im trying to unpack a .Net Themida 2.0.5.0 packed file and having trouble with PE fixing
so far i was able to do the following
- get the version of packer used
- dump the file
- fix the section header (.text, .sdata)
- delete the section added by the packer (not sure if i did this right, i deleted the section header and data named Themida)
- added .reloc section
- fixed the SizeOfCode, SizeOfHeaders & SizeOfUninitialzed Data
- replaced BaseOfCode with RVA of .text
- replaced BaseOfData with RVA of .rsrc
im not sure with SizeOfInitialized Data since the value raw size of .sdata is quite large and if i try to add up all the RAW sizes CFF Explorer crashes
and i couldnt find _CorExeMain (searching from Hex Editor of CFF) to fix the Import Directory RVA
can anyone enlighten me on this?






