upxshit.txt
来自「700个脱壳脚本, 可以放在在OD的ollyscript Plugin中.」· 文本 代码 · 共 32 行
TXT
32 行
/*
EOP finder for upxshit 0.6 (snaker) & UPX
It also works for a "standalone" UPX packed program
Author : mimas
*/
var x
loop:
findop eip, #E9??# // find jump to next loop
mov x, $RESULT
sub x, eip
cmp x, 10 // (@jmp - eip) use to be 10,
// we can handle different loop size this way
ja stub
go $RESULT
sto
jmp loop
stub:
// the terrific UPX OEP finder
eob end
sto
mov x, esp
bphws x, "r"
run
end:
bphwc x
sto
ret
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?