asprotect 1.0 oep finder.txt
来自「700个脱壳脚本, 可以放在在OD的ollyscript Plugin中.」· 文本 代码 · 共 71 行
TXT
71 行
/*////////////////////////////////////////////////// ASProtect 1.0 Unpacking script v0.1(for win2k/xp only) Author: loveboom Email : loveboom%163.com OS : WinXP sp2,Ollydbg 1.1,OllyScript v0.92 Date : 2004-12-25 Action: Find OEP Config: Ignore all exceptions Note : If you have one or more question, email me please,thank you!//////////////////////////////////////////////////*/var espvalvar countvar addrlblset: msgyn "Setting:Ignore all exceptions." cmp $RESULT,1 je start retstart: mov count,2 mov espval,esp sub espval,4 gpa "LocalAlloc","kernel32.dll" //Get API function 'LocalAlloc' cmp $RESULT,0 je lblabort bp $RESULTlbl1: runlbl2: cmp count,0 je lbl3 dec count jmp lbl1lbl3: mov addr,esp add addr,4 mov [addr],40 bc $RESULT bphws espval,"r"lblesto: esto esto esto estolbl4: bphwc espval findop eip,#C3# //Find command 'RETN' cmp $RESULT,0 je lblabort go $RESULT stolbloep: cmt eip,"oep" msg "Script by loveboom[DFCG[FCG][US],Thank you for using my script!" retlblabort: msg "Script abort!Maybe target is not protect by Asprotect 1.0." ret
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?