Well there used to be a script for this but it wont work anymore because the packer has changed. Actually it was much harder to unpack before. Everything gets easier all the time
.
Ok, this is in text version. No need to record it because it's so short.
- Tools needed: OllyDbg (prefer ver 1.10), ImpREC
1. Ignore all exceptions in OllyDbg.
2. Load the dekaron.exe in Olly.
3. The entrypoint will look like this:
4. Step over/into the first
pushad command.
5. Put a hardware breakpoint on the esp register --> Word/Dword
on Access.
6. Execute
shift+F9.
7. Now you should find yourself at a routine before the OriginalEntryPoint:
8.
Disable the hardware breakpoint put earlier (Debug --> Hardware breakpoints --> Delete 1).
9. Put a breakpoint (press F2) on the unconditional jump.
9. Execute Shift+F9 then remove the breakpoint (press F2 again).
10. Step over/into the unconditional jump.
11. You should land here:
12. Now launch ImpREC, dump the target with ImpREC. Put the OriginalEntryPoint in the OEP grid and press Auto Search. Then press Get Imports.
13. After that choose Fix dump and choose your dumped file and you're done
.