VS2019 generated DeBug version of the program to find the main function

Mark this:

He wrote a packer, the packer is to be compiled using VS2019, presentation time looking around the main function was dizzy, and rollovers, and record it.

x64dbg commissioning and operation to the following location after F9:

image.png

F8 to run at the following location:

image.png

F7 to enter the Call, there were two Call:

image.png

F7 into a second Call, jump to the following positions:

image.png

Continue to follow up, find the following location:

image.png

F7 follow-up, to reach the following locations :( arrow is the main function, the target program is a console program, but three consecutive push, features a Call does not appear, but the program ends really balance stack of three parameters -> add esp, c)

image.png

F7 follow:

image.png

F7 continue to write our own code where:

image.png

End


Guess you like

Origin blog.51cto.com/14317856/2409347