某国内大型网游公司反调试器附加研究

搞了一个晚上,天终于亮了,问题也解决了,VMP加检测DEBUG,再加代码DEBUG

看了部分记录就知道了。。。原来很简单。

 

想CE就CE,想OD就OD 爽,累了。。。闪

 

ThreadId:a8d8 ==Starting:
ThreadId:a8d8 ==Loading:
ThreadId:a8d8 ==LoadLibraryExW:'RPCRT4.dll',0x0,0x0,Address 0x76e30000:
ThreadId:a8d8 ==LoadLibraryExW:'rpcrt4.dll',0x0,0x0,Address 0x7dc10000:
ThreadId:a8d8 ==LoadLibraryExW:'C:/WINDOWS/system32/mswsock.dll',0x0,0x0,Address 0x7db70000:
ThreadId:a8d8 ==LoadLibraryExW:'hnetcfg.dll',0x0,0x0,Address 0x69660000:
ThreadId:a8d8 ==LoadLibraryExW:'C:/WINDOWS/System32/wshtcpip.dll',0x0,0x0,Address 0x71a40000:
ThreadId:a8d8 ==LoadLibraryExW:'WS2_32.dll',0x0,0x0,Address 0x71b60000:
ThreadId:a8d8 ==LoadLibraryExW:'kernel32.dll',0x0,0x0,Address 0x7d4f0000:
ThreadId:a8d8 ==ReMapFile://./SICE://./ASDF:
ThreadId:a8d8 ==ReMapFile://./SIWVID:SAME:
ThreadId:a8d8 ==ReMapFile://./NTICE:SAME:
ThreadId:a8d8 ==ReMapFile://./ICEEXT:SAME:
ThreadId:a8d8 ==ReMapFile://./SYSERBOOT:SAME:

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值