lkou 发表于 2011-3-11 12:11

VMSweeper v1.4 beta 10

Added:
1. Improved layout is completely erased IAT.
2. Improved detection of the names of API functions.
3. Resizing Virtual Segment intermediate code (VMS size option in the ini file).
4. Tracking the memory contents and the entire stack to create intermediate code.
5. Improved devirtualization conditional jumps.
6. Code analyzer detects two types of code: a clean and obfuscate. They were previously in the group "Cancelled".
7. Devirtualization instruction sub esp without flags.
8. Processing of the entry to VM type call xx (can decompile any intermediate input in the VM).
9. Automatic mode code analysis VM. Go to this mode on demand after the first restart the application.
Code obtained in this mode can be worse than the code obtained in manual mode (Ctrl+F2 -> -> Shift+F1), but
allows you to quickly check whether the decompiled code. In this mode works only static code analyzer.
Fixed:
1. Processing of transit (blank) out of the VM.
2. Fixed exception when restoring compliance VM registers and CPU.
3. Determining the number of arguments obfuscate function.
4. Pikode can be detected in any segment of the analyzed application.

Hmily 发表于 2011-3-11 12:20

http://www.52pojie.cn/forum-redirect-goto-findpost-ptid-80613-pid-1672952.html我是在之前帖子里更新的.

lkou 发表于 2011-3-11 12:24

老大那你帖子标题改改吧,要不别人都不知道。。。

Hmily 发表于 2011-3-11 12:58

回复 lkou 的帖子

就留着你这个吧.

bobo53051 发表于 2011-3-13 21:51

lkou 大牛这个是对VM的插件吗?暂时不会用先下载了保留一份了。{:1_912:}

yjd333 发表于 2011-3-15 13:51

一直不懂得怎么用,唉!
页: [1]
查看完整版本: VMSweeper v1.4 beta 10