View Single Post
Old 05-03-2008, 08:24 AM
bigmouse bigmouse is offline
Senior Member
Join Date: Sep 2007
Posts: 125

its library mode decrypted the whole assembly at once.
the only problem is , after decrypted, its also wiped some header values.
we can use disk image to fixthe memory image .
after fixed, dump memory section.

seems to .net reactor itself using a diffent protection type.
it only decrypt one type each time, but also can by easily unpacked.

here is the unpacked file of its latest version v3.7.9.1
interest in .NET Reverse Engineering.

.Net Assembly Rebuilder - a tool to rebuild dumped assemblies.
Re-Max - a tool to unpack maxtocode protected assemblies.
Reply With Quote