Yaro
March 25th, 2010, 13:55
Hi all, it's my first post here.
I have some problems to unpack an exe file, but let me explain better.
First step i have done it was to check what type of packer was used, but nothing, i have tryed peid, die and others, but they say me no packers found. The only one what said me something more was paid with a userdb in a hardmode scan:
Molebox 2.0
Entropy: 7.86 (Packed)
EP Check: Packed
Fast Check: Not Packed
I have tryed all guide i know for unpack molebox or unpacker but nothing,
I also tryed to find manually oep but olly doesn't put on bp after pushad(or maybe don't say me it) and after execution doesn't change nothing, and doesn't jump to other call oep like in guide, but to an pop esi and next a leave.
The only file unpacked of it i have created it seems to be unpacked, i can see all ascii reference and the all program execution on a debug. But when i try to run it the program doesn't work and crash.
Someone can help me? or just send me a good guide to unpack molebox? not guide like "here the file, press f7 and you will find oep".
Thx.
I have some problems to unpack an exe file, but let me explain better.
First step i have done it was to check what type of packer was used, but nothing, i have tryed peid, die and others, but they say me no packers found. The only one what said me something more was paid with a userdb in a hardmode scan:
Molebox 2.0
Entropy: 7.86 (Packed)
EP Check: Packed
Fast Check: Not Packed
I have tryed all guide i know for unpack molebox or unpacker but nothing,
I also tryed to find manually oep but olly doesn't put on bp after pushad(or maybe don't say me it) and after execution doesn't change nothing, and doesn't jump to other call oep like in guide, but to an pop esi and next a leave.
The only file unpacked of it i have created it seems to be unpacked, i can see all ascii reference and the all program execution on a debug. But when i try to run it the program doesn't work and crash.
Someone can help me? or just send me a good guide to unpack molebox? not guide like "here the file, press f7 and you will find oep".
Thx.