Posted December 27, 201410 yr [unPackMe] Simple .NET Unpack Me Protected with a private version of my .NET protector. If you can unpack write a tutorial! Edited October 25, 20168 yr by CodeCracker Removed attachement: sorry!
January 13, 201510 yr here is my unpacked file @abcd how did you fix the strings? (i used a lame way ,by using windbg to dump strings )Unpacked.rar
February 19, 201510 yr Didn't meant to bump an old thread but CodeCracker clearly exhorted those who achieved the unpacking of this to write a tutorial, probably for better understanding of those who are like me that don't have enough understanding could then understand how to approach better ways of unpacking... Kindest Regards,ULI-R0
April 6, 201510 yr here is my unpacked file @abcd how did you fix the strings? (i used a lame way ,by using windbg to dump strings ) Unfortunately your exe ripped from 2nd post as proved the res "SimpleUnpackMe.MainForm.resources" was my rename because de4dot rename was ns0,class0.resources You just remove two namespace and all anti method from my exe and rebuild by visual studio , Ripper should get ban , i can prove evidence that his posted exe ripped , i can see that . Original embeded dumped exe no had version info which i see clear he ripped the second post exe. the string restored in original dumped exe by key " 0 1 2 .. . xd fake : " (i used a lame way ,by using windbg to dump strings )" Edited April 6, 201510 yr by Death
April 6, 201510 yr Unfortunately your exe ripped from 2nd post as proved the res "SimpleUnpackMe.MainForm.resources" was my rename because de4dot rename was ns0,class0.resources You just remove two namespace and all anti method from my exe and rebuild by visual studio , Ripper should get ban , i can prove evidence that his posted exe ripped , i can see that . Original embeded dumped exe no had version info which i see clear he ripped the second post exe. the string restored in original dumped exe by key " 0 1 2 .. . xd fake : " (i used a lame way ,by using windbg to dump strings )" you retard do you think that you are the only one able to unpack a .net unpackme! just fix MetaDataHeader and you will find file table (same as Confuser)! get embd file and fix couple things like the target architecture in file header...etc,then use ModuleToAssembly you can get the resource and strings by setting breakpoint at AppDomain.CurrentDomain.SetData or you can find them in overlay of the file now can you shut up ? Edited April 6, 201510 yr by n0th!ng
April 6, 201510 yr i never said i can do that , it simple all man can do that , but i just see you are the one posted the file is proper ripped , because you file res and my file res is same so i no need explain more , xd can you provide the command you used in windbg ?and can you explain about it why it res name as same mine there should be 3 res and explain about it the res rename .
April 6, 201510 yr i never said i can do that , it simple all man can do that , but i just see you are the one posted the file is proper ripped , because you file res and my file res is same so i no need explain more , xd can you provide the command you used in windbg ? and can you explain about it why it res name as same mine there should be 3 res and explain about it the res rename . for that you question you can answer by yourself look at this (in method's token: 0x06000040) AppDomain.CurrentDomain.SetData("SimpleUnpackMe.MainForm.resources", data); any way i won't provide any further information because i don't see any need for that and for the second time you suspect me for nonsense reason , do you have a problem with me ? Edited April 6, 201510 yr by n0th!ng
April 6, 201510 yr oh my gosh.... what's wrong with you ..@abcd @n0th!ng...... This is a communication platform ... The most important thing is to learn from each other..... Edited April 6, 201510 yr by 381400744
Create an account or sign in to comment