pavka Posted June 17, 2007 Posted June 17, 2007 (edited) unpacked &scrpts1.unpack exe/*//////////////////////////////////////////////////Назначение скрипта MoleBox/////////////////////////////////////////////////*/var patchvar countervar ImageBasevar OEPvar iat_startvar Startmsg "Add ignore custom exption or ranges [EF000007]"mov counter,0gmi eip,MODULEBASEmov ImageBase,$RESULTask "Введите адрес секции SFX" cmp $RESULT, 0je quitmov Start,$RESULTfind Start,#FFD0#cmp $RESULT,0je quitmov OEP,$RESULTmov patch,$RESULTsub patch,EBPHWS patch,"x"runBPHWC patchfind eip,#558BEC83EC48C645FC01C745F800000000EB09#cmp $RESULT,0je quitmov patch,$RESULTmov [patch],#C3#BPHWS patch,"x"runmov iat_start,eaxBPHWC patchBPHWS OEP,"x"runBPHWC OEPsticmt eip, "Oep"sub OEP,ImageBasesub iat_start,ImageBasemov counter,ImageBaseadd counter,3Cmov counter,[counter]add counter,ImageBaseadd counter,28mov [counter],OEPadd counter,58mov [counter],iat_startDPE "dump.exe",eipmsg "The file is unpacked! Remove unnecessary section in Dump"retquit:MSG "Not MoleBox"ret2. extract dll//////////////////////////////////////////////////Назначение скрипта MoleBox extr/////////////////////////////////////////////////*/var patchvar dllwrvar size_dllvar img_dllvar Startmsg "Add ignore custom exption or ranges [EF000007]"ask "Введите адрес секции SFX" // начало секции где находиться епcmp $RESULT, 0je quitmov Start,$RESULTfind Start,#FFD0#cmp $RESULT,0je quitmov OEP,$RESULTmov patch,$RESULTsub patch,EBPHWS patch,"x"runBPHWC patchfind eip,#8B45C48B4DF0#cmp $RESULT,0je quitmov dllwr,$RESULTBPHWS dllwr,"x"loop:runstimov img_dll,eaxfind img_dll,#5045#mov size_dll,$RESULTadd size_dll,50mov size_dll,[size_dll]eval "Name dll in ebx, damp partial address:{img_dll} , size:{size_dll}! If it is necessary, choose active dump engine ->IntelDump"msg $RESULTpausejmp loopMoleBox_Pro_2.6.4.2534.rar Edited June 17, 2007 by pavka
Angel-55 Posted June 18, 2007 Posted June 18, 2007 it's at that tuts4you homepage Apakekdah Link: http://www.tuts4you.com/download.php?view.1710 BTW, nice script Pavka
euverve Posted November 19, 2009 Posted November 19, 2009 How to use this script and what is the output file of this?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now