Help, Can anyone deobfuscate this..
i am a beginner and tried to deobfuscate this, but unable to find the obfust\cator used for this.. can some help me to deobfuscate this..
Show us what work you have done yourself in trying to solve your problem.
Hey git, could you please remove my double topic post "Unknown obfuscator, cant deobfuscate myself"!
Vinsak -> You could have atleast post the EXE and not a link to the install file. Im sure nobody really wants to install some random software in an attempt to help you deobfuscate/unpack it.
Anyways, I got down to your dirty work for you.
This exe (ManshiRT.exe) is obfuscated using a generic/custom obfuscator. It seems that method names have been obfuscated. This application should be fairly easy to reverse, considering that its not been packed and doesnt run in a VM. There is a resource file with some encrypted strings.
There is a method in the exe for decrypting these strings.
Your software uses NETZ as a packer and something (not sure what exactly) as obfuscator. TehAvatar posted strings from packer layer so they are quite useless..
The interesting stuff is packed. Use any generic .NET dumper to unpack it and then analyze unpacked files. ;)
It's protected with SmartAssembly, or at least uses the same
renaming and strings encryption styles.
here is the clean file : http://archiv.to/GET/FILE4C45A89C61112
[Please DO NOT reply to yourself. If you have info to add then use the Edit button to add it to you previous post]
thanks for the unpacked file.
was someone able to reverse it completely.....not able to remove its limitations.
im using a .net reflector & chking each file & dll in the unpacked/clean file gvn above.
mi on right track?
|All times are GMT -4. The time now is 10:53 AM.|
Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2022, Jelsoft Enterprises Ltd.