arm_open_mutexa.txt

来自「700个脱壳脚本, 可以放在在OD的ollyscript Plugin中.」· 文本 代码 · 共 43 行

TXT
43
字号
/*
Armadillo script OpenMutexA
Exceptions c000001e
invalid or privileged instruction
*/

dbh

var pBuffer
var OpenMutexA
var VirtualProtect

gpa "OpenMutexA", "kernel32.dll" 
mov OpenMutexA, $RESULT
bp OpenMutexA
run


//Breakpoint
bc OpenMutexA
mov pBuffer, esp
log pBuffer
add pBuffer, 0c
mov pBuffer, [pBuffer]
log [pBuffer]

exec 
PUSHAD 
push {pBuffer}
push 0
push 0
CALL kernel32.CreateMutexA 
POPAD 
jmp kernel32.OpenMutexA 
ende 

gpa "VirtualProtect", "kernel32.dll" 
mov VirtualProtect, $RESULT
log VirtualProtect
bp VirtualProtect
run
bc VirtualProtect

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?