首页
社区
课程
招聘
[转帖]Oreans UnVirtualizer ODBG Plug-in UnVirtualizes CISC Themida/WL/CodeVirtualize Ma
2011-3-30 14:41 4543

[转帖]Oreans UnVirtualizer ODBG Plug-in UnVirtualizes CISC Themida/WL/CodeVirtualize Ma

2011-3-30 14:41
4543
原帖 http://forum.tuts4you.com/index.php?showtopic=25548&st=0&p=120663&hl=+themida%20+dll&fromsearch=1&#entry120663

Hi All

This tool will help conversion VirtualOpcodes -> Assembly Instruction
restoring the original code of your virtualized Application, the basic engine
was from CodeUnvirtualizer, my other tool

[Features]
- Supports WinLicense/Themida/CodeVirtualizer Cisc Machines
- Supports almost all common opcodes
- Supports CHECK_MACRO_PROTECTION
- Supppots MultiBranch Tech

[Use]
- Right-click on the jump leading to the Virtual Machine Area and press Unvirtualize (If machine isn't found
you have to click again, after checking that the full machine was correctly deofuscated)

[Oreans UnVirtualizer]
[v1.0]
- First public Version
[v1.1]
- Fixed Decode GenV1
- Added CALL [EBX+ESI+0x234234]
- Video logs Added
- Updated OreansJunk.cfg
[v1.2]
- Fixed Decode MovV1
- Added REP - REPNE - CMPS - MOVS - LODS - STOS - SCAS Instructions
- Added CISC-2 Micro-opcodes UnVirtualizer
- Fixed Decode MovV2
- OreansJunk.cfg updated
- OreansAssembler.cfg updated
- Added Virtual Opcode Mutation Tech
- Fixed Jcc Jumps leading outside Virtual Machine
- Fixed Crash on reading Register Handlers
- Cisc_Vo_Dump.txt is no longer created

[Request]
- Since is almost impossible to create a full database with every opcode combination
I would appreciate if you got errors by some unknown opcodes, wrong decompiled, etc
a full diagnosis including Cisc_Vo_Dump.txt, Cisc_Vo_Syntax.txt, Cisc_Uv_Dump.txt and
Cisc_Iat_XXXXXX.txt file on your report

OreansUnVirtualizer 1.1 Sample
http://www.sendspace.com/file/1lscnw

Last Update: 2011/03/27 17:49 GMT-5
OreansUnVirtualizer 1.2

本地下载
Oreans UnVirtualizer 1.2.rar

我没测试过 看回帖好像bug还有很多

[培训]《安卓高级研修班(网课)》月薪三万计划,掌 握调试、分析还原ollvm、vmp的方法,定制art虚拟机自动化脱壳的方法

上传的附件:
收藏
点赞0
打赏
分享
最新回复 (1)
雪    币: 291
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
冷煞xiaosan 2011-3-30 15:15
2
0
是的  在TUTS和exetools讨论的都很激烈~~~经常出现期间卡死....
游客
登录 | 注册 方可回帖
返回