[unpackme] Xheo Codeveil Unpackme


I?ve to say that I?ve no idea what to unpack here. I?ve bypassed the layers and a CALL EAX I think went to "OEP" or better said a call to a .NET function that executes the app....

Is this done then?


All of them that was on the hands sonny27 must be overcome...

*am i right, in writing english... :innocent: *


Edited by Apakekdah
Its a .net app so the unpacked copy should be loadable in .NET Reflector or any other .net decompiler,

and ofcource the file needs to be fully runnable :)

Send me ur unpacked copy when ur done ;)


LibX // RETeam

Hee bro how are u doing?! I never see u online anymore :(

We should have a chat on IRC some time :)

hehe i will back on irc soon

ive droped crackin for 2,5years now im trying to get back on tracks :)

but many new ****s came and this EXECRYPTOR makes me sick ;/

hi LibX,

I?ve reached OEP but my dump always refuses to run. I believe that I?ve fixed the Header correctly but it that this was not enough :(

Could you please help me unpacking this file?


Same here, finding OEP is very easy, for a short version just BP the Jump Dword right above the Entrypoint ;)

Anyway, I dumped and then fixed the header so at least it starts.

It immediately crashes with some .NET error message, bla bla...

I dont belive unpacking .NET is that easy, there are some tricks for sure, like magled meta data, dunno :/ Never unpacked .NET apps except for NsPack and even there I used one of the automatic .NET generic unpackers (which works pretty fine most of the time)...

You wouldnt have posted it if it was that easy, huh ? ;)

  • 3 weeks later...

Hehe I was lazy. Hex editor in your hands, and warm your seat up a bit, and you can code a xor packer in a day. Amazing that companies sell them for 2k.

I dont think LibX actually coded this himself ? Or did he ? :o

He coded the unpackme, but not the packer...

Anyway, if you dont mind you could share your source w/ the forum members, might help somebody...

No must, though... if you want to keep things private ;)

  • 2 weeks later...

Its not that hard if u take a little time to look closer at the stub ;)

And no i didn't code this packer myself :P thank god :P

  • 3 months later...

Hmm looked at the tutorial again. It only shows you how to get a dump, but not how to decrypt the MSIL, so the dump is non-functioning :|

