var bpaddr //Break point address
var addr
start: //script start
gpa "LoadLibraryA","kernel32.dll" //GetProcAddress
mov bpaddr,$RESULT
bphws bpaddr,"x"
esto
BPHWC bpaddr
rtu
sti
findop A11000, #0337#
//cmp $RESULT,0
//je l1
mov addr,$RESULT
add addr,2
fill addr,4,90
findop A11000, #3DFF0F0000#
mov addr,$RESULT
bphws addr,"x"
run
BPHWC addr
sti
sti
sti
sti
sti
sti
sti
sti
sti
cmt eip,"这里就是stolencode 每个jmp上面就是一直F7!最后一个就是oep"
msg "Script by WiNrOOt,Thank you for using my Script!"
ret
l1:
msg "sorry"
ret