首页
社区
课程
招聘
[转帖]Code Unvirtualizer BETA 0.1
发表于: 2009-3-9 02:35 12484

[转帖]Code Unvirtualizer BETA 0.1

2009-3-9 02:35
12484

Hi, as promised, here is a little tool that will help to reverse the CodeVirtualizer and the Themida /WinLicense Virtual Machine

Must Remark , is a BETA, it suppors almost no opcodes, MultibranchSystem is not well implemented, but the handler deofuscation is, also there is a small engine that help to recognize the Iat position with the Handler ID

Information
- if you want a full diagnosis of a specific handler, chnage Diagnosis_Handler_Number on the ini file (read number as decimal)
- if Dump Virtual Machine doesn't fail it generates two txt files
   .  LogMatchIatData.txt conatins IAT with corresponding Handler ID
   .  LogVMData.txt contains decrypted data
- if  GetVirtualOpcodes doesn't fail it generates two txt files
   .  LogVirtualOpcode.txt Contains the sequence of decrypted handlers id
   .  LogDumpedSyntax.txt contains the hnalderids in 'readable code'
- OreansSyntax.cfg contains the information to convert from ID to CVSyntax

Limitations(for now)
- MultiBranchSystem engine may fail
- Some Sequences may be wrong deofuscated
- OreansSyntax.cfg is poorly developed
- Stops at any unknown opcode
- FakeOpcodes is not implmented yet

GEtVirtualOpcode will fail if you didn't executed first DumpVirtualMachine(coz it reads LogMatchIatData.txt)

Bugs reporst and suggestions are welcome
have fun :P

Parameters
Number of Handlers MUST BE A8H

http://img21.imageshack.us/img21/2594/cvpushkey.jpg
http://img21.imageshack.us/img21/2015/cvpushstartdata.jpg

ps:用VC6动态链接编译的,没装VC6的得自己找库


[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

上传的附件:
收藏
免费 7
支持
分享
最新回复 (15)
雪    币: 7309
活跃值: (3788)
能力值: (RANK:1130 )
在线值:
发帖
回帖
粉丝
2
版主教教我们怎么用吧
2009-3-9 09:30
0
雪    币: 2067
活跃值: (82)
能力值: ( LV9,RANK:180 )
在线值:
发帖
回帖
粉丝
3
等楼上学会再来学习
2009-3-9 09:40
0
雪    币: 287
活跃值: (102)
能力值: ( LV8,RANK:130 )
在线值:
发帖
回帖
粉丝
4
学习
膜拜
2009-3-9 10:24
0
雪    币: 107
活跃值: (404)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
难道是........................

不管怎么样,,膜拜先吧..............
2009-3-9 11:36
0
雪    币: 8209
活跃值: (4518)
能力值: ( LV15,RANK:2473 )
在线值:
发帖
回帖
粉丝
6
我想知道“1加1等于几?”
2009-3-9 11:45
0
雪    币: 1946
活跃值: (248)
能力值: (RANK:330 )
在线值:
发帖
回帖
粉丝
7
太难了,完全不懂啊



我也想知道
2009-3-9 14:11
0
雪    币: 347
活跃值: (30)
能力值: ( LV9,RANK:420 )
在线值:
发帖
回帖
粉丝
8
这个要膜拜一下的
2009-3-9 15:06
0
雪    币: 6075
活跃值: (2236)
能力值: (RANK:1060 )
在线值:
发帖
回帖
粉丝
9
这一位上等于0
2009-3-9 17:00
0
雪    币: 102
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
10
已经有新版本更新了。好象。
2009-3-19 02:18
0
雪    币: 2411
活跃值: (1412)
能力值: ( LV4,RANK:50 )
在线值:
发帖
回帖
粉丝
11
是的, 在這裡.

Little Update, deofucation system improved, also now support some MultiBranch System, OreansSyntax improved, Virtual Opcode reader stops at handler end

http://www.sendspace.com/file/86684o

Don't know why can't update.

Also added a helpèr txt(CV_Syntax.txt) if you want to add more syntaxes (This is a referential file, is not readed by the application) 


轉自:

hxxp://forum.exetools.com/showthread.php?t=12112
2009-3-19 11:18
0
雪    币: 193
活跃值: (1389)
能力值: ( LV6,RANK:90 )
在线值:
发帖
回帖
粉丝
12
CodeUnVirtualizer 0.2
顺便上传了下,那个网站需要代理才能够访问
上传的附件:
2009-3-19 13:47
0
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
13
[QUOTE=;]...[/QUOTE]
CodeUnVirtualizer 0.3
_http://www.sendspace.com/file/rrsj43
2009-4-1 17:18
0
雪    币: 86
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
14
有很多都不太懂!
2009-4-2 18:48
0
雪    币: 208
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
15
顶下,这么强大的东西
2009-4-22 15:39
0
雪    币: 218
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
16
v1.0
http://www.sendspace.com/file/qk0y8d
2009-11-23 23:07
0
游客
登录 | 注册 方可回帖
返回
//