[声明]:纯属技术交流
[对象]:flyODBG
查壳 UPX 0.89.6 - 1.02 / 1.05 - 1.24 -> Markus & Laszlo
OD载入.flyODBG,也就是对flyODBG脱壳,
00581ED0 > 60 pushad
00581ED1 BE 00304F00 mov esi,flyODBG.004F3000
00581ED6 8DBE 00E0F0FF lea edi,dword ptr ds:[esi+FFF0E>
00581EDC 57 push edi
00581EDD 83CD FF or ebp,FFFFFFFF
00581EE0 EB 10 jmp short flyODBG.00581EF2
00581EE2 90 nop
00581EE3 90 nop
用Esp定律.走到00581ED1,在命令行中输入hr 12ffa4
然后F9
00582048 - E9 B3EFE7FF jmp flyODBG.00401000 //OEP
0058204D 0000 add byte ptr ds:[eax],al
0058204F 0068 20 add byte ptr ds:[eax+20],ch
00582052 58 pop eax
00582053 000421 add byte ptr ds:[ecx],al
00582056 58 pop eax
00582057 001B