700个脱壳脚本, 可以放在在OD的ollyscript Plugin中.

源代码在线查看: fsg 2.00 oep finder #4.txt

软件大小: 643 K
上传用户: peterzhang1982
关键词: ollyscript Plugin 700 脚本
下载地址: 免注册下载 普通下载 VIP

相关代码

				/*
				 *  FSG 2.0 OEP Finder v0.1
				 *  Author: TQN
				 *  OS    : WinXP or Win2K, OllyDbg v1.10, OllyScript v0.85
				 *  Date  : 2004-5-25
				 *  Config: None
				 */
				
				var addr
				var opcode
				
				start:
				    gpa "GetProcAddress","kernel32.dll"
				    bp  $RESULT
				    eob @@1
				    run
				
				@@1:
				    mov addr, [esp]
				    sub addr, 8
				    mov opcode, [addr]
				    and opcode, FFFF
				    cmp opcode, 63FF
				    je  @@2
				    eob @@1
				    run
				
				@@2:
				    bc  $RESULT
				    cmt addr,"A jump to OEP found, can make inline patching here!"
				    bp  addr
				    eob @@End
				    run
				
				@@End:
				    msg "Will jump to OEP"
				    bc  addr
				    sto
				    cmt eip,"OEP here. We can dump it now!"
				    ret
							

相关资源