pespin 0.b - 0.3 oep finder.txt

来自「700个脱壳脚本, 可以放在在OD的ollyscript Plugin中.」· 文本 代码 · 共 42 行

TXT
42
字号
/*
2h15 PM Tuesday 11 January 2005
PESpin 0.b - 0.3 OEP Finder without Method "Remove OEP"
Tested with PESpin 0.b & PESpin 0.3
Author : dqtln
Email : dqtlncrk@gmail.com
OS : WinXP Pro SP1 , OllyDbg 1.10 , OllyScript 0.92
Website : www.phudu.com
For opinions & bugreport send me a email
Thank you very much
*/


msgyn "Please check Options/Exceptions/INT3 breaks"
cmp $RESULT,0
je dqtln3
var x
sto
sto
bphws esp,"r"
mov x,esp
run

dqtln1:
esto
cmp eax,FF
jne dqtln1
je dqtln2

dqtln2:
esto
sto
bphwc x
msg "Please press No if have a question"
an eip
cmt eip,"This is the OEP - Found by dqtln"
msg "Dump and fix IAT now - Good day"
ret

dqtln3:
msg "Script Abort"
ret

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?