吾爱破解 - 52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 5282|回复: 5
收起左侧

[Scripts] PECompact 2.xx_Find_OEP_n_IAT_Fix_REA

[复制链接]
Hmily 发表于 2009-6-18 12:46
script này dựa trên tuts tìm Magic point PEcompact 2.x của phongvucba.


/*
Script written by Computer Angel 26/May/2009
base on phongvucba(REAOnline.net) fixing IAT method using magic JMP

Usage:
+ Run script at PECompact Entrypoint with debugger hide plugins

History:
+ 26/May/2009: Draft version
*/

BC
BPHWC
mov tmp,[eip],1
cmp tmp,B8
jne error
mov saveaddr0,[eip+1],4

find_OEP_jmp:
findmem #FFE0#,saveaddr0
cmp $RESULT,0
je error
mov jmp_EAX,$RESULT

find_alloc:
gpa "VirtualAlloc", "kernel32.dll"
bp $RESULT
esto
bc eip
rtr
mov save_alloc,eax

hook_GetModule:
gpa "GetModuleHandleA", "kernel32.dll"
bp $RESULT
bpgoto $RESULT, find_magic
esto

find_magic:
mov find_addr,[esp],4
gmemi find_addr,MEMORYBASE
cmp $RESULT,save_alloc
jne find_next
findmem #FFE0558BEC83C4FC#,save_alloc
cmp $RESULT,0
je find_next
mov find_addr2,$RESULT
findmem #75??33C0#, find_addr2
cmp $RESULT,0
je find_next
mov magic_addr,$RESULT
mov [magic_addr],EB,1
bc eip
jmp to_OEP

find_next:
bc eip

to_OEP:
bp jmp_EAX
esto
bc eip
sti
cmt eip,"OEP found by Computer Angel, REATeam"
ret

error:
msg "Error!"
ret

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

qinglianzi 发表于 2009-8-1 16:20
谢谢你  今天正好用的上
252339439 发表于 2009-10-19 22:11
xtaymim 发表于 2010-1-11 20:42
rwx110 发表于 2010-1-13 16:17
好的东西呀 谢谢
avzhongjiezhe 发表于 2010-2-23 17:02
PECompact手脱就行,脚本更方便一些,谢谢分享
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则

返回列表

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-11-15 07:00

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表