⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 activemark 5.4x remove selfchecks.txt

📁 700个脱壳脚本, 可以放在在OD的ollyscript Plugin中.
💻 TXT
字号:
/*AM 5.4x selfcheck remover script by russiankid.It will finds and disables new AM selfcheck (which was added since AM v5.4).This script should be run at new EP (can be run on original target after upack script or on dumped target).*//*the code that do the ckeck:0050978D   8845 E0          MOV BYTE PTR SS:[EBP-20],AL00509790   E8 BE170000      CALL dumped_.0050AF5300509795   8DBE B4000000    LEA EDI,DWORD PTR DS:[ESI+B4]0050979B   895D FC          MOV DWORD PTR SS:[EBP-4],EBX0050979E   57               PUSH EDI0050979F   E8 2FF00500      CALL dumped_.005687D3005097A4   84C0             TEST AL,AL005097A6   59               POP ECX005097A7   75 0A            JNZ SHORT dumped_.005097B3005097A9   FF35 10DB4F00    PUSH DWORD PTR DS:[4FDB10]005097AF   53               PUSH EBX005097B0   57               PUSH EDI005097B1   EB 41            JMP SHORT dumped_.005097F4005097B3   399E 60010000    CMP DWORD PTR DS:[ESI+160],EBX005097B9   74 43            JE SHORT dumped_.005097FE*/var FixAddrvar SeqAddrfind eip,#E8????????8DBEB4000000895DFC57E8#mov SeqAddr,$RESULTcmp SeqAddr,0je SeqAddrNotFoundadd SeqAddr,10mov FixAddr,[SeqAddr]add FixAddr,SeqAddradd FixAddr,4mov [FixAddr],#B001C3#dec SeqAddreval "New ActiveMark selfcheck fixed in the call at: {SeqAddr}"msg $RESULTretSeqAddrNotFound:msg "Could not find sequence to fix!"ret

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -