PEBundle 壳 有脚本或者工具直接脱吗
PESniffer:PEBundle v3.10PEiDScan:PEBundle 2.0x - 2.4x-> Jeremy Collake 自己在google里面搜索下吧.. /*
//////////////////////////////////////////////////////////////
// PEBundle 2.0x - 2.4x OEP finder
// Author: hacnho/VCT2k4
// Email : [email protected]
// Website: http://nhandan.info/hacnho
// OS : WinXP Pro, OllyDbg 1.10 Final, OllyScript v0.85
/////////////////////////////////////////////////////////
*/
sti
sti
eob Break
findop eip, #9D68#
bphws esp,"r"
run
Break:
sto
sto
sto
an eip
log eip
cmt eip, "This is the OEP! Found by hacnho/VCT2k4"
MSG "Dumped and fix IAT now! Thanx for using my Script...!"
ret 直接脱 的没有什么用啊 /:011
页:
[1]