曾经写了这么个脚本片断来跟踪mslrh,先打开open trace,然后......
var addr
var eipval
lbl1:
sti
mov eipval,eip
cmp eipval,xxxx //判断 是否为API调用
je lblapi
//这里加上你自己想要处理的代码片段
and eipval,ffff0000
cmp eipval,310f
jne lbl1
fill eip,2,90
sti
sti
fill eipval,1,0f
inc eipval
fill eipval,1,31
jmp lbl1