Reverse Engineering Team Board

Reverse Engineering Team Board (http://www.reteam.org/board/index.php)
-   .NET Reverse Engineering (http://www.reteam.org/board/forumdisplay.php?f=28)
-   -   help me unpack the exe (http://www.reteam.org/board/showthread.php?t=3102)

nifty 10-29-2010 11:56 AM

help me unpack the exe
 
hi,
can anybody unpack/deobfuscate the attached exe. also it would be great if you can describe the procedure on how to do it. i am a neophyte in this field :)

http://rapidshare.com/files/427806778/ODIN-AB.zip

thanks in advance,
Nifty.

ac!d 10-29-2010 07:58 PM

next time post some scan logs so people know what protection is used on the file they are downloading.

here is the Protection ID output:

Scanning ->.\ODIN-AB.exe
File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 762368 (0BA200h) Byte(s)
[File Heuristics] -> Flag : 00000000000001001100000000000000 (0x0004C000)
[!] dotNet Reactor v4.0 (or newer) protected !
[i] Setting: Native File Mode

[CompilerDetect] -> Visual C++ 9.0 (Visual Studio 2008)
- Scan Took : 0.187 Second(s) [0000000BBh tick(s)]


All times are GMT -4. The time now is 12:20 PM.

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2022, Jelsoft Enterprises Ltd.