网上看到的一篇文章,有助于脱壳学习,就转载过来了,也没找到文章出处,不知如何标明了。
Microsoft Visual C++ 6.0
00496EB8 >/$
00496EB9
00496EBB
00496EBD
00496EC2
00496EC7
00496ECD
00496ECE
00496ED5
---------------------------------------------------------------------------------------
Microsoft Visual Basic 5.0 / 6.0
00401166
0040116C >
00401171 E8 F0FFFFFF
00401176 0000
00401178 0000
0040117A 0000
0040117C 3000
或省略第一行的JMP
00401FBC >
00401FC1 E8 EEFFFFFF
00401FC6 0000
00401FC8 0000
00401FCA 0000
00401FCC 3000
00401FCE 0000
----------------------------------------------------------------------
BC++
0040163C > $ /EB 10
0040163E
0040163F
00401640
00401641
00401642
00401643
00401644
00401645
00401646
00401647
00401648
00401649
0040164A . |98E04E00
0040164E > \A1 8BE04E00 MOV EAX,DWORD PTRDS:[4EE08B]
00401653 .
00401656 .
0040165B .
0040165C .
0040165E .
00401663 .
-----------------------------------------------------------------------------------------------
Borland Delphi 6.0 - 7.0
00509CB0 > $
00509CB1 .
00509CB3 .
00509CB6 .
00509CB7 .
00509CB8 .
00509CB9 .
00509CBB .
00509CBE .
00509CC3 .
-----------------------------------------------------------------------------------------------
易语言入口
00401000 >
00401005 50
00401006 E8 BB010000
0040100B 55
0040100C 8BEC
0040100E 81C4 F0FEFFFF add esp,-110
00401014 E9 83000000
00401019 6B72 6E 6C
0040101D 6E
也可能是这样的入口
Microsoft Visual C++ 6.0 [Overlay] E语言
00403831 >/$
00403832
00403834
00403836
0040383B
00403840
00403846
00403847
-------------------------------------------------------------------
MASM32 / TASM32入口
00401258 >/$
0040125A
0040125F
00401264
00401266
0040126B
0040126D
0040126F
00401275