Any Ideas? (Debugging Cabalmain.exe)

09/23/2009 21:41 howcow95#31
well sure enough I used chimprec in place of imprec and it worked...........................

well... now when i try to open the supposedly fixed dump it gives me

[Only registered and activated users can see links. Click Here To Register...]


this also happens when i try to open it in olly
09/24/2009 20:31 oren_studio#32
i think i did it finally, removed themida completely. ran it normally, and peid didn't detect any protection. so happy!
on to the tracing part next! weeeeeeeeeeeeeeeeeeee! :p:p:p:p
09/24/2009 20:34 howcow95#33
how!!!!! pm me !!!.... and wait so you can run your unpacked.exe by itself?
09/24/2009 20:39 oren_studio#34
Quote:
Originally Posted by howcow95 View Post
how!!!!! pm me !!!.... and wait so you can run your unpacked.exe by itself?
yep :p
09/24/2009 21:14 howcow95#35
pmed you back :P and also you just used one script?
09/24/2009 21:21 Teandormus#36
LOL GUYS :D SEND ME UR UNPACKD CABALMAIN O_O
09/24/2009 21:24 howcow95#37
ill do it if i can find it out AND you mail me cookies
09/24/2009 21:48 Teandormus#38
lol i will , giimme adress
09/24/2009 23:58 NovaCygni#39
Quote:
Originally Posted by howcow95 View Post
pmed you back :P and also you just used one script?
I have scripts for every packer, padder and obfusk'ers in existance ;) between raping Cabal and being the first botter on DragonSky it saves alot of time ;) :mofo: Id happilly make a full ollydbg Toolkit for epvpers with the relative scripts/plugins for Cabal but I lack so much in motivation..... Im sure -Chrome- knows what Im referring to, SALOMON and Lowyfre need a firm kick in the asses! (* Ill save u another wall of text chrome about how they happilly Leeched my work and help before then allowed those insults because I removed my work from epvpers -.- *)
09/25/2009 00:07 howcow95#40
Quote:
Originally Posted by NovaCygni View Post
I have scripts for every packer, padder and obfusk'ers in existance ;) between raping Cabal and being the first botter on DragonSky it saves alot of time ;) :mofo: Id happilly make a full ollydbg Toolkit for epvpers with the relative scripts/plugins for Cabal but I lack so much in motivation..... Im sure -Chrome- knows what Im referring to, SALOMON and Lowyfre need a firm kick in the asses! (* Ill save u another wall of text chrome about how they happilly Leeched my work and help before then allowed those insults because I removed my work from epvpers -.- *)
PM's work O.O hehe and as for motivation your helping mankind!!!

P.S I'll give you some of the cookies that Vegi is gunna send me

but yea hopefully oren could point me in the right direction I've spent a while just trying many dif combinations and retsarting my comp soooooooo many times over and over and over


Btw is there a way to edit upgrade success through cabalmain.exe aswell? I am absolutely hating my upgrading luck atm >.>
09/25/2009 00:49 Teandormus#41
Doh i want some guides ._. howcow u already unpacked urs cabalmain ?:> i need do the same for cabal eu but im newbie in coding awww
09/25/2009 01:02 howcow95#42
i don't relly think I unpacked ... I use one script to find the OEP and unpack and it says it thinks it found it then i right click and hit search for all ref text strings and then I get a code that actually makes sense.... but whenever i try to dump/fix it I never succeed
09/25/2009 01:16 oren_studio#43
Themida is not as simple as other protectors as rebuilding the IAT is a pain in the ass and varies from version to version. Use the script i've posted to search the real OEP, rebuild the IAT in olly, fix it with UIF, dump it, and fix imports with Chimprec .Heard Imprec does not import d3dx9.dll correctly; I'd never bothered to check though just to save the hassle :p

[Only registered and activated users can see links. Click Here To Register...]
09/25/2009 02:18 howcow95#44
the script to find the OEP is... Themida + WinLicense 1.1.x.x - 1.9.x.x OEP Finder.txt amiright?? I;ve been suing this ALL along just can't find the right combo of things to do after but yea ima try what you just posted... just wana confirm im using right oep finder
09/25/2009 02:39 oren_studio#45
Quote:
Originally Posted by howcow95 View Post
the script to find the OEP is... Themida + WinLicense 1.1.x.x - 1.9.x.x OEP Finder.txt amiright?? I;ve been suing this ALL along just can't find the right combo of things to do after but yea ima try what you just posted... just wana confirm im using right oep finder
yes.the OEP that u get using the script is correct, but then u need to fix IAT too manually or using other scripts.