you should unpack original file without starting cf
Is there an alternative way of unpacking 'crossfire.exe'? I can't unpack it using OllyDBG it's closing by itself after hgwc detects it, and if I opened it after hgwc closes, only half of the address are listed inside the OllyDBG, with 17mb file size (I cannot find the wall array). I also used Kernel Detective, and it automatically closes after xtrap detects it. Can anyone help me? I can't find the right bypass to use.
- - - Updated - - -
Anyway, 'crossfire.exe' hid itself in the process list on OllyDBG.
you should unpack original file without starting cf