exe32pack 1.3x oep finder.txt
来自「700个脱壳脚本, 可以放在在OD的ollyscript Plugin中.」· 文本 代码 · 共 28 行
TXT
28 行
// EXE32Pack 1.3X oep
// by Mr.David
// www.chinadfcg.com
var addr1
dbh //隐藏调试器
gpa "IsDebuggerPresent","kernel32.dll"
mov addr1,$RESULT //捷径 API断点IsDebuggerPresent
bp addr1
run
bc addr1 //Clear break point //取消断点
rtu //Alt+F9
sto
find eip,#FFE0# //特征花指令 jmp eax
mov addr1,$RESULT
bp addr1
run
BC addr1
sto
cmt eip,"OEP1 Or Next Shell To Get,Please dumped it,Enjoy!"
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?