![]() |
|
|
|
#1
|
||||
|
||||
|
Deathway, it's superb, but has a problem.
on two samples, OllyDbg was crashed for decoding second vm reference. I mean it only unvirtualize one region at each run of OllyDbg (OllyIce). For WL, the main problem is finding the first instruction. What's your idea about code in attachment? I tested several possible address, but there was no success!
__________________
In memory of UnREal RCE... |
| The Following User Says Thank You to Newbie_Cracker For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#2
|
||||
|
||||
|
... I suggest this address,
00D2477D in case there isn't success, maybe you could upload your target, Remember that not all the functions end with EB 10, because compilers do some align to functions like NOP, MOV EDI,EDI, LEA ESP, [ESP], and Themida omits this kind of instruction, specially if no jump nor Jcc leads to that instruction About the crash, is from Quicktablewindow function, will do some test, but now I don't have any clue about the error. Last edited by Deathway; 04-08-2011 at 03:15. |
| The Following User Gave Reputation+1 to Deathway For This Useful Post: | ||
Newbie_Cracker (04-09-2011) | ||
| The Following User Says Thank You to Deathway For This Useful Post: | ||
Indigo (07-19-2019) | ||
|
#3
|
||||
|
||||
|
Yeah, that was correct. How did you choose that? I checked many addresses, but didn't think about last one.
__________________
In memory of UnREal RCE... |
| The Following User Says Thank You to Newbie_Cracker For This Useful Post: | ||
Indigo (07-19-2019) | ||
![]() |
| Tags |
| codevirualizer, decompiler |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| [VB. NET 2010] Oreans Unvirtualizer plugin file processor | giv | Source Code | 0 | 07-21-2015 16:18 |