[Discussion] Removing DC Flag

08/25/2009 02:11 dlnqt#46
change 1A to 1B? :D
08/25/2009 02:38 brian86#47
oops! im sorry!! im not in there yet! im really confuse on how to atach olly cause it is detected evertym i try to atach it! T_T. im finish unpacking cabal.exe..
08/25/2009 04:11 ibonehj15#48
Quote:
Originally Posted by brian86 View Post
oops! im sorry!! im not in there yet! im really confuse on how to atach olly cause it is detected evertym i try to atach it! T_T. im finish unpacking cabal.exe..
question
kwes-chun
howd you unpack cabalmain.exe?
wanna ask

then
COULD SOMEBODY POST HERE THE OTHER STEPS
hehe ^^
kidding aside though im serious enough to start w/ this
cheers people
i cant leech exact infos here though at least
ure all here to answer my lil questions???
08/25/2009 04:57 logan432#49
Quote:
Originally Posted by ibonehj15 View Post
question
kwes-chun
howd you unpack cabalmain.exe?
wanna ask

then
COULD SOMEBODY POST HERE THE OTHER STEPS
hehe ^^
kidding aside though im serious enough to start w/ this
cheers people
i cant leech exact infos here though at least
ure all here to answer my lil questions???
it is said in page 3 of this thread

btw thanks to you all
08/25/2009 05:40 xDemonBane#50
it does work.... ^_^ thanks for all the tips...
08/25/2009 05:50 jaypee02#51
nice topic.. :) tnx for those giving some tips :)
08/25/2009 06:40 kenlyn26#52
Quote:
Originally Posted by juandelacruz1103 View Post
nova , dlnqt , 168atomica after i unpack cabal using OllyDbg and it stop at the Entry Point, how can i know/find the OEP ? thanks hope i can learn wat u guys have learn..
[Only registered and activated users can see links. Click Here To Register...]
08/25/2009 07:13 juandelacruz1103#53
after i unpack cabalmain.exe den run it manually i got detected. ive DL hidedebugger and phantom but i cant find hideolly. i tried searching the net. cud u give me the link pls. thanks.
08/25/2009 10:27 dlnqt#54
@Nova

Is Ollydbg + OllyDMP compatible with the packer of cabal? Don't you need the exact type of unpacker (Yoda + ASP AFAIK)?
08/25/2009 11:21 NovaCygni#55
Quote:
Originally Posted by dlnqt View Post
@Nova

Is Ollydbg + OllyDMP compatible with the packer of cabal? Don't you need the exact type of unpacker (Yoda + ASP AFAIK)?
Yup... I think ive got Y0da's Aspack Depax for that job as one of the plugins for PEiD
08/25/2009 11:25 ibonehj15#56
Quote:
Originally Posted by logan432 View Post
it is said in page 3 of this thread

btw thanks to you all
thanx for this
i only got yoda cryptor and asprotect
well gonna try this things...i think
cheers again ^^:rtfm:
08/25/2009 12:00 dlnqt#57
Quote:
Originally Posted by NovaCygni View Post
Yup... I think ive got Y0da's Aspack Depax for that job as one of the plugins for PEiD
Can't find the ASPackDie plugin for PEiD as it has not made public since the maker said it had a lot of bugs :| Getting the program would mean getting the program from him directly, I found the original ASPackDie 1.41 but it's not a plugin for PEiD..
08/25/2009 14:29 logan432#58
do you need to repack the cabalmain.exe after you unpack it?
08/25/2009 18:11 gr13ver#59
hi! im new to this thing but i'm willing to learn i just downloaded ollydbg 1.10 and phantom but can't seem to find hideolly plugin. i kept on changing settings of phantom but can't seem to make the right settings can any1 help?
08/25/2009 18:47 bboyecko#60
damn. I copied cabalmain.exe to another folder ( as not to fuck up he real one by accident) and i kept wondering why it just terminate with no way to get it to work...meh <.<

now on to finding the flag and done

thnx qoe and all the others :D