Reverse Engineering RET Homepage RET Members Reverse Engineering Projects Reverse Engineering Papers Reversing Challenges Reverser Tools RET Re-Search Engine Reverse Engineering Forum Reverse Engineering Links

Go Back   Reverse Engineering Team Board > Reverse Engineering Board > File Unpacking
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #1  
Old 11-15-2011, 01:40 PM
NewbieHere NewbieHere is offline
Junior Member
 
Join Date: Nov 2011
Posts: 3
Default [Help] Packed file cant be unpacked

Hi guys,

I have an .exe file. It works good and so on.
In previous versions it was packed with UPX, but since the last Update everything fails, nothing can unpack it, but it is 100% packed

PEiD says: Nothing found [Overlay] *

Here Ive uploaded the .exe
Hope someboby here can unpack it

thx in anvance
Reply With Quote
  #2  
Old 11-15-2011, 02:19 PM
kao kao is offline
Senior Member
 
Join Date: Sep 2007
Posts: 184
Default

Packed with Themida.
Reply With Quote
  #3  
Old 11-15-2011, 02:20 PM
handy1234 handy1234 is offline
Member
 
Join Date: Sep 2011
Posts: 25
Default hello

try to scan in Protection id v6.4 latest it will say something right
Reply With Quote
  #4  
Old 11-15-2011, 02:21 PM
NewbieHere NewbieHere is offline
Junior Member
 
Join Date: Nov 2011
Posts: 3
Default

And gow can I unpack it, or is there any chance of unpacking it?

Can you do it if you can would be great
Reply With Quote
  #5  
Old 11-15-2011, 02:25 PM
handy1234 handy1234 is offline
Member
 
Join Date: Sep 2011
Posts: 25
Default hello

-=[ ProtectionID v0.6.4.0 JULY]=-
(c) 2003-2010 CDKiLLER & TippeX
Build 07/08/10-17:57:05
Ready...
Scanning -> C:\Users\Admin\Downloads\Programs\metin2client.exe
File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 2417972 (024E534h) Byte(s)
-> File Appears to be Digitally Signed @ Offset 024B000h, size : 01348h / 04936 byte(s)
-> File has 8684 (021ECh) bytes of appended data starting at offset 024C348h
[File Heuristics] -> Flag : 00000000000000001100000000110111 (0x0000C037)
[!] Themida v2.0.1.0 - v2.1.2.0 (or newer) detected !
[i] Hide PE Scanner Option used
- Scan Took : 0.875 Second(s)
Reply With Quote
  #6  
Old 11-15-2011, 02:37 PM
NewbieHere NewbieHere is offline
Junior Member
 
Join Date: Nov 2011
Posts: 3
Default

OK, it is packed with Themida thats now clear.

But does anyone here knows how to unpack it? I need the unpacked file for debugging it then
Reply With Quote
  #7  
Old 11-16-2011, 09:27 AM
handy1234 handy1234 is offline
Member
 
Join Date: Sep 2011
Posts: 25
Default hello

pm me the link
Reply With Quote
  #8  
Old 11-27-2011, 11:25 AM
star.love91 star.love91 is offline
Member
 
Join Date: Mar 2011
Posts: 24
Default plz unpack exe is packed by themida

who has tutorials how to unpack all protects dlls, exe

Last edited by star.love91 : 12-04-2011 at 03:17 AM.
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump





Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2020, Jelsoft Enterprises Ltd.