- UID
- 76514
注册时间2014-7-2
阅读权限40
最后登录1970-1-1
独步武林
TA的每日心情 | 无聊 2024-12-4 16:27 |
---|
签到天数: 644 天 [LV.9]以坛为家II
|
楼主 |
发表于 2020-3-2 20:10:04
|
显示全部楼层
本帖最后由 哥又回来了 于 2020-3-2 20:17 编辑
KEY.rar
(1.54 KB, 下载次数: 1)
测试文件。
2020-03-02 20:15:53:507: [8948][BAYMAX]: PYG.DLL ver: 3.0.1.1025 模块加载
2020-03-02 20:15:53:507: [8948][BAYMAX]: Process Attach:样本2\KEY.EXE
2020-03-02 20:15:53:531: [8948][BAYMAX]: Not Find Baymax IniFile
2020-03-02 20:15:53:532: [8948][BAYMAX]: Proc KEY.EXE Module KEY.EXE Name KEY.EXE
2020-03-02 20:15:53:533: [8948][BAYMAX]: Proc KEY.EXE Module KEY.EXE Name KEY.EXE
2020-03-02 20:15:53:533: [8948][BAYMAX]: 设置断点补丁条目
2020-03-02 20:15:53:533: [8948][BAYMAX]: 非 NS_TYPE_SETRVABREAK 类型 0
2020-03-02 20:15:53:533: [8948][BAYMAX]: 断点补丁地址 004011BE 补丁数据 KG:[V:2,R:1,B:0,T:1]:M,U,EDX,0
2020-03-02 20:15:53:533: [8948][BAYMAX]: 设置断点
2020-03-02 20:15:53:533: [8948][BAYMAX]: 解析异常断点数据成功 ThreadId: 7384
2020-03-02 20:15:53:533: [8948][BAYMAX]: 设置INT3断点
2020-03-02 20:15:53:533: [8948][BAYMAX]: 设置 0xCC 004011BE
2020-03-02 20:15:53:534: [8948][BAYMAX]: 设置INT3断点成功 004011BE
2020-03-02 20:15:53:534: [8948][BAYMAX]: 断点补丁地址 004011C9 补丁数据 KG:[V:2,R:1,B:0,T:1]:S,SN:\r\n
2020-03-02 20:15:53:534: [8948][BAYMAX]: 设置断点
2020-03-02 20:15:53:534: [8948][BAYMAX]: 解析异常断点数据成功 ThreadId: 7384
2020-03-02 20:15:53:534: [8948][BAYMAX]: 设置INT3断点
2020-03-02 20:15:53:534: [8948][BAYMAX]: 设置 0xCC 004011C9
2020-03-02 20:15:53:534: [8948][BAYMAX]: 设置INT3断点成功 004011C9
2020-03-02 20:15:53:534: [8948][BAYMAX]: 初始化完成 ...
2020-03-02 20:15:53:534: [8948][BAYMAX]: End StartHook()
2020-03-02 20:15:53:534: [8948][BAYMAX]: 补丁设置初始化完成,若有HOOK或下断点操作,将会在下方进行打印输出。
2020-03-02 20:15:56:018: [8948][BAYMAX]: Find BreakPointInt3 ThreadId: 7384 1 0 0
2020-03-02 20:15:56:018: [8948][BAYMAX]: PREV Mode 当前断点 004011BE Byte 68
2020-03-02 20:15:56:018: [8948][BAYMAX]: PREV 68
2020-03-02 20:15:56:019: [8948][BAYMAX]: 当前INT3断点 符合触发条件进行处理 004011BE
2020-03-02 20:15:56:019: [8948][BAYMAX]: NsFixThreadContext Type 4
2020-03-02 20:15:56:019: [8948][BAYMAX]: INT3断点永久模式 设置NextIp 计数减一: 0
2020-03-02 20:15:56:019: [8948][BAYMAX]: INT3断点 获取NEXT IP: 004011C3
2020-03-02 20:15:56:019: [8948][BAYMAX]: Error Type
2020-03-02 20:15:56:019: [8948][BAYMAX]: NEXT_IP 004011C3 BYTE 8D
2020-03-02 20:15:56:019: [8948][BAYMAX]: DealInt3Exception 004011BE
2020-03-02 20:15:56:019: [8948][BAYMAX]: ThreadId: 7384 DR0 00000000 DR1 00000000 DR2 00000000 DR3 00000000 DR7 00000000
2020-03-02 20:15:56:019: [8948][BAYMAX]: Find BreakPointInt3 ThreadId: 7384 0 1 0
2020-03-02 20:15:56:019: [8948][BAYMAX]: NEXT_IP Mode Break: 004011C3 恢复断点为 004011BE
2020-03-02 20:15:56:019: [8948][BAYMAX]: NEXT 8D PREV CC
2020-03-02 20:15:56:019: [8948][BAYMAX]: Error Type
2020-03-02 20:15:56:019: [8948][BAYMAX]: DealInt3Exception 004011C3
2020-03-02 20:15:56:019: [8948][BAYMAX]: ThreadId: 7384 DR0 00000000 DR1 00000000 DR2 00000000 DR3 00000000 DR7 00000000
2020-03-02 20:15:56:020: [8948][BAYMAX]: Find BreakPointInt3 ThreadId: 7384 1 0 0
2020-03-02 20:15:56:020: [8948][BAYMAX]: Error Type
2020-03-02 20:15:56:020: [8948][BAYMAX]: PREV Mode 当前断点 004011C9 Byte 50
2020-03-02 20:15:56:020: [8948][BAYMAX]: PREV 50
2020-03-02 20:15:56:020: [8948][BAYMAX]: 当前INT3断点 符合触发条件进行处理 004011C9
2020-03-02 20:15:56:020: [8948][BAYMAX]: NsFixThreadContext Type 4
2020-03-02 20:15:56:020: [8948][BAYMAX]: INT3断点永久模式 设置NextIp 计数减一: 0
2020-03-02 20:15:56:020: [8948][BAYMAX]: INT3断点 获取NEXT IP: 004011CA
2020-03-02 20:15:56:020: [8948][BAYMAX]: NEXT_IP 004011CA BYTE 6A
2020-03-02 20:15:56:020: [8948][BAYMAX]: DealInt3Exception 004011C9
2020-03-02 20:15:56:020: [8948][BAYMAX]: ThreadId: 7384 DR0 00000000 DR1 00000000 DR2 00000000 DR3 00000000 DR7 00000000
2020-03-02 20:15:56:020: [8948][BAYMAX]: Find BreakPointInt3 ThreadId: 7384 0 1 0
2020-03-02 20:15:56:020: [8948][BAYMAX]: Error Type
2020-03-02 20:15:56:020: [8948][BAYMAX]: NEXT_IP Mode Break: 004011CA 恢复断点为 004011C9
2020-03-02 20:15:56:020: [8948][BAYMAX]: NEXT 6A PREV CC
2020-03-02 20:15:56:020: [8948][BAYMAX]: DealInt3Exception 004011CA
2020-03-02 20:15:56:020: [8948][BAYMAX]: ThreadId: 7384 DR0 00000000 DR1 00000000 DR2 00000000 DR3 00000000 DR7 00000000
|
|