穿透EXECryptor 2.2x 保护体系

【目     标】:自己写的一个小程序
【工     具】:OllyDbg v1.1(diy版) Process Explorer v9.25
【任     务】:穿透ExeCryptor 2.2x保护体系
【操作平台】:Windows xp sp2
【作     者】: LOVEBOOM[DFCG][FCG][CUG]
【相关链接】: 见附件
【简要说明】: 这东西困了我很久了,早就狠狠的玩它一把,外壳的保护保护体系和其它很多外壳相比确实强了不少、狠了不少,针对OD更是火上加油,使得很多用OD的朋友倍感不便,让OD不方便调试,并不表示我们没有好办法来对付它。今次,我们就来小小试身解除Execryptor的保护体系,让你的OD可以不脱壳也同样操作和分析加密保护的程序。今天yock问了,自己找了下,找到这东西,因此整理下,放出来和大家共享,也算是2005年的年终作品,祝大家有个开心的圣诞,2006活的更精彩!
【详细过程】:
我们先来看看ExeCryptor软件本身的说明。
ExeCryptor 原软件说明:
EXECryptor - is a powerful tool used for an application code protection from reverse engineering, analysis and modifications, based on a brand new metamorphing code tranformation technology, that allows to significantly increase software security. With EXECryptor the code block to protect is disassembling and becomes a subject of nondeterminate transformations, which destroys the visible logical code structure. After the code transformation it remains executable and working as it is supposed to but it cannot be neither analysed nor modificated. There is no concept of the code decryption with EXECryptor unlike the others. Protected code blocks are always in the executable state and they are executed as a transformed code. Code restoration becomes an NP-hard problem.
EXECryptor has the innovative very powerful antidebug, antitrace and import protection features. EXECryptor allows to work with the short registration keys of 12/16 characters long. It is based on new generation of HardKey algorithm - cryptographically strong ultrashort digital signature. Algorithm is based on NP-hard problem of finding solution of low degree equation system in Galua field. The algorithm has good resistance and allows to get digital signature 60bits long. In addition to advanced protection features EXECryptor allows to compress code and resources of your application.
后面还有一大堆就不全部copy下来了,跟过这个外壳的朋友也应该知道这个外壳的保护体系就非常强悍的,如果用ollydbg进行脱壳或分析将会出非常困难并且费时间的事。

全篇文章有图片在这里就不好贴上来,全文内容请参见:http://bbs.pediy.com/showthread.php?s=70f87c6c6003488ca89a56c00830baf8&threadid=19629(看雪论坛)

  • 1
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值