Exetools

Exetools (https://forum.exetools.com/index.php)
-   Community Tools (https://forum.exetools.com/forumdisplay.php?f=47)
-   -   Oreans UnVirtualizer ODBG Plug-in (WL/TMD/CV) (https://forum.exetools.com/showthread.php?t=13391)

giv 11-14-2013 17:17

Quote:

Originally Posted by ___da-brain___ (Post 87766)
Hello,

I was wondering if you have an updated version for TIGER and FISH new VM ?

Do you think is easy to reverse a newer VM?

b30wulf 11-15-2013 01:56

Quote:

Originally Posted by giv (Post 87995)
Do you think is easy to reverse a newer VM?

are you serious? :) he calls Chuck Norris and VM revers it self :D:D:D:D

giv 11-16-2013 00:16

lol
Many of us don't have knowledge to reverse a simple crackme.

Deathway 01-31-2014 10:11

1 Attachment(s)
[v1.7]
- FISH machine avaible (WHITE and RED variants)
- Added Vm signatures

Hi all, the new version of this plug-in supports the FISH virtual machine, WHITE and RED variants.

Some words about this machine...

It mixes both CISC and RISC architecture, but the code isn't like template anymore, every virtual machine has a new different number of handlers, and every handler contains a different execution path, a little tricky, but nothing that can't be 'devirtualized' ;), maybe i'll write a paper about FISH and TIGER machines later.

Some specs that aren't coded yet:
- Support for Check macro;
- Sort algo is very unstable
- This plugin may crash when deofuscating very rare sequences, (most of them are 'expected' specially when crash was due to an ud2 instruction).
- Suppor for BLACK variants ;)

... About TIGER, I have no plans for the moment, but it isn't very different from FISH analog.
Plug-in was tested with 2.2.6.0 version, other versions may have variants that this plug-in couldn't handle.


Deathway.

Conquest 01-31-2014 12:31

Quote:

Originally Posted by Deathway (Post 89678)
[v1.7]
- FISH machine avaible (WHITE and RED variants)
- Added Vm signatures

Hi all, the new version of this plug-in supports the FISH virtual machine, WHITE and RED variants.

Some words about this machine...

It mixes both CISC and RISC architecture, but the code isn't like template anymore, every virtual machine has a new different number of handlers, and every handler contains a different execution path, a little tricky, but nothing that can't be 'devirtualized' ;), maybe i'll write a paper about FISH and TIGER machines later.

Some specs that aren't coded yet:
- Support for Check macro;
- Sort algo is very unstable
- This plugin may crash when deofuscating very rare sequences, (most of them are 'expected' specially when crash was due to an ud2 instruction).
- Suppor for BLACK variants ;)

... About TIGER, I have no plans for the moment, but it isn't very different from FISH analog.
Plug-in was tested with 2.2.6.0 version, other versions may have variants that this plug-in couldn't handle.


Deathway.

LF> the paper . thanks for the great update

giv 01-31-2014 16:07

Is amaizing how fast you do the update.
It seems that you have a very good knownledge of the VM's.
Bravo and thank you!

benney 01-31-2014 21:43

thank you for the update, nice work Deathway!

ahmadmansoor 02-01-2014 04:29

Really nice work Deathway.
but any example files or update for movie tut .
many thanks .

Deathway 02-05-2014 11:03

1 Attachment(s)
[v1.8]
- FISH BLACK variant avaible
- Fixed deofuscation order (GenV6)
- New deofucation scheme for FISH machine
- New smart code tracer for FISH machines
- Stack sort for FISH commands
- Improved management of memory (faster deofuscation)
- Added movzx reg32, [esp+eax+memoffset] on CISC machines
- Added a message prompt when the opcode buffer is not enough
- Added LEAVE instruction for FISH machines
- Added support for CALLs to VM section in FISH machines
- CHECK_PROTECTION macro disabled, now it must be restored by hand
- Fixed QWORD incorrect names for some opcodes
- Fixed a problem when deofuscating RISC machines

Thanks people for all your reports, the plug-in becomes more powerful every day.

Now it fully supports FISH machines.
CHECK_PROTECTION macro has been disbled, it must be restored by hand, there were many troubles when handling this kind of macro.
CodeVirtualizer machines aren't supported (FISH-TIGER).
Hope you like this new update, happy reversing :)


Deathway.

giv 02-05-2014 14:41

So fast.
Congrats amigo.

DMichael 09-26-2014 14:57

anyone still own the video tutorial deathway made?

DA3MON_CRACK3R 12-23-2014 16:14

hi
i try doing modify this program but i not found source of this program
i am sorry for my bad english

giv 12-24-2014 14:52

Quote:

Originally Posted by DMichael (Post 94824)
anyone still own the video tutorial deathway made?

I will give you a hand.
Quote:

http://www11.zippyshare.com/v/35048094/file.html

Conquest 12-24-2014 17:00

Quote:

Originally Posted by DA3MON_CRACK3R (Post 96286)
hi
i try doing modify this program but i not found source of this program
i am sorry for my bad english

closed source. even if it gets open source , those who will be able to make future progress, are already good enough to make something similar like this.

1ST 04-23-2015 03:29

why do i get machine signature not found?


All times are GMT +8. The time now is 00:24.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX