Author Topic: AutoIt3 Decompiler  (Read 13450 times)

0 Members and 1 Guest are viewing this topic.

October 24, 2007, 12:02:10 am
Read 13450 times

sowhat-x

  • Guest
http://maghia.free.fr/Board/viewtopic.php?t=234

Useful to keep an eye on this thread...from time to time,
cw2k posts newer versions of his decompiler there...it's open source also.  :)

Note though that the..."AutoIt people",
weren't happy at all learning about the abilities of this tool:
they actually banned/removed the whole thread in their forums regarding it.
Fairly understandable from their own point of view...in the final end,
who doesn't want to protect his code and intellectual properties etc.
But well,there are also other problems to be solved in this world as well...  :D

October 24, 2007, 03:49:26 pm
Reply #1

bobby

  • Special Members
  • Hero Member

  • Offline
  • *

  • 322
    • Malzilla
Is it updated to extract the files too?
The version I have extracts only the script.

October 25, 2007, 06:14:04 am
Reply #2

sowhat-x

  • Guest
...to be honest,bobby,I haven't had the opportunity to 'play' around with the latest version yet...
so I just archived both v1.8 and v1.9 in case their needed...
I also had a very older one somewhere here that "simply" extracted the script...

The .7z archive of the v1.9 comes with a few samples as well,I'll probably give it a try in the next days....
What I see though,is that except from obviously updating it to deal with newer versions,
he has also added support for a couple of custom-made AutoIt obfuscators...

November 03, 2007, 03:58:58 am
Reply #3

sowhat-x

  • Guest
...he-he,seems like cw2k is quite busy...  :D
He just released a decompiler/unpacker for "Quick Batch File Compiler",
sources in Delphi also available... :)

http://maghia.free.fr/Board/viewtopic.php?t=855

...I had heard of Quick Batch File Compiler,wasn't aware of ScriptCryptor though...
anyone that has came across samples made with them?
I'll try getting a copy in order to have a look,figure out PEiD sigs or so if needed...
===========================
bobby,I had the opportunity tonight,
of playing a bit around with cw2k's AutoIt decompiler (v1.92)...
I tested it against an AutoHotKey-based malware (not AutoIt),and well,
at least in my case,it successfully extracted all the embedded executables...  :)

November 03, 2007, 05:40:41 am
Reply #4

bobby

  • Special Members
  • Hero Member

  • Offline
  • *

  • 322
    • Malzilla
Aaa, what a nice morning :D
Coffee + good news = excellent mood.

Thanks. 

May 16, 2008, 03:36:28 pm
Reply #5

sowhat-x

  • Guest