre></div></div>

<p>然后F8单步，直到执行到如下代码处：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">00F3658C</span>    <span style="color: #0000ff;">50</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00F3658D</span>    FF15 9032F700   <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F73290<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.CloseHandle</span>
<span style="color: #adadad; font-style: italic;">00F36593</span>    5E              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">esi</span>
<span style="color: #adadad; font-style: italic;">00F36594</span>    5B              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">00F36595</span>    8BE5            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">esp</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">00F36597</span>    5D              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">00F36598</span>    C3              <span style="color: #00007f; font-weight: bold;">retn</span></pre></div></div>

<p>有的文章说alt+f9直接执行到返回，但是我执行时没有效果，所以直接F8单步也可。这里注意观察代码窗口，如果正常的话会出现红色的字体一闪而过，也就是代码正确解压了，否则就是出错了，重复</p>
<p>上面的步骤即可。<br />
然后一直F8在这个调用返回后会执行到如下代码处：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">00F53414</span>    83C4 <span style="color: #0000ff;">04</span>         <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">esp</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">4</span>
<span style="color: #adadad; font-style: italic;">00F53417</span>    B9 E004F800     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> 0F804E0
<span style="color: #adadad; font-style: italic;">00F5341C</span>    E8 4F8EFBFF     <span style="color: #00007f; font-weight: bold;">call</span>    00F0C270
<span style="color: #adadad; font-style: italic;">00F53421</span>    0FB6C0          <span style="color: #00007f; font-weight: bold;">movzx</span>   <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #00007f;">al</span>
<span style="color: #adadad; font-style: italic;">00F53424</span>    85C0            <span style="color: #00007f; font-weight: bold;">test</span>    <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00F53426</span>    <span style="color: #0000ff;">74</span> 0C           <span style="color: #00007f; font-weight: bold;">je</span>      <span style="color: #000000; font-weight: bold;">short</span> 00F53434
<span style="color: #adadad; font-style: italic;">00F53428</span>    6A <span style="color: #0000ff;">01</span>           <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #0000ff;">1</span>
<span style="color: #adadad; font-style: italic;">00F5342A</span>    B9 E004F800     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> 0F804E0
<span style="color: #adadad; font-style: italic;">00F5342F</span>    E8 7C7BFCFF     <span style="color: #00007f; font-weight: bold;">call</span>    00F1AFB0
<span style="color: #adadad; font-style: italic;">00F53434</span>    C705 40C7F700 B&amp;gt<span style="color: #666666; font-style: italic;">;mov     dword ptr [F7C740], 0F76EBC</span>
<span style="color: #adadad; font-style: italic;">00F5343E</span>    B9 24F6F700     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> 0F7F624
<span style="color: #adadad; font-style: italic;">00F53443</span>    E8 E8FFFAFF     <span style="color: #00007f; font-weight: bold;">call</span>    00F03430
<span style="color: #adadad; font-style: italic;">00F53448</span>    C745 F0 <span style="color: #0000ff;">0000000</span>&amp;gt<span style="color: #666666; font-style: italic;">;mov     dword ptr [ebp-10], 0</span>
<span style="color: #adadad; font-style: italic;">00F5344F</span>    8D4D E8         <span style="color: #00007f; font-weight: bold;">lea</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">18</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53452</span>    <span style="color: #0000ff;">51</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">00F53453</span>    <span style="color: #0000ff;">68</span> 4035F500     <span style="color: #00007f; font-weight: bold;">push</span>    0F53540
<span style="color: #adadad; font-style: italic;">00F53458</span>    FF15 9801F800   <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80198<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F5345E</span>    83C4 <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">esp</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">8</span>
<span style="color: #adadad; font-style: italic;">00F53461</span>    8B15 440BF800   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80B44<span style="color: #009900; font-weight: bold;">&#93;</span>          <span style="color: #666666; font-style: italic;">; NB_SMS.00400000</span>
<span style="color: #adadad; font-style: italic;">00F53467</span>    <span style="color: #0000ff;">8955</span> E4         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>1C<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">edx</span>
<span style="color: #adadad; font-style: italic;">00F5346A</span>    B8 1F000000     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">1F</span>
<span style="color: #adadad; font-style: italic;">00F5346F</span>    C1E0 <span style="color: #0000ff;">02</span>         <span style="color: #00007f; font-weight: bold;">shl</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">2</span>
<span style="color: #adadad; font-style: italic;">00F53472</span>    8B0D 2C0BF800   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80B2C<span style="color: #009900; font-weight: bold;">&#93;</span>          <span style="color: #666666; font-style: italic;">; NB_SMS.0067D398</span>
<span style="color: #adadad; font-style: italic;">00F53478</span>    8B15 2C0BF800   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80B2C<span style="color: #009900; font-weight: bold;">&#93;</span>          <span style="color: #666666; font-style: italic;">; NB_SMS.0067D398</span>
<span style="color: #adadad; font-style: italic;">00F5347E</span>    8B35 2C0BF800   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">esi</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80B2C<span style="color: #009900; font-weight: bold;">&#93;</span>          <span style="color: #666666; font-style: italic;">; NB_SMS.0067D398</span>
<span style="color: #adadad; font-style: italic;">00F53484</span>    8BB6 <span style="color: #0000ff;">88000000</span>   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">esi</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">esi</span><span style="color: #339933;">+</span><span style="color: #0000ff;">88</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F5348A</span>    <span style="color: #0000ff;">3372</span> <span style="color: #0000ff;">14</span>         <span style="color: #00007f; font-weight: bold;">xor</span>     <span style="color: #00007f;">esi</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">14</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F5348D</span>    <span style="color: #0000ff;">333401</span>          <span style="color: #00007f; font-weight: bold;">xor</span>     <span style="color: #00007f;">esi</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #339933;">+</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53490</span>    <span style="color: #0000ff;">0375</span> E4         <span style="color: #00007f; font-weight: bold;">add</span>     <span style="color: #00007f;">esi</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>1C<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53493</span>    <span style="color: #0000ff;">8975</span> F4         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #000000; font-weight: bold;">C</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">esi</span>
<span style="color: #adadad; font-style: italic;">00F53496</span>    8B45 <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53499</span>    <span style="color: #0000ff;">8338</span> <span style="color: #0000ff;">00</span>         <span style="color: #00007f; font-weight: bold;">cmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">0</span>
<span style="color: #adadad; font-style: italic;">00F5349C</span>    <span style="color: #0000ff;">75</span> <span style="color: #0000ff;">43</span>           <span style="color: #00007f; font-weight: bold;">jnz</span>     <span style="color: #000000; font-weight: bold;">short</span> 00F534E1
<span style="color: #adadad; font-style: italic;">00F5349E</span>    8B0D 2C0BF800   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80B2C<span style="color: #009900; font-weight: bold;">&#93;</span>          <span style="color: #666666; font-style: italic;">; NB_SMS.0067D398</span>
<span style="color: #adadad; font-style: italic;">00F534A4</span>    8B15 2C0BF800   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80B2C<span style="color: #009900; font-weight: bold;">&#93;</span>          <span style="color: #666666; font-style: italic;">; NB_SMS.0067D398</span>
<span style="color: #adadad; font-style: italic;">00F534AA</span>    8B81 <span style="color: #0000ff;">80000000</span>   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">80</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534B0</span>    <span style="color: #0000ff;">3342</span> <span style="color: #0000ff;">14</span>         <span style="color: #00007f; font-weight: bold;">xor</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">14</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534B3</span>    8B0D 2C0BF800   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80B2C<span style="color: #009900; font-weight: bold;">&#93;</span>          <span style="color: #666666; font-style: italic;">; NB_SMS.0067D398</span>
<span style="color: #adadad; font-style: italic;">00F534B9</span>    <span style="color: #0000ff;">3341</span> <span style="color: #0000ff;">40</span>         <span style="color: #00007f; font-weight: bold;">xor</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">40</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534BC</span>    <span style="color: #0000ff;">8945</span> E0         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">20</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00F534BF</span>    8B55 <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534C2</span>    8B42 <span style="color: #0000ff;">18</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">18</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534C5</span>    <span style="color: #0000ff;">50</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00F534C6</span>    8B4D <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534C9</span>    8B51 <span style="color: #0000ff;">14</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">14</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534CC</span>    <span style="color: #0000ff;">52</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">edx</span>
<span style="color: #adadad; font-style: italic;">00F534CD</span>    8B45 <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534D0</span>    8B48 <span style="color: #0000ff;">10</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #339933;">+</span><span style="color: #0000ff;">10</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534D3</span>    <span style="color: #0000ff;">51</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">00F534D4</span>    8B55 F4         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #000000; font-weight: bold;">C</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534D7</span>    2B55 E0         <span style="color: #00007f; font-weight: bold;">sub</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">20</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534DA</span>    FFD2            <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #00007f;">edx</span>
<span style="color: #adadad; font-style: italic;">00F534DC</span>    <span style="color: #0000ff;">8945</span> FC         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">4</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00F534DF</span>    EB 4B           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> 00F5352C
<span style="color: #adadad; font-style: italic;">00F534E1</span>    8B45 <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534E4</span>    <span style="color: #0000ff;">8338</span> <span style="color: #0000ff;">01</span>         <span style="color: #00007f; font-weight: bold;">cmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">1</span>
<span style="color: #adadad; font-style: italic;">00F534E7</span>    <span style="color: #0000ff;">75</span> <span style="color: #0000ff;">43</span>           <span style="color: #00007f; font-weight: bold;">jnz</span>     <span style="color: #000000; font-weight: bold;">short</span> 00F5352C
<span style="color: #adadad; font-style: italic;">00F534E9</span>    8B0D 2C0BF800   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80B2C<span style="color: #009900; font-weight: bold;">&#93;</span>          <span style="color: #666666; font-style: italic;">; NB_SMS.0067D398</span>
<span style="color: #adadad; font-style: italic;">00F534EF</span>    8B15 2C0BF800   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80B2C<span style="color: #009900; font-weight: bold;">&#93;</span>          <span style="color: #666666; font-style: italic;">; NB_SMS.0067D398</span>
<span style="color: #adadad; font-style: italic;">00F534F5</span>    8B81 <span style="color: #0000ff;">80000000</span>   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">80</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534FB</span>    <span style="color: #0000ff;">3342</span> <span style="color: #0000ff;">14</span>         <span style="color: #00007f; font-weight: bold;">xor</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">14</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F534FE</span>    8B0D 2C0BF800   <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>F80B2C<span style="color: #009900; font-weight: bold;">&#93;</span>          <span style="color: #666666; font-style: italic;">; NB_SMS.0067D398</span>
<span style="color: #adadad; font-style: italic;">00F53504</span>    <span style="color: #0000ff;">3341</span> <span style="color: #0000ff;">40</span>         <span style="color: #00007f; font-weight: bold;">xor</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">40</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53507</span>    <span style="color: #0000ff;">8945</span> DC         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">24</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00F5350A</span>    8B55 <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F5350D</span>    8B42 <span style="color: #0000ff;">04</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">4</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53510</span>    <span style="color: #0000ff;">50</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00F53511</span>    8B4D <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53514</span>    8B51 <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ecx</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53517</span>    <span style="color: #0000ff;">52</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">edx</span>
<span style="color: #adadad; font-style: italic;">00F53518</span>    6A <span style="color: #0000ff;">00</span>           <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #0000ff;">0</span>
<span style="color: #adadad; font-style: italic;">00F5351A</span>    8B45 <span style="color: #0000ff;">08</span>         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">8</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F5351D</span>    8B48 0C         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #339933;">+</span><span style="color: #000000; font-weight: bold;">C</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53520</span>    <span style="color: #0000ff;">51</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">ecx</span>
<span style="color: #adadad; font-style: italic;">00F53521</span>    8B55 F4         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #000000; font-weight: bold;">C</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53524</span>    2B55 DC         <span style="color: #00007f; font-weight: bold;">sub</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">24</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F53527</span>    FFD2            <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #00007f;">edx</span>                              <span style="color: #666666; font-style: italic;">; 这里就是程序的入口点，直接F7跟入就到了程序的入口点了</span>
<span style="color: #adadad; font-style: italic;">00F53529</span>    <span style="color: #0000ff;">8945</span> FC         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">4</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00F5352C</span>    8B45 FC         <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">4</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00F5352F</span>    5E              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">esi</span>
<span style="color: #adadad; font-style: italic;">00F53530</span>    8BE5            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">esp</span><span style="color: #339933;">,</span> <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">00F53532</span>    5D              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">00F53533</span>    C3              <span style="color: #00007f; font-weight: bold;">retn</span>
<span style="color: #adadad; font-style: italic;">00F53534</span>    CC              int3</pre></div></div>

<p>然后一直F8知道执行的注释中所说的入口点，然后跟入即可：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">00401480</span>   <span style="color: #339933;">/</span>EB <span style="color: #0000ff;">10</span>           <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">short</span> <span style="color: #0000ff;">00401492</span>
<span style="color: #adadad; font-style: italic;">00401482</span>   |<span style="color: #0000ff;">66</span><span style="color: #339933;">:</span>623A         <span style="color: #00007f; font-weight: bold;">bound</span>   <span style="color: #00007f;">di</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edx</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00401485</span>   |<span style="color: #0000ff;">43</span>              <span style="color: #00007f; font-weight: bold;">inc</span>     <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">00401486</span>   |2B2B            <span style="color: #00007f; font-weight: bold;">sub</span>     <span style="color: #00007f;">ebp</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebx</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00401488</span>   |<span style="color: #0000ff;">48</span>              <span style="color: #00007f; font-weight: bold;">dec</span>     <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">00401489</span>   |<span style="color: #0000ff;">4F</span>              <span style="color: #00007f; font-weight: bold;">dec</span>     <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">0040148A</span>   |<span style="color: #0000ff;">4F</span>              <span style="color: #00007f; font-weight: bold;">dec</span>     <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">0040148B</span>   |4B              <span style="color: #00007f; font-weight: bold;">dec</span>     <span style="color: #00007f;">ebx</span>
<span style="color: #adadad; font-style: italic;">0040148C</span>   |<span style="color: #0000ff;">90</span>              <span style="color: #00007f; font-weight: bold;">nop</span>
<span style="color: #adadad; font-style: italic;">0040148D</span>  <span style="color: #339933;">-</span>|E9 98F05100     <span style="color: #00007f; font-weight: bold;">jmp</span>     0092052A
<span style="color: #adadad; font-style: italic;">00401492</span>   \A1 8BF05100     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>51F08B<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00401497</span>    C1E0 <span style="color: #0000ff;">02</span>         <span style="color: #00007f; font-weight: bold;">shl</span>     <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span> <span style="color: #0000ff;">2</span>
<span style="color: #adadad; font-style: italic;">0040149A</span>    A3 8FF05100     <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>51F08F<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">0040149F</span>    <span style="color: #0000ff;">52</span>              <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #00007f;">edx</span>
<span style="color: #adadad; font-style: italic;">004014A0</span>    6A <span style="color: #0000ff;">00</span>           <span style="color: #00007f; font-weight: bold;">push</span>    <span style="color: #0000ff;">0</span>
<span style="color: #adadad; font-style: italic;">004014A2</span>    E8 CFCF1100     <span style="color: #00007f; font-weight: bold;">call</span>    <span style="color: #0000ff;">0051E476</span>                         <span style="color: #666666; font-style: italic;">; jmp 到 kernel32.GetModuleHandleA</span>
<span style="color: #adadad; font-style: italic;">004014A7</span>    8BD0            <span style="color: #00007f; font-weight: bold;">mov</span>     <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span> <span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">004014A9</span>    E8 129C0F00     <span style="color: #00007f; font-weight: bold;">call</span>    004FB0C0
<span style="color: #adadad; font-style: italic;">004014AE</span>    5A              <span style="color: #00007f; font-weight: bold;">pop</span>     <span style="color: #00007f;">edx</span>
<span style="color: #adadad; font-style: italic;">004014AF</span>    E8 709B0F00     <span style="color: #00007f; font-weight: bold;">call</span>    004FB024</pre></div></div>

<p>到此最主要的工作就完成了，剩下的就是修复了。<br />
3.这里需要说明的是，修复输入表的时候由于输入表不连续直接修复会有很多指针无效：</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">0051E368</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">20115600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561120</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; ADVAPI32.GetUserNameA</span>
<span style="color: #adadad; font-style: italic;">0051E36E</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">24115600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561124</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; ADVAPI32.RegCloseKey</span>
<span style="color: #adadad; font-style: italic;">0051E374</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">28115600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561128</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; ADVAPI32.RegCreateKeyExA</span>
<span style="color: #adadad; font-style: italic;">0051E37A</span>  <span style="color: #339933;">-</span> FF25 2C115600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>56112C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; ADVAPI32.RegOpenKeyExA</span>
<span style="color: #adadad; font-style: italic;">0051E380</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">30115600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561130</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; ADVAPI32.RegQueryValueExA</span>
<span style="color: #adadad; font-style: italic;">0051E386</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">34115600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561134</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; ADVAPI32.RegSetValueExA</span>
<span style="color: #adadad; font-style: italic;">0051E38C</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">14135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561314</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.Beep</span>
<span style="color: #adadad; font-style: italic;">0051E392</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">18135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561318</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.CloseHandle</span>
<span style="color: #adadad; font-style: italic;">0051E398</span>  <span style="color: #339933;">-</span> FF25 1C135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>56131C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.CompareStringA</span>
<span style="color: #adadad; font-style: italic;">0051E39E</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">20135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561320</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.CreateDirectoryA</span>
<span style="color: #adadad; font-style: italic;">0051E3A4</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">24135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561324</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.CreateEventA</span>
<span style="color: #adadad; font-style: italic;">0051E3AA</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">28135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561328</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.CreateFileA</span>
<span style="color: #adadad; font-style: italic;">0051E3B0</span>  <span style="color: #339933;">-</span> FF25 2C135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>56132C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.CreateThread</span>
<span style="color: #adadad; font-style: italic;">0051E3B6</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">30135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561330</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.DebugBreak</span>
<span style="color: #adadad; font-style: italic;">0051E3BC</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">34135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561334</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; ntdll.RtlDeleteCriticalSection</span>
<span style="color: #adadad; font-style: italic;">0051E3C2</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">38135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561338</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.DeleteFileA</span>
<span style="color: #adadad; font-style: italic;">0051E3C8</span>  <span style="color: #339933;">-</span> FF25 3C135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>56133C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; ntdll.RtlEnterCriticalSection</span>
<span style="color: #adadad; font-style: italic;">0051E3CE</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">40135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561340</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.EnumCalendarInfoA</span>
<span style="color: #adadad; font-style: italic;">0051E3D4</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">44135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561344</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.ExitProcess</span>
<span style="color: #adadad; font-style: italic;">0051E3DA</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">48135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561348</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.FileTimeToDosDateTime</span>
<span style="color: #adadad; font-style: italic;">0051E3E0</span>  <span style="color: #339933;">-</span> FF25 4C135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>56134C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.FileTimeToLocalFileTime</span>
<span style="color: #adadad; font-style: italic;">0051E3E6</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">50135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561350</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.FindClose</span>
<span style="color: #adadad; font-style: italic;">0051E3EC</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">54135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561354</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.FindFirstFileA</span>
<span style="color: #adadad; font-style: italic;">0051E3F2</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">58135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561358</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.FindNextFileA</span>
<span style="color: #adadad; font-style: italic;">0051E3F8</span>  <span style="color: #339933;">-</span> FF25 5C135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>56135C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.FindResourceA</span>
<span style="color: #adadad; font-style: italic;">0051E3FE</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">60135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561360</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.FormatMessageA</span>
<span style="color: #adadad; font-style: italic;">0051E404</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">64135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561364</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.FreeLibrary</span>
<span style="color: #adadad; font-style: italic;">0051E40A</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">68135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561368</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.FreeResource</span>
<span style="color: #adadad; font-style: italic;">0051E410</span>  <span style="color: #339933;">-</span> FF25 6C135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>56136C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetACP</span>
<span style="color: #adadad; font-style: italic;">0051E416</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">70135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561370</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetCPInfo</span>
<span style="color: #adadad; font-style: italic;">0051E41C</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">74135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561374</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetCommandLineA</span>
<span style="color: #adadad; font-style: italic;">0051E422</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">78135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561378</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetComputerNameA</span>
<span style="color: #adadad; font-style: italic;">0051E428</span>  <span style="color: #339933;">-</span> FF25 7C135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>56137C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetCurrentProcessId</span>
<span style="color: #adadad; font-style: italic;">0051E42E</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">80135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561380</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetCurrentThreadId</span>
<span style="color: #adadad; font-style: italic;">0051E434</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">84135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561384</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetDateFormatA</span>
<span style="color: #adadad; font-style: italic;">0051E43A</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">88135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561388</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetDiskFreeSpaceA</span>
<span style="color: #adadad; font-style: italic;">0051E440</span>  <span style="color: #339933;">-</span> FF25 8C135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>56138C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetEnvironmentStringsA</span>
<span style="color: #adadad; font-style: italic;">0051E446</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">90135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561390</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetEnvironmentVariableA</span>
<span style="color: #adadad; font-style: italic;">0051E44C</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">94135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561394</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetFileAttributesA</span>
<span style="color: #adadad; font-style: italic;">0051E452</span>  <span style="color: #339933;">-</span> FF25 <span style="color: #0000ff;">98135600</span>   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">561398</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetFileSize</span>
<span style="color: #adadad; font-style: italic;">0051E458</span>  <span style="color: #339933;">-</span> FF25 9C135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>56139C<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetFileType</span>
<span style="color: #adadad; font-style: italic;">0051E45E</span>  <span style="color: #339933;">-</span> FF25 A0135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613A0<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; ntdll.RtlGetLastWin32Error</span>
<span style="color: #adadad; font-style: italic;">0051E464</span>  <span style="color: #339933;">-</span> FF25 A4135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613A4<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetLocalTime</span>
<span style="color: #adadad; font-style: italic;">0051E46A</span>  <span style="color: #339933;">-</span> FF25 A8135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613A8<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetLocaleInfoA</span>
<span style="color: #adadad; font-style: italic;">0051E470</span>  <span style="color: #339933;">-</span> FF25 AC135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613AC<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetModuleFileNameA</span>
<span style="color: #adadad; font-style: italic;">0051E476</span>  <span style="color: #339933;">-</span> FF25 B0135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613B0<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetModuleHandleA</span>
<span style="color: #adadad; font-style: italic;">0051E47C</span>  <span style="color: #339933;">-</span> FF25 B4135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613B4<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetOEMCP</span>
<span style="color: #adadad; font-style: italic;">0051E482</span>  <span style="color: #339933;">-</span> FF25 B8135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613B8<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetPrivateProfileStringA</span>
<span style="color: #adadad; font-style: italic;">0051E488</span>  <span style="color: #339933;">-</span> FF25 BC135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613BC<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetProcAddress</span>
<span style="color: #adadad; font-style: italic;">0051E48E</span>  <span style="color: #339933;">-</span> FF25 C0135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613C0<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetProcessHeap</span>
<span style="color: #adadad; font-style: italic;">0051E494</span>  <span style="color: #339933;">-</span> FF25 C4135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613C4<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetProfileStringA</span>
<span style="color: #adadad; font-style: italic;">0051E49A</span>  <span style="color: #339933;">-</span> FF25 C8135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613C8<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetStartupInfoA</span>
<span style="color: #adadad; font-style: italic;">0051E4A0</span>  <span style="color: #339933;">-</span> FF25 CC135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613CC<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetStdHandle</span>
<span style="color: #adadad; font-style: italic;">0051E4A6</span>  <span style="color: #339933;">-</span> FF25 D0135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613D0<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetStringTypeA</span>
<span style="color: #adadad; font-style: italic;">0051E4AC</span>  <span style="color: #339933;">-</span> FF25 D4135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613D4<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetStringTypeExA</span>
<span style="color: #adadad; font-style: italic;">0051E4B2</span>  <span style="color: #339933;">-</span> FF25 D8135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613D8<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetStringTypeW</span>
<span style="color: #adadad; font-style: italic;">0051E4B8</span>  <span style="color: #339933;">-</span> FF25 DC135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613DC<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetSystemDefaultLangID</span>
<span style="color: #adadad; font-style: italic;">0051E4BE</span>  <span style="color: #339933;">-</span> FF25 E0135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">5613E0</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetSystemInfo</span>
<span style="color: #adadad; font-style: italic;">0051E4C4</span>  <span style="color: #339933;">-</span> FF25 E4135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">5613E4</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetThreadLocale</span>
<span style="color: #adadad; font-style: italic;">0051E4CA</span>  <span style="color: #339933;">-</span> FF25 E8135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #0000ff;">5613E8</span><span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetTickCount</span>
<span style="color: #adadad; font-style: italic;">0051E4D0</span>  <span style="color: #339933;">-</span> FF25 EC135600   <span style="color: #00007f; font-weight: bold;">jmp</span>     <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #009900; font-weight: bold;">&#91;</span>5613EC<span style="color: #009900; font-weight: bold;">&#93;</span>               <span style="color: #666666; font-style: italic;">; kernel32.GetTimeZoneInformation</span></pre></div></div>

<p>这里可以发现第一个dll的输入表距离第二个dll的输入表较远，直接修复得到的指针都是无效的，这里需要先修复第一个，然后再修复后面的即可：<br />
第一次按照iat自动搜索的结结果修复即可，长度填100，目标是先修复第一个dll的输入表：<br />
第二次填出第二个dll的起始位置：161314长度填1000直接搜索删除无效指针，修复dump后的文件即可.<br />
<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2009/08/yodas-protector-1-3-ashkbiz-danehkar-unpack/" title="yoda's Protector 1.3 -> Ashkbiz Danehkar 手脱笔记” rel=”bookmark inlinks”>yoda&#8217;s Protector 1.3 -> Ashkbiz Danehkar 手脱笔记</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/07/unpack-64bit-exe-via-ida-debug-plugin/" title="IDA + Debug 插件 实现64Bit Exe脱壳" rel="bookmark inlinks">IDA + Debug 插件 实现64Bit Exe脱壳</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/07/ida-pe6-dll-unpack/" title="实战IDA PE+ DLL脱壳" rel="bookmark inlinks">实战IDA PE+ DLL脱壳</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/04/imp64/" title="imp64" rel="bookmark inlinks">imp64</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/08/packer-unpack/" title="普通壳的脱壳方法和脱壳技巧【转载】" rel="bookmark inlinks">普通壳的脱壳方法和脱壳技巧【转载】</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/06/pecompact-2-x-jeremy-collake-overlay-unpack/" title="PECompact 2.x -> Jeremy Collake [Overlay] 脱壳” rel=”bookmark inlinks”>PECompact 2.x -> Jeremy Collake [Overlay] 脱壳</a><span class="count">( 2 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/11/scylla-v0-5a-x64x86-imports-reconstruction/" title="Scylla v0.5a- x64/x86 Imports Reconstruction" rel="bookmark inlinks">Scylla v0.5a- x64/x86 Imports Reconstruction</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/03/asprotect-1-23-rc4-1-3-08-24-alexey-solodovnikov-stolen-code/" title="ASProtect 1.23 RC4 - 1.3.08.24 -> Alexey Solodovnikov 脱壳Stolen code 修复” rel=”bookmark inlinks”>ASProtect 1.23 RC4 &#8211; 1.3.08.24 -> Alexey Solodovnikov 脱壳Stolen code 修复</a><span class="count">( 0 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2010/03/armadillo-v6-x-minimum-protection-unpack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MEW 11 1.2 -&gt; NorthFox/HCC 脱壳脚本</title>
		<link>http://www.h4ck.org.cn/2009/10/mew-11-1-2-northfoxhcc/</link>
		<comments>http://www.h4ck.org.cn/2009/10/mew-11-1-2-northfoxhcc/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 02:18:55 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[脱壳『Unpack』]]></category>
		<category><![CDATA[OD]]></category>
		<category><![CDATA[Packer]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=487</guid>
		<description><![CDATA[//////////////////////////////////////////////////
// FileName : MEW 11 V1.0-V1.2.osc
// Comment : MEW 11 V1.0-V1.2 OEP Find
// Environment : WinXP SP2,OllyDbg V1.10,OllyScript V0.92
// Author : fly
// WebSite : http://www.unpack.cn
// Date : 2005-10-03 20:30
//////////////////////////////////////////////////]]></description>
			<content:encoded><![CDATA[
<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
</pre></td><td class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #339933;">//////////////////////////////////////////////////</span>
<span style="color: #339933;">//</span>  FileName    <span style="color: #339933;">:</span>  MEW <span style="color: #0000ff;">11</span> V1<span style="color: #339933;">.</span>0<span style="color: #339933;">-</span>V1<span style="color: #339933;">.</span>2<span style="color: #339933;">.</span>osc
<span style="color: #339933;">//</span>  <span style="color: #000000; font-weight: bold;">Comment</span>     <span style="color: #339933;">:</span>  MEW <span style="color: #0000ff;">11</span> V1<span style="color: #339933;">.</span>0<span style="color: #339933;">-</span>V1<span style="color: #339933;">.</span>2 OEP Find
<span style="color: #339933;">//</span>  Environment <span style="color: #339933;">:</span>  WinXP SP2<span style="color: #339933;">,</span>OllyDbg V1<span style="color: #339933;">.</span>10<span style="color: #339933;">,</span>OllyScript V0<span style="color: #339933;">.</span>92
<span style="color: #339933;">//</span>  Author      <span style="color: #339933;">:</span>  fly
<span style="color: #339933;">//</span>  WebSite     <span style="color: #339933;">:</span>  http<span style="color: #339933;">://</span>www<span style="color: #339933;">.</span>unpack<span style="color: #339933;">.</span>cn
<span style="color: #339933;">//</span>  Date        <span style="color: #339933;">:</span>  <span style="color: #0000ff;">2005</span><span style="color: #339933;">-</span><span style="color: #0000ff;">10</span><span style="color: #339933;">-</span><span style="color: #0000ff;">03</span> <span style="color: #0000ff;">20</span><span style="color: #339933;">:</span><span style="color: #0000ff;">30</span>
<span style="color: #339933;">//////////////////////////////////////////////////</span>
#log
&nbsp;
MSGYN <span style="color: #7f007f;">&quot;Plz Clear All BreakPoints  And  Set Debugging Option Ignore All Excepions Options  !&quot;</span>
<span style="color: #00007f; font-weight: bold;">cmp</span> $RESULT<span style="color: #339933;">,</span> <span style="color: #0000ff;">0</span>
<span style="color: #00007f; font-weight: bold;">je</span> TryAgain
&nbsp;
<span style="color: #339933;">//</span>GameStart――――――――――――――――――――――――――――――――
&nbsp;
<span style="color: #00007f; font-weight: bold;">sti</span>
find eip<span style="color: #339933;">,</span> #C30000#
<span style="color: #00007f; font-weight: bold;">cmp</span> $RESULT<span style="color: #339933;">,</span> <span style="color: #0000ff;">0</span>
<span style="color: #00007f; font-weight: bold;">je</span> NoFind
eob <span style="color: #000000; font-weight: bold;">Break</span>
<span style="color: #00007f;">bp</span> $RESULT
log $RESULT
&nbsp;
esto
GoOn<span style="color: #339933;">:</span>
esto
&nbsp;
<span style="color: #000000; font-weight: bold;">Break</span><span style="color: #339933;">:</span>
<span style="color: #00007f; font-weight: bold;">cmp</span> eip<span style="color: #339933;">,</span>$RESULT
<span style="color: #00007f; font-weight: bold;">jne</span> GoOn
bc $RESULT
sto
&nbsp;
<span style="color: #339933;">//</span>GameOver――――――――――――――――――――――――――――――――
&nbsp;
log eip
cmt eip<span style="color: #339933;">,</span> <span style="color: #7f007f;">&quot;This is the OEP! Found By: fly&quot;</span>
MSG <span style="color: #7f007f;">&quot;Just : OEP !  Dump and Fix IAT.  Good Luck  &quot;</span>
<span style="color: #00007f; font-weight: bold;">ret</span>
&nbsp;
NoFind<span style="color: #339933;">:</span>
MSG <span style="color: #7f007f;">&quot;Error! Maybe It's not MEW 11 V1.0-V1.2 ! &quot;</span>
<span style="color: #00007f; font-weight: bold;">ret</span>
&nbsp;
TryAgain<span style="color: #339933;">:</span>
MSG <span style="color: #7f007f;">&quot; Please  Try  Again   !   &quot;</span>
<span style="color: #00007f; font-weight: bold;">ret</span></pre></td></tr></table></div>

<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2009/08/ollydbg-2-0-beta-2-200j/" title=" OllyDbg 2.0 beta 2 (200j) " rel="bookmark inlinks"> OllyDbg 2.0 beta 2 (200j) </a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/01/vmprotect-1-70-4-%e7%a0%b4%e8%a7%a3%e7%89%88/" title="VMProtect 1.70.4 破解版" rel="bookmark inlinks">VMProtect 1.70.4 破解版</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/09/zprotect-v1-4-1-carcked/" title="加密强壳ZProtect v1.4.1破解版" rel="bookmark inlinks">加密强壳ZProtect v1.4.1破解版</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/08/od-break-points/" title="OD常用断点 ^_^ 很全很全" rel="bookmark inlinks">OD常用断点 ^_^ 很全很全</a><span class="count">( 1 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/11/od-unicode-string-format-convert-v0-1/" title="OD Unicode String Format Convert v0.1" rel="bookmark inlinks">OD Unicode String Format Convert v0.1</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/09/%e5%bc%ba%e5%a4%a7%e7%9a%84%e4%bf%ae%e6%94%b9%e7%89%88%e6%9c%acollydbgollydrx-1-0/" title="强大的修改版本OllyDbg:OllyDRX 1.0" rel="bookmark inlinks">强大的修改版本OllyDbg:OllyDRX 1.0</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/07/decomeas-asprotect-killer/" title="DecomeAS -Asprotect killer " rel="bookmark inlinks">DecomeAS -Asprotect killer </a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/04/ollydbg-v2-01-alpha-3/" title="OllyDbg v2.01 (alpha 3)" rel="bookmark inlinks">OllyDbg v2.01 (alpha 3)</a><span class="count">( 1 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2009/10/mew-11-1-2-northfoxhcc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>700+ OllyDbgScripts</title>
		<link>http://www.h4ck.org.cn/2009/09/700-ollydbgscripts/</link>
		<comments>http://www.h4ck.org.cn/2009/09/700-ollydbgscripts/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 01:13:45 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[脱壳『Unpack』]]></category>
		<category><![CDATA[软件共享『SoftWare』]]></category>
		<category><![CDATA[OD]]></category>
		<category><![CDATA[Plugin]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=278</guid>
		<description><![CDATA[2008-04-05 20:47 220 32Lite 0.03a OEP Finder v0.1.txt
2006-01-15 00:00 218 32Lite 0.03a OEP V0.1.txt
2008-05-18 00:33 218 32LITE 0.03A OEP-FINDER V.0.1.txt
2004-11-14 19:55 218 32Lite 0.03a.txt
2008-05-18 00:33 2,490 ActiveMark 5.4x Level 2 EP Finder + Fix CRC.txt
2008-05-18 00:33 1,380 ActiveMark 5.4x Remove Selfchecks.txt
2008-05-18 00:33 474 ActiveMark 5.xx Level 2 EP Finder.txt
2006-01-15 00:00 801 ActiveMark Level 2 EP Finder.txt
2006-01-15 00:00 441 ActiveMark Patching Script.txt
2008-04-05 20:50 2,648 activemark54x.txt]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.h4ck.org.cn/soft/crack/Odscript.rar">猛击此处下载文件! </a> <img src='http://www.h4ck.org.cn/wp-content/plugins/smilies-themer/Julianus/20x20-big_smile.png' alt=':)' class='wp-smiley' /> :)</p>
<p>2008-04-05 20:47 220 32Lite 0.03a OEP Finder v0.1.txt<br />
2006-01-15 00:00 218 32Lite 0.03a OEP V0.1.txt<br />
2008-05-18 00:33 218 32LITE 0.03A OEP-FINDER V.0.1.txt<br />
2004-11-14 19:55 218 32Lite 0.03a.txt<br />
2008-05-18 00:33 2,490 ActiveMark 5.4x Level 2 EP Finder + Fix CRC.txt<br />
2008-05-18 00:33 1,380 ActiveMark 5.4x Remove Selfchecks.txt<br />
2008-05-18 00:33 474 ActiveMark 5.xx Level 2 EP Finder.txt<br />
2006-01-15 00:00 801 ActiveMark Level 2 EP Finder.txt<br />
2006-01-15 00:00 441 ActiveMark Patching Script.txt<br />
2008-04-05 20:50 2,648 activemark54x.txt<br />
2008-04-05 20:50 4,919 AddrEnc.txt<br />
2008-04-05 20:50 1,075 AHpack 0.1 OEP Finder .txt<br />
2008-04-05 20:50 1,017 AHTeam EP Protector 0.3a.txt<br />
2008-04-05 20:50 1,227 AHTeam EP Protector 0.3b.txt<br />
2006-01-15 00:00 3,515 Alex Protector 1.0 Beta 2 Fix IAT + Remove Junk Code v0.1.txt<br />
2008-04-05 20:50 3,515 ALEX PROTECTOR 1.0 BETA2 V0.1.txt<br />
2006-01-15 00:00 3,515 ALEX Protector1.0.txt<br />
2008-04-05 20:50 801 AM.level2.ep.finder.txt<br />
2008-04-05 20:51 396 AM.patching.script.txt<br />
<span id="more-278"></span><br />
2004-07-14 19:44 767 anti-debug_lastex.txt<br />
2004-06-10 12:10 7,207 Arm 3.7Std_release.txt<br />
2008-04-05 20:51 3,301 arm IAT Elimination.txt<br />
2008-04-05 20:51 540 ARM PROTECTOR 0.1 &#8211; EXE SHIELD 0.8 OEP FINDER.txt<br />
2006-01-15 00:00 540 ARM Protector 0.1 OEP Finder.txt<br />
2005-02-08 00:53 1,655 Arma-General.txt<br />
2004-07-14 19:44 7,194 arma37.txt<br />
2008-04-05 20:52 359 arma4.30a.txt<br />
2006-01-15 00:00 2,283 Armadillo 3.6x &#8211; 4.xx OEP Finder + Fix Magic Jumps.txt<br />
2006-09-10 12:30 7,194 Armadillo 3.70 Unpack.txt<br />
2006-01-15 00:00 4,010 Armadillo 3.xx &#8211; 4.00 Nanomites VA Finder v1.0.txt<br />
2006-09-10 12:31 3,001 Armadillo 3.xx DLL Unpack v0.1.txt<br />
2006-01-15 00:00 1,635 Armadillo 3.xx Unpack (Standard Protection) v0.1.txt<br />
2006-01-15 00:00 856 Armadillo 4.20 Public Builds OEP Finder (only for CopyMem2 + Debug Blocker).txt<br />
2008-04-05 20:52 1,820 Armadillo 4.30a &#8211; standard script.txt<br />
2006-09-10 12:31 1,715 Armadillo 4.30a Simple Unpacking Script.txt<br />
2008-04-05 20:53 3,009 Armadillo 4.42 CopyMem2 Decrypt Code Sections.txt<br />
2008-04-05 20:53 4,968 Armadillo 4.42 CopyMem2 Detach from Client + Fix Import Table Elimination.txt<br />
2006-09-10 12:31 3,752 Armadillo 4.xx CopyMem2 (Fix IAT).txt<br />
2006-01-15 00:00 853 Armadillo 4.xx OEP Finder.txt<br />
2008-04-05 20:53 319 Armadillo ArmVar.txt<br />
2008-04-05 20:53 6,357 Armadillo CheckFlags v2.txt<br />
2006-01-15 00:00 3,250 Armadillo Detach from Client + Unpack (Hipu 1000 Bytes Method).txt<br />
2006-01-15 00:00 7,272 Armadillo Detach from Client + Unpack (Ricardo 1000 Bytes Method) v0.1.txt<br />
2006-01-15 00:00 8,127 Armadillo Detach from Client + Unpack (Tenketsu 1000 Bytes Method) v0.1.txt<br />
2006-01-15 00:00 1,388 Armadillo Detach from Client.txt<br />
2006-01-15 00:00 941 Armadillo Detach.txt<br />
2006-01-15 00:00 1,018 Armadillo Detective (Debug Blocker or CopyMem2).txt<br />
2006-01-15 00:00 6,625 Armadillo Detective v1.00.txt<br />
2006-01-15 00:00 1,635 Armadillo Find Nag.txt<br />
2006-01-15 00:00 7,684 Armadillo IAT Destruction.txt<br />
2008-04-05 20:54 3,176 Armadillo IAT Eliminator.txt<br />
2008-04-05 20:54 461 Armadillo IAT Script v2.txt<br />
2008-04-05 20:54 274 Armadillo Magic Jump Finder.txt<br />
2008-04-05 20:54 3,870 Armadillo NanoTables v2.txt<br />
2006-01-15 00:00 921 Armadillo OEP Finder (CopyMem2).txt<br />
2006-01-15 00:00 3,083 Armadillo OEP Finder + Fix Magic Jumps + Fix Anti-Dump.txt<br />
2006-01-15 00:00 606 Armadillo OpenMutexA.txt<br />
2006-01-15 00:00 1,468 Armadillo Repair IAT Elimination.txt<br />
2006-01-15 00:00 1,500 Armadillo Standard (Pause).txt<br />
2006-01-15 00:00 1,655 Armadillo Standard Unpack (Specific).txt<br />
2006-01-15 00:00 1,994 Armadillo Standard Unpack + Strategic Code Splicing.txt<br />
2006-01-15 00:00 1,637 Armadillo Standard Unpack.txt<br />
2006-01-15 00:00 5,325 Armadillo V4.0-V4.4.Standard.Protection OEP Finder.txt<br />
2005-11-07 18:19 5,533 Armadillo V4.0-V4.4.Standard.Protection.osc<br />
2004-11-28 20:40 6,625 ARMADiLLO_Detective_v1.00_ollyscript.txt<br />
2003-12-30 03:51 6,625 ARMADiLLO_Detective_v1_ollyscript.txt<br />
2004-07-14 19:44 1,323 arma_detach.txt<br />
2004-07-14 19:44 3,109 arma_unpack.txt<br />
2008-04-05 20:55 921 armcopy2-1.txt<br />
2008-04-05 20:51 3,159 arm_3x_dll.txt<br />
2008-04-05 20:51 1,635 arm_3x_unpack.txt<br />
2008-04-05 20:51 856 arm_4x_debug_blocker_copymem_oep_finder.txt<br />
2008-04-05 20:51 815 arm_4x_oep_finder.txt<br />
2008-04-05 20:51 3,083 arm_anti_dump.txt<br />
2008-04-05 20:51 1,994 arm_code_splicing_unpack.txt<br />
2008-04-05 20:51 921 arm_copymem.txt<br />
2008-04-05 20:51 1,388 arm_detach.txt<br />
2008-04-05 20:51 3,250 arm_detach_1000_bytes_method.txt<br />
2008-04-05 20:51 6,636 arm_detective.txt<br />
2008-04-05 20:51 784 arm_getmodule.txt<br />
2008-04-05 20:51 2,285 arm_magic_jump.txt<br />
2008-04-05 20:51 7,684 arm_oep_finder.txt<br />
2008-04-05 20:51 606 arm_open_mutexa.txt<br />
2008-04-05 20:52 432 arm_script_rica.txt<br />
2008-04-05 20:52 1,655 arm_standard.txt<br />
2008-04-05 20:52 4,010 arm_va_finder.txt<br />
2008-04-05 20:55 219 asp2.1oep.txt<br />
2006-01-15 00:00 391 ASPack (a).txt<br />
2006-01-15 00:00 126 ASPack (b).txt<br />
2006-01-15 00:00 265 ASPack 1.08.02 OEP Finder.txt<br />
2008-04-05 20:55 243 ASPACK 1.X-2.X OEP FINDER V.0.1.txt<br />
2004-11-14 15:40 243 ASpack 1.x-2.x.txt<br />
2006-01-15 00:00 663 ASPack 2.11 OEP Finder.txt<br />
2006-01-15 00:00 1,730 ASPack 2.12 DLL Unpack Finder.txt<br />
2008-04-05 20:55 1,727 ASPACK 2.12 DLL UNPACK SCRIPT.txt<br />
2006-01-15 00:00 612 ASPack 2.12 OEP Finder #1.txt<br />
2006-01-15 00:00 950 ASPack 2.12 OEP Finder #2.txt<br />
2006-01-15 00:00 247 ASPack 2.12 OEP Finder #3.txt<br />
2008-05-18 00:33 948 ASPACK 2.12 [DeAtH HaS cOMe].txt<br />
2008-05-18 00:33 607 ASPACK 2.12 [dOsKey].txt<br />
2008-05-18 00:33 612 ASPACK 2.12 [hacnho[VCT2k4]].txt<br />
2008-05-18 00:33 242 ASPACK 2.12 [Reverend].txt<br />
2005-11-24 02:28 1,726 aspack.212.dll-unpack.txt<br />
2005-11-24 02:28 242 aspack.212.oep.txt<br />
2004-07-14 19:44 113 aspack.txt<br />
2008-04-05 20:55 1,838 ASPACKDLL.txt<br />
2004-07-14 19:44 252 aspack_1.08.02.txt<br />
2004-07-14 19:44 590 aspack_212.txt<br />
2008-04-05 20:55 911 aspoepgen.txt<br />
2004-01-23 19:16 132 ASPR 1.23RC4.txt<br />
2004-05-27 01:28 937 ASPR 1.23RC4findOEP.txt<br />
2006-08-07 15:44 33,902 Aspr2.XX_IATfixer_v2.2s.osc<br />
2007-01-15 09:52 128,069 Aspr2.XX_unpacker_v1.0SC.osc<br />
2008-02-18 15:09 133,459 Aspr2.XX_unpacker_v1.13SC.osc<br />
2004-07-14 19:44 158 asprbp.txt<br />
2008-04-05 20:56 6,536 Aspro2_AIP2.txt<br />
2006-01-15 00:00 182 ASProtect #1 Breakpoint Last Exception.txt<br />
2006-01-15 00:00 259 ASProtect #2 Find Stolen Bytes.txt<br />
2006-01-15 00:00 131 ASProtect #3 Last Exception.txt<br />
2006-01-15 00:00 934 ASProtect #4 OEP Finder.txt<br />
2006-01-15 00:00 822 ASProtect #5 Anti-Debug Last Exception.txt<br />
2008-04-05 20:56 1,167 ASProtect 1.0 OEP Finder.txt<br />
2008-04-05 20:56 1,237 ASPROTECT 1.0 UNPACKING SCRIPT 0.1.txt<br />
2008-04-05 20:56 673 ASPROTECT 1.2 &#8211; 1.2c OEP-FINDER.txt<br />
2008-04-05 20:56 301 ASPROTECT 1.2-1.2C OEP FINDER V.0.1.txt<br />
2004-11-22 13:55 301 ASProtect 1.2-1.2c.txt<br />
2006-01-15 00:00 674 ASProtect 1.20 &#8211; 1.20c OEP Finder.txt<br />
2006-01-15 00:00 1,044 ASProtect 1.22 &#8211; 1.23 Beta 21 &#8211; Find OEP and stolen bytes.txt<br />
2006-01-15 00:00 559 ASProtect 1.22 &#8211; 1.23 Beta 21 &#8211; Find target&#8217;s OEP.txt<br />
2008-04-05 20:56 1,044 ASProtect 1.22 &#8211; 1.23 Beta 21 OEP Finder and Stolen Bytes.txt<br />
2008-04-05 20:57 740 ASProtect 1.22 &#8211; 1.23 Beta 21 OEP Finder v0.1b.txt<br />
2008-04-05 20:57 559 ASProtect 1.22 &#8211; 1.23 Beta 21 OEP Finder.txt<br />
2008-05-18 00:33 568 ASPROTECT 1.22 &#8211; 1.23 BETA 21 [1].txt<br />
2008-05-18 00:33 1,045 ASPROTECT 1.22 &#8211; 1.23 BETA 21 [2].txt<br />
2004-11-22 15:34 794 ASPROTECT 1.22 &#8211; 1.23 BETA 21-RC1.txt<br />
2005-03-08 21:30 1,057 ASProtect 1.22 &#8211; 1.23 Beta 21.txt<br />
2008-04-05 20:57 767 Asprotect 1.23 RC4 Anti-Debug + Last Exception.txt<br />
2008-04-05 20:57 790 ASPROTECT 1.23 RC4 OEP-FINDER.txt<br />
2004-08-04 04:35 788 Asprotect 1.23 RC4.txt<br />
2008-04-05 20:57 1,159 ASProtect 1.2x &#8211; 1(1).txt<br />
2006-01-15 00:00 1,351 ASProtect 1.2x &#8211; 1.3x (Registered) OEP Finder &amp; Olly Hide.txt<br />
2008-05-18 00:33 1,324 ASPROTECT 1.2x &#8211; 1.3x [REGISTERED] 2.txt<br />
2005-04-17 20:29 1,270 ASPROTECT 1.2x &#8211; 1.3x [REGISTERED].txt<br />
2008-04-05 20:57 1,254 ASProtect 1.2x &#8211; 1.txt<br />
2008-04-05 20:57 458 ASProtect 1.3 Lite OEP Finder.txt<br />
2008-04-05 20:57 696 ASProtect 1.3 Repair Sto.txt<br />
2006-01-15 00:00 2,064 Asprotect 1.30b Import Recovery + OEP Finder (Delphi &amp; ImageBase 400000).txt<br />
2006-01-15 00:00 1,588 ASProtect 1.30b Stolen Code Finder v0.1.txt<br />
2008-05-18 00:33 1,924 ASPROTECT 1.30b [Mario555].txt<br />
2006-01-15 00:00 2,766 ASProtect 1.31b Import Recovery + OEP Finder (Delphi &amp; Imagebase 400000).txt<br />
2008-04-05 20:58 2,577 ASProtect 1.31b Import Recovery + OEP Finder (Delphi).txt<br />
2008-05-18 00:33 2,577 ASPROTECT 1.31b [Mario555].txt<br />
2008-04-05 20:58 1,588 ASPROTECT 1.3b STOLEN CODE FINDER.txt<br />
2008-04-05 20:58 17,964 ASProtect 1.3x &#8211; 2.xx IAT Repair Script v1.02.txt<br />
2008-04-05 20:58 2,297 ASProtect 1.3x &#8211; 2.xx OEP Finder v0.1.txt<br />
2006-01-15 00:00 1,343 ASProtect 1.3x OEP Finder #1.txt<br />
2006-01-15 00:00 1,322 ASProtect 1.3x OEP Finder #2.txt<br />
2006-01-15 00:00 2,374 ASProtect 1.3x OEP Finder #3.txt<br />
2008-04-05 20:58 4,706 ASProtect 1.3x OEP Finder + IAT Rebuilder (Call to Call).txt<br />
2008-04-05 20:59 3,799 ASProtect 1.3x OEP Finder + IAT Rebuilder (Call to JMP).txt<br />
2008-04-05 20:59 1,924 ASProtect 1.txt<br />
2008-04-05 20:59 5,623 ASProtect 1.xx Generic OEP Finder + IAT Recovery.txt<br />
2006-01-15 00:00 2,425 ASProtect 2.0 Clear Junk Code + Stop Stolen Code.txt<br />
2006-01-15 00:00 8,462 ASProtect 2.0 Import Recovery + Scrambled Code Recovery (Delphi &amp; Imagebase 400000).txt<br />
2006-01-15 00:00 885 ASProtect 2.0 OEP Finder.txt<br />
2008-04-05 20:59 897 ASPROTECT 2.0 OEP-FINDER .txt<br />
2008-04-05 20:59 2,313 ASProtect 2.0 Stop Stolen Code.txt<br />
2008-05-18 00:33 8,447 ASPROTECT 2.0 UNPACK SCRIPT [DELPHI].txt<br />
2004-12-14 22:19 8,460 ASProtect 2.0 Unpack.txt<br />
2005-01-09 02:11 854 Asprotect 2.00 OEP.txt<br />
2005-01-09 02:10 8,446 Asprotect 2.00 unpacker.txt<br />
2008-04-05 20:59 960 ASProtect 2.0x Automatic SHIFT+F9.txt<br />
2008-04-05 20:59 2,313 ASProtect 2.0x Clear Junk Code + Stop Stolen Code.txt<br />
2008-04-05 20:59 5,149 ASProtect 2.0x Fix IAT with Import Elimination Optimized.txt<br />
2008-04-05 20:59 2,986 ASProtect 2.0x Fix IAT.txt<br />
2008-04-05 20:59 1,670 ASProtect 2.0x Log all HIGHMEM Calls.txt<br />
2008-04-05 20:59 1,468 ASProtect 2.0x OEP Finder + Stolen Code Finder + Fix IAT Jumps.txt<br />
2008-04-05 20:59 2,078 ASProtect 2.0x Patch JMP or CALL.txt<br />
2008-04-05 20:59 3,214 ASProtect 2.0x Rebuild Thunks for VC++.txt<br />
2008-05-18 00:33 3,629 ASProtect 2.0x Resolve API&#8217;s To HIGHMEM Calls(1).txt<br />
2008-05-18 00:33 3,629 ASProtect 2.0x Resolve API&#8217;s to HIGHMEM Calls.txt<br />
2008-04-05 21:00 199 ASProtect 2.1 OEP Finder.txt<br />
2008-04-05 21:00 3,400 ASProtect 2.3 Build 04.26 OEP Finder v1.01.txt<br />
2008-04-05 21:00 8,022 ASProtect 2.txt<br />
2006-01-15 00:00 6,051 ASProtect 2.x Fix IAT with Import Elimination #1.txt<br />
2006-01-15 00:00 6,536 ASProtect 2.x Fix IAT with Import Elimination #2.txt<br />
2006-01-15 00:00 6,932 ASProtect 2.x Fix IAT with Import Elimination #3.txt<br />
2008-04-05 21:00 2,605 ASProtect 2.x Stop stolen code.txt<br />
2008-04-05 21:00 3,083 ASProtect 2.xx IAT Recovery.txt<br />
2008-04-05 21:00 1,503 ASProtect 2.xx Virtual Machine Jump Redirector.txt<br />
2008-04-05 21:00 36,512 ASProtect 2.xx Virtual Machine Rebuilder.txt<br />
2008-04-05 21:00 158 ASProtect BP.txt<br />
2006-01-15 00:00 5,962 ASProtect Generic OEP Finder and Import Recovery.txt<br />
2008-05-18 00:33 5,962 ASPROTECT GENERIC SCRIPT [Orion].txt<br />
2006-01-15 00:00 1,343 ASProtect Last Exception + OEP.txt<br />
2006-01-15 00:00 833 ASProtect OEP Finder (all versions).txt<br />
2006-01-15 00:00 935 ASProtect OEP Finder.txt<br />
2006-01-15 00:00 259 ASProtect Stolen Code Finder.txt<br />
2008-04-05 21:01 259 ASProtect Stolen Code.txt<br />
2008-04-05 21:01 2,425 ASPROTECT TEST SCRIPT V2.0.txt<br />
2005-11-24 02:29 673 asprotect.12.12c.oep.txt<br />
2008-04-05 21:01 8,470 ASProtect.v2.0.txt<br />
2006-01-15 00:00 1,237 Asprotect1.0.txt<br />
2004-11-18 12:28 694 Asprotect1.x.txt<br />
2004-07-14 19:44 1,485 asprotect_13b_stolen_code.txt<br />
2004-07-14 19:44 855 asprsoep.txt<br />
2004-07-14 19:44 223 asprsto.txt<br />
2005-11-24 02:29 1,045 aspr_1.22-1.23.oep.stolenbytes.txt<br />
2004-07-14 19:44 734 aspr_123_rc4.txt<br />
2004-07-14 19:44 1,924 aspr_130b.txt<br />
2004-07-14 19:44 2,577 aspr_131b.txt<br />
2005-11-24 02:30 897 aspr_2.0.oep.txt<br />
2005-11-24 02:30 8,447 aspr_2.0.unpack.txt<br />
2008-04-05 20:56 6,934 ASPr_API.txt<br />
2004-07-14 19:44 5,623 aspr_generic.txt<br />
2006-01-15 00:00 149 BamBam 0.01 OEP Finder.txt<br />
2008-04-05 21:01 2,282 Beria 0.07 &#8211; OEP Finder + Detach Process.txt<br />
2008-04-05 21:01 2,282 Beria 0.07 &#8211; OEP Finder.txt<br />
2008-04-05 21:01 1,398 Copy of arm_detach.txt<br />
2008-04-05 21:01 6,513 copymem.txt<br />
2006-01-15 00:00 265 Crunch 5.0.txt<br />
2006-01-15 00:00 333 Crunch v1.0 Heuristic.txt<br />
2004-11-22 11:04 333 Crunch v1.0.txt<br />
2008-04-05 21:01 337 CRUNCHPE HEURISTIC OEP FINDER V.0.1.txt<br />
2008-04-05 21:01 315 CrunchPE Heuristic OEP Finder v0.1.txt<br />
2004-11-26 19:17 337 CrunchPE Heuristic.txt<br />
2006-01-15 00:00 288 Crypt 1.0 OEP Finder &amp; Unpacker.txt<br />
2008-04-05 21:02 288 CRYPT 1.0 OEP-FINDER &amp; UNPACKER.txt<br />
2008-04-05 21:02 288 Crypt 1.txt<br />
2005-11-24 02:30 288 crypt.1.0.txt<br />
2006-01-15 00:00 1,419 DBPE 2.x OEP Finder v0.1.txt<br />
2006-01-15 00:00 2,732 DBPE 2.x OEP Finder v0.2.txt<br />
2006-01-15 00:00 1,779 DBPE 2.x OEP Finder v0.3.txt<br />
2006-01-15 00:00 2,828 DBPE 2.x OEP Finder v0.4.txt<br />
2008-05-18 00:33 2,604 DBPE 2.x OEP-FINDER 0.3 [loveboom].txt<br />
2008-05-18 00:33 2,828 DBPE 2.x OEP-FINDER 0.4 [loveboom].txt<br />
2008-04-05 21:02 1,361 DBPE 2.x Unpack v0.1.txt<br />
2008-04-05 21:02 1,361 DBPE 2.x Unpack.txt<br />
2008-05-18 00:33 1,779 DBPE 2.x [loveboom].txt<br />
2005-11-24 02:30 1,779 DBPE.2x.oep.txt<br />
2004-07-14 19:44 2,604 dbpe2x.txt<br />
2004-07-14 19:44 1,361 dbpe_2.x.txt<br />
2009-08-18 10:00 &lt;DIR&gt; Delphi &amp; VB事件断点查找脚本<br />
2008-04-05 21:02 7,272 DetachFarther_MethodRicardo_hipu_benina.txt<br />
2008-04-05 21:02 8,127 DetachFarther_MethodTenketsu_hipu_benina.txt<br />
2008-04-05 21:02 866 Duals eXe 1.0 OEP Finder.txt<br />
2008-04-05 21:02 214 Dxpack 0.86 OEP Finder v0.1.txt<br />
2006-01-15 00:00 227 DXPACK 0.86.txt<br />
2006-01-15 00:00 1,498 Encrypt PE 2003.5.18 OEP Finder v0.1.txt<br />
2008-04-05 21:02 1,498 ENCRYPTPE 2003.5.18 OEP FINDER 0.1.txt<br />
2009-02-13 11:47 &lt;DIR&gt; EncryptPE V2.2007.4.11.Service UnPacK脚本<br />
2008-04-05 21:02 2,908 Enigma 1.02 OEP Finder.txt<br />
2008-05-18 00:33 3,588 Enigma 1.txt<br />
2008-05-18 00:33 882 Escargot 0.1 OEP Finder.txt<br />
2008-05-18 00:33 479 EXE Shield 0.5 to 0.8 OEP Finder.txt<br />
2006-01-15 00:00 540 Exe Shield 0.8 OEP Finder.txt<br />
2004-11-19 23:32 1,434 EXE Stealth2.72.txt<br />
2004-03-14 19:39 710 EXE Stealth2.74.txt<br />
2006-01-15 00:00 476 Exe32Pack 1.3X OEP Finder.txt<br />
2004-11-24 12:49 476 EXE32Pack 1.3X.txt<br />
2006-01-15 00:00 630 Exe32Pack 1.42 OEP Finder &amp; Unpacker.txt<br />
2008-05-18 00:33 635 EXE32PACK 1.42 OEP FINDER.txt<br />
2006-01-15 00:00 698 Exe32Pack 1.43 OEP Finder &amp; Unpacker.txt<br />
2008-05-18 00:33 698 Exe32Pack 1.43 OEP Finder.txt<br />
2008-05-18 00:33 691 Exe32pack 1.43&#8230;, OEP Finder &amp; Unpacker.txt<br />
2008-05-18 00:33 630 Exe32Pack 1.txt<br />
2006-01-15 00:00 929 ExeCryptor 1.53 OEP Finder v0.1.txt<br />
2006-01-15 00:00 955 ExeCryptor 1.5x OEP Finder v0.1.txt<br />
2008-05-18 00:33 901 EXECRYPTOR 1.5x OEP-FINDER.txt<br />
2006-01-15 00:00 2,206 ExeCryptor 2.xx IAT Rebuilder v1.1.txt<br />
2008-05-18 00:33 876 ExeCryptor1.53 OEP Finder v0.1.txt<br />
2004-07-14 19:44 901 execryptor_1.5x.txt<br />
2008-04-17 10:31 9,849 Execryptor_IAT_Fixer_1.01&amp;amp<br />
2008-05-18 00:33 479 EXESHIELD 0.5 &#8211; 0.8 (ARM PROTECTOR 0.1).txt<br />
2006-01-15 00:00 499 ExeShield 0.5 to 0.8 OEP Finder.txt<br />
2008-05-18 00:33 513 ExeShield 0.8 OEP Finder.txt<br />
2004-07-14 19:44 479 exeshield_0x.txt<br />
2006-01-15 00:00 458 ExeStealth 2.7 OEP Finder v0.1.txt<br />
2008-05-18 00:33 406 EXESTEALTH 2.7 OEP-FINDER.txt<br />
2006-01-15 00:00 1,434 ExeStealth 2.72 OEP Finder &amp; Patch IAT v0.1.txt<br />
2006-01-15 00:00 682 ExeStealth 2.74 OEP Finder v0.1.txt<br />
2008-05-18 00:33 648 EXESTEALTH 2.74 OEP-FINDER.txt<br />
2006-01-15 00:00 1,053 ExeStealth 3.04 &amp; Morphine 2.7 OEP Finder.txt<br />
2008-05-18 00:33 1,037 EXESTEALTH 3.04 AND MORPHINE 2.7.txt<br />
2004-07-14 19:44 406 exestealth_2.7.txt<br />
2004-07-14 19:44 648 exestealth_2.74.txt<br />
2008-05-18 00:33 1,053 exestealth_3.04_morphie_2.7.txt<br />
2006-01-15 00:00 1,906 eXPressor 1.2 OEP Finder.txt<br />
2008-05-18 00:33 1,839 EXPRESSOR 1.2.0.1 OEP FINDER.txt<br />
2006-01-15 00:00 127 eXPressor 1.3.0.1 OEP Finder.txt<br />
2006-01-15 00:00 589 EZip 1.0 OEP Finder #1.txt<br />
2006-01-15 00:00 546 EZip 1.0 OEP Finder #2.txt<br />
2006-01-15 00:00 519 EZip 1.0 OEP Finder #3.txt<br />
2008-05-18 00:33 569 EZIP 1.0 OEP FINDER.txt<br />
2004-11-14 15:56 295 EZIP 1.0.txt<br />
2004-07-14 19:44 569 ezip_10.txt<br />
2008-04-05 21:02 291 E_ZIP 1.0 OEP-FINDER &amp; UNPACKER.txt<br />
2008-05-18 00:33 590 FatMike DLL Loader Script.txt<br />
2008-05-18 00:33 503 FatMike IAT Resolver Script.txt<br />
2006-01-15 00:00 2,379 Flexlm 7.2 Seedfinder v2.0.txt<br />
2008-05-18 00:33 2,379 FLEXLM 7.2+ SEEDFINDER SCRIPT.txt<br />
2005-11-24 02:31 2,379 flexlm.7.2+.txt<br />
2006-01-15 00:00 2,497 FOR GATHERING IAT INFORMATION.txt<br />
2008-05-18 00:33 177 FRENCH LAYOR 1.81 &#8211; OEP FINDER.txt<br />
2008-05-18 00:33 166 French Layor 1.81 OEP Finder.txt<br />
2008-05-18 00:33 220 FSG 1.0 OEP-FINDER.txt<br />
2006-01-15 00:00 220 FSG 1.00 OEP Finder #1.txt<br />
2006-01-15 00:00 852 FSG 1.00 OEP Finder #2.txt<br />
2008-05-18 00:33 207 FSG 1.00 OEP Finder.txt<br />
2008-05-18 00:33 833 FSG 1.33 OEP FINDER 0.2 [loveboom].txt<br />
2006-01-15 00:00 268 FSG 1.33 OEP Finder v0.1 #1.txt<br />
2006-01-15 00:00 649 FSG 1.33 OEP Finder v0.1 #3.txt<br />
2008-05-18 00:33 247 FSG 1.33 OEP Finder v0.1.txt<br />
2006-01-15 00:00 889 FSG 1.33 OEP Finder v0.2 #2.txt<br />
2008-05-18 00:33 833 FSG 1.33 OEP Finder v0.2.txt<br />
2008-05-18 00:33 223 FSG 2.0 OEP Finder.txt<br />
2008-05-18 00:33 239 FSG 2.0 OEP-FINDER.txt<br />
2006-01-15 00:00 223 FSG 2.00 OEP Finder #1.txt<br />
2006-01-15 00:00 622 FSG 2.00 OEP Finder #2.txt<br />
2006-01-15 00:00 722 FSG 2.00 OEP Finder #3.txt<br />
2006-01-15 00:00 666 FSG 2.00 OEP Finder #4.txt<br />
2006-01-15 00:00 227 FSG 2.00 OEP Finder #5.txt<br />
2008-05-18 00:33 757 FSG 2.00 OEP Finder v0.1.txt<br />
2008-05-18 00:33 213 FSG 2.00 OEP Finder.txt<br />
2004-11-17 13:58 278 fsg2.0.txt<br />
2004-07-14 19:44 247 fsg_1.33.txt<br />
2004-07-14 19:44 833 fsg_1.33_2.txt<br />
2004-07-14 19:44 223 fsg_2_0.txt<br />
2006-01-15 00:00 1,120 GameHouse Media Packer OEP Finder.txt<br />
2008-05-18 00:33 1,120 GAMEHOUSE MEDIA PACKER OEP-FINDER.txt<br />
2008-05-18 00:33 1,057 GameHouse Media Protector OEP Finder.txt<br />
2008-05-18 00:33 977 Generic VB OEP Finder.txt<br />
2008-05-18 00:33 5,167 Get Executable PE Information.txt<br />
2008-05-18 00:33 1,059 GHF Protector OEP Finder.txt<br />
2008-05-18 00:33 2,821 Hying PeLock 0.4.x OEP Finder v0.1.txt<br />
2008-05-18 00:33 4,989 Hying PeLock 0.7 OEP Finder v0.1.txt<br />
2006-01-15 00:00 2,979 Hying v0.4x.txt<br />
2006-01-15 00:00 5,295 Hying v0.7x.txt<br />
2008-05-18 00:33 2,979 HYING&#8217;PELOCK 0.4.X UNPACK SCRIPT 0.1.txt<br />
2008-05-18 00:33 5,295 HYING&#8217;PELOCK 0.7 UNPACK SCRIPT 0.1.txt<br />
2008-05-18 00:33 5,295 HYINGv0.7x.txt<br />
2008-05-18 00:33 1,426 IAT_ Elimination_2.txt<br />
2008-05-18 00:33 2,265 IAT_Elimination.txt<br />
2006-01-15 00:00 670 JDPack &#8211; JDProtect OEP Finder v0.1.txt<br />
2008-05-18 00:33 670 JDPACK &#8211; JDPROTECT OEP-FINDER.txt<br />
2008-05-18 00:33 1,237 JDPack 0.9 &#8211; 1.01 OEP Finder.txt<br />
2006-01-15 00:00 1,014 JDPack 1.01 OEP Finder v0.1.txt<br />
2008-05-18 00:33 1,063 JDPACK 1.01 OEP-FINDER.txt<br />
2004-11-14 18:16 238 JDPack 1.01.txt<br />
2008-05-18 00:33 846 Kagra Armadillo 4.XX oep finder.txt<br />
2008-05-18 00:33 899 KByS Packer 0.28 Beta OEP Finder.txt<br />
2006-01-15 00:00 695 Krypton 0.5 OEP Finder v0.1.txt<br />
2008-05-18 00:33 659 KRYPTON 0.5 OEP-FINDER.txt<br />
2004-06-10 12:22 700 Krypton0.5.txt<br />
2004-07-14 19:44 659 krypton_0.5.txt<br />
2008-05-18 00:33 871 LAMECRYPT 1.0 OEP-FINDER.txt<br />
2006-01-15 00:00 874 LameCrypt v1.0 OEP Finder.txt<br />
2004-07-14 19:44 114 lastex.txt<br />
2008-05-18 00:33 987 Magic Call BP for Delphi.txt<br />
2008-05-18 00:33 293 Magic Jump Finder Script.txt<br />
2008-05-18 00:33 501 MEW 1.0 OEP Finder.txt<br />
2008-05-18 00:33 501 MEW 10 EXE-CODER 1.0 OEP-FINDER.txt<br />
2006-01-15 00:00 501 MEW 10 SE v1.0 OEP Finder #1.txt<br />
2006-01-15 00:00 207 MEW 10 SE v1.0 OEP Finder #2.txt<br />
2008-05-18 00:33 472 MEW 10 SE v1.0 OEP Finder.txt<br />
2008-05-18 00:33 709 MEW 11 SE 1.1 OEP-FINDER.txt<br />
2008-05-18 00:33 231 MEW 11 SE 1.2 [Darus].txt<br />
2008-05-18 00:33 877 MEW 11 SE 1.2 [DeAtH HaS cOMe].txt<br />
2006-01-15 00:00 736 MEW 11 SE v1.1 OEP Finder.txt<br />
2006-01-15 00:00 877 MEW 11 SE v1.2 OEP Finder #1.txt<br />
2006-01-15 00:00 522 MEW 11 SE v1.2 OEP Finder #2.txt<br />
2008-05-18 00:33 215 MEW 11 SE v1.2b OEP Finder.txt<br />
2006-01-15 00:00 231 MEW 11 SE vb1.2 OEP Finder.txt<br />
2005-11-24 02:32 877 mew.1.2.txt<br />
2004-07-14 19:44 501 mew10_1_0.txt<br />
2006-01-15 00:00 1,233 MoleBox 2.3 Pro OEP Finder v0.1.txt<br />
2008-05-18 00:33 538 MoleBox 2.5.7 OEP Finder.txt<br />
2008-05-18 00:33 914 MoleBox 2.x.x Fix IAT + OEP Finder v0.11.txt<br />
2008-05-18 00:33 914 MOLEBOX 2.x.x FIX IAT+OEP-FINDER 0.11.txt<br />
2008-05-18 00:34 990 MOLEBOX 2.x.x FIX IAT+OEP-FINDER 0.2.txt<br />
2008-05-18 00:33 591 MOLEBOX 2.X.X.X OEP FINDER.txt<br />
2006-01-15 00:00 521 MoleBox 2.xx OEP Finder &amp; Patch IAT.txt<br />
2008-05-18 00:34 914 MoleBox 2.xx OEP Finder + Fix IAT v0.11.txt<br />
2008-05-18 00:33 935 MoleBox 2.xx OEP Finder + Fix IAT v0.2.txt<br />
2006-01-15 00:00 967 MoleBox 2.xx OEP Finder + Fix IATv0.11.txt<br />
2006-01-15 00:00 573 MoleBox 2.xx OEP Finder.txt<br />
2008-05-18 00:33 990 MoleBox2.TXT<br />
2004-11-17 19:19 521 MoleBox2.X 跳过IAT加密.TXT<br />
2004-07-14 19:45 914 molebox_2x.txt<br />
2006-01-15 00:00 743 Morphine 1.2 OEP Finder v0.1.txt<br />
2008-05-18 00:34 705 MORPHINE 1.2 OEP-FINDER.txt<br />
2006-01-15 00:00 685 Morphine 1.3 OEP Finder v0.1.txt<br />
2008-05-18 00:34 657 MORPHINE 1.3 OEP-FINDER.txt<br />
2004-07-14 19:45 705 morphine_1.2.txt<br />
2004-07-14 19:45 657 morphine_13.txt<br />
2008-05-18 00:34 2,732 MSLRH 0.31 OEP Finder v6.txt<br />
2008-05-18 00:33 1,730 MSLRH 0.31a OEP Finder v0.1.txt<br />
2006-01-15 00:00 1,823 MSLRH v0.31A Find OEP &amp; Fix IAT.txt<br />
2008-05-18 00:33 1,823 MSLRH v0.31A UNPACK SCRIPT v0.1.txt<br />
2008-05-18 00:33 1,823 MSLRH v0.31A.txt<br />
2008-05-18 00:33 2,950 MSLRH_0.31 UNPACKING SCRIPT.txt<br />
2004-11-17 14:07 273 Neolite 2.0 .txt<br />
2006-01-15 00:00 158 NeoLite 2.0 OEP Finder #1.txt<br />
2006-01-15 00:00 940 NeoLite 2.0 OEP Finder #2.txt<br />
2006-01-15 00:00 179 NeoLite 2.0 OEP Finder #3.txt<br />
2008-05-18 00:34 158 NEOLITE 2.0 [DarK_m00n[CiM]].txt<br />
2008-05-18 00:33 938 NEOLITE 2.0 [DeAtH HaS cOMe].txt<br />
2004-01-23 21:21 179 neolite 2.0.txt<br />
2004-07-14 19:45 98 neolite20.txt<br />
2008-05-18 00:34 1,118 nProtect GameGuard Script.txt<br />
2006-01-15 00:00 513 NsPack 1.3 OEP Finder #1.txt<br />
2006-01-15 00:00 250 NsPack 1.3 OEP Finder #2.txt<br />
2008-05-18 00:34 250 NSPACK 1.3 OEP FINDER V.0.1.txt<br />
2008-05-18 00:33 494 NsPack 1.3 OEP Finder.txt<br />
2004-11-14 15:03 250 NSpack 1.3.txt<br />
2006-01-15 00:00 698 NsPack 2.0 &#8211; 2.3 OEP Finder v0.1.txt<br />
2006-01-15 00:00 197 NsPack 2.4 &#8211; 2.6 OEP Finder.txt<br />
2006-01-15 00:00 520 NsPack 2.9 OEP Finder.txt<br />
2006-01-15 00:00 160 NsPack 3.4 OEP Finder.txt<br />
2008-05-18 00:34 1,119 NsPack 3.5 OEP Finder.txt<br />
2006-01-15 00:00 1,740 Obsidium 1.061 OEP Finder v0.1 (for VB only).txt<br />
2008-05-18 00:34 1,740 OBSIDIUM 1.061 VB ONLY [loveboom].txt<br />
2006-01-15 00:00 2,505 Obsidium 1.1.1.4 Unpack (not for VB).txt<br />
2008-05-18 00:34 2,588 OBSIDIUM 1.1.1.4.txt<br />
2008-05-18 00:34 2,806 Obsidium114.txt<br />
2004-07-14 19:45 1,638 obsidium_1_0061.txt<br />
2008-05-18 00:34 3,975 ohshit.txt<br />
2008-05-18 00:34 5,488 ohyeah.txt<br />
2008-05-18 00:34 359 Olls Script_Generic_OEP Finder_PECompact_2.xx_by_Max_Zero.txt<br />
2006-01-15 00:00 337 Packman 0.0.0.1 OEP Finder.txt<br />
2008-05-18 00:34 250 PC PESHRINKER 0.71 OEP-FINDER.txt<br />
2008-05-18 00:34 233 PC Shrinker 0.71 OEP Finder v0.1.txt<br />
2004-11-15 12:36 250 PC Shrinker 0.71.txt<br />
2006-01-15 00:00 250 PC Shrinker v0.71 OEP Finder.txt<br />
2006-01-15 00:00 934 PC-Guard 5.0 OEP and Patch IAT v0.1b.txt<br />
2008-05-18 00:34 1,267 PC-GUARD 5.0 OEP FINDER 0.1.txt<br />
2006-01-15 00:00 1,228 PC-Guard 5.0 OEP Finder v0.1.txt<br />
2008-05-18 00:34 1,166 PC-GUARD 5.0 OEP-FINDER.txt<br />
2004-11-22 21:24 934 PC-Guard 5.0.txt<br />
2004-07-14 19:45 1,166 pcguard_150.txt<br />
2008-05-18 00:34 1,267 PCGURAD5.TXT<br />
2008-05-18 00:34 509 Pe Compackt neuste version.txt<br />
2008-05-18 00:34 511 PE COMPACT 0.9x OEP-FINDER.txt<br />
2008-05-18 00:34 154 PE COMPACT 1.76 OEP-FINDER.txt<br />
2008-05-18 00:34 371 PE COMPACT 1.84 OEP-FINDER.txt<br />
2008-05-18 00:34 403 PE COMPACT 2.00-2.38 OEP FINDER.txt<br />
2008-05-18 00:34 442 PE COMPACT 2.40 OEP-FINDER.txt<br />
2008-05-18 00:34 668 PE COMPACT 2.xx OEP-FINDER [2].txt<br />
2008-05-18 00:34 924 PE COMPACT 2.xx OEP-FINDER.txt<br />
2006-01-15 00:00 200 PE Diminisher 0.1 OEP Finder #1.txt<br />
2006-01-15 00:00 323 PE Diminisher 0.1 OEP Finder #2.txt<br />
2008-05-18 00:34 185 PE Diminisher 0.1 OEP Finder.txt<br />
2006-01-15 00:00 628 PE Lock NT 2.04 OEP Finder.txt<br />
2008-05-18 00:34 200 PE-DIMINISHER 1.0 OEP-FINDER.txt<br />
2004-11-22 15:18 433 PE-SHiELD V0.25.txt<br />
2008-05-18 00:34 604 PEBUNDLE 2.0x &#8211; 2.4x OEP-FINDER.txt<br />
2006-01-15 00:00 604 PeBundle 2.0x to 2.4x OEP Finder.txt<br />
2008-05-18 00:34 565 PEBundle 2.0x.txt<br />
2006-01-15 00:00 781 PEbundle 2.3 OEP &amp; Patch IAT.txt<br />
2008-05-18 00:34 781 PEBUNDLE 2.3 OEP + PATCH IAT.txt<br />
2008-08-20 19:54 722 PeBundle 2.3 OEP Finder + Patch IAT.osc<br />
2008-05-18 00:34 735 PeBundle 2.3 OEP Finder + Patch IAT.txt<br />
2004-11-24 12:24 781 PEbundle V2.3 Oep+ Patch IAT.txt<br />
2005-01-09 02:48 581 pebundle_2x.txt<br />
2006-01-15 00:00 579 PeCompact 0.9x OEP Finder.txt<br />
2006-01-15 00:00 154 PeCompact 1.76 OEP Finder.txt<br />
2006-01-15 00:00 371 PeCompact 1.84 OEP Finder.txt<br />
2006-01-15 00:00 263 Pecompact 1.x OEP Finder v0.1.txt<br />
2004-11-14 15:40 263 Pecompact 1.x.txt<br />
2006-01-15 00:00 416 PeCompact 2.00 to 2.38 OEP Finder.txt<br />
2006-01-15 00:00 617 PECompact 2.01a OEP Finder.txt<br />
2008-05-18 00:34 441 PeCompact 2.40 OEP Finder v0.1.txt<br />
2005-01-08 22:26 357 PeCompact 2.40 OEP Finder.txt<br />
2006-01-15 00:00 672 PeCompact 2.64 OEP Finder.txt<br />
2008-05-18 00:34 1,049 PeCompact 2.78 OEP Finder.txt<br />
2004-11-17 15:24 668 PECompact 2.x.txt<br />
2006-01-15 00:00 951 PeCompact 2.xx OEP Finder #1.txt<br />
2006-01-15 00:00 668 PECompact 2.xx OEP finder v0.1 #2.txt<br />
2008-05-18 00:34 951 PeCompact 2.xx OEP Finder.txt<br />
2005-01-12 21:55 956 PECompact 2.xx.txt<br />
2006-01-15 00:00 906 PeCompact OEP Finder.txt<br />
2008-05-18 00:34 263 PECOMPACT V.1.X OEP FINDER.txt<br />
2006-01-15 00:00 1,002 Pecompact v2.08 OEP Finder.TXT<br />
2008-05-18 00:34 339 Pecompact.txt<br />
2005-01-09 02:48 540 pecompact2.02.txt<br />
2005-01-08 22:27 865 PeCompact2.xx.OEP.txt<br />
2008-05-18 00:34 1,002 pecompact208.TXT<br />
2004-07-14 19:45 133 pecompact_1_76.txt<br />
2004-07-14 19:45 338 pecompact_1_84.txt<br />
2005-01-04 19:14 883 PeCompact_2.08.txt<br />
2004-11-14 19:14 323 PEDiminishe 0.1.txt<br />
2004-07-14 19:45 185 pediminisher_1_0.txt<br />
2006-01-15 00:00 1,399 PeLock 1.06 Cracked version OEP Founder v1.0 for VB.txt<br />
2006-01-15 00:00 3,254 PeLock 1.06 OEP Finder + Stolen Code + Remove Junk JMP&#8217;s &amp; Code.txt<br />
2006-01-15 00:00 2,037 PeLock 1.0x Fix IAT + Junk Code + Stolen Code v0.1.txt<br />
2008-05-18 00:34 4,403 PeLock 1.0x Fix IAT + Junk Code + Stolen Code.txt<br />
2008-05-18 00:34 2,035 PELOCK 1.0x [loveboom].txt<br />
2008-05-18 00:34 3,028 PeLock 1.txt<br />
2008-05-18 00:34 628 PELOCK 2.04 OEP-FINDER.txt<br />
2004-06-10 12:23 1,399 PeLock1.06c.txt<br />
2008-05-18 00:34 2,163 PELock1.x.txt<br />
2004-07-14 19:45 598 pelock_204.txt<br />
2006-01-15 00:00 758 PEncrypt 4.0 Find Oep 0.1b.TXT<br />
2008-05-18 00:34 758 PENCRYPT 4.0 OEP FINDER 0.1B.txt<br />
2004-11-19 16:23 758 PEncrypt 4.0.TXT<br />
2006-01-15 00:00 253 PEPack 1.0 &#8211; ANAKiN OEP Finder #3.txt<br />
2006-01-15 00:00 906 PePack 1.0 OEP Finder #1.txt<br />
2006-01-15 00:00 144 PePack 1.0 OEP Finder #2.txt<br />
2008-05-18 00:34 873 PePack 1.0 OEP Finder v0.1.txt<br />
2008-05-18 00:34 131 PePack 1.0 OEP Finder.txt<br />
2008-05-18 00:34 144 PEPACK 1.0 OEP-FINDER II.txt<br />
2008-05-18 00:34 961 PEPACK 1.0 OEP-FINDER.txt<br />
2004-11-16 19:04 253 PEPack 1.0.txt<br />
2008-05-18 00:34 495 PePack1.0.txt<br />
2004-07-14 19:45 131 pepack10.txt<br />
2006-01-15 00:00 2,488 PeShield 0.25 OEP Finder #1.txt<br />
2006-01-15 00:00 433 PeShield 0.25 OEP Finder #2.txt<br />
2008-05-18 00:34 408 PeShield 0.25 OEP Finder v0.1.txt<br />
2008-05-18 00:34 2,379 PeShield 0.25 OEP Finder.txt<br />
2008-05-18 00:34 2,488 PESHIELD 0.25 OEP-FINDER.txt<br />
2008-05-18 00:34 433 PESHIELD 0.25 [2].txt<br />
2004-07-14 19:45 2,379 peshield.txt<br />
2008-05-18 00:34 665 PeSpin 0.0b &#8211; 0.3 OEP Finder.txt<br />
2006-01-15 00:00 1,008 PEspin 0.1 stolen OEP and Patch IAT v0.1.txt<br />
2008-05-18 00:34 957 PESPIN 0.3 &#8211; 1.0 STOLEN BYTES &amp; OEP FINDER.txt<br />
2008-05-18 00:34 1,713 PESPIN 0.3 AND 0.4 VB UNPACK SCRIPT.txt<br />
2006-01-15 00:00 965 PeSpin 0.3 Stolen Code Finder v0.1.txt<br />
2008-05-18 00:34 965 PESPIN 0.3 STOLEN CODE FINDER.txt<br />
2006-01-15 00:00 1,904 PeSpin 0.3 Unpacker.txt<br />
2006-01-15 00:00 1,713 PeSpin 0.3x to 0.4x Unpack v0.1 (for VB only).txt<br />
2006-01-15 00:00 1,023 PeSpin 0.7 OEP Finder #1.txt<br />
2006-01-15 00:00 1,284 PeSpin 0.7 OEP Finder #2.txt<br />
2008-05-18 00:34 978 PeSpin 0.7 OEP Finder.txt<br />
2008-05-18 00:34 1,282 PESPIN 0.7 OEP-FINDER.txt<br />
2006-01-15 00:00 4,176 PeSpin 0.7 Stolen Code Finder v0.1.txt<br />
2006-01-15 00:00 1,467 PeSpin 0.7 Unpacker.txt<br />
2008-05-18 00:34 1,023 PESPIN 0.7 [hacnho[VCT2k4]].txt<br />
2008-05-18 00:34 4,174 PESPIN 0.7 [loveboom].txt<br />
2008-05-18 00:34 706 PESPIN 0.b &#8211; 0.3 OEP FINDER.txt<br />
2006-01-15 00:00 1,863 PeSpin 1.0 &#8211; 1.3 Fix Code Redirection Table.txt<br />
2008-05-18 00:34 764 PESPIN 1.0 OEP FINDER.txt<br />
2006-01-15 00:00 2,582 PeSpin 1.0 Unpacker.txt<br />
2006-01-15 00:00 1,134 PeSpin 1.1 &#8211; 1.3 Find Encrypted Markers.txt<br />
2008-05-18 00:34 2,512 PESPIN 1.1 STOLEN CODE FINDER 0.1.txt<br />
2008-05-18 00:34 2,387 PeSpin 1.1 Stolen Code Finder v0.1.txt<br />
2006-01-15 00:00 3,054 PeSpin 1.1 Unpacker.txt<br />
2006-01-15 00:00 3,183 PeSpin 1.3 Beta 2 (Private) Debug.txt<br />
2006-01-15 00:00 3,889 PeSpin 1.3 Beta 2 (Private) Detach From Client + Fix Code + Fix Nanomites.txt<br />
2008-05-18 00:34 3,663 PeSpin 1.3 Beta2.txt<br />
2006-01-15 00:00 615 PeSpin 1.3 OEP + Stolen Code Finder.txt<br />
2008-05-18 00:34 2,574 PeSpin 1.3 OEP Finder + Stolen Code Finder + Fix IAT + Junk Code v0.1.txt<br />
2008-05-18 00:34 615 PeSpin 1.3 OEP Finder + Stolen Code Finder.txt<br />
2006-01-15 00:00 3,226 PeSpin 1.3 Unpacker.txt<br />
2008-05-18 00:34 1,281 PeSpin 1.304 &#8211; Rebuild Thunks for VC++.txt<br />
2008-05-18 00:34 1,407 PeSpin 1.txt<br />
2008-05-18 00:34 1,397 PeSpin 1.x &#8211; Code Redirection Fixer.txt<br />
2006-01-15 00:00 1,487 PeSpin 1.x Delphi &amp; VC++ IAT Repair.txt<br />
2006-01-15 00:00 677 PeSpin Fixed.txt<br />
2004-11-27 19:24 1,008 PESpin V0.1.txt<br />
2008-05-18 00:34 4,479 PESPIN v0.7.TXT<br />
2006-01-15 00:00 2,512 PESpin v1.1 Stolen Code Finder.txt<br />
2008-05-18 00:34 2,512 pespin v1.1.txt<br />
2008-05-18 00:34 2,600 PESpin v1.3 &#8211; unpacker.txt<br />
2008-05-18 00:34 1,472 PESpin0.3sc.TXT<br />
2004-07-14 19:45 921 pespin_0.3.txt<br />
2004-07-14 19:45 1,618 pespin_0304_vb.txt<br />
2004-07-14 19:45 978 pespin_07.txt<br />
2006-01-15 00:00 1,044 Petite 2.2 OEP finder &amp; Patch IAT.txt<br />
2006-01-15 00:00 427 Petite 2.2 OEP Finder.txt<br />
2008-05-18 00:34 427 PETITE 2.2 OEP-FINDER.txt<br />
2004-11-22 08:53 1,044 Petite 2.2 Patch IAT.txt<br />
2004-11-20 12:42 303 Petite 2.2.txt<br />
2008-05-18 00:34 324 PETITE 2.3 UNPACKING SCRIPT.txt<br />
2008-05-18 00:34 310 Petite 2.txt<br />
2008-05-18 00:34 1,152 PETITE2.2.txt<br />
2004-07-14 19:45 395 petite22.txt<br />
2006-01-15 00:00 516 PeX 0.99 OEP Finder.txt<br />
2008-05-18 00:34 516 PEX 0.99 OEP-FINDER.txt<br />
2004-07-14 19:45 479 pex_0_99.txt<br />
2006-01-15 00:00 218 PKLite32 1.1 OEP Finder #1.txt<br />
2006-01-15 00:00 180 PKLite32 1.1 OEP Finder #2.txt<br />
2008-05-18 00:34 168 PKLite32 1.1 OEP Finder v0.1.txt<br />
2008-05-18 00:34 205 PKLite32 1.1 OEP Finder.txt<br />
2008-05-18 00:34 180 PKLITE32 1.1 OEP-FINDER [2].txt<br />
2008-05-18 00:34 218 PKLITE32 1.1 OEP-FINDER.txt<br />
2004-11-14 19:51 180 PKLITE32 1.1.txt<br />
2004-07-14 19:45 205 pklite32_1.1.txt<br />
2008-05-18 00:34 541 Pokiemagic_ASPR2_OEP.txt<br />
2008-05-18 00:34 1,343 PolyCrypt OEP Finder.txt<br />
2006-01-15 00:00 357 Protection Plus 4.xx OEP Finder + Import Fixer.txt<br />
2006-01-15 00:00 351 Protection Plus OEP Finder.txt<br />
2008-05-18 00:34 351 PROTECTION PLUS OEP-FINDER.txt<br />
2004-07-14 19:45 319 protection_plus_oep.txt<br />
2005-03-18 21:52 10,001 README.TXT<br />
2008-05-18 00:34 6,312 SDProtect 1.12 OEP Finder.txt<br />
2006-02-03 16:22 6,304 sdprotect.1.12.txt<br />
2008-05-18 00:34 1,132 SecuROM 4.xx &#8211; 4.84.75+ (Main Executables) OEP Finder v1.1.txt<br />
2008-05-18 00:34 1,106 SecuROM 4.xx &#8211; 4.84.75+ (Other Executable) OEP Finder v1.1.txt<br />
2008-05-18 00:34 1,004 SECUROM CODE SECTION BP SETTER.txt<br />
2008-05-18 00:34 1,184 SECUROM OEP SCRIPT 1.1 [MAIN EXE].txt<br />
2008-05-18 00:34 1,155 SECUROM OEP SCRIPT 1.1 [NOT MAIN EXE].txt<br />
2006-01-15 00:00 720 SLVc0deProtector 0.61 OEP Finder.txt<br />
2008-05-18 00:34 901 SOFTSENTRY 3.0 OEP FINDER 0.1.txt<br />
2006-01-15 00:00 901 SoftSentry 3.0 OEP Finder v0.1.txt<br />
2008-05-18 00:34 901 SoftSentry3.txt<br />
2004-06-10 12:24 261 stolen bytes.txt<br />
2004-06-10 12:24 1,590 Stolen code Finder.txt<br />
2006-01-15 00:00 885 Stone Pe-ExeEncrypter 1.13 OEP Finder.txt<br />
2008-05-18 00:34 790 STONE&#8217;S PE ENCRYPTER 1.13 OEP FINDER 0.1.txt<br />
2008-05-18 00:34 2,769 SVK PROTECTOR 1.3x SCRIPT [loveboom].txt<br />
2008-05-18 00:34 609 SVK PROTECTOR OEP-FINDER.txt<br />
2008-05-18 00:34 3,054 svk1.32.TXT<br />
2006-01-15 00:00 2,827 SVKP 1.3x Fix Imports + OEP + Stolen Code v0.2.txt<br />
2008-05-18 00:34 2,642 SVKP 1.3x Stolen Code Finder v0.2.txt<br />
2006-01-15 00:00 609 SVKP 1.4x Stolen Code + OEP Finder.txt<br />
2006-01-15 00:00 981 SVKP IAT Fix.txt<br />
2008-05-18 00:34 542 SVKP OEP Finder.txt<br />
2006-01-15 00:00 609 SVKP Stolen Code + OEP Finder.txt<br />
2004-07-14 19:45 542 svkpoep.txt<br />
2004-07-14 19:45 2,642 svkp_13x.txt<br />
2008-05-18 00:34 949 TELOCK 0.9 &#8211; 1.0 (PRIVATE) OEP-FINDER.txt<br />
2006-01-15 00:00 949 tElock 0.9 to 1.0 (private) OEP Finder v0.1.txt<br />
2004-06-10 12:24 999 tElock 0.9-1.0 OEP Finder.txt<br />
2008-05-18 00:34 969 TELOCK 0.9.TXT<br />
2006-01-15 00:00 526 tElock 0.98 OEP Finder v1.0 #1.txt<br />
2006-01-15 00:00 742 tElock 0.98 OEP Finder v1.0 #4.txt<br />
2008-05-18 00:34 526 tElock 0.98 OEP Finder v1.0.txt<br />
2006-01-15 00:00 585 tElock 0.98 OEP Finder v1.1 #2.txt<br />
2008-05-18 00:34 534 tElock 0.98 OEP Finder v1.1.txt<br />
2006-01-15 00:00 609 tElock 0.98 OEP Finder v1.2 #3.txt<br />
2008-05-18 00:34 557 tElock 0.98 OEP Finder v1.2.txt<br />
2008-05-18 00:34 609 TELOCK 0.98 OEP-FINDER 1.2 [SHaG].txt<br />
2005-10-15 00:57 7,877 tELock V0.8X-V0.9X.osc<br />
2006-01-15 00:00 988 telock-forgot.txt<br />
2004-11-20 13:05 742 Telock0.98x.txt<br />
2004-07-18 22:19 609 telock098.osc<br />
2004-07-18 22:19 557 telock098.txt<br />
2004-07-14 19:45 908 telock_0.9.txt<br />
2008-05-18 00:34 276 THE AMAZING UPX OEP-FINDER V2.txt<br />
2006-01-15 00:00 1,120 Thinstall 2.521 OEP Finder.txt<br />
2008-05-18 00:34 2,083 Thinstall.2.521.txt<br />
2008-05-18 00:34 1,120 Thinstall_v2_521.txt<br />
2008-01-23 10:55 27,345 TMDScript-1.9.1+_private_0.7.txt<br />
2005-02-23 20:32 760 ultraprot1_def.txt<br />
2008-05-18 00:34 799 ULTRAPROTECT 1.x &#8211; ACPROTECT 1.22 OEP.txt<br />
2008-05-18 00:34 1,171 ULTRAPROTECT 1.x &#8211; ACPROTECT 1.22 VB.txt<br />
2006-01-15 00:00 799 UltraProtect 1.xx ACProtect 1.22 OEP Finder (none Delphi).txt<br />
2006-01-15 00:00 1,171 UltraProtect 1.xx ACProtect 1.22 OEP Finder (VB only).txt<br />
2004-07-14 19:45 760 uprot1_def.txt<br />
2004-07-14 19:45 1,112 uprot1_vb.txt<br />
2006-01-15 00:00 902 UPX &amp; UPX Scrambler OEP Finder v0.1.txt<br />
2008-05-18 00:34 902 UPX &amp; UPX-SCRAMBLER OEP FINDER 0.1.txt<br />
2006-01-15 00:00 475 UPX &amp; UPXShit 0.6 OEP Finder.txt<br />
2008-05-18 00:34 344 UPX 1.txt<br />
2004-11-14 14:48 297 Upx 1.x.txt<br />
2006-01-15 00:00 374 UPX 1.xx &amp; UPX Protector 1.0 OEP Finder v0.1.txt<br />
2008-05-18 00:34 374 UPX 1.xx &amp; UPX PROTECTOR 1.0 OEP-FINDER.txt<br />
2006-01-15 00:00 805 UPX Find OEP &amp; Dump.TXT<br />
2008-05-18 00:34 1,045 UPX Lock 1.0 OEP Finder.txt<br />
2006-01-15 00:00 276 UPX OEP Finder v2.0.txt<br />
2008-05-18 00:34 628 UPX OEP Finder.txt<br />
2006-01-15 00:00 534 UPX Protector 1.0x OEP Finder.txt<br />
2008-05-18 00:34 534 UPX PROTECTOR 1.0x OEP-FINDER.txt<br />
2006-01-15 00:00 277 UPX Scrambler RC1.x OEP Finder #1.txt<br />
2008-05-18 00:34 265 UPX Scrambler RC1.x OEP Finder.txt<br />
2008-05-18 00:34 277 UPX SCRAMBLER RC1.x OEP-FINDER.txt<br />
2006-01-15 00:00 268 UPX-Scrambler RC1.x OEP finder v0.1b #2.txt<br />
2004-11-19 12:19 268 UPX-Scrambler RC1.x.txt<br />
2004-01-26 02:52 276 UPX.osc<br />
2004-07-14 19:45 262 UPX.txt<br />
2004-07-14 19:45 511 upxprotector_10x.txt<br />
2004-07-14 19:45 265 upxscr_rc1.txt<br />
2008-05-18 00:34 475 UPXSHIT 0.06 AND UPX OEP-FINDER.txt<br />
2006-01-15 00:00 475 UPXShit 0.6 OEP Finder.txt<br />
2006-01-15 00:00 198 UPXShit 0.x OEP Finder.txt<br />
2004-11-19 11:59 198 UPXShit 0.x.txt<br />
2008-05-18 00:34 475 upxshit.txt<br />
2004-07-14 19:45 444 upxshit006.txt<br />
2004-07-14 19:45 344 upx_upxprot.txt<br />
2008-05-18 00:34 3,950 VAFinder.txt<br />
2008-05-18 00:34 1,611 VCasm Junk Code Removers.txt<br />
2008-05-18 00:34 1,698 VCASM SCRIPT.txt<br />
2006-01-15 00:00 1,698 VCASM.txt<br />
2008-05-18 00:34 912 VGCRYPT 0.75 BETA &#8211; OEP FINDER 0.1.txt<br />
2006-01-15 00:00 539 VGCrypt PE Encryptor 0.75 OEP Finder #1.txt<br />
2006-01-15 00:00 347 VGCrypt PE Encryptor 0.75 OEP Finder #2.txt<br />
2006-01-15 00:00 915 VGCrypt PE Encryptor 0.75 OEP Finder #3.txt<br />
2008-05-18 00:34 908 VGCrypt PE Encryptor 0.75 OEP Finder v0.1.txt<br />
2004-11-20 12:54 347 VGCrypt PE Encryptor V0.75.txt<br />
2008-05-18 00:34 508 Virogen Crypt 0.75 OEP Finder.txt<br />
2008-05-18 00:34 539 VIROGEN CRYPT 0.75 OEP-FINDER.txt<br />
2004-07-14 19:45 508 virogen_075.txt<br />
2008-05-18 00:34 784 WINKRIPT 1.0 OEP FINDER 0.1.txt<br />
2006-01-15 00:00 877 WinKripT 1.0 OEP Finder v0.1.txt<br />
2008-05-18 00:34 2,566 WinKripT 1.0 OEP Finder.txt<br />
2006-01-15 00:00 320 WinUpack 0.30 OEP Finder.txt<br />
2006-01-15 00:00 465 WinUpack 0.31 &#8211; 0.32 OEP Finder.txt<br />
2006-01-15 00:00 328 WinUpack 0.38 OEP Finder.txt<br />
2006-01-15 00:00 971 WWPack32 1.20 Demo OEP Finder v0.1.txt<br />
2008-05-18 00:34 969 WWPACK32 1.20 DEMO OEP-FINDER.txt<br />
2008-05-18 00:34 971 WWPack32 1.20 OEP Finder v0.1.txt<br />
2006-01-15 00:00 179 WWPack32 1.20 OEP Finder.txt<br />
2008-05-18 00:34 179 WWPACK32 1.20 OEP-FINDER.txt<br />
2008-05-18 00:34 495 WWPACK32 1.x OEP-FINDER V.0.1B.txt<br />
2004-11-22 10:39 495 WWPack32 1.x.txt<br />
2006-01-15 00:00 495 WWPack32 1.xx OEP Finder.txt<br />
2004-07-14 19:45 449 y0da_crypter_1.2.txt<br />
2008-05-18 00:34 507 YODA&#8217;S CRYPTER 1.2 OEP-FINDER.txt<br />
2008-05-18 00:34 665 YODA&#8217;S CRYPTER 1.3 OEP-FINDER.txt<br />
2008-05-18 00:34 1,808 YODA&#8217;S CRYPTER V.1.2-1.3.txt<br />
2008-05-18 00:34 1,502 YODA&#8217;S CRYPTER V.1.X MODIFIED.txt<br />
2004-11-20 18:56 1,808 yoda&#8217;s Crypter V1.2-1.3.txt<br />
2004-11-20 20:12 1,502 yoda&#8217;s cryptor 1.x modified.txt<br />
2008-05-18 00:34 645 YODA&#8217;S PROTECTOR 1.02 OEP FINDER.txt<br />
2008-05-18 00:34 562 YODA&#8217;S PROTECTOR 1.0b OEP-FINDER.txt<br />
2007-08-12 19:38 3,592 yoda&#8217;s Protector V1.03.X.osc<br />
2008-05-18 00:34 1,715 Yodas Crypter 1.2 OEP + Patch IAT v0.1.txt<br />
2006-01-15 00:00 1,808 Yodas Crypter 1.2 OEP and Patch IAT v0.1.txt<br />
2006-01-15 00:00 507 Yodas Crypter 1.2 OEP Finder v0.1.txt<br />
2006-01-15 00:00 668 Yodas Crypter 1.3 OEP Finder.txt<br />
2008-05-18 00:34 1,421 Yodas Crypter 1.x (Modified) OEP Finder + Patch IAT v0.1b.txt<br />
2006-01-15 00:00 1,502 Yodas cryptor 1.x modified OEP and Patch IAT v0.1b.txt<br />
2006-01-15 00:00 649 Yodas Protector 1.02 OEP Finder.txt<br />
2006-01-15 00:00 2,090 Yodas Protector 1.03.x Unpack.txt<br />
2006-01-15 00:00 475 Yodas Protector 1.0b OEP Finder.txt<br />
2006-01-15 00:00 3,243 _Call Magicas Delphi.txt<br />
2006-01-15 00:00 2,020 _Punto magico VC++.txt<br />
2004-02-25 13:59 11,843 中文ReadMe.txt<br />
2004-02-25 00:55 247 变形fsg1.33.txt<br />
2004-02-25 14:12 996 普通fsg1.33.txt<br />
2004-11-17 13:55 649 普通变形 fsg1.33.txt<br />
<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2009/08/ollydbg-plugins/" title="Ollydbg插件" rel="bookmark inlinks">Ollydbg插件</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/10/mew-11-1-2-northfoxhcc/" title="MEW 11 1.2 -> NorthFox/HCC 脱壳脚本” rel=”bookmark inlinks”>MEW 11 1.2 -> NorthFox/HCC 脱壳脚本</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/02/pluginfix-v1-01by-bob-team-peid/" title="PluginFix v1.01[By BoB / Team PEiD]" rel="bookmark inlinks">PluginFix v1.01[By BoB / Team PEiD]</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/09/%e5%bc%ba%e5%a4%a7%e7%9a%84%e4%bf%ae%e6%94%b9%e7%89%88%e6%9c%acollydbgollydrx-1-0/" title="强大的修改版本OllyDbg:OllyDRX 1.0" rel="bookmark inlinks">强大的修改版本OllyDbg:OllyDRX 1.0</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/11/od-unicode-string-format-convert-v0-1/" title="OD Unicode String Format Convert v0.1" rel="bookmark inlinks">OD Unicode String Format Convert v0.1</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/11/ollysubscript-1-4-1%e6%b1%89%e5%8c%96%e7%89%88/" title="OllySubScript 1.4.1汉化版" rel="bookmark inlinks">OllySubScript 1.4.1汉化版</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/11/ollydbg-2-01-intermediate-alpha/" title="OllyDbg 2.01 intermediate alpha" rel="bookmark inlinks">OllyDbg 2.01 intermediate alpha</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/08/ollydbg-2-0-beta-2-200j/" title=" OllyDbg 2.0 beta 2 (200j) " rel="bookmark inlinks"> OllyDbg 2.0 beta 2 (200j) </a><span class="count">( 0 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2009/09/700-ollydbgscripts/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>ExeInfo PE ver. 0.0.2.4  by A.S.L  ( c ) 2006.03 &#8211; 2009.xx</title>
		<link>http://www.h4ck.org.cn/2009/08/exeinfo-pe-ver-0-0-2-4-by-a-s-l-c-2006-03-2009-xx/</link>
		<comments>http://www.h4ck.org.cn/2009/08/exeinfo-pe-ver-0-0-2-4-by-a-s-l-c-2006-03-2009-xx/#comments</comments>
		<pubDate>Sat, 22 Aug 2009 04:38:26 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[脱壳『Unpack』]]></category>
		<category><![CDATA[软件共享『SoftWare』]]></category>
		<category><![CDATA[PETools]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=106</guid>
		<description><![CDATA[___________________________________________________________________________

ExeInfo PE ver. 0.0.2.4  by A.S.L  ( c ) 2006.03 - 2009.xx

freeware version     for Windows XP

Windows 32 PE executable  file checker , compilators, exe packers ....

with solve hint for unpack  /  internal exe tools / rippers

___________________________________________________________________________]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://a.imagehost.org/view/0033/exeinfo"><img src="http://a.imagehost.org/0033/exeinfo.png" border="0" width="494" height="237" alt="ImageHost.org" /></a><br />
___________________________________________________________________________</p>
<p>ExeInfo PE ver. 0.0.2.4  by A.S.L  ( c ) 2006.03 &#8211; 2009.xx</p>
<p>freeware version     for Windows XP</p>
<p>Windows 32 PE executable  file checker , compilators, exe packers &#8230;.</p>
<p>with solve hint for unpack  /  internal exe tools / rippers</p>
<p>___________________________________________________________________________<br />
<a href="http://cid-16507ea1777422ae.skydrive.live.com/self.aspx/.Public/PETools/exeinfope.zip">猛击此处下载！</a><br />
<span id="more-106"></span><br />
Internal Tools Menu :<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>- overlay remover                     &#8211; generate new file without overlay data<br />
- save overlay as external file<br />
- EP Corrector ( for Delphi / C++ 5/6 )         &#8211; generate many exe file with Entry Point<br />
- EP Corrector ( for Delphi v.5 ) Runtime       &#8211; correct EP<br />
- XoR permutator (xor,or,shl..)       		- create one file with xor data ( 255&#215;2000 bytes )<br />
- Section splitter                    		- save exe sections as files &amp; exe header<br />
- 8 / 16 bit string finder            		- enter 8 bit string = searching 16 bit strings &amp; 8 bit ( F7 key )<br />
- REGistry call finder + CLSID        		- find registry call &amp;  regedit.exe strings<br />
- overlay xor uncrypter               		- uncrypt one byte crypted exe in ovl.<br />
- External exe file runner            		- ( from exeinfopeRUN.cfg ) &#8211; txt user file list to run</p>
<p>File Menu :<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>+ Rename file<br />
+ Copy file As.. *.bak<br />
+ Execute &#8211; create executable process  ( exe )<br />
+ Execute &#8211; windows ext. associate     ( dll ,zip &#8230; )<br />
+ Delete file ( ALt+Del) &#8211; work in multiscan mode<br />
+ Run multifile scanner mode ( Directory scan )<br />
+ &#8211; view global log file ( c:\Raport-exeinfo-log.txt )<br />
- delete global log file ( no confirm )</p>
<p>Rippers Menu :<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>- www address searcher inside exe   &#8211; work on any file</p>
<p>- ExE inside ExE ( Win32 Pe windows executable)      &#8211; work on any file</p>
<p>Archives ripper :<br />
- Zip archives inside ExE  www.winzip.com  &#8211; work on any file<br />
- Rar archives inside ExE  www.rarlab.com  &#8211; work on any file<br />
- 7z  archives inside ExE  www.7-zip.org   &#8211; work on any file<br />
- CAB MS archives inside ExE  (for MSI installers ) &#8211; work on any file</p>
<p>- SWF flash Adobe animation files ( internal length fixer for non exe files )<br />
- ICO nonstandard icon ripper</p>
<p>Graphics ripper submenu :<br />
BMP , PNG , JPG ( JFIF only !!! ) , GIF ( static pic. only )</p>
<p>- ( All in one ) &#8211; for lazy boys ( without &#8216;www address&#8217; )</p>
<p>keys :</p>
<p>F1 key  &#8211; keyboard help<br />
F2 key  &#8211; Multiple file scanner for *.exe files<br />
F3 key  &#8211; external view ( hiewdemo.exe or hiew32.exe ) path directory<br />
F4 key  &#8211; external test ( peid.exe ) path directory<br />
F5 key  &#8211; external test RDG Packer Detector ( I read location from Win registry )<br />
F6 key  &#8211; external test DiE.exe Detect it Easy  ( I read location from Win registry &#8211; shell integration req.)<br />
F7 key  &#8211; 8 / 16 bit String finder<br />
F9 key  &#8211; <img src='http://www.h4ck.org.cn/wp-content/plugins/smilies-themer/Julianus/20x20-big_smile.png' alt=':-)' class='wp-smiley' /> UPX pack<br />
F10 key &#8211; <img src='http://www.h4ck.org.cn/wp-content/plugins/smilies-themer/Julianus/20x20-big_smile.png' alt=':-)' class='wp-smiley' /> UPX unpack<br />
Alt+S   &#8211; ZOOM Window x2 !</p>
<p>Alt+Delete &#8211; delete file</p>
<p>“+” ,”-” &#8211; Numeric KEY =  adjust transparent Form</p>
<p>Non executable file detection :</p>
<p>Image file   &#8211; jpg , png , mng ,gif (87/89) , bmp , tiff<br />
Sound file   &#8211; mp3 (ID3/noID) ,wma , ogg<br />
Video file   &#8211; avi (divx/xvid) , wmv , mpg , 3GP , mov , mp4/m4v<br />
Archive file &#8211; 7zip ,zip ,rar , gzip , bzip</p>
<p>other : chm (Microsoft HTML Help), msi , pdf , xml , fws , cws , php , html , hlp , mdb , lnk ,reg.</p>
<p>Overlay detector :</p>
<p>01. zip archives<br />
02. cab archives<br />
03. SWF Flash object  ( packed &amp; unpacked format )<br />
04. Executable PE file<br />
05. 7zip archives<br />
06. RAR archives<br />
07. MSI/DOC/XLS</p>
<p>- Plugins like a Peid.exe ( 70 % compatible  )</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>Multiscaner use &#8211; command line :</p>
<p>- Exeinfope *.sys  ( show all .sys files )</p>
<p>- Exeinfope *.* /s ( Show All PE files and sent to log file ( s = silent mode no GUI !  -&gt; !ExEinfo-Multiscan.log  )<br />
Exeinfope *.exe /s</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>*ACM &#8211; anti cheat mechanism ( anti fake sign )</p>
<p>_______________________________________________________________________</p>
<p>www site :      www.exeinfo.xwp.pl</p>
<p>Mirror  : 	www.exeinfo.cjb.net</p>
<p>_______________________________________________________________________</p>
<p>ExeInfo detection list :<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>001. RealArcade Wrapper ( Microsoft Visual C++ )  50% detection not all versions<br />
002. Borland Delphi ( 2.0 &#8211; 7.0 )<br />
003. Microsoft Visual C++ ver. 5.0 ~ 6.0 ( exe )<br />
004. Microsoft Visual C++ ver. 7.x ( exe ,dll)<br />
005. PEtite 2.x -&gt; Ian Luck<br />
006. UPX exe 0.89.6 &#8211; 1.02 / 1.05 &#8211; 1.93B -&gt; Markus &amp; Laszlo<br />
007. UPX dll file &#8211; 1.93Beta -&gt; Markus &amp; Laszlo<br />
008. Aspack v2.12 -&gt; Alexey Solodovnikov<br />
009. EXECryptor v.2.3.1-6  ( www.strongbit.com )<br />
010. Morphine ver.2.7b  ( plugin Peid.exe )</p>
<p>011. AC protect 2.0 by  RIScO Software Inc. ( www.ultraprotect.com )<br />
012. ASprotect 2.1 reg ( www.aspack.com/asprotect.htm )  only exe files DLL files detect as ASpack <img src='http://www.h4ck.org.cn/wp-content/plugins/smilies-themer/Julianus/20x20-big_smile.png' alt=':)' class='wp-smiley' /> <br />
013. AHTeam EP Protector ver.0.3 priv<br />
014. WinUpack 0.39 final by Dwing  ( http://dwing.51.net )  :-((<br />
015. Software Compress ver. 1.2 Lite &#8211; www.bgsopt.com<br />
016. PEcompact ver.2.78a &#8211; 2.98  &#8211; www.bitsum.com<br />
017. nsPack ver.2.3 unreg &#8211; by North Star  &#8211;  www.nsdsn.com<br />
018. nsPack ver.3.0 &#8211; 4.1 reg &#8211; by North Star  &#8211;  www.nsdsn.com<br />
019. Mole Box 2.5.7  by Teggo. &#8211; www.molebox.com</p>
<p>020. Microsoft Visual C++ ver. 8  ( ??? )<br />
021. EXE Guarder 1.8 &#8211; 2.1 (2006/2008 unreg)  www.exeicon.com/exeguarder<br />
022. EXE Wrapper ver. 2.3-2.5 ( www.533soft.com/exewrapper ) &#8211; how to remove password<br />
023. Exe password protector 1.0.5.100  (protect/unprotect)<br />
024. TASM / MASM<br />
025. MS Visual Basic 5.0-6.0   dll<br />
026. MS Visual Basic 5.0-6.0   exe</p>
<p>027. Armadillo 4.4x &#8211; 4.62  32bit   &#8211;  www.siliconrealms.com ( effectiveness = 60% )<br />
028. Enigma protector v1.1x   &#8211; www.enigma.izmuroma.ru ?Sukhov Vladimir 2004-2006<br />
029. SVK-Protector v1.32 demo  &#8211;  Pavol Cerven &#8211; www.anticracking.sk</p>
<p>030. Generic check : ASprotect 1.? old version  ( www.aspack.com/asprotect.htm )  exe only<br />
031. Generic check &#8211; AC protect 1.? by  RIScO Software Inc. ( www.ultraprotect.com )<br />
032. Packman v1.0 Brandon LaCombe  ( http://packman.cjb.net )<br />
033. modified exe , EP code = Borland Delphi ( 2.0 &#8211; 7.0 )<br />
034. ExeStealth V2.76  www.webtoolmaster.com<br />
035. FSG v2.0   F[ast] S[mall] G[ood]  &#8211; www.xtreeme.prv.pl</p>
<p>036. Generic check &#8211; Aspack v2.1x -&gt; Alexey Solodovnikov<br />
037. Aspack v2.12b? -&gt; Alexey Solodovnikov<br />
038. Program protector v2.1unreg ( exe password &#8211; DECODE PASS ! ) &#8211; www.blumentals.net<br />
039. Obsidium v1.3 software protection system (demo) &#8211; www.obsidium.de<br />
040. ARMprotector v0.1 by SMOKE 2004<br />
041. ARMprotector v0.3 by SMOKE 2004<br />
042. SDProtector Profesional Edition v1.12  ( 2003 ) &#8211;   www.sdprotector.com</p>
<p>043. Themida 1.0 -1.3? &#8211; Adv.Win.Software Protection System (c) 2004-2005 Oreans Technologies &#8211; www.oreans.com<br />
044. yodas Protector v1.03.3 &#8211;  http://yodap.has.it  2004-2006<br />
045. yoda&#8217;s Crypter v1.3 &#8211; Ashkbiz Danehkar  2004-2005<br />
046. PE-Pack v0.99 (c) 1998 by ANAKiN<br />
047. WATCOM C/C++ 1988-1995<br />
048. Microsoft CAB SFX module<br />
049. Generic check : Microsoft Visual C++ vx.x<br />
050. UPX -&gt; Markus &amp; Laszlo ver. [ 2.00 ] &lt;- version info from file<br />
051. PeSpin v1.304 public by CyberBob &#8211; http://pespin.w.interia.pl<br />
052. UPX -&gt; Markus &amp; Laszlo ver. [ ] &#8211; EXE modified!!!<br />
053. UPX -&gt; with extra sections &#8211; Real EP resolver   ( [ ] &#8211; required Fast scan unchecked )<br />
054. PolyEnE v0.01+ Polymorphic Encryptor (c) 2001 Lennart Hedlund   ( [ ] &#8211; required Fast scan unchecked )<br />
055. Nullsoft PiMP Stub &#8211; ( read from Ovl  : NullsoftInst3&#8243; )<br />
056. eXpressor PE Packer v1.4.5.1  &#8211; www.cgsoftlabs.ro   ( exe , dll )<br />
057. Thinstall 2.4x &#8211; 2.5x -&gt; Jitit Software  &#8211; www.thinstall.com<br />
058. Thinstall 2.7x  -&gt; Jitit Software  &#8211; www.thinstall.com<br />
059. Nullsoft scriptable install system 2.xx &#8211; ( read from Ovl  : NullsoftInst )<br />
060. Inno Setup Module [SFX] &#8211; Borland Delphi Inno Setup Module [unknown]</p>
<p>061. Private EXE Protector 1.7 ( 2003-2006 )  www.setisoft.com<br />
062. Excalibur v1.03r (c) by forgot -&gt; read from file [ Excalibur (c) DFCG ] , http://www.breezer.ful.cn<br />
063. MSLRH v.032a &#8211; SISTEMA DE PROTECCION ANTICRACKEO<br />
064. ShareGuard Loader V3.6 Zapper Software &#8211; www.zapperSoftware.com<br />
065. Borland C++ 1999<br />
066. Zip Sfx Archive<br />
067. Rar Sfx Archive<br />
068. 7-Zip Sfx Archive<br />
069. WinZip Sfx ver. 8.x   www.winzip.com<br />
070. Zylom Game Installer zip Sfx ( MS Visual C++ 7.0 )<br />
071. Borland C++  2002 /2005 &#8211; Copyright 200X Borland Corporation<br />
072. WinZip Sfx ( generic check ) www.winzip.com<br />
073. Lock Express 2.0 Build 9.2 &#8211; 1997-2006 Sciensoft Research Inc<br />
074. FreeBASIC Compiler v0.14-0.17  (c) 2004-2006 Andre Victor T.Vicentini &#8211; console App.<br />
075. generic check : InstallShield 2003 ( MS Visual C++ 5/6.0 )</p>
<p>076. InstallAware Setup Squeezer InstallShield &#8211; www.installaware.com ( 7zip archive )<br />
077. Installer Nullsoft PiMP Stub ( UPX pack )<br />
078. Generic check : Nullsoft PiMP Stub installer<br />
079. ASprotect 1.1c old version  ( www.aspack.com/asprotect.htm )<br />
080. Microsoft Visual C# / Basic.NET<br />
081. Setup Dev INSTALLER ?Version 1.3 ?Shere Khan ?November 2005 ( MS Visual C++ 5/6.0 )<br />
082. Dev-C++ Compiler v4.9.9.2 &#8211; Bloodshed Software ( www.bloodshed.net )<br />
083. Generic check : EXE STICKER like DotFix FakeSigner<br />
084. DotFix FakeSigner v3.4 ( ASPR Stub ) http://fakesigner.dotfix.net<br />
085. PeLock v.1.x Bartosz W骿cik www.pelock.prv.pl<br />
086. MS IExpress 2.0 &#8211; Win32 Cabinet Self-Extractor<br />
087. generic check : MS IExpress x.x &#8211; CAB installer (  in section II )<br />
088. InstallShield (R) Setup Launcher  v.7.x  CAB file ( MS Visual C++ 5/6.0 )<br />
089. PEcompact ver.1.41 &#8211; v1.84  &#8211; www.bitsum.com<br />
090. ORiEN ver.2.11~2.12  &#8211; ( 1994-2003 http://zalexf.narod.ru )<br />
091. VMProtect v.1.2x (demo) 2003-2006 PolyTech &#8211; www.polytech.ural.ru ( only EP protection )<br />
092. FASM ver. 1.67  50% detection<br />
093. Private exe Protector v1.9x &#8211; www.setisoft.com ( morph )<br />
094. Krypton The Krypter ver.0.3 by Yado &#8211; www.lockless.com<br />
095. MEW 11 SE 1.2 by Northfox (2004)  &#8211;  Northfox.uw.hu<br />
096. PEncrypt 4.0 Public Release / 4.0 Phi -&gt; junkcode &#8211;  www.junkcode.cjb.net<br />
097. SDProtector Pro Edition v.1.16  ( 1.1 SDP! ) &lt;- info from file.   www.sdprotector.com<br />
098. PE Diminisher v.0.1 ( 1999 ) &#8211; www.phrozencrew.com/~teraphy<br />
099. !EP (EXE Pack) v1.0   g-l-u-k [TeaM - X] 2005 &#8211;  www.softprot.cjb.net<br />
100. [G!X]&#8216;s Protector v1.2   &#8211;  http://breezer.ys168.com<br />
101. Active PE Scrambler / APES / v. 1.0   (2005)  [TeaM - X]  &#8211; www.team-x.ru<br />
102. (UPX) PowerArchiver 2006 [ ZIP/ CAB/ unknown ] SFX v.9.63.x &#8211; www.powerarchiver.com<br />
103. GameHouse.com installer ( MS Visual C++ )  inside  Wise Installer<br />
104. Dev-C++ Compiler v4.9.9.2 ( MINGW 32 v5.x.x ) &#8211; Bloodshed Software ( www.bloodshed.net )<br />
105. Hide&amp;Protect v1.0x ( 2005 ) &#8211; www.SoftWar-protect.com<br />
106. WWPack32 ver 1.xx  ( 1997,98 ) by P. Warezak and R.Wierzbicki<br />
107. CHAOS Self Extractor 3.9 (1998-2006) ( WWPack-ed ) http://safeSofthome.com<br />
!108. Xtreme-Protector v.1.08 (c) 2003 www.oreans.com/xprotector/xprot.htm<br />
109. LCC Win32 v1.x  ( Jacob Navia )  http://www.cs.virginia.edu/~lcc-win32/<br />
110. LCC Win32 v1.x DLL ( Jacob Navia ) www.cs.virginia.edu/~lcc-win32<br />
111. Hmimys-Packer v1.0<br />
112. ExeFog v.1.1x &#8211; 2005 &#8211; www.bagie.xost.ru<br />
113. PolyCrypt PE v.2.1.x  ( 2004-2005 ) &#8211; www.jlabsoftware.com (exe/dll)<br />
114. SimplePack v1.0 &#8211; 1.2 ( LZMA / APLIB &#8211; Packman compression library 1999-2005 Igor Pavlov )<br />
115. SimplePack v1.11 &#8211; 1.2x ( Method 2 NT )<br />
116. Unopix Version 1.10 Final 2006 Scrambler for PE files ( exe/dll )<br />
!117. PPC PROTECT ver 1.1 ( 2006 )  Alexey Gorchakov   www.ppc-protect.com<br />
118. Inno Setup Uninstaller &#8211; Borland Delphi<br />
119. Armadillo v2.5x &#8211; v2.6x &#8211;  www.siliconrealms.com<br />
120. DotFix NiceProtect v1.2  by GPcH Soft ( 2006 ) &#8211; www.niceprotect.com<br />
121. CreateInstall v4.x Gentee ( 2004 &#8211; 2008 ) &#8211; www.createinstall.com ( free/light/full)<br />
122. Gentee Programming Language ?2004-2006  www.gentee.com<br />
123. RLPack v.1.11 BasicEdition ( uses aPLib 0.42 ) http://ap0x.jezgra.net<br />
124. ReversingLabsProtector 0.7.4beta  http://ap0x.headcoders.net<br />
125. Install Creator Pro ver.2.0 ( 2003 )  &#8211; www.clickteam.com<br />
126. PowerBasic /CC 3.0x/CC 4.0/Win 7.0x/Win 8.0x &#8211;  www.powerbasic.com<br />
127. WinUHA ver.2.0  Sfx Archive &#8211; www.winuha.com  ( UPX )<br />
128. ZipGenius 6.0.x  Sfx Archive &#8211; www.zipgenius.it ( Borland Delphi )<br />
129. PEbundle ver.3.20 ( 2003 ) Jeremy Collake  &#8211; www.bitsum.com /<br />
/ Alloy Executable Compressor v.4.x- Copyright ?2000-2006 PGWARE &#8211; www.pgware.com<br />
130. Lazy Assembler  Version 0.53 (26 Sep 2006) Freeware (c) 2000-2006 Stepan Polovnikov<br />
131. nPack v1.1.300 (aPlib ) by NEOx ( 2006 )  www.uinc.ru<br />
132. Installer &#8211; Setup Factory 6.0 &#8211; 7.0  Indigo Rose Corporation ( 2006 ) MS V C++ 6.0<br />
133. dePack by deNULL &#8211; www.ooooQ.cn<br />
134. Goat&#8217;s PE Mutilator v.1.6 ( 2005 ) &#8211; www.geocities.com/killereaglesoftware<br />
135. RLPack v.1.14-1.18 BasicEdition ( uses aPLib 0.43 / LZMA 4.30  ) http://ap0x.jezgra.net<br />
136. VBOWatch protector v2.0  Copyright [c] 2006 MoonLight &#8211; www.ooooQ.cn<br />
137. Generic check : build like &#8211; Private exe Protector v2.0 &#8211; www.setisoft.com<br />
138. Easy Code v.1.0x ( GUI for assembler ) Ramon Sala &#8211; www.easycoder.org<br />
139. Mole Box 2.6.1  by Teggo. &#8211; www.molebox.com<br />
140. SLVcOdeProtector v.1.12 by SLV  &#8211; www.ooooQ.cn<br />
141. Exewrap MFC Application v.1.0 ( 2003 )<br />
142. Microsoft Visual C++ 8 compiler ( 2006 )<br />
143. RosAsm -V2.039c &#8211; http://betov.free.fr ( effectiveness 80 % )<br />
144. Software Compress ver. 1.4 Lite &#8211; www.bgsopt.com<br />
145. Intel (R) C++ Compiler<br />
146. FreePascal ver : FPC 1 &#8211; 2 Win32 -&gt; (Berczi Gabor, Pierre Muller &amp; Peter Vreman)<br />
147. Open WATCOM C/C++32 Portions Copyright (c) Sybase 1988-2002<br />
148. File2Pack SFX v.2.0 2006 (F2P Self Extractor ) SHOW PASSWORD! &#8211; www.mental9production.com ( MS VB5/6 )<br />
149. PV Logiciels dotNet Protector 4.0 2003-2005   http://dotnetprotector.pvlog.com<br />
150. ReflexiveArcade Game wrapped file   ( *.RWG )<br />
151. DAStub Dragon Armor (BamBam0.0.4.1) from Orient 2006 www.ooooQ.cn<br />
152. Akala EXE Lock ver.3.20 www.zero2000.com (Aspack v2.12 -&gt; Alexey Solodovnikov) &#8211; PASSWORD DECODER(N) OR HOW TO REMOVE PASSWORD<br />
153. BeRoEXEPacker &#8211; Version 1.00 &#8211; Copyright (C) 2006, Benjamin BeRo Rosseaux  ( Exe/DLL )<br />
154. EXE Password Protector v.1.1  (MSV C++ v7) &#8211; www.eltima.com/products/exe-password &#8211; INFO HOW TO REMOVE PASSWORD<br />
155. AGInstaller 1.9.12 ( UPX pack ) Copyright (c) 2001-2006 Agentix Software  &#8211; www.aginstaller.com<br />
156. CreateInstall v2003.3.5  www.createinstall.com/www.gentee.com ( EP check &amp; OVL )<br />
157. Protection PLUS &#8211; Instant plus (software key) 2.0.98.0 (2005) &#8211; www.softwarekey.com  Concept Software<br />
158. Wise Installation System! std/pro 9.02 (c) Wise Solutions Inc. &#8211; www.wise.com<br />
159. Wise Installation System! ver. ?.? (c) Wise Solutions Inc. &#8211; www.wise.com<br />
160. Wise Uninstaller Wizard (sec3)  &#8211; www.wise.com &#8211; MS Visual C++ ver.6<br />
161. m9P Editor Plus v.1.0.300 Distributable Executable Rich Text &#8211; DERT?X ﹎ental9Production, 2005 &#8211;  www.mental9Production.com &#8211; INFO HOW TO REMOVE PASSWORD<br />
162. Nullsoft uninstaller &#8211; www.nullsoft.com &#8211; ( UPX packed )<br />
163. Nullsoft uninstaller &#8211; www.nullsoft.com<br />
164. Softwrap (XTREAMLOK) ver. 1.x~3.x &#8211; www.softwrap.com ( exe/dll )<br />
165. RLPack v.1.14-16 Full Edition &#8211; False signatures unichecker<br />
166. RLPack v.1.14-16 Full Edition ( uses aPLib 0.43 / LZMA 4.3x  ) http://ap0x.jezgra.net<br />
167. Salfeld Computer EXE Password  2004 v 7.114.0.0 trial &#8211; www.salfeld.com ( Borland Delphi )<br />
168. Wise for Windows Installer pro 4.21 ( CAB )  &#8211; www.wise.com<br />
169. Tarma Installer ver. 2.99.xx (2005)  Tarma Software Research Pty Ltd. &#8211; www.tarma.com ( MS Visual C++ )<br />
170. NTkrnl Secure Suite v.01 packer or protector &#8211; www.ntkrnl.com ( exe )<br />
171. NTkrnl Secure Suite v.01 packer or protector &#8211; www.ntkrnl.com ( dll )<br />
172. [dUP2 -&gt; diablo2oo2]  v.2.1x patchengine ( patch ) &#8211; Mircosoft MacroAssembler  &#8211; http://diablo2oo2.cjb.net<br />
173. [dUP2 -&gt; diablo2oo2]  v.2.1x patchengine ( loader installer ) &#8211; Mircosoft MacroAssembler  &#8211; http://diablo2oo2.cjb.net<br />
174. PE password encryptor 31-01-2000 by SMT ( asm ) &#8211; [ OEP finder included ]<br />
175. WinUDA 0.271 sfx ( 2004 ) by Dwing  http://dwing.51.net<br />
176. kkrunchy 0.1x &gt;&gt; radical exe packer &#8211; www.farbrausch.de/~fg/kkrunchy OR www.farb-rausch.com<br />
177. kkrunchy 0.23 alpha 2 &gt;&gt; radical exe packer (c) f. giesen 2003-2005  &#8211; www.farbrausch.de/~fg/kkrunchy<br />
178. CyberInstaller Suite 2006 1.1 &#8211; SilverCyberTech 2003-2007<br />
179. Eurora3D &#8211; free installator &#8211; www.extramedia.co.yu/eurora3d  ( ASM )<br />
180. Microsoft Visual C++ ver. 7.1 [DEBUG] exe<br />
181. Fucking Fake File 1.0 by wspomagacz 2005.11( EXE Binder exe,jpg hidden inside] )<br />
182. Anskya Polymorphic Packer V 1.3 Code By Anskya<br />
183. Self-Extracting Archive Utility (SEAU) ver. 15.0  2006 ( Aspack v2.12 -&gt; Alexey Solodovnikov ) &#8211; http://gammadyne.com<br />
184. PE-Pack v 1.0 (c) 1998 by ANAKiN<br />
185. PKLITE32(tm) &#8211; Version 1.1 02-15-1999 ( exe )<br />
186. PKLITE32(tm) &#8211; Version 1.1 02-15-1999 ( DLL )<br />
187. EncryptPE V2.2006.10.25 China Cracking Group &#8211; www.encryptpe.com<br />
188. CC386 Version 3.28.1.6 Copyright (C) (GPL)  LADSoft 1994-2006<br />
189. PC Guard for Win32 V5.01  &#8211;  www.sofpro.com<br />
190. JDPack ver 1.01 ( 2005 ) &#8211; www.tlzj18.com ???<br />
191. Netopsystems AG INSTALLER FEAD(R) SFX (MS C++)  &#8211; www.netopsystems.com ( packed UPX &amp; not packed )<br />
192. Borland C++  1995~1998  &#8211; www.borland.com<br />
193. eXpressor PE Packer v1.5.0.1  &#8211; www.cgsoftlabs.ro<br />
194. Excelsior Installer v1.0 2003-2007 ( MS Visual C++ 6.0 ) &#8211; www.excelsior-usa.com<br />
195. tElock v0.98 Freeware PE-Compressor/Encryptor (c) 2000-2001 by tE!<br />
196. UPX Lock v1.02  (2007.02) &#8211; www.team-x.ru<br />
197. softSENTRY 3.00  1999 &#8211; 20/20 Software Inc. www.twenty.com ( site closed )<br />
198. DxPack ver 0.86  ( 2001.06 )<br />
199. Neolite 2.0 -&gt; Neoworx Inc. ( 1999.03.20 ) &#8211; www.neoworx.com  ( site closed )<br />
200. ZipWorx SecureEXE v3.0 (2004-2007) www.zipworx.com (Neolite packed)<br />
201. [ PE-DIY Tools V1.10 2004 ] by A.Young (PoJieYong) &#8211; www.w-yong.com  ( how to unprotect,oep info )<br />
!202. aUS v0.5 beta ( upx scrambler 2005.08 ) &#8211; http://ap0x.headcoders.net ( bad link? )<br />
203. EXE protector 2.01a  Eyhab Hillail ( 1998-2003 )- http://oxygen72.tripod.com ( how unprotect pass )<br />
204. 32Lite 0.03a -&gt; Oleg Prokhorov   www.????<br />
205. aPackage SFX v.1.14 2001-2002 Joergen Ibsen [32Lite v0.03a packed]<br />
206. NTPacker V2.1 by ErazerZ (2005.12) ErazerZ@gmail.com ( zPlib / XOR / aPlib+xor )<br />
207. WinHKI v1.77 SFX 2000-2007 by Hanspeter Imp ( hki archive only ) www.winhki.com (packed PEcompact ver.2.7x)<br />
208. nBinder 5.1.0 ( 24.03.2007 MSV C++ 8.0 ) NKProds Software &#8211;  www.nkprods.com<br />
.209. (Basic check) : Securom 7.1 -&gt; Sony DADC  &#8211; www.securom.com<br />
210. Cexe Executable Compressor v1.0b Copyright 1999, Tinyware, Inc. &#8211; www.tinyware.com by Scott Ludwig<br />
211. ASprotect 2.3 SKE ( www.aspack.com/asprotect.htm ) 25%<br />
212. Easypano Virtual Tour player ( MSV C++ )  &#8211; www.easypano.com<br />
213. PeX v0.99  bart/CrackPl (2000) (APLib 0.26 by J.Ibsen)  &#8211; longdiy.myrice.com<br />
214. YZPack v.2.0b.aplib (c) UsAr ( 2007.03 )<br />
215. YZPack v.1.1 LZMA (c) UsAr ( 2006.08 )<br />
216. YZPack v.1.2 aplib/LZMA (c) UsAr ( 2007.03 )<br />
217. ExeStealth V2.72 (Share.ver) &#8211;   www.webtoolmaster.com<br />
218. Generic check : ExeStealth V?.? (share.ver) &#8211;   www.webtoolmaster.com<br />
219. ExeStealth V2.x (Regg.ver) &#8211;   www.webtoolmaster.com<br />
220. nsPack ver.1.x &#8211; x.x by North Star  &#8211;  www.nsdsn.com<br />
221. Microsoft Visual C++ 6 DLL<br />
222. exe32pack 1.42  Copyright 1999-2004 www.SteelBytes.com<br />
223. Protect Exe 0.4 Beta ( PROEX ) 2002 &#8211; www.dpaehl.de.cx ( UPX packed )<br />
224. SexyPacker v.1.0.1.0 ( c ) 2001 &#8211; www.smalleranimals.com ( SFX ) MSV C++ 5.0<br />
225. ID Executable Password 1.2 (c) 2005 Fastlink2 Build: 08/08/2005 &#8211; www.idsecuritysuite.com &#8211; !SHOW PASSWORD!<br />
226. ID Application Protector v.1.2 Unreg (c) 2005 Fastlink2 &#8211; www.idsecuritysuite.com ( OEP info ,how to clear TRIAL)<br />
227. Pelles C for Windows v2.xx &#8211; 4.50 ExE ( 1999-2006 ) &#8211; www.smorgasbordet.com/pellesc<br />
228. Wise for Windows Installer pro ?.?? ( CAB in section 4 ) MS C++  &#8211; www.wise.com<br />
229. WinUtilities 5.2 EXE Protector 1.0 ( 2002-2007 ) YL Computing Inc. &#8211; www.ylcomputing.com &#8211;  ( Info how Pass remove/unprotect )<br />
230.  [section protection] VMProtect v.1.25 &#8211; 1.x (demo) 2003-2006 PolyTech &#8211; www.polytech.ural.ru<br />
231. REALbasic 2007 R2 Standard Edition ( 1997-2007 REAL Software ) &#8211; www.realbasic.com ( exe only )<br />
232. UPX 3.0 -&gt; Markus &amp; Laszlo ver. [ 3.00 ] &lt;- info from file. ( sign for DEV C++ compiler )<br />
233. Microsoft Visual C++ ver. 7.1 EXE/DLL  (3 bytes sign &#8211; easy to false)<br />
234. Beria v0.07 public WIP ( 2005 ) &#8211; symbiont ( aPlib )<br />
235. NoodleCrypt version 2 by NoodleSpa ( 2000.08 )<br />
236. VPacker v0.02.10 by tt.t (exe only 2006.04 aPlib)<br />
237. Private exe Protector v.2.00-2.15 ( 18.04.2007 ) www.setisoft.com<br />
238. Free Pascal Compiler v.2.1.4 i386 GUI APP ( 11.05.2007 ) Berczi Gabor &#8211; www.freepascal.org<br />
239. Free Pascal Compiler v.2.1.4 i386 CON APP ( 11.05.2007 ) Berczi Gabor &#8211; www.freepascal.org<br />
240. Free Pascal Compiler v.2.1.4 i386 DLL APP ( 11.05.2007 ) Berczi Gabor &#8211; www.freepascal.org<br />
241. Installshield v.12 (MSV C++ )  www.installshield.com / www.macrovision.com<br />
242. generic check2 : InstallShield v.12-14 2008 ( MS Visual C++) www.installshield.com / www.macrovision.com<br />
243. FASM ( 1.3x -1.67 ) 2004-2007 http://flatassembler.net &#8211; Tomasz Grysztar<br />
244. Thinstall VS 3.0.x  -&gt; Jitit Software  &#8211; www.thinstall.com<br />
245. Astrum InstallWizard v2.24.20 ( 1999-2006 ) &#8211; www.thraexsoftware.com ( MS Visual C++ )<br />
246. WinZip SelfExtractor 3.0 ( MSV C++ v7 ) 1996-2006 WinZip Int. LCC &#8211; www.winzip.com<br />
247. Wise Instalation Express v7.0 2006 (SFX CAB) MSV C++ &#8211; wise.com / ALTIRIS<br />
248. VisageSoft Installer ? WISE for Win/.msi ( MSCF CAB ) Borland C++ &#8211; www.visagesoft.com</p>
<p>249. ST Protector v1.5 SE ( 2006 ) &#8211; Silent Software &#8211; www. ???<br />
250. (exe) Visual Protect v2.5.7 ( 2000.12  www.visagesoft.com<br />
251. (dll) Visual Protect v2.5.7 ( 2000.12  www.visagesoft.com<br />
252. eXpressor PE Packer v1.5.0.1 (MODE: Protection) &#8211; www.cgsoftlabs.ro<br />
253. The Enigma Protector 1.31 unreg (2007.06.15) &#8211; Vladimir Sukhov &#8211; www.enigmaprotector.com ( exe/dll )<br />
254. generic check: (exe) Visual Protect ( 2000? )  www.visagesoft.com<br />
255. RCryptor 1.6d by Vaska ( 2007.01 ) only exe file protector &#8211; ( OEP info )<br />
256. Polymorph Crypter,Beta Morphnah (c) puccxak.com ( 2007.05 ) &#8211; ( OEP info )<br />
257. Pohernah v1.0.3 puccxak.com ( 2007.03 )<br />
258. QIP[Crypt] ( 2007.06 ) Borland Delphi Crypter<br />
259. SimbiOZ (RUS)  ! Rootkit exe hider ! ( OEP info &#8211; for C++/Delphi )<br />
260. AsdPack2 ( EP overflow exe &#8211; Delphi or C++ detector )  [ detection 75% ]<br />
261. QSetup Instalation Suite 8.5.0.4 &#8211; 26.05.2007 &#8211; www.pantaray.com<br />
262. Perplex PE-protector v1.01devel  2002-2003 by [tc] GiveMe5/BliZZaRD<br />
263. Mole Box 2.6.4  by Teggo. &#8211; www.molebox.com<br />
264. !EP (exe pack) v1.4 (lite) final  &#8211; Team-X  ( 2007.04 ) www.team-x.ru , http://exetools.blog.com.cn<br />
265. DalKrypt 1.0 by DalKiT &#8211; www.dalkit.fr.st (26.10.2003) Anti-SI, Anti-Debug, Anti-Dump<br />
266. NackedPacker v1.0 by BigBoote ( 2004.01-2007.06? )- www.PEArmor.com<br />
267. WATCOM C/C++32 Run-Time system (c) Sybase Inc, 1988-2000<br />
268. MS Visual C++ v.5 DLL Method 1 ( MS VBasic kit library )   ACM*<br />
269. Open Source Code Crypter 1.0 by p0ke (9.06.2007) &#8211; www.swerat.com &#8211; http://unnamed.bot.nu ( Borland Delphi )<br />
270. Private Personal Packer (PPP) Version 1.0.2 (13.03.2007) &#8211; www.ConquestOfTroy.com  ACM*<br />
271. Wise for Windows Installer v.?.?? ( CAB in section 4 ) MS C++ 7.0<br />
272. Inteli check : unknown Installer &#8211; MSCF Cab file<br />
273. Armadillo x.x ~ 5.0  32bit  [exe -low protection only]<br />
274. Armadillo x.x ~ 5.0  32bit  [Dll-std protection]<br />
275. Inteli check : MASM assembler ( no signature )<br />
276. Inteli check : unknown ver. WATCOM C/C++32 (c) Sybase 1988-200?<br />
277. inteli check : Dev &#8211; ( MINGW 32 v ?.?.? ) &#8211; Bloodshed Software ( www.bloodshed.net )<br />
278. Borland Delphi 2006 ? &#8211; www.borland.com<br />
279. Borland C++ &#8211; ( DLL ) Copyright 1994/96 , 1999  Borland Intl.<br />
280. CRYPToCRACk&#8217;s PE Protector 0.9.3 (2007.01) Lukas Fleischer &#8211; cryptocrack.de<br />
281. Break-Into-Pattern, a.k.a BIP, v0.1 (2006.01) &#8211; http://n0name.exmuros.net http://undergroundkonnekt.net<br />
282. DotFix NiceProtect 2.5 (with internal packer) GPcH Soft &#8211; www.niceprotect.com<br />
283. DotFix NiceProtect 2.5 (Krypton sign) GPcH Soft &#8211; www.niceprotect.com<br />
284. DotFix NiceProtect 2.5 (SVKP 1.3x sign) GPcH Soft &#8211; www.niceprotect.com<br />
285. DotFix NiceProtect 2.5 (Visual C++ sign) GPcH Soft &#8211; www.niceprotect.com<br />
286. Borland Delphi ( Component ) xxxx &#8211; www.borland.com<br />
287. Microsoft Visual C++ ver. x.x DLL (5-8)<br />
288. Microsoft Visual C++ ver. 8.0 DLL ( 83 )  ACM*<br />
289. Microsoft Visual C++ ver. 7.xx DLL ( 83 )</p>
<p>290. Private exe Protector v.2.25 ( 28.06.2007 ) www.setisoft.com<br />
291. Microsoft Visual C++ ver. 9.0 exe ( E8 )<br />
292. Microsoft Visual C++ ver. 9.0 DLL ( 8B )<br />
293. PEiD Plugin -&gt; Exe Converter v.1.00 ( BobSoft )<br />
294. MarjinZ EXE-Scrambler SE ( MS Visual C++ 8.0 )<br />
295. Microsoft Visual C++ v7.10/8.0/9.0 DLL ( 8B )<br />
296. Borland VCL Component for .NET ( Borland Developer Studio 4 (c) 2006 v.10.0.2 )<br />
297. PDF2EXE v1.0 CoolPDF Software &#8211;  www.pdf2exe.com ( 2006.10 ) &#8211; PASSWORD DECODER <img src='http://www.h4ck.org.cn/wp-content/plugins/smilies-themer/Julianus/20x20-big_smile.png' alt=':-)' class='wp-smiley' /> <br />
298. RealBasic v.?.? ExE  &#8211; www.realbasic.com<br />
299. RealBasic v.?.? DLL  &#8211; www.realbasic.com<br />
300. Generic check &#8211; Aspack vx.x -&gt; Alexey Solodovnikov<br />
301. generic ckeck : FreePascal ver : FPC 1.x.x<br />
302. UPX -&gt; (exe) Markus &amp; Laszlo ver. 0.72 OBSOLETE VER. ( 12.05.1999 ) ACM*<br />
303. UPX -&gt; (dll) Markus &amp; Laszlo ver. 0.72 OBSOLETE VER. ( 12.05.1999 ) ACM*<br />
304. ScanTime UnDetectable by MarjinZ ( STUD RC4 1.0 ) Marjinz-Crypter.exe<br />
305. Free Pascal Compiler version 2.0.4 [2006/08/21] for i386 ACM*<br />
306. Active Basic v4.24.00 ?2006.04.08 (exe) Discoversoft  &#8211; www.activebasic.com ( Japan ) *ACM<br />
307. Aspack v2.0/2.001  -&gt; Alexey Solodovnikov &#8211; www.aspack.com<br />
308. Play Basic v.1.0x &#8211; 1.63 ( 2D game creator ) www.playbasic.com</p>
<p>309. (exe) UPX obsolete ver. 0.50 &#8211; 0.72 -&gt; Markus &amp; Laszlo<br />
310. ANDpakk2 v0.06 (Jul 18 2006) Dmitry “AND” Andreev &#8211; http://and.intercon.ru<br />
311. ANDpakk2 v0.18 (Jul 16 2007) 2006,2007 Dmitry “AND” Andreev  &#8211; http://and.intercon.ru<br />
312. PEiD-Bundle v1.03 by BoB (2007.03.30) &#8211; www.secretashell.com/BobSoft<br />
313. Exe Stealth Packer or Protector v.3.16   &#8211;  www.webtoolmaster.com (NTkrnl)<br />
314. 20to4 v2004.04.18 Copyright 2001-2004 20to4.net<br />
315. Borland C++ 1995 DLL    *ACM<br />
316. nBinder LIMITED v4.0 2006 &#8211; www.nkprod.ro  ( MSV C++ 8.0 )<br />
317. mkfpack llydd (aPlib) 28.05.2007<br />
318. KByS 0.28 beta EXE ( shoooo ) china 2006.05.23 *ACM<br />
319. KByS 0.28 beta DLL ( shoooo ) china 2006.05.23 *ACM<br />
320. Microsoft Visual C++ ver. 8.0 DEBUG / Visual Studio 2005 (FF) *ACM<br />
321. mPack &#8211; mario PACKer version 0.0.2 (c) DeltaAziz<br />
322. WinUDA 0.291 clasic sfx 2005 by Dwing  http://dwing.51.net<br />
323. Cryptic v2.1 &#8211; EXE Crypter Copyright [c] 2007.09.26 Tughack ( MS Visual Basic exe stub )<br />
324. aSm Protector v1.0 Copyright [c] 2007.09.29 AT4RE<br />
325. AverCryptor v.1.02beta by Sec|Null os1r1s ( 2007.08.23 ) &#8211; www.secnull.org<br />
326. Muckis Protector 2 coded 2007 by Mucki    *ACM<br />
327. Rewolf DLL packager v1.0 V.2007 http://rewolf.prv.pl    ( OEP info )<br />
328. x86 Virtualizer ReWolf ( VIII.2007 ) &#8211; http://rewolf.pl</p>
<p>329. BeRo Tiny Pascal Compiler ( EXE ) http://bero.0ok.de<br />
330. CDS SS V1.0 beta1 (c) CyberDoom [Team-X member] ( 2005.12.18 ) *ACM<br />
331. [dUP2 -&gt; diablo2oo2]  v.2.16 patchengine ( loader installer ) &#8211; Microsoft MacroAssembler  &#8211; http://diablo2oo2.cjb.net<br />
332. Borland C++ 2002 &amp; 2005 DLL &#8211; www.borland.com<br />
333. WinUpack 0.37-0.39 by Dwing  &#8212;  http://dwing.51.net (BE&amp;60 sign)<br />
334. Flash2X EXE Packager ver.2.1.0 2007 &#8211; http://flash2x.net/exepackager ( Borland Delphi ) &#8211; RIP HINTs<br />
335. D1S1G PEiD Plugin by D1N  ( 10-24-2007 ) PEiD Signature and PE Overlay Tool  ( only OVL protection )<br />
336. WinUtilities EXE Protect 2.1 &#8211; www.ylcomputing.com (MS C++ 6.0) ( how to pass remove )<br />
337. Hacker&#8217;s Patcher version 0.07 Veacheslav Patkov ( 2007.09.21 ) &#8211; http://patkov-site.narod.ru/eng.html<br />
338. Enigma Protector 1.35 (2007.10.12)- www.enigmaprotector.com ,Vladimir Sukhov<br />
339. FSG v1.33  F[ast] S[mall] G[ood]  &#8211; www.xtreeme.prv.pl  *ACM<br />
340. FishPE Shield v.1.1x Crypt by HellFish ( http://hellfish.ys168.com ) &#8211; sign NOT TESTED trojan<br />
341. Microsoft Visual C++ v4.2 DLL  *ACM</p>
<p>342. 32lite DLL [32Lite v0.03a]<br />
343. FishPE Shield v.2.0.x Crypt by HellFish ( http://hellfish.ys168.com )<br />
344. SmartE protection -&gt; Microsoft ( trial/CD check/&#8230;)<br />
345. Microsoft Visual Basic v6.0 DLL<br />
346. Dev-C++ Compiler v4 old &#8211; Bloodshed Software ( www.bloodshed.net )<br />
347. Dev-C++  DLL ( MINGW 32 v x.x.x )- Bloodshed Software ( www.bloodshed.net ) ASLsign<br />
348. PhrozenCrew PE Shrinker (c)1999 by Virogen  version 0.71 beta  06/27/99<br />
349. DarkCrypt v1.2 priv by DMX (2007.12.25)<br />
350. yoda&#8217;s Crypter 1.2 http://yodap.has.it ( 2001.01.14 )    *ACM<br />
351. yoda&#8217;s Crypter 1.1 http://yodap.has.it ( 2000.12.29 )    *ACM<br />
352. XPack : freeware packer (c)2007 JoKo, Version 0.98 02/18/2007 &#8211; www.soft-lab.de/joko/ExePack.htm<br />
353. XComp : freeware packer (c)2007 JoKo, Version 0.98 02/18/2007 &#8211; www.soft-lab.de/joko/ExePack.htm<br />
354. Microsoft Visual C++ ver. 8.0 DLL (83_II)<br />
355. VMProtect v.1.6x (demo) 2003-2008 PolyTech &#8211; www.vmprotect.ru<br />
356. SIS-Crypt ( 2005.10.29 )<br />
357. Microsoft Visual C++ ver. 3.x (3~4)<br />
358. ExeSax v.0.9.1 EXE encryptor ( CAVE Method only ) 2006.09.18<br />
359. Luck007 2.7 GUI (exe) by Luckliuliu@yahoo.com ( 2007.06.07 ) str( 60%)<br />
360. WinKrypt v1.0 Copyright ?1999 MrCrimson/[WkT!99]    *ACM<br />
361. HASP HL Protection V1.X -&gt; Aladdin &#8211; www.aladdin.co.il<br />
362. Setup Factory for Win Installer v.1.1.1017 (21.11.2007) www.IndigoRose.com<br />
363. PECRC ver.0.88chn<br />
364. Microsoft Visual C++ ver. x.x DLL (55-10b)<br />
365. (U/R) Private exe Protector v.2.5 ( 12.01.2008 ) www.setisoft.com<br />
366. PeSpin v1.32 (2008.03.09) by CyberBob &#8211; http://pespin.w.interia.pl<br />
367. Thunderbolt 0.02 deXep (2005.04.15)<br />
368. Hying&#8217;s Armor v0.765 &#8211; China Cracking Group (2000-2001) (no options)<br />
369. Hying&#8217;s Armor v0.765 &#8211; China Cracking Group (2000-2001) (option: VC6++ sign)<br />
370. Generic check : Hying&#8217;s Armor v0.765 &#8211; China Cracking Group (2000-2001)<br />
371. ZProtect v1.3.0.0 26.02.2008 (demo) 2006-2008 Lifeengines &#8211; www.zprotect.cn (exe/dll)<br />
372. Armadillo v1.xx &#8211; v2.xx or 2.51 &#8211; 3.xx DLL Stub -&gt; Silicon Realms Toolworks<br />
373. Obsidium v1.3.5.4 (exe/dll) &#8211; 2008.02.04 Obsidium Software &#8211; www.obsidium.de<br />
374. Obsidium v1.2.5.8 Obsidium Software &#8211; www.obsidium.de<br />
375. nPack v1.1.800.2008 / 2.0.100 by NEOx (03.03.2008) &#8211; www.uinc.ru    *ACM</p>
<p>376. eXpressor PE Packer v1.6.0.1 (08.03.2008) &#8211; www.cgsoftlabs.ro<br />
377. Smart Install Maker v5.0x www.sminstall.com  ( delphi stub )<br />
378. morph EXECryptor v.2.2.x-2.4.x (IAT)  ( www.strongbit.com )<br />
379. UPX-Scrambler Release Candidate 1.03 by ㎡nT畂L (2001.04.08) exe<br />
380. STL Packer 1.3 &#8211; By Stel128  *ACM<br />
381. tElock 0.99 &#8211; 1.0 private -&gt; tE!<br />
382. Borland Delphi DLL ( 2.0 &#8211; 3.0 )    *ACM 1992 &#8211; www.borland.com<br />
383. mPack &#8211; mario PACKer version 0.0.3 (c) DeltaAziz *ACM<br />
384. Themida/Winlicense v.1.9.x.x (compress) -&gt; Oreans Technologies &#8211; www.oreans.com<br />
385. MPRESS v0.77 &#8211; MATCODE comPRESSor for executables (C) 2007,2008, MATCODE Software &#8211; www.matcode.com<br />
386. MPRESS v0.75b &#8211; MATCODE comPRESSor for executables (C) 2007,2008, MATCODE Software &#8211; www.matcode.com</p>
<p>387. Microsoft Visual C++ v9.0 ( e8 ) www.microsoft.com<br />
388. ActiveMARK 5.x &#8211; 6.x -&gt; Trymedia Systems &#8211; www.trymedia.com    *ACM<br />
389. (E8) Microsoft Visual C++ 9.0 &#8211; Visual Studio 2008<br />
390. Microsoft Visual C# / Basic.NET / MS Visual Basic 2005/2008<br />
391. TTProtect 1.0 &#8211; 2007/2008  &#8211; www.ttprotect.com (.net/dll)<br />
392. TTProtect 1.0 &#8211; 2007/2008  &#8211; www.ttprotect.com (exe)<br />
393. MPRESS v1.05 &#8211; MATCODE comPRESSor for executables (C) 2007,2008, MATCODE Software &#8211; www.matcode.com<br />
394. MPRESS v1.07 &#8211; MATCODE comPRESSor for executables (C) 2007,2008, MATCODE Software &#8211; www.matcode.com<br />
395. EncryptPE V2.2008.6.18 China Cracking Group &#8211; www.encryptpe.com<br />
396. Empathy 2.1 Exe password  2007.08 (using : PE-Inject Engine 1.0 by M.Strechovsky ) ( pass decode max.12 char)<br />
397. Microsoft Visual Basic v4.0-6.0 DLL (5A)<br />
398. Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 (4xFF25)<br />
399. Borland C++ Copyright ( No Copyr. sign )<br />
400. !EPack 1.4 lite final &#8211; by 6aHguT / Team-X 2006.08<br />
401. Securom 7.3x.xxxx -&gt; Sony DADC  &#8211; www.securom.com<br />
402. Securom 7.xx.xxxx * -&gt; Sony DADC  &#8211; www.securom.com<br />
403. *Safedisc V4.50.000 -&gt; Macrovision Corporation</p>
<p>404. X-Crypter 2.0 by X-zero (Delphi stub) 2008.07 &#8211; WL-group.net<br />
405. AT4RE Protector v1.0 By Mouradpr    *ACM<br />
406. Russian_Cryptor_v1.0 by master3 (2007.05)<br />
407. Obsidium v1.3.6.3 &#8211; www.obsidium.de<br />
408. RLPack v.1.20.1 Full Edition stub (EXE- aPLib 0.43 / LZMA 4.3x  ) http://ap0x.jezgra.net    *ACM<br />
409. RLPack v.1.20.1 Full Edition stub (DLL- aPLib 0.43 / LZMA 4.3x  ) http://ap0x.jezgra.net<br />
410. Generic check : RLPack 1.20 with fake signature<br />
411. Flashback Protector v1.0 beta1/3 ( no fake sign ) build 2008.08.17  &#8211; http://www.team-x.ru/Fashback/Protector<br />
412. Flashback Protector v1.0 beta1/3 (with FAKE sign) build 2008.08.17 &#8211; http://www.team-x.ru/Fashback/Protector<br />
413. SecurePE  1.5 RC4 &#8211; www.deepzone.org?<br />
414. Morphnah Beta2 (c) puccxak.com ( 2007.05 )<br />
415. EXECryptor v2.1x (No protEP) *** -&gt; softcomplete.com<br />
416. Aspack Scrambler v0.2 KuNgBiM / [CCG] &#8211; 08.01.2008<br />
417. Cobol compiler (417) exe</p>
<p>418. WinAce / SFX Factory v2.x 32-bit (PEtite 2.x Stub)<br />
419. Armadillo 6.0x EXE 32bit  &#8211;  www.siliconrealms.com    *ACM<br />
420. Armadillo 6.x  DLL 32bit &#8211;  www.siliconrealms.com    *ACM<br />
421. InstallStation Installer v.1.0.5 &#8211; http://installstation.com<br />
422. fEaRz Packer v0.3 (Private-1) RC4 Encrypt ( Delphi )<br />
423. RDG packer v.0.x ( VB Crypter ) 2008.09    *ACM<br />
424. Macromedia Flash Player 8.0 (2005) &#8211;  www.macromedia.com    *ACM<br />
425. REAL Basic 2008 ( MS Visual C++ 8.0 stub ) www.realsoftware.com<br />
426. Themida &amp; WinLicense 2.0.x.0 &#8211; struct (Hide from PE scanners type II,III,IV,V)<br />
427. Lindersoft SetupBuilder Developer v6.7 (2008) &#8211; Lindersoft.com<br />
428. Clarion v.6.0 (1993-2006) &#8211; www.Softvelocity.com<br />
429. Advanced Installer v.6.x  2003-2008 by www.caphyon.com ( MSC++ ) .MSI only ovl<br />
430. Poly!Crypt v.2.8 (2007.03) by [BUNG]  &#8211; *structure lame detector ( 75% )<br />
431. Tarma?Installer v.4.5 www.tarma.com  &#8211; 1990-2008 Tarma Software Research Pty Ltd  ( MSC++ stub ) ver.fromfile<br />
432. The Enigma Protector 1.5x &#8211; 1.6.1 [1.52] (2008.08/12) &#8211; Vladimir Sukhov &#8211; www.enigmaprotector.com<br />
433. Themida &amp; WinLicense 2.0 &#8211; struct* (Hide from PE scanners typeI)<br />
434. Angel&#8217;s Crypteur v0.2 2008.10.25 (C++ stub) &#8211; www.idyliccoderz.fr.cr<br />
435. Fearz crypter 2.2.0 &#8211; by fEaRz ( Delphi stub )    *ACM<br />
436. Saddam crypter v2.0 By 4bo3tb ( 2008.09.25 ) Delphi stub    *ACM<br />
437. Hack Hound &#8211; HH Crypter 2.2 by Hydrargirum for www.hackhound.org ( 2008.11.02 Delphi stub )    *ACM<br />
438. InstallShield?2009 v15 Pro &#8211; www.installshield.com &#8211; Acresso Software Inc. (MSC++)<br />
439. Hack Hound &#8211; HH Crypter 1.0.4 (Mod.Huex) by Hydrargirum for www.hackhound.org ( 2008.08.08 Delphi stub )    *ACM<br />
440. TTProtect 1.0.5 &#8211; 2008.08.17 (max/obf) &#8211; www.ttprotect.com    *ACM<br />
441. TTProtect 1.0.5 &#8211; 2008.08.17 (std/max/net) &#8211; www.ttprotect.com    *ACM<br />
442. TTProtect 1.0.5 dll &#8211; 2008.08.17 (max/obf) &#8211; www.ttprotect.com    *ACM<br />
443. Secure Shade 1.8 by Kizar 02-07-2008 (C++ stub)<br />
444. skD Undetectabler 2.0 pro (Delphi stub) &#8211; (C) White Fire Crew 2006-2007 ( *unprotect)</p>
<p>445. Obsidium V1.3.0.0 &#8211; 1.3.5.2 Obsidium Software &#8211; www.obsidium.de (6s)    *ACM<br />
446. ZProtect v1.4.0.0 ( 18.10.2008 demo ) 2006-2008 Lifeengines &#8211; www.zprotect.cn (exe/dll)<br />
447. PureBasic 4.20 (05/23/2008) &#8211; www.purebasic.com   Fantaisie Software *ACM  exe<br />
448. PureBasic 4.20 (05/23/2008) &#8211; www.purebasic.com   Fantaisie Software *ACM  DLL<br />
449. Intel Chipset Device Software installer  v1.1.15.0 ( MSV C++ )<br />
450. N.C.P.H Packer v1.2 by HK2005 ( sign as Aspack 2.12 fake ) *ACM<br />
451. Securom 7.1 (and new release version detector) -&gt; Sony DADC  &#8211; www.securom.com<br />
452. ZProtect v1.4.3.2 (demo) 04.12.2008 &#8211; 2006-2008 Lifeengines &#8211; www.zprotect.cn (exe/dll)<br />
453. Obsidium V1.3.?.? &#8211; ?.?.?.? Obsidium Software &#8211; www.obsidium.de ( unknown ver. )<br />
454. IcebergLock 3.10.x.xx  &#8211; Iceberg Software Lab  &#8211; www.ibsoftlab.com    *ACM<br />
455. EncryptPE V2.2007.4.11 China Cracking Group &#8211; www.encryptpe.com    *ACM</p>
<p>456. Free Pascal Lazarus Project v0.9.26 beta 2008-10-05  &#8211; http://sourceforge.net/projects/lazarus<br />
457. DRPU Setup Creator v.2.0.1.5 ( C++ ) &#8211; www.setupcreator.com    *ACM<br />
458. ST Ultra Pack 2 v0.6s (2008.10.30) Created by Silent Software &amp; Silent Shield &#8211; www.ssoft.wz.cz    *ACM<br />
459. Ionic Wind Software Compiler *EXE (Aurora 1.0 / Emergence Basic v1.67 )  &#8211; www.ionicwind.com<br />
460. Ionic Wind Software Compiler *DLL (Aurora 1.0 / Emergence Basic v1.67 )  &#8211; www.ionicwind.com<br />
461. Armadillo ver.4.20 min. compress &#8211;  www.siliconrealms.com (exe)<br />
462. GoAsm.Exe Version 0.56.4m &#8211; Copyright Jeremy Gordon 2001/9 &#8211; www.GoDevTool.com (exe)<br />
463. Mew 10 packer v1.0 Coded by Northfox 2004.03.06 ( AVir : malicious packer ) &#8211; http://northfox.uw.hu    *ACM<br />
464. www.elefun-games.com GameWrapper ( MSV C++ 8.0 )  v.1.0.0.1<br />
465. RDG Tejon Crypter v0.4 ( MS VB 6.1 ) &#8211; www.rdgsoft.8k.com    *ACM<br />
466. NonstandarD &#8211; Microsoft Visual Basic 5.0 -6.x  www.microsoft.com<br />
467. DCrypt v.0.9b &#8211; drmist ( cryper )<br />
468. HipACryp &#8211; 0.0.1  Coded By Departure! ( 2008.11.08 ) &#8211; www.Cheesydoodle.com    *ACM<br />
469. Armadillo ver.4.xx min. compress &#8211; Generic Detector &#8211;  www.siliconrealms.com<br />
470. Hying&#8217;s PE-Armor v0.75 &#8211; www.ccg.org.cn</p>
<p>471. Setup Factory 8.0 &#8211; ( 06.12.2008 ) ( MSV C++ 8.0 ) www.indigorose.com<br />
472. Autoit v3.3.0.0  ?999-2008 Jonathan Bennett &amp; AutoIt Team ( 24.12.2008 ) &#8211; www.autoitscript.com/autoit3<br />
473. Steam Stub &#8211; www.valvesoftware.com &#8211; Steam is a digital distribution, digital rights management, multiplayer<br />
474. RoguePack v4.0 BETA 1 by The Rogue  ( C++ v6.0 stub / 21.11.2008 ) www.descargashack.com<br />
475. RDG Tejon Crypter v0.5 &#8211; 2009.01.22 ( MS VB 6.1 ) &#8211; www.rdgsoft.8k.com    *ACM<br />
476. McAfee Download Manager SelfExtractor v.2.x &#8211; 3.x ( MSVC++ 8.0 ) www.mcafee.com<br />
477. RDG Tejon Crypter v0.6 &#8211; 2009.02.01 ( MS VB 6.1 ) &#8211; www.rdgsoft.8k.com    *ACM<br />
478. Generic detector ( add fake sections ) &#8211; Flashback scrambler 1.3.1<br />
479. AZProtect 0&#215;0001 by AlexZ aka AZCRC (2006.05.27 ) azsoft@nm.ru    *ACM<br />
480. CryptExe v1.0 ( 07.12.2008 &#8211; Delphi v7 stub ) &#8211; http://pasotech.altervista.org<br />
481. S.Crypter ( 2008.07.12 &#8211; MS VBasic v6 stub + ovl )  EP Drunked    *ACM<br />
482. Gamehouse Installer v.1.0/1 ( MSV C++ v7 ) www.gamehouse.com<br />
483. Gamehouse Trial wrapper ( .garr ) www.gamehouse.com  (noTrial info)<br />
484. RAR SFX stub ( Borland C++ 1999 )<br />
485. Private exe Protector v.3.0.1 unr. ( 18.02.2009 ) &#8211; www.setisoft.com<br />
486. RDG Tejon Crypter v0.7 &#8211; 2009.03.11 ( MS VB 6.1 ) &#8211; http://rdgsoft.8k.com/Tejon.html    *ACM<br />
487. RDG Tejon Crypter v0.8 &#8211; 2009.03.16 ( MS VB 6.1 ) &#8211; http://rdgsoft.8k.com/Tejon.html    *ACM<br />
488. RDG Tejon Crypter v0.9 &#8211; 2009.03.29 ( MS VB 6.1 ) &#8211; http://rdgsoft.8k.com/Tejon.html    *ACM<br />
489. RDG PolyPack v.0.1 Beta / v.1.1 &#8211; www.RDGSoFT.8k.com    *ACM  &#8211; ver from file<br />
490. VMProtect 1.70.4 &#8211; 1.8 ( 2009.02/04 ) NoNS.opt. Detector &#8211; PolyTech &#8211; www.vmprotect.ru<br />
491. [dUP2 -&gt; diablo2oo2]  v.2.19 patchengine ( patch ) &#8211; MASM &#8211; http://diablo2oo2.cjb.net<br />
492. [ loader installer ] &#8211; diablo2oo2&#8242;s Universal Patcher [dUP] Version: 2.19 ( 27.03.2009 ) &#8211; http://diablo2oo2.cjb.net<br />
493. [ simple loader ] &#8211; diablo2oo2&#8242;s Universal Patcher [dUP] Version: 2.19 ( 27.03.2009 ) &#8211; http://diablo2oo2.cjb.net<br />
494. MoleBox Pro 2.3640 prod.ver 2.7.0  Teggo Software Ltd. &#8211; www.molebox.com<br />
495. Drony Application Protect v3.0 beta9 ( 22 Nov 2005 ) dronyx@gmail.com<br />
496. Gentee installer custom &#8211; www.gentee.com<br />
497. MPRESS v2.05 -&gt; [v2.05] &#8211; MATCODE comPRESSor for executables (C) 2007,2009, MATCODE Software &#8211; www.matcode.com<br />
498. Ghost Installer Studio  v.4.7 &#8211; www.ethalone.com &#8211; Copyright (C) 2008 Ethalone Solutions, Inc ( xor only &#8211; UPX &amp; not UPX-ed )<br />
499. Oberon Media Game Runner v.1.0.0.8  MS C++8.0 ( Extracts and runs the game setup ) &#8211; http://corp.oberon-media.com<br />
500. ZProtect v1.4.8.0 Demo ( 23 III 2009 ) &#8211; www.peguard.com &#8211; 2006-2009 Lifeengines &#8211; www.zprotect.cn (exe/dll)<br />
501. MEW exe-packer v0.1 beta (2004.02.11) alias &gt; Mew5 exe-coder 0.1 beta / ver.1.0  &#8211; http://Northfox.uw.hu    *ACM<br />
502. ExeDefender v1.0 by InternalBytes software (2009.05.04 open-source) &#8211; www.internalbytes.net<br />
503. EXECryptor v.2.3.8-2.4.1 noPack-noImp  ( www.strongbit.com )<br />
504. Digital Mars D Compiler v2.029 (c) 1999-2009 by Digital Mars &#8211; www.digitalmars.com ( exe )<br />
505. Virtual Pascal v2.1 ( 2004.10.18 ) Copyright (C) 1996-2000 www.vpascal.com-bad link<br />
506. ASProtect V2.X DLL -&gt; Alexey Solodovnikov<br />
507. StealthPE v2.2 &#8211; STE@LTh PE by Flashback/Team-X &#8211; 2008.05.19<br />
508. VMware ThinApp 4.0.2 &#8211; 20.02.2009 &#8211; Copyright 2006-2009 VMware, Inc. www.thinstal.com / www.vmware.com<br />
509. MPRESS v2.12 -&gt; [v2.12] &#8211; MATCODE comPRESSor for executables (C) 2007,2009.05.11, MATCODE Software &#8211; www.matcode.com<br />
510. WildTangent Game wrapper 2.2.0.xx &#8211;  www.wildtangent.com www.wildgames.com<br />
511. RealArcade Wrapper (.garr) www.realarcade.com<br />
512. GPScript Programming Language v5.0 &#8211; 2007.11.20 &#8211; Copyright(C) 2001 &#8211; 2003, GPcH Soft &#8211; www.dotfix.net<br />
513. QuickPack NT 0.1 alpha  07.09.2007 ( aPlib )<br />
514. NoobyProtect SE 1.5.8.0 (c) 2009 Nooby &#8211; www.safengine.com</p>
<p>_______________________________________________________________________</p>
<p>www.exeinfo.go.pl<br />
_______________________________________________________________________</p>
<p>2009.06.28 ( c ) A.S.L.<br />
<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2010/01/vmprotect-1-70-4-%e7%a0%b4%e8%a7%a3%e7%89%88/" title="VMProtect 1.70.4 破解版" rel="bookmark inlinks">VMProtect 1.70.4 破解版</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/12/uppp-v0-6-retail-patch-creater-by-ufo-pu55y/" title="uPPP.v0.6.Retail Patch Creater by UFO-pu55y" rel="bookmark inlinks">uPPP.v0.6.Retail Patch Creater by UFO-pu55y</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/01/pe-header-editor-v1-0/" title="PE头移位工具 v1.0" rel="bookmark inlinks">PE头移位工具 v1.0</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/02/explorersuite-13-12-09/" title="ExplorerSuite.13.12.09" rel="bookmark inlinks">ExplorerSuite.13.12.09</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/12/dup-2-21-beta-9/" title="dUP 2.21 BETA  9" rel="bookmark inlinks">dUP 2.21 BETA  9</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/05/winhex-16-0-sr-2-%e3%80%90share%e3%80%91/" title="WinHex 16.0 SR-2 【share】" rel="bookmark inlinks">WinHex 16.0 SR-2 【share】</a><span class="count">( 1 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/03/ultra-compare-7-0-sn/" title="Ultra Compare 7.0 序列号" rel="bookmark inlinks">Ultra Compare 7.0 序列号</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/03/ilspy-and-reflector/" title=".Net静态反编译工具 ILSpy and Reflector" rel="bookmark inlinks">.Net静态反编译工具 ILSpy and Reflector</a><span class="count">( 0 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2009/08/exeinfo-pe-ver-0-0-2-4-by-a-s-l-c-2006-03-2009-xx/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>yoda&#8217;s Protector 1.3 -&gt; Ashkbiz Danehkar 手脱笔记</title>
		<link>http://www.h4ck.org.cn/2009/08/yodas-protector-1-3-ashkbiz-danehkar-unpack/</link>
		<comments>http://www.h4ck.org.cn/2009/08/yodas-protector-1-3-ashkbiz-danehkar-unpack/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 05:24:50 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[脱壳『Unpack』]]></category>
		<category><![CDATA[Unpack]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=90</guid>
		<description><![CDATA[目标：Agama Web Buttons2.52

用od载入后忽略所有异常，对code段下F2断点，F9运行，注意观察堆栈窗口，直到出现Se handle]]></description>
			<content:encoded><![CDATA[<p>目标：Agama Web Buttons2.52</p>
<p>用od载入后忽略所有异常，对code段下F2断点，F9运行，注意观察堆栈窗口，直到出现Se handle<br />
<a href="http://a.imagehost.org/view/0202/1_64" target="_blank"><img src="http://a.imagehost.org/0202/1_64.png" border="0" alt="ImageHost.org" width="590" height="275" /></a><br />
<span id="more-90"></span><br />
跟入处理的数据，ctrl+g转到61390B</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">0061390B</span>     <span style="color: #0000ff;">55</span>                   <span style="color: #00007f; font-weight: bold;">push</span> <span style="color: #00007f;">ebp</span>  <span style="color: #666666; font-style: italic;">;F2断点</span>
<span style="color: #adadad; font-style: italic;">0061390C</span>     8BEC                 <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">ebp</span><span style="color: #339933;">,</span><span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">0061390E</span>     <span style="color: #0000ff;">57</span>                   <span style="color: #00007f; font-weight: bold;">push</span> <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">0061390F</span>     <span style="color: #0000ff;">36</span><span style="color: #339933;">:</span>8B45 <span style="color: #0000ff;">10</span>           <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span><span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">ss</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">+</span><span style="color: #0000ff;">10</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00613913</span>     3E<span style="color: #339933;">:</span>8BB8 C4000000     <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">edi</span><span style="color: #339933;">,</span><span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">ds</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #339933;">+</span>C4<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">0061391A</span>     3E<span style="color: #339933;">:</span>FF37              <span style="color: #00007f; font-weight: bold;">push</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">ds</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edi</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">0061391D</span>     33FF                 <span style="color: #00007f; font-weight: bold;">xor</span> <span style="color: #00007f;">edi</span><span style="color: #339933;">,</span><span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">0061391F</span>     <span style="color: #0000ff;">64</span><span style="color: #339933;">:</span>8F07              <span style="color: #00007f; font-weight: bold;">pop</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">fs</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">edi</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00613922</span>     3E<span style="color: #339933;">:</span><span style="color: #0000ff;">8380</span> C4000000 <span style="color: #0000ff;">08</span>  <span style="color: #00007f; font-weight: bold;">add</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">ds</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #339933;">+</span>C4<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span><span style="color: #0000ff;">8</span>
<span style="color: #adadad; font-style: italic;">0061392A</span>     3E<span style="color: #339933;">:</span>8BB8 A4000000     <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">edi</span><span style="color: #339933;">,</span><span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">ds</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #339933;">+</span>A4<span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">00613931</span>     C1C7 <span style="color: #0000ff;">07</span>              <span style="color: #00007f; font-weight: bold;">rol</span> <span style="color: #00007f;">edi</span><span style="color: #339933;">,</span><span style="color: #0000ff;">7</span>
<span style="color: #adadad; font-style: italic;">00613934</span>     3E<span style="color: #339933;">:</span>89B8 B8000000     <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">ds</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #339933;">+</span>B8<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span><span style="color: #00007f;">edi</span>                 <span style="color: #666666; font-style: italic;">; edi就是程序入口点</span>
<span style="color: #adadad; font-style: italic;">0061393B</span>     B8 <span style="color: #0000ff;">00000000</span>          <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span><span style="color: #0000ff;">0</span>
<span style="color: #adadad; font-style: italic;">00613940</span>     <span style="color: #0000ff;">5F</span>                   <span style="color: #00007f; font-weight: bold;">pop</span> <span style="color: #00007f;">edi</span>
<span style="color: #adadad; font-style: italic;">00613941</span>     C9                   <span style="color: #00007f; font-weight: bold;">leave</span>
<span style="color: #adadad; font-style: italic;">00613942</span>     C3                   <span style="color: #00007f; font-weight: bold;">retn</span></pre></div></div>

<p>下F2断点，shift+F9运行，中断后开始单步运行，注意寄存器窗口，标注的edi就是程序入口点，直接转到edi数值。F2下断。shift+F9运行，中断后即可用LordPe脱壳。</p>

<div class="wp_syntax"><div class="code"><pre class="asm" style="font-family:monospace;"><span style="color: #adadad; font-style: italic;">0052F814</span>     <span style="color: #0000ff;">55</span>                   <span style="color: #00007f; font-weight: bold;">push</span> <span style="color: #00007f;">ebp</span> <span style="color: #666666; font-style: italic;">;F2断点</span>
<span style="color: #adadad; font-style: italic;">0052F815</span>     8BEC                 <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">ebp</span><span style="color: #339933;">,</span><span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">0052F817</span>     83C4 E4              <span style="color: #00007f; font-weight: bold;">add</span> <span style="color: #00007f;">esp</span><span style="color: #339933;">,-</span>1C
<span style="color: #adadad; font-style: italic;">0052F81A</span>     33C0                 <span style="color: #00007f; font-weight: bold;">xor</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span><span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">0052F81C</span>     <span style="color: #0000ff;">8945</span> E4              <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">ss</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span>1C<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span><span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">0052F81F</span>     <span style="color: #0000ff;">8945</span> E8              <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">ss</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">18</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span><span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">0052F822</span>     <span style="color: #0000ff;">8945</span> EC              <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">ss</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">ebp</span><span style="color: #339933;">-</span><span style="color: #0000ff;">14</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span><span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">0052F825</span>     B8 FCF35200          <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span>Agama<span style="color: #339933;">.</span>0052F3FC
<span style="color: #adadad; font-style: italic;">0052F82A</span>     E8 E975EDFF          <span style="color: #00007f; font-weight: bold;">call</span> Agama<span style="color: #339933;">.</span>00406E18
<span style="color: #adadad; font-style: italic;">0052F82F</span>     33C0                 <span style="color: #00007f; font-weight: bold;">xor</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span><span style="color: #00007f;">eax</span>
<span style="color: #adadad; font-style: italic;">0052F831</span>     <span style="color: #0000ff;">55</span>                   <span style="color: #00007f; font-weight: bold;">push</span> <span style="color: #00007f;">ebp</span>
<span style="color: #adadad; font-style: italic;">0052F832</span>     <span style="color: #0000ff;">68</span> 31FB5200          <span style="color: #00007f; font-weight: bold;">push</span> Agama<span style="color: #339933;">.</span>0052FB31
<span style="color: #adadad; font-style: italic;">0052F837</span>     <span style="color: #0000ff;">64</span><span style="color: #339933;">:</span>FF30              <span style="color: #00007f; font-weight: bold;">push</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">fs</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span>
<span style="color: #adadad; font-style: italic;">0052F83A</span>     <span style="color: #0000ff;">64</span><span style="color: #339933;">:</span><span style="color: #0000ff;">8920</span>              <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">fs</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span><span style="color: #00007f;">eax</span><span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span><span style="color: #00007f;">esp</span>
<span style="color: #adadad; font-style: italic;">0052F83D</span>     B9 <span style="color: #0000ff;">34655300</span>          <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">ecx</span><span style="color: #339933;">,</span>Agama<span style="color: #339933;">.</span>00536534
<span style="color: #adadad; font-style: italic;">0052F842</span>     BA <span style="color: #0000ff;">30655300</span>          <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">edx</span><span style="color: #339933;">,</span>Agama<span style="color: #339933;">.</span>00536530
<span style="color: #adadad; font-style: italic;">0052F847</span>     B8 2C655300          <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span>Agama<span style="color: #339933;">.</span>0053652C
<span style="color: #adadad; font-style: italic;">0052F84C</span>     E8 EFEDFFFF          <span style="color: #00007f; font-weight: bold;">call</span> Agama<span style="color: #339933;">.</span>0052E640
<span style="color: #adadad; font-style: italic;">0052F851</span>     833D 2C655300 <span style="color: #0000ff;">10</span>     <span style="color: #00007f; font-weight: bold;">cmp</span> <span style="color: #000000; font-weight: bold;">dword</span> <span style="color: #000000; font-weight: bold;">ptr</span> <span style="color: #00007f;">ds</span><span style="color: #339933;">:</span><span style="color: #009900; font-weight: bold;">&#91;</span>53652C<span style="color: #009900; font-weight: bold;">&#93;</span><span style="color: #339933;">,</span><span style="color: #0000ff;">10</span>
<span style="color: #adadad; font-style: italic;">0052F858</span>     7C 0C                <span style="color: #00007f; font-weight: bold;">jl</span> <span style="color: #000000; font-weight: bold;">short</span> Agama<span style="color: #339933;">.</span>0052F866
<span style="color: #adadad; font-style: italic;">0052F85A</span>     813D <span style="color: #0000ff;">30655300</span> <span style="color: #0000ff;">240300</span>&amp;gt<span style="color: #666666; font-style: italic;">;cmp dword ptr ds:[536530],324</span>
<span style="color: #adadad; font-style: italic;">0052F864</span>     7D <span style="color: #0000ff;">0F</span>                <span style="color: #00007f; font-weight: bold;">jge</span> <span style="color: #000000; font-weight: bold;">short</span> Agama<span style="color: #339933;">.</span>0052F875
<span style="color: #adadad; font-style: italic;">0052F866</span>     B8 48FB5200          <span style="color: #00007f; font-weight: bold;">mov</span> <span style="color: #00007f;">eax</span><span style="color: #339933;">,</span>Agama<span style="color: #339933;">.</span>0052FB48                        <span style="color: #666666; font-style: italic;">; ASCII &quot;This software requires 16 bit colors adapter and 800x640 resolution as the minimu!&quot;</span></pre></div></div>

<p><a href="http://cid-16507ea1777422ae.skydrive.live.com/self.aspx/.Public/%e7%a0%b4%e8%a7%a3%e5%88%86%e6%9e%90/awbsetup.rar">猛击此处下载测试程序！</a><br />
<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2011/11/scylla-v0-5a-x64x86-imports-reconstruction/" title="Scylla v0.5a- x64/x86 Imports Reconstruction" rel="bookmark inlinks">Scylla v0.5a- x64/x86 Imports Reconstruction</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/07/unpack-64bit-exe-via-ida-debug-plugin/" title="IDA + Debug 插件 实现64Bit Exe脱壳" rel="bookmark inlinks">IDA + Debug 插件 实现64Bit Exe脱壳</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/04/imp64/" title="imp64" rel="bookmark inlinks">imp64</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/06/pecompact-2-x-jeremy-collake-overlay-unpack/" title="PECompact 2.x -> Jeremy Collake [Overlay] 脱壳” rel=”bookmark inlinks”>PECompact 2.x -> Jeremy Collake [Overlay] 脱壳</a><span class="count">( 2 )</span></li>
<li><a href="http://www.h4ck.org.cn/2011/07/ida-pe6-dll-unpack/" title="实战IDA PE+ DLL脱壳" rel="bookmark inlinks">实战IDA PE+ DLL脱壳</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/03/armadillo-v6-x-minimum-protection-unpack/" title="Armadillo V6.X Minimum Protection 【脱壳】" rel="bookmark inlinks">Armadillo V6.X Minimum Protection 【脱壳】</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2009/08/packer-unpack/" title="普通壳的脱壳方法和脱壳技巧【转载】" rel="bookmark inlinks">普通壳的脱壳方法和脱壳技巧【转载】</a><span class="count">( 0 )</span></li>
<li><a href="http://www.h4ck.org.cn/2010/03/asprotect-1-23-rc4-1-3-08-24-alexey-solodovnikov-stolen-code/" title="ASProtect 1.23 RC4 - 1.3.08.24 -> Alexey Solodovnikov 脱壳Stolen code 修复” rel=”bookmark inlinks”>ASProtect 1.23 RC4 &#8211; 1.3.08.24 -> Alexey Solodovnikov 脱壳Stolen code 修复</a><span class="count">( 0 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2009/08/yodas-protector-1-3-ashkbiz-danehkar-unpack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

