
离线
|
本帖最后由 yujunqiang 于 2021-12-9 16:53 编辑
关于 VBto Converter V2.89 逆向(目标为Armadillo 4.54保护)
VBto Converter是来自国外的一款简单实用,功能强大的VB源码转换工具,它是一款实用的编程小控件,可以将Microsoft Visual Basic 6.0 project(包括源代码)转换成MS VC++ MFC, VC++.NET (CLR), VBNET, C#, J#, Borland C++ Builder, Borland Delphi源文件。可以将MS Visual Basic 6.0窗体资源文件转换成MS VC++ 或 VBNET 项目,支持VS 2010, Delphi 2010、支持FileSystemObject、支持VB.Data (VB.NET, C#, C++Builder, Delphi)。
使用ArmaGeddon v2.2导出解壳程序,程序无法运行,需要人工修改:
Loading target:
VBto.exe
Process ID: 2168
EnumWindows: ArmaGeddon v2.2 for WinXP (32-bit final)
Processing target...
==========================================
Debug Blocker detected
child Process ID: 2788
child Thread ID: 22F0
==========================================
CopyMem2 detected
CopyMem2 completed
==========================================
No splices found.
==========================================
Dumping target...
Dump done!
Saved to: vb2.exe
==========================================
Rebuilding Imports...
Rebuilding Imports completed
Return code: 0
Now, you should test your target. Good luck :)
==========================================
IAT RVA: 00632124
IAT Size: 00000FF0
OEP VA: 004016F0
OEP RVA: 000016F0
OEP call return VA: 00FA00AD
Exit Process ID: 2168
使用 dillodie_v1.6解壳,程序成功解壳:
软件下载dillodie V1.6 http://down1.downxia.com/down/ha_dillodie_wzdbzd.rar
CreateProcess...
--> Filename: VBto.exe
--> Process ID: 00001B2C
Debugblocker detected...
Entering Child Process...
--> Process ID: 000019D0
New Thread created. ID: 00001AD8
New Thread created. ID: 000005E4
New Thread created. ID: 00001448
IAT Initialization hooked...
--> 0033CCB6
Rebuilding Import Table...
--> Thunk @ 00A32124 = IMAGEHLP.DLL!ImageNtHeader
--> Thunk @ 00A32128 = IMAGEHLP.DLL!ImageRvaToVa
.......
--> Thunk @ 00A3310C = OLEAUT32.DLL!Ordinal0000000B
--> Thunk @ 00A33110 = OLEAUT32.DLL!Ordinal00000008
Call OEP hooked...
--> 0034008C
--> 003400AB
New Thread created. ID: 00002348
OEP resolved to: 004016F0
CopyMemII detected...
--> Decrypting Codepage @ 00401000
--> Decrypting Codepage @ 00402000
.......
--> Decrypting Codepage @ 007A4000
--> Decrypting Codepage @ 007A5000
Scanning for potential Nanomites...
--> Analyzing Int3 @ 004012AE --> No Nanomites Used...
Aborting Nanomite Scan...
Resolving Nanomites...
Dumping PE Sections...
Done. I did all of this in 10 seconds!
程序完美解壳,可以运行,但程序测试转换VB6代码,保存转换时,弹出Trial Version试用版不能超过800行代码,
使用x32dbg调试程序,找到弹出对话框在62D594,使用NOP代替CALL,程序能够转换代码了。
检查转换后的代码,超过800的代码部分被截断,程序没有完美逆向。需要找到正式注册的汇编代码。期待高手指导。
程序官方下载:VBto Converter http://www.vbto.net/SetupVBto.exe
解壳后的程序无法上传。
|
评分
-
参与人数 30 | HB +25 |
THX +12 |
收起
理由
|
一路走来不容易
| + 1 |
|
|
459121520
| + 1 |
|
|
WolfKing
| |
+ 1 |
[吾爱汇编论坛52HB.COM]-学破解防破解,知进攻懂防守! |
冷亦飞
| + 1 |
|
|
飞刀梦想
| |
+ 1 |
|
liugu0hai
| + 1 |
+ 1 |
[吾爱汇编论坛52HB.COM]-软件反汇编逆向分析,软件安全必不可少! |
crosssss
| + 1 |
|
[吾爱汇编论坛52HB.COM]-学破解防破解,知进攻懂防守! |
bnjzzheng
| |
+ 1 |
[吾爱汇编论坛52HB.COM]-学破解防破解,知进攻懂防守! |
ghostxu
| + 1 |
|
[吾爱汇编论坛52HB.COM]-学破解防破解,知进攻懂防守! |
nypht1228
| + 1 |
|
|
hackysh
| + 1 |
|
|
消逝的过去
| |
+ 1 |
[吾爱汇编论坛52HB.COM]-吃水不忘打井人,给个评分懂感恩! |
kalove
| + 1 |
|
|
zxjzzh
| |
+ 1 |
[吾爱汇编论坛52HB.COM]-学破解防破解,知进攻懂防守! |
阿桂哥
| + 1 |
|
[吾爱汇编论坛52HB.COM]-吃水不忘打井人,给个评分懂感恩! |
hetao8003200
| + 2 |
|
|
Tian_52HB
| |
+ 1 |
|
一寸灰
| + 1 |
|
[快捷评语]--吃水不忘打井人,给个评分懂感恩! |
87481067
| + 1 |
+ 1 |
[快捷评语]--你将受到所有人的崇拜! |
hnymsh
| + 1 |
|
|
w_xh73
| + 1 |
+ 1 |
[快捷评语]--积极评分,从我做起。感谢分享! |
jzat
| + 1 |
+ 1 |
|
mengzhisuoliu
| + 1 |
|
|
mxx852
| + 1 |
+ 1 |
|
1300841139
| + 1 |
|
|
lies
| + 1 |
|
|
king51999
| + 1 |
|
[快捷评语]--积极评分,从我做起。感谢分享! |
playboy
| + 1 |
|
|
boot
| + 1 |
+ 1 |
[通知]学破解论坛即将在近期更名为吾爱汇编论坛WWW.52HB.COM |
531814517
| + 1 |
|
|
查看全部评分
|