Posted July 10, 200718 yr This is my first unpackme.. The exe protected with KERIS protector.... Maybe is very easy ... UnPackMe_1.rar
July 10, 200718 yr It crashes when I try to execute it However at a quick glance it looks like the main part of the file is a crypted overlay with a loader to decrypt it - am I correct? Is Keris a new team packer/protector, I have never heard of it before, where to get it? Ted.
July 10, 200718 yr Crashes for me too but not looked into it.pavka's unpacked one works fine though. The skin is indeed nice - the work of JetCodE! from ICU.
July 10, 200718 yr Smal script1 Layer//////////////////////////////////////////////var rgnvar szGPA "VirtualAlloc","kernel32.dll"bp $RESULTrunBC eiprturtrstiFIND eip,#6681384D5A#bp $RESULTrunbc eipmov rgn,eaxfind rgn,#5045#mov sz,$RESULTadd sz,50mov sz,[sz]eval " damp partial in LordPe select IntelDump address:{rgn} , size:{sz}"msg $RESULTret////////////////////////////////////////////////2 Layer////////////////////////////////////////////////var rgnvar szGPA "VirtualAlloc","kernel32.dll"bp $RESULTrunBC eiprtuFIND eip,#F3A4#bp $RESULTrunbc eipmov rgn,esifind rgn,#5045#mov sz,$RESULTadd sz,50mov sz,[sz]dm rgn, sz, "dump.exe"Msg "File Unpacked!"ret
July 10, 200718 yr Seems the only requirement is run it in a debugger, crashes for me if not. When the parent process terminates dump the second process with lordpe and thats it, no fixing at all needed.
July 11, 200718 yr it used to run on my computer ... bt from last night it's crashing and this error message pops up: Runtime error 216 at FFF000F0 Edited July 11, 200718 yr by nick_name
July 11, 200718 yr Author @Teddy Rogers KERIS is handmade by Indonesian Reverser and still evaluation so not for public right now @pavka Great job man
July 14, 200718 yr Author @zako This unpackme just protected with mophine with just dump the unpackme, without repairing it will be done try the second unpackme Edited July 14, 200718 yr by B_S
Create an account or sign in to comment