反调试反反编译反虚拟机
本帖最后由 云在天 于 2020-3-12 16:45 编辑In order to compress, just use UPX3.09 to packing and the function list is
[*]Anti-debugging
[*]Anti-Dumping
[*]Anti-VM
[*]Anti-Disassembly
It is easy...
If anyone can not solve it, I will release second version. It will show the process of which function is checking.
Success:
All flag is
like this
the idea and GUI from LordNoteworthy
反虚拟机还玩个几把 https://github.com/LordNoteworthy/al-khaser 和这个好像呀。。 我是实体机欸?
UPX3.09 脱壳麻烦 你这该反的都反了{:301_992:} 反反反反反.... 虚拟机别反啊老慌了 {:1_925:} 感觉代码都没改 ..sharpod 基本都处理了 只有一个 NtSetInformationThread_ThreadHideFromDebugger手动就过了 真机...解压到桌面出现三红,用x32dbg打开也是三红..... 没中文说明吗?看不懂,大神。 Win7 SP1-存在误杀?没运行任何一个与调试相关的东西。