首页
社区
课程
招聘
[求助]一个.Net Reactor的壳
2016-12-10 23:21 17209

[求助]一个.Net Reactor的壳

2016-12-10 23:21
17209
一个.Net程序,查出来是.Net Reactor,直接用Reflector打开显示“索引超出了数组界限”,de4dot脱不掉。OD直接打不开。

这个程序之前的版本都是我自己脱壳破解的,但是因为基础薄弱能力有限,再加上作者不断更新,到这个版本终于还是一个人解决不了了。但是以后我还是想尽量靠自己的能力破解。所以还是希望大神们能够尽量详细地说明一下方法,我将感激不尽!



[培训]《安卓高级研修班(网课)》月薪三万计划,掌握调试、分析还原ollvm、vmp的方法,定制art虚拟机自动化脱壳的方法

上传的附件:
收藏
免费 0
打赏
分享
最新回复 (40)
雪    币: 62
活跃值: (36)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
小小小青年 2016-12-11 14:14
2
0
很明显这是reactor5.x 你需要去de4作者博客下载最新的源码编译
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-11 14:40
3
0
吾爱破解上好像有针对5.0的de4dot,但是我没有账号。能发给我一份吗
雪    币: 452
活跃值: (205)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
yinhuo 2016-12-11 19:18
4
0
http://www16.zippyshare.com/v/K0f1KuLg/file.html
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-11 20:47
5
0
谢谢。不过好像还是不行。

de4dot v3.1.41592.3405 Copyright (C) 2011-2015 de4dot@gmail.com
Latest version and source code: https://github.com/0xd4d/de4dot

== Support .Net Reactor5.0.0.0 Fixed By Wuhensoft ==

Args:
  "m.exe"
  "-vv"
  1: Unknown
  0: Agile.NET
  0: Babel .NET
  0: CodeFort
  0: CodeVeil
  0: CodeWall
Deobfuscating control flow: System.Void <Module>::.cctor() (06000001)
Deobfuscating control flow: System.Void <Module>::???  ??????() (06000002)
  0: Confuser
  0: Crypto Obfuscator
Deobfuscating control flow: System.Void <Module>::.cctor() (06000001)
  0: DeepSea
  0: Dotfuscator
  0: .NET Reactor 3.x
Deobfuscating control flow: System.String ???  ??????.???  ??????::???  ??????(S
ystem.Int32) (060016A1)
Deobfuscating control flow: System.Void <PrivateImplementationDetails>{D79237C7-
8508-4364-A19F-2553A2C89ED7}::Main() (060017E3)
Deobfuscating control flow: System.Void <PrivateImplementationDetails>{D79237C7-
8508-4364-A19F-2553A2C89ED7}::.cctor() (060017E6)
110: .NET Reactor 4.x
  0: Eazfuscator.NET
  0: Goliath.NET
  0: ILProtector
  0: MaxtoCode
  0: MPRESS
  0: Rummage
  0: Skater .NET
  0: SmartAssembly
  0: Spices.Net
  0: Xenocode
Detected .NET Reactor (F:\de4dot-Support.Reactor5.0-wuhensoft\m.exe)
Cleaning F:\de4dot-Support.Reactor5.0-wuhensoft\m.exe
Deobfuscating control flow: System.Void ???  ??????.???  ??????::???  ??????() (
060016AB)
WARNING: Could not find method having code RVA 00002089
WARNING: Could not find method having code RVA 00002091
WARNING: Could not find method having code RVA 00002099
WARNING: Could not find method having code RVA 000020A1
WARNING: Could not find method having code RVA 000020A9
WARNING: Could not find method having code RVA 000020B9
WARNING: Could not find method having code RVA 000020C1
WARNING: Could not find method having code RVA 000020C9
WARNING: Could not find method having code RVA 000020D1
WARNING: Could not find method having code RVA 000020E1
WARNING: Could not find method having code RVA 000020E9
WARNING: Could not find method having code RVA 000020F1
WARNING: Could not find method having code RVA 000020F9
WARNING: Could not find method having code RVA 00002101
WARNING: Could not find method having code RVA 00002111
WARNING: Could not find method having code RVA 00002119
WARNING: Could not find method having code RVA 00002121
WARNING: Could not find method having code RVA 00002129
WARNING: Could not find method having code RVA 00002139
WARNING: Could not find method having code RVA 00002141
WARNING: Could not find method having code RVA 00002149
WARNING: Could not find method having code RVA 00002151
WARNING: Could not find method having code RVA 00002159
WARNING: Could not find method having code RVA 00002169
WARNING: Could not find method having code RVA 00002171
WARNING: Could not find method having code RVA 00002179
WARNING: Could not find method having code RVA 00002181
WARNING: Could not find method having code RVA 00002189
WARNING: Could not find method having code RVA 00002199
WARNING: Could not find method having code RVA 000021A1
WARNING: Could not find method having code RVA 000021A9
WARNING: Could not find method having code RVA 000021B1
WARNING: Could not find method having code RVA 000021B9
WARNING: Could not find method having code RVA 000021C1
WARNING: Could not find method having code RVA 000021C9
WARNING: Could not find method having code RVA 000021D1
WARNING: Could not find method having code RVA 000021D9
WARNING: Could not find method having code RVA 000021E1
WARNING: Could not find method having code RVA 000021FC
WARNING: Could not find method having code RVA 0000220C
WARNING: Could not find method having code RVA 0000221C
WARNING: Could not find method having code RVA 0000222C
WARNING: Could not find method having code RVA 0000223C
WARNING: Could not find method having code RVA 0000224C
WARNING: Could not find method having code RVA 0000225C
WARNING: Could not find method having code RVA 0000226C
WARNING: Could not find method having code RVA 0000228C
WARNING: Could not find method having code RVA 000022AC
WARNING: Could not find method having code RVA 000022CC
WARNING: Could not find method having code RVA 000022EC
WARNING: Could not find method having code RVA 0000230D
WARNING: Could not find method having code RVA 00002315
WARNING: Could not find method having code RVA 0000231D
WARNING: Could not find method having code RVA 00002325
WARNING: Could not find method having code RVA 0000232D
WARNING: Could not find method having code RVA 00002335
WARNING: Could not find method having code RVA 0000233D
WARNING: Could not find method having code RVA 00002345
WARNING: Could not find method having code RVA 0000234D
WARNING: Could not find method having code RVA 00002355
WARNING: Could not find method having code RVA 0000235D
WARNING: Could not find method having code RVA 00002365
WARNING: Could not find method having code RVA 0000236D
WARNING: Could not find method having code RVA 00002375
WARNING: Could not find method having code RVA 0000237D
WARNING: Could not find method having code RVA 00002385
WARNING: Could not find method having code RVA 0000238D
WARNING: Could not find method having code RVA 000023A5
WARNING: Could not find method having code RVA 000023AD
WARNING: Could not find method having code RVA 000023B5
ERROR:
ERROR:
ERROR:
ERROR: -------------------------------------------------------------------------
-----
ERROR: Stack trace:
ERROR:    在 de4dot.code.deobfuscators.MethodBodyParser.ParseMethodBody2(IBinary
Reader reader, Byte[]& code, Byte[]& extraSections)
ERROR:    在 de4dot.code.deobfuscators.MethodBodyParser.ParseMethodBody(IBinaryR
eader reader, Byte[]& code, Byte[]& extraSections)
ERROR:    在 de4dot.code.deobfuscators.dotNET_Reactor.v4.MethodsDecrypter.Decryp
t(MyPEImage peImage, ISimpleDeobfuscator simpleDeobfuscator, DumpedMethods& dump
edMethods, Dictionary`2 tokenToNativeCode, Boolean unpackedNativeFile)
ERROR:    在 de4dot.code.deobfuscators.dotNET_Reactor.v4.Deobfuscator.GetDecrypt
edModule(Int32 count, Byte[]& newFileData, DumpedMethods& dumpedMethods)
ERROR:    在 de4dot.code.ObfuscatedFile.Deobfuscate()
ERROR:    在 de4dot.cui.FilesDeobfuscator.DeobfuscateAllFiles(IEnumerable`1 allF
iles)
ERROR:    在 de4dot.cui.FilesDeobfuscator.DeobfuscateAll()
ERROR:    在 de4dot.cui.FilesDeobfuscator.DoIt()
ERROR:    在 de4dot.cui.Program.Main(String[] args)
ERROR:
ERROR:
ERROR: Caught an exception:
ERROR:
ERROR: -------------------------------------------------------------------------
-----
ERROR: Message:
ERROR:   引发类型为“de4dot.code.deobfuscators.InvalidMethodBody”的异常。
ERROR: Type:
ERROR:   de4dot.code.deobfuscators.InvalidMethodBody
ERROR: -------------------------------------------------------------------------
-----
ERROR:
ERROR: Try the latest version!
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-12 22:02
6
0
有大神能教我手动脱也行啊
雪    币: 504
活跃值: (10)
能力值: ( LV3,RANK:30 )
在线值:
发帖
回帖
粉丝
crackdung 2016-12-14 13:14
7
0
文件呢?
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-14 17:49
8
0
最顶上,A.ZIP那个
雪    币: 504
活跃值: (10)
能力值: ( LV3,RANK:30 )
在线值:
发帖
回帖
粉丝
crackdung 2016-12-15 11:24
9
0
我用的de4dot修改版,得到这个,希望能帮到你

A1.rar
上传的附件:
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-15 21:48
10
0
[QUOTE=crackdung;1457302]我用的de4dot修改版,得到这个,希望能帮到你

A1.rar[/QUOTE]

看上去好像不行,不过还是谢谢了。
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-17 14:01
11
0
还有谁能破啊
雪    币: 33
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
QYDZA 2016-12-17 20:41
12
0
楼主的问题解决了吗?我现在也遇到这样的问题
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-18 07:32
13
0
还没有……
雪    币: 0
活跃值: (11)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
tjrichter 2016-12-18 08:46
14
0
东西发来试试
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-18 10:18
15
0
最上面A.ZIP
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-20 21:50
16
0
谁有办法破啊
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-21 22:07
17
0
我只需要改两处代码,有可能不需要脱壳,直接用dnspy。但是目前我还没时间来试验
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-23 23:20
18
0
壳已经可以脱掉了,但是不能完美运行……直接丢dnspy好像不行
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-25 12:16
19
0
遇到了这种问题
WARNING: Could not find all arguments to method System.String ???  ??????.???  ??????::???  ??????(System.Int32) (060016A3), instr: IL_000F: ldarg
该怎么办?
雪    币: 255
活跃值: (252)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
釜森 2016-12-26 12:55
20
0
试一下不知可用?
上传的附件:
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-26 23:40
21
0
谢谢!的确可以!
请问怎么做到的?
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-28 13:00
22
0
能把详细方法告诉我吗?
雪    币: 255
活跃值: (252)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
釜森 2016-12-28 13:09
23
0
用的是de4dot3.1.41592改进版加参数,具体你可试,再详细了,估计下一版本就没有办法了
雪    币: 197
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
HeXacker 2016-12-28 13:11
24
0
我试过了,有可能不是github上的版本。麻烦您发过来一份吧
雪    币: 255
活跃值: (252)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
釜森 2016-12-28 13:26
25
0
具体哪一个,我记不清了,我一共在网上下了3个,只有一个行。你加的什么参数?
游客
登录 | 注册 方可回帖
返回