securom 4.xx - 4.84.75+ (other executable) oep finder v1.1.txt

来自「700个脱壳脚本, 可以放在在OD的ollyscript Plugin中.」· 文本 代码 · 共 50 行

TXT
50
字号
/* SECUROM OEP SCRIPT (not main executable Version 1.1) By Nukacola This script is using the CreateEventA method to get the OEP of a Securom wrapped file it should only work with the other executables. For the main executable use my other script. You have to run your securom protected file one time in olly before using this script or it won't work correctly. If you have the plugin installed, which deleted the udd files from olly directory you have to run it each time before you want to use this script. I guess it's working with Securom from ??? up to 4.84.75  Exceptions: Check all Exceptions but not "Memory Access Violation" and add80000004 (SINGLE STEP),C0000005 (ACCESS VIOLATIONC000008F (FLOAT INEXACT RESULT)C0000094 (INTEGER DIVIDE BY ZERO).*/gpa "CreateEventA", "kernel32.dll"bp $RESULTrun // startrun // bp 1run // bp 2bc $RESULTrtrstifindop eip,#0f84#bp $RESULTrunbc $RESULTstististostostostostostostosticmt eip, "<- SECUROM OEP ->"Msg "Welcome to the SECUROM OEP >---< Set new origin here make a dump and don't forget to fix the imports"ret

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?