![]() |
![]() |
![]() |
![]() |
![]() |
||||||||||
|
||||||||||||||
![]() |
#1
|
|||
|
|||
![]() hi,
can anybody unpack/deobfuscate the attached exe. also it would be great if you can describe the procedure on how to do it. i am a neophyte in this field ![]() http://rapidshare.com/files/427806778/ODIN-AB.zip thanks in advance, Nifty. |
#2
|
|||
|
|||
![]() next time post some scan logs so people know what protection is used on the file they are downloading.
here is the Protection ID output: Scanning ->.\ODIN-AB.exe File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 762368 (0BA200h) Byte(s) [File Heuristics] -> Flag : 00000000000001001100000000000000 (0x0004C000) [!] dotNet Reactor v4.0 (or newer) protected ! [i] Setting: Native File Mode [CompilerDetect] -> Visual C++ 9.0 (Visual Studio 2008) - Scan Took : 0.187 Second(s) [0000000BBh tick(s)] |