Quote:
Originally Posted by 0xNOP
Hello,
Basically I'm initiating myself on VMProtect because someone came to me looking for help to see if I could help him reversing a program ...
The thing is, that I need some pointers on how to work with VMProtect,...
I will really appreciate any help anyone could bring to me and aid me on this clash of protected code vs reversing.
|
Hello friend,
Since you have not mentioned it, I believe that you are not familiar with
LCF-AT's scripts and concepts for unwrapping VMP.
See here :
https://forum.tuts4you.com/topic/30733-vmprotect-ultra-unpacker-10/
You need to register on the forum (for free).
I think that the scripts can still work on VMP v3 as well but definitely, the CONCEPTS etc of VM Protect can be learned very well by watching her videos.
They will help you immensely in your unpacking quest !
Another EXCELLENT paper on this topic, titled "Unpacking Virtualization Obfuscators" can be found here :
http://static.usenix.org/event/woot09/tech/full_papers/rolles.pdf
Good luck