Reverse Engineering RET Homepage RET Members Reverse Engineering Projects Reverse Engineering Papers Reversing Challenges Reverser Tools RET Re-Search Engine Reverse Engineering Forum Reverse Engineering Links

Go Back   Reverse Engineering Team Board > Reverse Engineering Board > File Unpacking
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #1  
Old 09-15-2011, 02:19 PM
resac resac is offline
Member
 
Join Date: Jun 2011
Posts: 41
Default Unknown Protection

Hello to all..
i am not getting what type of protection is this file having. please seniors help me to find this protection. and mainly this application is developed in VB..

link --> http://www.mediafire.com/?92b5u3b2a17nfjo

Thank you in advance
Reply With Quote
  #2  
Old 09-16-2011, 10:18 AM
ac!d ac!d is offline
Member
 
Join Date: Sep 2010
Posts: 25
Default

Scanning -> .\BM_FORAIR.exe
File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 7823360 (0776000h) Byte(s)
[File Heuristics] -> Flag : 00000000000000001100000000100010 (0x0000C022)
[!] Themida v2.0.1.0 - v2.1.8.0 (or newer) detected !
[i] Hide PE Scanner Option used

- Scan Took : 0.734 Second(s) [0000002DEh tick(s)]
Reply With Quote
  #3  
Old 09-16-2011, 12:42 PM
resac resac is offline
Member
 
Join Date: Jun 2011
Posts: 41
Default

thanks brother. But which sacner you used?
Reply With Quote
  #4  
Old 09-16-2011, 09:49 PM
ac!d ac!d is offline
Member
 
Join Date: Sep 2010
Posts: 25
Default

Protection ID
Reply With Quote
  #5  
Old 09-16-2011, 11:48 PM
resac resac is offline
Member
 
Join Date: Jun 2011
Posts: 41
Default

even used Protection id but it said unknown protection. and how to unpack this brother?
Reply With Quote
  #6  
Old 09-18-2011, 11:05 AM
ac!d ac!d is offline
Member
 
Join Date: Sep 2010
Posts: 25
Default

a new protection id will be out soon (atm we are still beta testing some things), so every one gets the latest detections

about the protection... read up some themida tutorials and also give the olly scripts on tuts4you a try. well documented stuff
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump





Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2022, Jelsoft Enterprises Ltd.