-
-
[旧帖] [求助]菜鸟问:邦忙看一下这段代码是怎么加密的 0.00雪花
-
发表于: 2007-11-23 09:34 2786
-
006E89F6 . 55 push ebp
006E89F7 . 68 2E8A6E00 push 006E8A2E
006E89FC . 64:FF30 push dword ptr fs:[eax]
006E89FF . 64:8920 mov dword ptr fs:[eax], esp
006E8A02 . 6A 01 push 1
006E8A04 . B1 01 mov cl, 1
006E8A06 . 8B15 18376D00 mov edx, dword ptr [6D3718] ; SyncBack.006D3764
006E8A0C . B8 B08A6E00 mov eax, 006E8AB0 ; {
006E8A11 . E8 3A6DFCFF call 006AF750
006E8A16 . 84C0 test al, al
006E8A18 . 74 0A je short 006E8A24
006E8A1A . 33C0 xor eax, eax
006E8A1C . 5A pop edx
006E8A1D . 59 pop ecx
006E8A1E . 59 pop ecx
006E8A1F . 64:8910 mov dword ptr fs:[eax], edx
006E8A22 . EB 7E jmp short 006E8AA2
006E8A24 > 33C0 xor eax, eax
006E8A26 . 5A pop edx
006E8A27 . 59 pop ecx
006E8A28 . 59 pop ecx
006E8A29 . 64:8910 mov dword ptr fs:[eax], edx
006E8A2C . EB 0A jmp short 006E8A38
006E8A2E .- E9 19C2D1FF jmp 00404C4C
006E8A33 . E8 E8C6D1FF call 00405120
006E8A38 > A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A3D . 8B00 mov eax, dword ptr [eax]
006E8A3F . E8 DC4ADDFF call 004BD520
006E8A44 . A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A49 . 8B00 mov eax, dword ptr [eax]
006E8A4B . 83C0 50 add eax, 50
006E8A4E . BA 088B6E00 mov edx, 006E8B08 ; syncbackse.chm
006E8A53 . E8 28CDD1FF call 00405780
006E8A58 . A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A5D . 8B00 mov eax, dword ptr [eax]
006E8A5F . BA 208B6E00 mov edx, 006E8B20 ; syncbackse
006E8A64 . E8 3745DDFF call 004BCFA0
006E8A69 . A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A6E . 8B00 mov eax, dword ptr [eax]
006E8A70 . C640 5B 00 mov byte ptr [eax+5B], 0
006E8A74 . A1 28E76A00 mov eax, dword ptr [6AE728]
006E8A79 . E8 7662FCFF call 006AECF4
006E8A7E . 8B0D EC396F00 mov ecx, dword ptr [6F39EC] ; SyncBack.006F2EE4
006E8A84 . A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A89 . 8B00 mov eax, dword ptr [eax]
006E8A8B . 8B15 18376D00 mov edx, dword ptr [6D3718] ; SyncBack.006D3764
006E8A91 . E8 A24ADDFF call 004BD538
006E8A96 . A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A9B . 8B00 mov eax, dword ptr [eax]
006E8A9D . E8 164BDDFF call 004BD5B8
006E8AA2 > 5F pop edi
006E8AA3 . 5E pop esi
006E8AA4 . 5B pop ebx
006E8AA5 E8 DACAD1FF call 00405584
006E8AAA . 0000 add byte ptr [eax], al
006E8AAC . 4C dec esp
006E8AAD . 0000 add byte ptr [eax], al
006E8AAF . 007B 00 add byte ptr [ebx], bh
006E8AB2 . 3000 xor byte ptr [eax], al
006E8AB4 . 37 aaa
006E8AB5 . 0032 add byte ptr [edx], dh
006E8AB7 . 0046 00 add byte ptr [esi], al
006E8ABA . 3800 cmp byte ptr [eax], al
006E8ABC . 3900 cmp dword ptr [eax], eax
006E8ABE . 46 inc esi
006E8ABF . 0045 00 add byte ptr [ebp], al
006E8AC2 . 2D 00390041 sub eax, 41003900
006E8AC7 . 0037 add byte ptr [edi], dh
006E8AC9 . 0045 00 add byte ptr [ebp], al
006E8ACC . 2D 00340044 sub eax, 44003400
006E8AD1 . 0031 add byte ptr [ecx], dh
006E8AD3 . 0042 00 add byte ptr [edx], al
006E8AD6 . 2D 00420035 sub eax, 35004200
006E8ADB . 0046 00 add byte ptr [esi], al
006E8ADE . 34 00 xor al, 0
006E8AE0 . 2D 00380036 sub eax, 36003800
006E8AE5 . 0042 00 add byte ptr [edx], al
006E8AE8 . 3900 cmp dword ptr [eax], eax
006E8AEA . 3800 cmp byte ptr [eax], al
006E8AEC . 41 inc ecx
006E8AED 00 db 00
006E8AEE . 3400 3800 410>unicode "48A1D2}",0
006E8AFE 00 db 00
006E8AFF 00 db 00
006E8B00 . FFFFFFFF dd FFFFFFFF
006E8B04 . 0E000000 dd 0000000E
006E8B08 . 73 79 6E 63 6>ascii "syncbackse.chm",0
006E8B17 00 db 00
006E8B18 . FFFFFFFF dd FFFFFFFF
006E8B1C . 0A000000 dd 0000000A
006E8B20 . 53 79 6E 63 4>ascii "SyncBackSE",0
006E89F7 . 68 2E8A6E00 push 006E8A2E
006E89FC . 64:FF30 push dword ptr fs:[eax]
006E89FF . 64:8920 mov dword ptr fs:[eax], esp
006E8A02 . 6A 01 push 1
006E8A04 . B1 01 mov cl, 1
006E8A06 . 8B15 18376D00 mov edx, dword ptr [6D3718] ; SyncBack.006D3764
006E8A0C . B8 B08A6E00 mov eax, 006E8AB0 ; {
006E8A11 . E8 3A6DFCFF call 006AF750
006E8A16 . 84C0 test al, al
006E8A18 . 74 0A je short 006E8A24
006E8A1A . 33C0 xor eax, eax
006E8A1C . 5A pop edx
006E8A1D . 59 pop ecx
006E8A1E . 59 pop ecx
006E8A1F . 64:8910 mov dword ptr fs:[eax], edx
006E8A22 . EB 7E jmp short 006E8AA2
006E8A24 > 33C0 xor eax, eax
006E8A26 . 5A pop edx
006E8A27 . 59 pop ecx
006E8A28 . 59 pop ecx
006E8A29 . 64:8910 mov dword ptr fs:[eax], edx
006E8A2C . EB 0A jmp short 006E8A38
006E8A2E .- E9 19C2D1FF jmp 00404C4C
006E8A33 . E8 E8C6D1FF call 00405120
006E8A38 > A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A3D . 8B00 mov eax, dword ptr [eax]
006E8A3F . E8 DC4ADDFF call 004BD520
006E8A44 . A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A49 . 8B00 mov eax, dword ptr [eax]
006E8A4B . 83C0 50 add eax, 50
006E8A4E . BA 088B6E00 mov edx, 006E8B08 ; syncbackse.chm
006E8A53 . E8 28CDD1FF call 00405780
006E8A58 . A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A5D . 8B00 mov eax, dword ptr [eax]
006E8A5F . BA 208B6E00 mov edx, 006E8B20 ; syncbackse
006E8A64 . E8 3745DDFF call 004BCFA0
006E8A69 . A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A6E . 8B00 mov eax, dword ptr [eax]
006E8A70 . C640 5B 00 mov byte ptr [eax+5B], 0
006E8A74 . A1 28E76A00 mov eax, dword ptr [6AE728]
006E8A79 . E8 7662FCFF call 006AECF4
006E8A7E . 8B0D EC396F00 mov ecx, dword ptr [6F39EC] ; SyncBack.006F2EE4
006E8A84 . A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A89 . 8B00 mov eax, dword ptr [eax]
006E8A8B . 8B15 18376D00 mov edx, dword ptr [6D3718] ; SyncBack.006D3764
006E8A91 . E8 A24ADDFF call 004BD538
006E8A96 . A1 C43E6F00 mov eax, dword ptr [6F3EC4]
006E8A9B . 8B00 mov eax, dword ptr [eax]
006E8A9D . E8 164BDDFF call 004BD5B8
006E8AA2 > 5F pop edi
006E8AA3 . 5E pop esi
006E8AA4 . 5B pop ebx
006E8AA5 E8 DACAD1FF call 00405584
006E8AAA . 0000 add byte ptr [eax], al
006E8AAC . 4C dec esp
006E8AAD . 0000 add byte ptr [eax], al
006E8AAF . 007B 00 add byte ptr [ebx], bh
006E8AB2 . 3000 xor byte ptr [eax], al
006E8AB4 . 37 aaa
006E8AB5 . 0032 add byte ptr [edx], dh
006E8AB7 . 0046 00 add byte ptr [esi], al
006E8ABA . 3800 cmp byte ptr [eax], al
006E8ABC . 3900 cmp dword ptr [eax], eax
006E8ABE . 46 inc esi
006E8ABF . 0045 00 add byte ptr [ebp], al
006E8AC2 . 2D 00390041 sub eax, 41003900
006E8AC7 . 0037 add byte ptr [edi], dh
006E8AC9 . 0045 00 add byte ptr [ebp], al
006E8ACC . 2D 00340044 sub eax, 44003400
006E8AD1 . 0031 add byte ptr [ecx], dh
006E8AD3 . 0042 00 add byte ptr [edx], al
006E8AD6 . 2D 00420035 sub eax, 35004200
006E8ADB . 0046 00 add byte ptr [esi], al
006E8ADE . 34 00 xor al, 0
006E8AE0 . 2D 00380036 sub eax, 36003800
006E8AE5 . 0042 00 add byte ptr [edx], al
006E8AE8 . 3900 cmp dword ptr [eax], eax
006E8AEA . 3800 cmp byte ptr [eax], al
006E8AEC . 41 inc ecx
006E8AED 00 db 00
006E8AEE . 3400 3800 410>unicode "48A1D2}",0
006E8AFE 00 db 00
006E8AFF 00 db 00
006E8B00 . FFFFFFFF dd FFFFFFFF
006E8B04 . 0E000000 dd 0000000E
006E8B08 . 73 79 6E 63 6>ascii "syncbackse.chm",0
006E8B17 00 db 00
006E8B18 . FFFFFFFF dd FFFFFFFF
006E8B1C . 0A000000 dd 0000000A
006E8B20 . 53 79 6E 63 4>ascii "SyncBackSE",0
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课
赞赏
赞赏
雪币:
留言: