.text:10116143 BF 20 A1 18 10 mov edi, offset unk_1018A120
.text:10116148 BA 28 B1 18 10 mov edx, offset aKLVljqKqvyTy ; "k]L}VLJQ]KqVy[Ty"
这两个地址字符串被加密了
用如下脚本解密:
#include<idc.idc>
static main()
{
auto nSrc,from;
from=ScreenEA();
from++;
from=Dword(from);
Message("%08x\n",from);
nSrc=Byte(from);
while(nSrc)
{
Message("%02x,0x%08.x\n",nSrc,from);
PatchByte(from,nSrc^0x35);
from++;
nSrc=Byte(from);
}
}