dbh //hide od
BPHWCALL //clear hardware breakpoint
BC //clear software breakpoint
BPMC //clear Memory breakpoint
bp 40AF0D//vm_retn=>retn 2c
log "VM Trace start!"
run_to_bp:
EOB bp_record //在下次中断发生时,跳转到指定标签处。
ESTO //step to bp(vmenginejmp) /相当于在OllyDbg按 SHIFT-F9。
bp_record:
log [esp] //记录
jmp run_to_bp
ret
BPHWCALL //clear hardware breakpoint
BC //clear software breakpoint
BPMC //clear Memory breakpoint
bp 40AF0D//vm_retn=>retn 2c
log "VM Trace start!"
run_to_bp:
EOB bp_record //在下次中断发生时,跳转到指定标签处。
ESTO //step to bp(vmenginejmp) /相当于在OllyDbg按 SHIFT-F9。
bp_record:
log [esp] //记录
jmp run_to_bp
ret