Unpacking cshell.dll
Can some one help me with unpacking cshell.dll?
Befor the patch I could find with what cshell.dll was packt.
Now I can't
Can some one help me to find what software cshell is packt with?
I tryed
RDG
PEID
exeinfo pe
Found:
Themida v2.0.1.0 - v2.1.2.0 (or newer) + Hide PE Scanner Option
isn't that execyptor thingy?
you dont need a unpacker, you need make a software that load the libray CShell.dll and then attach this with Ollydbg...
Damn looks so complicated lawl.
If you open the PE Header, then you see the MZ, but the code after it is so small :S
That can't be good
You can right click on CShell .text and then dump it into a .mem file but i dont know what to do next.
I released the CShell unpacked after patch if you want it.
I make a video how I did it.
Maby I do somting wrong :P
If you need some help with unpacking cshell ask me via pm
You can ask Blood about this, he's really pro at it.
@UltraPGNoob, no outside link :/
@hahaz sry. i replaced the link by an uploaded file.