// Emits the routine that receives the AI VM's verified 73-entry handler table. // Run through Ghidra headless analysis; the original PE remains read only. import ghidra.app.decompiler.DecompInterface; import ghidra.app.script.GhidraScript; import ghidra.program.model.address.Address; import ghidra.program.model.listing.Function; public class ExportAiVmTableInstall extends GhidraScript { private static final long ADDRESS = 0x10011E70L; @Override public void run() throws Exception { Address address = currentProgram.getAddressFactory().getDefaultAddressSpace() .getAddress(ADDRESS); Function function = currentProgram.getFunctionManager().getFunctionAt(address); println("===== AI VM handler table install ====="); if (function == null) { println("missing"); return; } DecompInterface decompiler = new DecompInterface(); decompiler.openProgram(currentProgram); println(decompiler.decompileFunction(function, 60, monitor).getDecompiledFunction().getC()); decompiler.dispose(); } }