//////////////////////////////////////////////////////////////////
/// MoleBox v2.3600 IAT处理脚本
/// by 徐超(ximo) QQ:178911980
/// http://www.54soft.com.cn
///http://www.52pojie.cn
///
/// 2009.1.10
////////////////////////////////////////////////////////////////
var addr
var EP
var vp
find eip,#60E8#
mov EP,$RESULT
add EP,1
bp EP
run
bc EP
mov addr,esp
bphws addr,"r"
gpa "VirtualProtect","kernel32.dll"
bp $RESULT
run
run
run
bc $RESULT
mov vp,[esp]
bp vp
run
bc vp
find eip,#8916#
bp $RESULT
run
bc $RESULT
repl eip, #8916#, #9090#, 10
run
bphwc addr
sto
sto
sti
cmt eip,"这里就是OEP!BY ximo[LCG]!"
MSG "感谢使用此脚本,现在可以脱壳了,若还有无效指针,请手动修改为GetProcAddress!"
ret