吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 17377|回复: 5
上一主题 下一主题
收起左侧

[Scripts] Enigma 4.xx to 5.xx Unpack Helper & HWID Patcher V1.0

[复制链接]
跳转到指定楼层
楼主
风吹屁屁凉 发表于 2016-5-6 14:51 回帖奖励
Hello Guys.

Here i made a script it can change the hwid of Enigma Target and find the OEP of it.

I am also added a short tutorial about it.

Have a try,

I am not good in writing scripts but Hopefully it will helpful for all of you.

https://forum.tuts4you.com/topic/38336-enigma-4xx-to-5xx-unpack-helper-hwid-patcher-v10/

[Asm] 纯文本查看 复制代码
//created by ramjane
//tested on many unpackme
//hope it will work fine
//www.psychogsmdestroyer.blogspot.com
bphwc
var hwid
var hwidsize
var hwidjmp
var bpad
var sec
var ENIGMA
var GetProcAddress
var RET
var tmp
var APIP
var EP
var allo
var pass
var prepatch
//////////////////////////////
//put hwid without "-"
/////////////////////////////
mov hwid, "63B2F42270363648F4A06F991621A7E75A61DF30"
/////////////////////////////
len hwid
mov hwidsize, $RESULT
mov EP,eip
gpa "GetProcAddress" , "Kernel32.dll"
mov GetProcAddress, $RESULT
alloc 1000
mov sec,$RESULT
mov [sec],#606A006A00E8837AAA906190#
eval "call {GetProcAddress}"
asm sec+05, $RESULT
mov eip,sec
bp eip+0B
bp GetProcAddress
run
bc eip
rtr
mov RET, eip
run
bc
mov eip,EP
bphws RET
esto
free sec
mov ENIGMA, esi
bphwc
var OEPBP
var VABP
var APICALL
gpa "VirtualAlloc", "kernel32.dll"
mov VABP, $RESULT
bp VABP
run
bc
rtr
sti
start:
alloc 1000
mov allo, $RESULT
mov [allo],#5E5B59595DC3#
find ENIGMA, #FF0081C2E0#
mov OEPBP,$RESULT
bphws OEPBP, "x"
find ENIGMA,#3D00F00000#
mov APICALL,$RESULT
eval "inc eax"
asm APICALL-15, $RESULT
eval "nop"
asm APICALL-14,$RESULT
mov EP,eip
find ENIGMA, #558BEC33C9515151515151538BD833C0#
mov bpad, $RESULT+180
find ENIGMA,#85d274188b5afc#
mov hwidjmp, $RESULT+23
alloc 1000
mov sec, $RESULT
mov [sec],#608BF850E84A73C27583F80C0F850D000000C7C128000000BE25001900F3A461E9A3739800#
mov [sec+25], hwid
gpa "lstrlenA", "kernel32.dll"
mov tmp, $RESULT
eval "call {tmp}"
asm sec+4, $RESULT
eval "cmp eax, {hwidsize}"
asm sec+9, $RESULT
eval "mov ecx, {hwidsize}"
asm sec+12, $RESULT
mov [sec+19], sec+25
gci hwidjmp, DESTINATION
mov tmp,$RESULT
eval "jmp {tmp}"
asm sec+20, $RESULT
eval "jmp {sec}"
asm hwidjmp, $RESULT
mov eip,EP
esto 
bphws ecx
run
sti
cmt eip, "OEP"
bphwc
msg "OEP found just fix VM API and Everything Should work \r\n\r\nCreated by Ramjane.\r\n\r\nThanks LCF-AT for his Great work."
ret

Enigma 4.xx to 5.xx Unpack Helper & HWID Patcher V1.0.rar

637.27 KB, 下载次数: 497, 下载积分: 吾爱币 -1 CB

免费评分

参与人数 1热心值 +1 收起 理由
Peace + 1 鼓励转贴优秀软件安全工具和文档!

查看全部评分

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

沙发
暮光之城 发表于 2016-5-6 15:00
这个占位  收费···  
头像被屏蔽
3#
woaipojie8888 发表于 2016-5-6 15:01
4#
xiawan 发表于 2016-5-6 17:17
5#
释然 发表于 2016-6-19 21:31
真是不错嘿嘿嘿
6#
fzx118 发表于 2017-11-15 19:32
风吹屁屁凉大大呀  !谢谢分享脚本!
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-4-19 17:39

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表