Reverse Engineering RET Homepage RET Members Reverse Engineering Projects Reverse Engineering Papers Reversing Challenges Reverser Tools RET Re-Search Engine Reverse Engineering Forum Reverse Engineering Links

Go Back   Reverse Engineering Team Board > Reverse Engineering Board > .NET Reverse Engineering
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #1  
Old 10-24-2009, 04:38 AM
tease tease is offline
Junior Member
 
Join Date: Oct 2009
Posts: 3
Default How to fix file which packed by INTELLILOCK

Dears,
I got a trouble,
The file is packed by "INTELLILOCK", I can not find "BSJB" in dumped file. So I don't know how to fix it. any ideas?

http://www.filesend.net/download.php...5a1ffe863176ec

Last edited by tease : 10-24-2009 at 04:57 AM.
Reply With Quote
  #2  
Old 10-24-2009, 05:12 AM
Kurapica Kurapica is offline
Senior Member
 
Join Date: May 2006
Location: Archives
Posts: 357
Default

How did you know it's intellilock ?

besides it's not packed at all, I think it's protected with a new version of .NET reactor, and there is no need for dumping here.

search for some old tutors on .NET reactor.

good luck
__________________
Life can only be understood backwards but It must be read forwards.
Reply With Quote
  #3  
Old 10-24-2009, 06:51 AM
tease tease is offline
Junior Member
 
Join Date: Oct 2009
Posts: 3
Default

Thanks kurapica, I got lots of knowledge from your artiles in the past.


I am sure this file is protected by intellilock, beacause I use the intellilock to protect the file and I haven't choose the "License Generator" options in intellilock, So you cannot see the namespace like "IntelliLock.Licensing".

I really have no idea. Could you please give me some suggestions.

Last edited by tease : 10-26-2009 at 02:05 PM.
Reply With Quote
  #4  
Old 10-24-2009, 07:45 AM
Kurapica Kurapica is offline
Senior Member
 
Join Date: May 2006
Location: Archives
Posts: 357
Default

I can find that string without dumping :




Anyway If you can't find it in runtime then it could be an anti-dump trick, I suggest you check this address in runtime : 0x0040F730
__________________
Life can only be understood backwards but It must be read forwards.
Reply With Quote
  #5  
Old 10-24-2009, 09:10 AM
tease tease is offline
Junior Member
 
Join Date: Oct 2009
Posts: 3
Default

Thanks kurapica, I will try it.
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump





Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2023, Jelsoft Enterprises Ltd.