Introduction - If you have any usage issues, please Google them yourself
When I first came into contact with the reverse side, I may not know what the static shell is, and KANXUE suggested that I send the article to drive the learning atmosphere. So the article came out.
My article is just an IDA tutorial, just using IDC to remove the shell from the IDB file and fix the API symbol, to the procedure that can be analyzed, and not fix the shell PE file.
Also, I took off MSLRHv0.31 a. Relatively simple shell, suitable for beginners
Packet : 95302923ida.rar filelist
Patch3.idc
Decode.idc
GetSym.idc
IATPATCH.idc
IDA实例教程.doc
ollyGetSym.txt
Patch1.idc
Patch2.idc
CleanJunkCode.idc
Patch4.idc
patch5.idc
Patch6.idc