Well I was looking at dlntq's guide to unpack CabalMain.exe and PH uses a dif packer than NA... NA uses themida. So I began my search for an unpacker, all the one shot unpackers I found would always give me internal errors. SOOO I got one that worked through olly. So I THINK I got it successfully unpacked in olly then I used ImportREC to dump it. After a long while of trying I finally got a cabal_dump.exe soo I tried to move onto the second unpack but to my horror when I scanned with DiE and PiED it tells me it's packed with themida? So I think I got the OEP wrong. Now today, I used PEtools to find the OEP which indeed tells me different then what olly was saying my OEP was, and according to this guide to unpacking themida you subtract the Image Base from OEP and sub it into the IAT's on ImportREC but I get a Negative OEP that way :confused:
Here's the guide I used
[Only registered and activated users can see links. Click Here To Register...]
Now I either need a dif way to dump or a simple confirmation if I got my first dump right. The cabal_dump.exe is 11.7 mb I need to unpack it once more according to dlntq to get the asm. So now I'm at a loss at what to do when I try to open cabal_dump.exe in olly it gives me an error and I think it gives me RETN 4. If someone is willing to help I can provide screenshots and more detail O.o Thanks in advance.
Here's the guide I used
[Only registered and activated users can see links. Click Here To Register...]
Now I either need a dif way to dump or a simple confirmation if I got my first dump right. The cabal_dump.exe is 11.7 mb I need to unpack it once more according to dlntq to get the asm. So now I'm at a loss at what to do when I try to open cabal_dump.exe in olly it gives me an error and I think it gives me RETN 4. If someone is willing to help I can provide screenshots and more detail O.o Thanks in advance.