用事实说话,OD访谈:这明明是VMP,不知楼主哪里看出来无壳了,丢进OD一看开头:
明显加壳了!!!
[Asm] 纯文本查看 复制代码 01814F37 > 9C pushfd
01814F38 60 pushad
01814F39 880424 mov byte ptr ss:[esp],al
01814F3C 9C pushfd
01814F3D C74424 24 A4068>mov dword ptr ss:[esp+0x24],0x858706A4
01814F45 887424 04 mov byte ptr ss:[esp+0x4],dh
01814F49 FF3424 push dword ptr ss:[esp] ; kernel32.75B1336A
01814F4C C64424 04 EB mov byte ptr ss:[esp+0x4],0xEB
01814F51 55 push ebp
01814F52 C74424 28 1B8B2>mov dword ptr ss:[esp+0x28],0xDA2D8B1B
01814F5A 68 F6D0B2C3 push 0xC3B2D0F6
01814F5F 8D6424 2C lea esp,dword ptr ss:[esp+0x2C]
01814F63 E9 5A4B0000 jmp 西瓜视频.01819AC2
VMP,哎,我也只能敬而远之了,坐等楼下出现大佬解答! |