arm_open_mutexa.txt
来自「700个脱壳脚本, 可以放在在OD的ollyscript Plugin中.」· 文本 代码 · 共 43 行
TXT
43 行
/*
Armadillo script OpenMutexA
Exceptions c000001e
invalid or privileged instruction
*/
dbh
var pBuffer
var OpenMutexA
var VirtualProtect
gpa "OpenMutexA", "kernel32.dll"
mov OpenMutexA, $RESULT
bp OpenMutexA
run
//Breakpoint
bc OpenMutexA
mov pBuffer, esp
log pBuffer
add pBuffer, 0c
mov pBuffer, [pBuffer]
log [pBuffer]
exec
PUSHAD
push {pBuffer}
push 0
push 0
CALL kernel32.CreateMutexA
POPAD
jmp kernel32.OpenMutexA
ende
gpa "VirtualProtect", "kernel32.dll"
mov VirtualProtect, $RESULT
log VirtualProtect
bp VirtualProtect
run
bc VirtualProtect
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?