Go Back   UnKnoWnCheaTs - Multiplayer Game Hacks and Cheats > Anti-Cheat Software & Programming > General Reversing

- Sponsored Advertisement -
http://www.myfpscheats.com/

Welcome to the UnKnoWnCheaTs - Multiplayer Game Hacks and Cheats.
You have to register before you can post and see and access any of the advanced forum features, please click the register link to proceed to the registration form. To start viewing threads or posts, select a forum that you want to visit from the selection below.
General Reversing
Anything relating to reverse engineering.
You are Unregistered, please register to gain Full access.    
Reply
 
Thread Tools

Oreans - Code Virtualizer Need Help
Old 03-08-2010, 02:01 AM   #1


xUrban's Avatar

Join Date: Mar 2010
Posts: 25
Reputation: 241
Rep Power: 0
xUrban is becoming A true Rep whorexUrban is becoming A true Rep whorexUrban is becoming A true Rep whore
Oreans - Code Virtualizer Need Help

Hello Guys ...

some piece of code in a game has been protected using Oreans's Code Virtualizer or a similar tool, maybe themida's codereplace macro or a similar one .
i would like to know how i can restore virtualized code back to x86 asm instructions.

Thanks To All UC-Forum for Any Help
xUrban is offline

Reply With Quote


Old 03-08-2010, 02:11 AM   #2
Follow me children

Jesus.'s Avatar

Join Date: Aug 2003
Posts: 3,255
Reputation: 42353
Rep Power: 592
Jesus. has a huge epeen!Jesus. has a huge epeen!Jesus. has a huge epeen!Jesus. has a huge epeen!Jesus. has a huge epeen!Jesus. has a huge epeen!Jesus. has a huge epeen!Jesus. has a huge epeen!Jesus. has a huge epeen!Jesus. has a huge epeen!Jesus. has a huge epeen!
Recognitions:
Members who have contributed financial support towards UnKnoWnCheaTs. Donation (2)
Points: 35,603, Level: 28
Points: 35,603, Level: 28 Points: 35,603, Level: 28 Points: 35,603, Level: 28
Activity: 3.3%
Activity: 3.3% Activity: 3.3% Activity: 3.3%
Last Achievements
Follow the mutated headers and rebuild.
__________________
Nigga who is UH.
IPancakes.
Jesus. is offline

Reply With Quote

Old 03-08-2010, 02:22 AM   #3


xUrban's Avatar

Threadstarter
Join Date: Mar 2010
Posts: 25
Reputation: 241
Rep Power: 0
xUrban is becoming A true Rep whorexUrban is becoming A true Rep whorexUrban is becoming A true Rep whore
Thanks But I did not understand ...

You might be a little more clear Thanks alot ^ ^
xUrban is offline

Reply With Quote

Old 03-14-2010, 05:34 PM   #4


xUrban's Avatar

Threadstarter
Join Date: Mar 2010
Posts: 25
Reputation: 241
Rep Power: 0
xUrban is becoming A true Rep whorexUrban is becoming A true Rep whorexUrban is becoming A true Rep whore
Cool

unkonw thanks alot now understand how thanks for helping
xUrban is offline

Reply With Quote

Old 03-14-2010, 07:39 PM   #5
Administrator

Alkatraz's Avatar

Join Date: Nov 2004
Location: In your darkest Fears you will find me!
Posts: 5,318
Reputation: 62788
Rep Power: 822
Alkatraz has a huge epeen!Alkatraz has a huge epeen!Alkatraz has a huge epeen!Alkatraz has a huge epeen!Alkatraz has a huge epeen!Alkatraz has a huge epeen!Alkatraz has a huge epeen!Alkatraz has a huge epeen!Alkatraz has a huge epeen!Alkatraz has a huge epeen!Alkatraz has a huge epeen!
Points: 55,278, Level: 35
Points: 55,278, Level: 35 Points: 55,278, Level: 35 Points: 55,278, Level: 35
Activity: 41.4%
Activity: 41.4% Activity: 41.4% Activity: 41.4%
Last Achievements
Award-Showcase
Do a live dump. You'll have enough info to go on
__________________


Sexy Siggy By zero_tolerance





Alkatraz is online now

Reply With Quote

Old 03-14-2010, 08:26 PM   #6


xUrban's Avatar

Threadstarter
Join Date: Mar 2010
Posts: 25
Reputation: 241
Rep Power: 0
xUrban is becoming A true Rep whorexUrban is becoming A true Rep whorexUrban is becoming A true Rep whore
yeah thanks alot Alkatraz i understand now how code work after replaced
xUrban is offline

Reply With Quote

Old 03-14-2010, 09:55 PM   #7
Retired Administrator

Strife's Avatar

Join Date: Jul 2006
Posts: 1,414
Reputation: 21922
Rep Power: 316
Strife has reputation that takes up 2GB of server space!Strife has reputation that takes up 2GB of server space!Strife has reputation that takes up 2GB of server space!Strife has reputation that takes up 2GB of server space!Strife has reputation that takes up 2GB of server space!Strife has reputation that takes up 2GB of server space!Strife has reputation that takes up 2GB of server space!Strife has reputation that takes up 2GB of server space!Strife has reputation that takes up 2GB of server space!Strife has reputation that takes up 2GB of server space!Strife has reputation that takes up 2GB of server space!
Points: 20,553, Level: 19
Points: 20,553, Level: 19 Points: 20,553, Level: 19 Points: 20,553, Level: 19
Activity: 1.2%
Activity: 1.2% Activity: 1.2% Activity: 1.2%
Last Achievements
Here's a pretty good article that breaks down Code Virtualizer by Oreans.

NOTE: Not sure how up to date it is.

http://tuts4you.com/download.php?view.2640
__________________
Thanks zero_tolerance for the sig!
Strife is offline

Reply With Quote

Old 03-22-2010, 07:55 AM   #8
wav


wav's Avatar

Join Date: Mar 2010
Location: In hell with Satan.
Posts: 12
Reputation: 147
Rep Power: 0
wav is in the shadow of all hacking legendswav is in the shadow of all hacking legends
Dump the vm instructions and match them up to a handler then work through what each handler does to match to x86 opcode.

assuming they aren't encrypted or obstuficated w/e
wav is offline

Reply With Quote

Old 03-26-2010, 04:19 AM   #9


xUrban's Avatar

Threadstarter
Join Date: Mar 2010
Posts: 25
Reputation: 241
Rep Power: 0
xUrban is becoming A true Rep whorexUrban is becoming A true Rep whorexUrban is becoming A true Rep whore
now xD I will rebuild code like UnknowHacker Said
xUrban is offline

Reply With Quote

Old 03-31-2010, 10:52 PM   #10
Posting Well

E.T.'s Avatar

Join Date: Dec 2009
Posts: 29
Reputation: 1814
Rep Power: 44
E.T. -- If this mans rep is lowered; we will all dieE.T. -- If this mans rep is lowered; we will all dieE.T. -- If this mans rep is lowered; we will all dieE.T. -- If this mans rep is lowered; we will all dieE.T. -- If this mans rep is lowered; we will all dieE.T. -- If this mans rep is lowered; we will all dieE.T. -- If this mans rep is lowered; we will all dieE.T. -- If this mans rep is lowered; we will all dieE.T. -- If this mans rep is lowered; we will all dieE.T. -- If this mans rep is lowered; we will all dieE.T. -- If this mans rep is lowered; we will all die
If it's the same one I was dealt with, a trick you can do is break right before the jump that takes you into the virtual machine. After you break there, set a hardware breakpoint on a part of the memory that you know is going to be accessed or modified by the virtualized code and run into the virtual machine. You should break at the raw devirtualized code, which of course you can dump.

However, you must unpack to memory and do this. You can't use a dumped version as the virtual machine will be broken.
E.T. is offline

Reply With Quote
Reply  

  • Submit Thread to Digg
  • Submit Thread to del.icio.us
  • Submit Thread to StumbleUpon
  • Submit Thread to Google
  • Submit Thread to Facebook
  • Submit Thread to My Yahoo!
  • Submit Thread to MySpace
  • Submit Thread to Twitter
  • Submit Thread to Reddit

« Ida | Olly »


Tags
code, oreans, virtualizer
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT +1. The time now is 05:05 PM.