VMProfiler  v1.8
vmprofiler is a c++ library which is used to statically analyze VMProtect 2 polymorphic virtual machines. This project is inherited in vmprofiler-qt, vmprofiler-cli, and vmemu.
Classes | Namespaces | Macros | Typedefs | Functions
vmutils.hpp File Reference
#include <Zydis/Utils.h>
#include <Zydis/Zydis.h>
#include <optional>
#include <vector>
#include <xmmintrin.h>
#include <Windows.h>

Go to the source code of this file.


struct  zydis_instr_t


 utils used by the other cpp files... misc things that get used a lot...
 utils pertaining to native registers...


#define NOMINMAX


using u8 = unsigned char
using u16 = unsigned short
using u32 = unsigned int
using u64 = unsigned long long
using u128 = __m128
using zydis_decoded_instr_t = ZydisDecodedInstruction
using zydis_register_t = ZydisRegister
using zydis_mnemonic_t = ZydisMnemonic
using zydis_routine_t = std::vector< zydis_instr_t >


zydis_register_t vm::util::reg::to64 (zydis_register_t reg)
 converts say... AL to RAX... More...
bool vm::util::reg::compare (zydis_register_t a, zydis_register_t b)
 compares to registers with each other... calls to64 and compares... More...
bool vm::util::get_fetch_operand (const zydis_routine_t &routine, zydis_instr_t &fetch_instr)
 get the instruction that fetches an operand out of VIP... More...
std::optional< zydis_routine_t::iterator > vm::util::get_fetch_operand (zydis_routine_t &routine)
 gets the instruction that fetches an operand out of VIP and returns an iterator to it... More...
void vm::util::print (zydis_routine_t &routine)
 prints a disassembly view of a routine... More...
void vm::util::print (const zydis_decoded_instr_t &instr)
 prints a single disassembly view of an instruction... More...
bool vm::util::is_jmp (const zydis_decoded_instr_t &instr)
 determines if a given decoded native instruction is a JCC... More...
bool vm::util::flatten (zydis_routine_t &routine, std::uintptr_t routine_addr, bool keep_jmps=false)
 flatten native instruction stream, takes every JCC (follows the branch)... More...
void vm::util::deobfuscate (zydis_routine_t &routine)
 deadstore deobfuscation of a flattened routine... More...

Macro Definition Documentation


#define NOMINMAX

Typedef Documentation

◆ u128

using u128 = __m128

◆ u16

using u16 = unsigned short

◆ u32

using u32 = unsigned int

◆ u64

using u64 = unsigned long long

◆ u8

using u8 = unsigned char

◆ zydis_decoded_instr_t

using zydis_decoded_instr_t = ZydisDecodedInstruction

◆ zydis_mnemonic_t

using zydis_mnemonic_t = ZydisMnemonic

◆ zydis_register_t

using zydis_register_t = ZydisRegister

◆ zydis_routine_t

using zydis_routine_t = std::vector< zydis_instr_t >