// Emits Handler(1), the second function in the AI DLL's verified 73-entry VM table. // Run through Ghidra headless analysis; the original PE remains read only. import ghidra.app.decompiler.DecompInterface; import ghidra.app.script.GhidraScript; import ghidra.program.model.address.Address; import ghidra.program.model.listing.Function; public class ExportAiVmHandler1 extends GhidraScript { private static final long ADDRESS = 0x10007fd0L; @Override public void run() throws Exception { Address address = currentProgram.getAddressFactory().getDefaultAddressSpace() .getAddress(ADDRESS); Function function = currentProgram.getFunctionManager().getFunctionAt(address); println("===== AI VM Handler(1) ====="); if (function == null) { println("missing"); return; } DecompInterface decompiler = new DecompInterface(); decompiler.openProgram(currentProgram); println(decompiler.decompileFunction(function, 60, monitor).getDecompiledFunction().getC()); decompiler.dispose(); } }