Jump to content
Tuts 4 You

ConfuserEx Light Test


Go to solution Solved by Mr-Toms,

Recommended Posts

Posted

Language : C#
Platform : Windows
OS Version : Windows 7 Above
Packer / Protector : ConfuserEx Plus Extra

Description :

Provide key, how?

Capture.JPG.ab29c5f5c9d6168b3d5169b2e45a1ddb.JPG.jpeg.f2b2cb7b186ab3830cd5c52e60790b7c.jpeg

UnPackMe.7z

  • Like 2
Posted (edited)

For unpacking

1) cawk unpacker
2) dump after decryption
3) fix EP
4) Proxy call fixer by Davicore
5) Strings decryptor by CC
6) Switch killer by CC
7) Dump resources (empty)
😎 Clean cctor and <module>methods

(maybe 4, 5 and 6 can be replaced by cawk unpacker again)

I will check the key algo tomorrow, don't have time now.

a29p-EP-anti2_noproxy_stringdec-cleaned_deobfuscated-res2-cctor-module.exe

 

--------------------------------------------------------

 

Username = "Usuario"

Code = "161308"

int length = username.length();
int num2 = length + 2 - 4 + 40 + 10;
return Convert.ToString(419 * num2 * length - length);

 

---------------------------------------------------

 

EDIT2: I have received a few PMs asking how to fix EP, so I will post the videos I used as reference here. Following this 2 videos you should be able to unpack confuserex fully.

 

 

Edited by cachito
Add result
  • Like 6
  • 4 weeks later...
  • 2 years later...
  • Solution
Posted

First thing you need to do is know what protection used on the .exe

so as we can see its use compressor and my step isnt debugging it manually
to grab original .exe

my step is 
1. i always use ManagedJiterFr4 to grab original .exe 
drag n drop then press execute then continue and you will see the original exe there its renamed to a29p
2. then press set asm then save asm 
3. goto dnspy to remove the Tamper ( you can do it manually , theres alot of tutorial on YT)
4. after you remove the tamper dont forget to set the right Entry Point , Luckily in this case theres no renamer used in Namespace so we can easily choose the right EP)
5. Then you should remove Ref Proxy ( you can use any proxy call fixer )
6. and you should remove CFlow ( use universal cfex cflow remover )
7. Decrypt string using ConstantDec by CS

and i think theres error on Activate Button ? it doesnt show anything when we put wrong key / the right key

 

koi_NoTamp_FixEP_NoProxy_NoCFlow-ConstantDec.exe

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...