分享
Armadillo Standard (Pause).txt
下载文档

ID:3399767

大小:1.46KB

页数:2页

格式:TXT

时间:2024-04-28

收藏 分享赚钱
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,汇文网负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
网站客服:3074922707
Armadillo Standard Pause Pause
/* .:TEAM RESURRECTiON:. Armadillo Standard+Pause Script by AvAtAr Modified By Teddy Rogers Tested on WinXP Pro SP2, OllyDbg v1.10, OllyScript v0.92 NOTES: - Remove all hardware breakpoints before run the script. - Add the following custom exceptions on OllyDbg: C0000005(ACCESS VIOLATION), C000001D(ILLEGAL INSTRUCTION) C000001E(INVALID LOCK SEQUENCE), C0000096(PRIVILEGED INSTRUCTION) */ var CreateMutexA var CreateThread var GetModuleHandleA var OpenMutexA var VirtualAlloc var JumpLocation var JumpLength var adata var regESP var OEP gpa "CreateMutexA", "kernel32.dll" mov CreateMutexA, $RESULT gpa "CreateThread", "kernel32.dll" mov CreateThread, $RESULT gpa "GetModuleHandleA", "kernel32.dll" mov GetModuleHandleA, $RESULT gpa "OpenMutexA", "kernel32.dll" mov OpenMutexA, $RESULT gpa "VirtualAlloc", "kernel32.dll" mov VirtualAlloc, $RESULT gmi eip,MODULEBASE find $RESULT,#2E6164617461# mov adata,$RESULT add adata,0c mov adata,[adata] gmi eip,MODULEBASE add adata,$RESULT bp OpenMutexA esto exec PUSH EDX PUSH 0 PUSH 0 CALL CreateMutexA JMP OpenMutexA ende bc OpenMutexA bphws GetModuleHandleA, "x" label1: esto rtu find eip, #0F84????????????????????74??????????EB??# cmp $RESULT,0 je label1 bphwc GetModuleHandleA mov JumpLocation, $RESULT mov JumpLength, JumpLocation add JumpLength, 2 mov JumpLength, [JumpLength] inc JumpLength mov [JumpLocation], 0E9 inc JumpLocation mov [JumpLocation], JumpLength pause

此文档下载收益归作者所有

下载文档
你可能关注的文档
收起
展开