用PEiD检查为EXECryptor 2.2.4 -> Strongbit/SoftComplete Development (h1)
忽略所有异常,OD载入:
00893001 > 60 pushad
00893002 E8 03000000 call 0089300A
00893007 - E9 EB045D45 jmp 45E634F7
0089300C 55 push ebp
0089300D C3 retn
0089300E E8 01000000 call 00893014
00893013 EB 5D jmp short 00893072
00893015 BB EDFFFFFF mov ebx, -13
0089301A 03DD add ebx, ebp
0089301C 81EB 00300200 sub ebx, 23000
00893022 83BD 22040000 0>cmp dword ptr [ebp+422], 0
00893029 899D 22040000 mov dword ptr [ebp+422], ebx
0089302F 0F85 65030000 jnz 0089339A
00893035 8D85 2E040000 lea eax, dword ptr [ebp+42E]
0089303B 50 push eax
0089303C FF95 4D0F0000 call dword ptr [ebp+F4D]
00893042 8985 26040000 mov dword ptr [ebp+426], eax
00893048 8BF8 mov edi, eax
0089304A 8D5D 5E lea ebx, dword ptr [ebp+5E]
0089304D 53 push ebx
0089304E 50 push eax
0089304F FF95 490F0000 call dword ptr [ebp+F49]
00893055 8985 4D050000 mov dword ptr [ebp+54D], eax
0089305B 8D5D 6B lea ebx, dword ptr [ebp+6B]
0089305E 53 push ebx
0089305F 57 push edi
00893060 FF95 490F0000 call dword ptr [ebp+F49]
00893066 8985 51050000 mov dword ptr [ebp+551], eax
0089306C 8D45 77 lea eax, dword ptr [ebp+77]
0089306F FFE0 jmp eax
在.reloc区段下断,F2,F9运行。在CODE区段下断F2,F9。
LordPE-->dump。打开ImportREC。
无法修复成功,高手看看能否处理?谢谢
[培训]科锐逆向工程师培训第53期2025年7月8日开班!