1
111Mutay
Guest
- Konu Yazar
- #1
Piyasada dolaşan OPCODE değiştirme yöntemlerini denedim fakat başarısız
Yardımcı olabilecek birisi varsa makbule geçer.

[COLOR=Red]// Client[/COLOR]
006FB9AE |. C64424 08 2B MOV BYTE PTR SS:[ESP+8],[COLOR=Red]2B
[/COLOR][COLOR=Red]// Ebenezer[/COLOR]
00478313 . E9 D2A80800 JMP 00502B13
00478318 90 NOP
00478319 90 NOP
0047831A 90 NOP
0047831B 90 NOP
0047831C 90 NOP
0047831D 90 NOP
0047831E 90 NOP
0047831F 90 NOP
00478320 90 NOP
00478321 90 NOP
00478322 > 4A DEC EDX
00478323 . 83FA 79 CMP EDX,79
00502B13 > 83FA 2B CMP EDX,[COLOR=Red]2B[/COLOR]
00502B16 . 74 17 JE SHORT 00502B2F
00502B18 . 83FA 01 CMP EDX,1
00502B1B . 74 17 JE SHORT 00502B34
00502B1D . 52 PUSH EDX
00502B1E . 8A96 9C800000 MOV DL,BYTE PTR DS:[ESI+809C]
00502B24 . 80FA 00 CMP DL,0
00502B27 . 5A POP EDX
00502B28 . 75 05 JNZ SHORT 00502B2F
00502B2A . BA FFFFFFFF MOV EDX,-1
00502B2F >^E9 EE57F7FF JMP 00478322
00502B34 > 50 PUSH EAX
00502B35 . 8B86 98800000 MOV EAX,DWORD PTR DS:[ESI+8098]
00502B3B . C640 71 01 MOV BYTE PTR DS:[EAX+71],1
00502B3F . 58 POP EAX
00502B40 .^EB ED JMP SHORT 00502B2F