能力值:
( LV2,RANK:10 )
2 楼
问问noody,他熟悉。
能力值:
( LV2,RANK:10 )
3 楼
//fuck vmp iat by nooby
//run the script at ep
//vmp code base = va of .vmp0
//vmp code size = size of .vmp0 var vmpbase
var vmpsize
var magic
var isfirst
var first
var decode
var dllname
var funcname
var stackdep
var sFile
mov sFile, "iat_log.txt"
mov isfirst, 0 mov magic, 0134AE5E
mov first, 01007412
mov decode, 01038841
mov stackdep, c Ask "vmp code base"
mov vmpbase, $RESULT
Ask "vmp code size"
mov vmpsize, $RESULT
bphws first, "x"
bphws magic, "x"
bphws decode, "x"
looper:
esto
cmp eip, first
je patch
cmp eip, magic
je setbp
cmp eip, decode
je patch
jmp looper
setbp:
cmp isfirst, 0
jne p1
inc isfirst
bpwm vmpbase, vmpsize
wrt sFile, "Fuck VMP IAT\r\n"
wrta sFile, "VA, DLL.FUNCTION\r\n"
p1:
mov tmp, eax
len [[esp+stackdep+4]]
readstr [[esp+stackdep+4]], $RESULT
mov dllname, $RESULT
len [[esp+stackdep]]
readstr [[esp+stackdep]], $RESULT
mov funcname, $RESULT
esti
esto
cmp eip, magic
je p1
cmp eip, first
je patch
cmp eip, decode
je patch
mov edx, tmp
wrta sFile, eax
wrta sFile, ", "
wrta sFile, dllname
wrta sFile, "."
wrta sFile, funcname
wrta sFile, "\r\n"
jmp looper
patch:
mov [decode], c3
end:
ret
能力值:
( LV2,RANK:10 )
4 楼
脱壳要动点脑筋!
能力值:
( LV2,RANK:10 )
5 楼
先谢谢你!先回去试试这个脚本