diff options
Diffstat (limited to 'tools/ghidra')
| -rw-r--r-- | tools/ghidra/ExportAiVmHandler0.java | 23 | ||||
| -rw-r--r-- | tools/ghidra/ExportAiVmTableInstall.java | 23 |
2 files changed, 46 insertions, 0 deletions
diff --git a/tools/ghidra/ExportAiVmHandler0.java b/tools/ghidra/ExportAiVmHandler0.java new file mode 100644 index 0000000..43e8046 --- /dev/null +++ b/tools/ghidra/ExportAiVmHandler0.java @@ -0,0 +1,23 @@ +// Emits the first function in the AI DLL's verified 73-entry VM handler table. +// Run through Ghidra headless analysis; the original PE remains read only. +import ghidra.app.decompiler.DecompInterface; +import ghidra.app.script.GhidraScript; +import ghidra.program.model.address.Address; +import ghidra.program.model.listing.Function; + +public class ExportAiVmHandler0 extends GhidraScript { + private static final long ADDRESS = 0x10008034L; + + @Override + public void run() throws Exception { + Address address = currentProgram.getAddressFactory().getDefaultAddressSpace() + .getAddress(ADDRESS); + Function function = currentProgram.getFunctionManager().getFunctionAt(address); + println("===== AI VM handler 0 ====="); + if (function == null) { println("missing"); return; } + DecompInterface decompiler = new DecompInterface(); + decompiler.openProgram(currentProgram); + println(decompiler.decompileFunction(function, 60, monitor).getDecompiledFunction().getC()); + decompiler.dispose(); + } +} diff --git a/tools/ghidra/ExportAiVmTableInstall.java b/tools/ghidra/ExportAiVmTableInstall.java new file mode 100644 index 0000000..842e7dc --- /dev/null +++ b/tools/ghidra/ExportAiVmTableInstall.java @@ -0,0 +1,23 @@ +// Emits the routine that receives the AI VM's verified 73-entry handler table. +// Run through Ghidra headless analysis; the original PE remains read only. +import ghidra.app.decompiler.DecompInterface; +import ghidra.app.script.GhidraScript; +import ghidra.program.model.address.Address; +import ghidra.program.model.listing.Function; + +public class ExportAiVmTableInstall extends GhidraScript { + private static final long ADDRESS = 0x10011E70L; + + @Override + public void run() throws Exception { + Address address = currentProgram.getAddressFactory().getDefaultAddressSpace() + .getAddress(ADDRESS); + Function function = currentProgram.getFunctionManager().getFunctionAt(address); + println("===== AI VM handler table install ====="); + if (function == null) { println("missing"); return; } + DecompInterface decompiler = new DecompInterface(); + decompiler.openProgram(currentProgram); + println(decompiler.decompileFunction(function, 60, monitor).getDecompiledFunction().getC()); + decompiler.dispose(); + } +} |
