Contribute  :  Web Resources  :  Past Polls  :  Site Statistics  :  Downloads  :  Forum  
    BiW ReversingThe challenge is yours    
 Welcome to BiW Reversing
 Sunday, April 02 2023 @ 10:24 AM CEST
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Help please to unpack this file

 
Post new topic   Reply to topic    www.reversing.be Forum Index -> Unpacking
View previous topic :: View next topic  
Author Message
doshka
New to the board
New to the board


Joined: 17 Apr 2008
Posts: 4

PostPosted: Fri Apr 18, 2008 12:12 pm    Post subject: Help please to unpack this file Reply with quote

Please can any one give help to unpack this file, i try all the tools i know but i cant able to unpack this file
you will find the link to the file in attachment
thanks



url.txt
 Description:
url to the file

Download
 Filename:  url.txt
 Filesize:  37 Bytes
 Downloaded:  1541 Time(s)

Back to top
View user's profile Send private message
Nacho_dj
Frequent poster
Frequent poster


Joined: 03 Jan 2006
Posts: 52

PostPosted: Sat Apr 19, 2008 11:35 am    Post subject: Reply with quote

Hello:

Could I know which tools have you used to try to unpack it?

Cheers

Nacho_dj

_________________
http://arteam.accessroot.com
Back to top
View user's profile Send private message Visit poster's website
doshka
New to the board
New to the board


Joined: 17 Apr 2008
Posts: 4

PostPosted: Sat Apr 19, 2008 12:43 pm    Post subject: Reply with quote

i try RL!dePacker and PEiD_v0.9
PEiD give me "Nothing found *" as a result, i try a hard core scan and the result was "UPX 0.89.6 - 1.02 / 1.05 - 1.24 -> Markus & Laszlo" but i still cant unpack the orginal file even if i use UPX
and the result was not good..
thanks
Back to top
View user's profile Send private message
Nacho_dj
Frequent poster
Frequent poster


Joined: 03 Jan 2006
Posts: 52

PostPosted: Sun Apr 20, 2008 4:42 pm    Post subject: Reply with quote

There are many packer detectors:
- RDG Packer Detector
- PE Detective (CFF Explorer Suite)
- ProtectionID
- A-Ray Scanner
...

If PE Id doesn't provide any clue, for sure any of these will do it...

Cheers

Nacho_dj

_________________
http://arteam.accessroot.com
Back to top
View user's profile Send private message Visit poster's website
doshka
New to the board
New to the board


Joined: 17 Apr 2008
Posts: 4

PostPosted: Sun Apr 20, 2008 6:24 pm    Post subject: Reply with quote

dear Nacho_dj thanks for your help
in fact i try many many tools and all the tools you list it i try it all but i cant even finde the OEP ..
cuz of that i attache the file to check it by your self or any one want to help

thanks again
Back to top
View user's profile Send private message
Nacho_dj
Frequent poster
Frequent poster


Joined: 03 Jan 2006
Posts: 52

PostPosted: Tue Apr 22, 2008 7:46 am    Post subject: Reply with quote

Ok, when tools don't help, there is a way: doing by ourselves.

What have you tried about debugging it? Have you got a clean dump?

_________________
http://arteam.accessroot.com
Back to top
View user's profile Send private message Visit poster's website
doshka
New to the board
New to the board


Joined: 17 Apr 2008
Posts: 4

PostPosted: Tue Apr 22, 2008 11:04 am    Post subject: Reply with quote

I try to dump the file and debug it but the problem that i cant found the OEP
thanks
Back to top
View user's profile Send private message
Nacho_dj
Frequent poster
Frequent poster


Joined: 03 Jan 2006
Posts: 52

PostPosted: Tue Apr 22, 2008 11:42 am    Post subject: Reply with quote

Have you tried setting a breakpoint when accessing to code section? This could be performed with ALT+M and then selecting the first section in your executable and then pushing F2 key to activate the breakpoint.

Normally it should enter in that section through the OEP...

_________________
http://arteam.accessroot.com
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    www.reversing.be Forum Index -> Unpacking All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group
 Copyright © 2023 BiW Reversing
 All trademarks and copyrights on this page are owned by their respective owners.
Powered By Geeklog 
Created this page in 0.90 seconds