首页
社区
课程
招聘
[转帖]Code Unvirtualizer BETA 0.1
发表于: 2009-3-9 02:35 12626

[转帖]Code Unvirtualizer BETA 0.1

2009-3-9 02:35
12626

Hi, as promised, here is a little tool that will help to reverse the CodeVirtualizer and the Themida /WinLicense Virtual Machine

Must Remark , is a BETA, it suppors almost no opcodes, MultibranchSystem is not well implemented, but the handler deofuscation is, also there is a small engine that help to recognize the Iat position with the Handler ID

Information
- if you want a full diagnosis of a specific handler, chnage Diagnosis_Handler_Number on the ini file (read number as decimal)
- if Dump Virtual Machine doesn't fail it generates two txt files
   .  LogMatchIatData.txt conatins IAT with corresponding Handler ID
   .  LogVMData.txt contains decrypted data
- if  GetVirtualOpcodes doesn't fail it generates two txt files
   .  LogVirtualOpcode.txt Contains the sequence of decrypted handlers id
   .  LogDumpedSyntax.txt contains the hnalderids in 'readable code'
- OreansSyntax.cfg contains the information to convert from ID to CVSyntax

Limitations(for now)
- MultiBranchSystem engine may fail
- Some Sequences may be wrong deofuscated
- OreansSyntax.cfg is poorly developed
- Stops at any unknown opcode
- FakeOpcodes is not implmented yet

GEtVirtualOpcode will fail if you didn't executed first DumpVirtualMachine(coz it reads LogMatchIatData.txt)

Bugs reporst and suggestions are welcome
have fun :P

Parameters
Number of Handlers MUST BE A8H

2d7K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3W2E0k6K6t1I4i4K6u0W2K9h3#2S2k6$3g2K6K9r3q4U0K9#2)9J5k6i4g2K6i4K6u0r3K9h3#2Y4x3U0q4Q4x3V1j5J5y4e0V1@1i4K6u0r3j5%4k6H3N6i4y4Z5K9$3g2&6i4K6u0W2K9Y4m8Y4
16eK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3W2E0k6K6t1I4i4K6u0W2K9h3#2S2k6$3g2K6K9r3q4U0K9#2)9J5k6i4g2K6i4K6u0r3K9h3#2Y4x3U0q4Q4x3V1j5J5x3o6p5#2i4K6u0r3j5%4k6H3N6i4y4Z5M7%4c8S2M7Y4c8V1j5i4c8S2i4K6u0W2K9Y4m8Y4

ps:用VC6动态链接编译的,没装VC6的得自己找库


[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

上传的附件:
收藏
免费 7
支持
分享
最新回复 (15)
雪    币: 7357
活跃值: (3878)
能力值: (RANK:1130 )
在线值:
发帖
回帖
粉丝
2
版主教教我们怎么用吧
2009-3-9 09:30
0
雪    币: 2067
活跃值: (82)
能力值: ( LV9,RANK:180 )
在线值:
发帖
回帖
粉丝
3
等楼上学会再来学习
2009-3-9 09:40
0
雪    币: 287
活跃值: (137)
能力值: ( LV8,RANK:130 )
在线值:
发帖
回帖
粉丝
4
学习
膜拜
2009-3-9 10:24
0
雪    币: 107
活跃值: (429)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
难道是........................

不管怎么样,,膜拜先吧..............
2009-3-9 11:36
0
雪    币: 8209
活跃值: (4559)
能力值: ( LV15,RANK:2473 )
在线值:
发帖
回帖
粉丝
6
我想知道“1加1等于几?”
2009-3-9 11:45
0
雪    币: 1946
活跃值: (303)
能力值: (RANK:330 )
在线值:
发帖
回帖
粉丝
7
太难了,完全不懂啊



我也想知道
2009-3-9 14:11
0
雪    币: 347
活跃值: (30)
能力值: ( LV9,RANK:420 )
在线值:
发帖
回帖
粉丝
8
这个要膜拜一下的
2009-3-9 15:06
0
雪    币: 6075
活跃值: (2236)
能力值: (RANK:1060 )
在线值:
发帖
回帖
粉丝
9
这一位上等于0
2009-3-9 17:00
0
雪    币: 102
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
10
已经有新版本更新了。好象。
2009-3-19 02:18
0
雪    币: 2493
活跃值: (1562)
能力值: ( LV4,RANK:50 )
在线值:
发帖
回帖
粉丝
11
是的, 在這裡.

Little Update, deofucation system improved, also now support some MultiBranch System, OreansSyntax improved, Virtual Opcode reader stops at handler end

cafK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4y4W2L8X3c8K6M7r3q4U0k6g2)9J5k6h3y4G2L8g2)9J5c8X3k6A6L8r3g2Q4x3V1j5^5y4U0j5^5y4r3)9`.

Don't know why can't update.

Also added a helpèr txt(CV_Syntax.txt) if you want to add more syntaxes (This is a referential file, is not readed by the application) 


轉自:

hxxp://forum.exetools.com/showthread.php?t=12112
2009-3-19 11:18
0
雪    币: 193
活跃值: (1489)
能力值: ( LV6,RANK:90 )
在线值:
发帖
回帖
粉丝
12
CodeUnVirtualizer 0.2
顺便上传了下,那个网站需要代理才能够访问
上传的附件:
2009-3-19 13:47
0
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
13
[QUOTE=;]...[/QUOTE]
CodeUnVirtualizer 0.3
_982K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4y4W2L8X3c8K6M7r3q4U0k6g2)9J5k6h3y4G2L8g2)9J5c8X3k6A6L8r3g2Q4x3V1k6J5M7Y4y4B7y4o6x3`.
2009-4-1 17:18
0
雪    币: 86
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
14
有很多都不太懂!
2009-4-2 18:48
0
雪    币: 208
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
15
顶下,这么强大的东西
2009-4-22 15:39
0
雪    币: 218
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
16
v1.0
6f7K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4y4W2L8X3c8K6M7r3q4U0k6g2)9J5k6h3y4G2L8g2)9J5c8X3k6A6L8r3g2Q4x3V1k6I4K9K6m8&6z5r3b7`.
2009-11-23 23:07
0
游客
登录 | 注册 方可回帖
返回