Check shell is ASPack2.12
first see pushad
a first reaction esp's law.
In esp at setting up the hardware execution breakpoints, then F9 to execute the next chart position
to continue down the road and found a widely spaced return address most of the OEP is
executed to unpack OEP
set OEP's RVA is 0x1000
dump IAT, for IAT file repair.
Cut out invalid pointer
dump Dump file to execute, view the execution results can be found to operate normally.
ASPack 2.12
Guess you like
Origin blog.csdn.net/AlexSmoker/article/details/104203324
Recommended
Ranking