标签为 "Ollydbg" 的存档

分享:一个unpack conficker worm的脚本

lclee 说:
i just finish the ollyscript
automated unpack the conficker worm
tested these sample with MD5
MD5:83c52b56b1ecbe23183bae5e05474e3e
MD5:6ee741c4e0d36d0dc9162a6e71943379
if want to get the sample, search the md5 from here
http://www.offensivecomputing.net/
hmm..still not perfect yet the
it just can automated unpack the conficker variant B
C still cannot

阅读更多…