unPECompact v1.43
TRW2000 vs Numega SoftIce
Written by McCodEMaN


Introduction

Greetings and welcome to the noble art of reverse engineering!

If you've read my unUPX essay you might remember that I told you about manual unpacking, decryption and what an important knowledge that really is!
Using Softice to extract the exe from this packer is very easy, so to make the exercise more fun I added a TRW solution. This essay could therefore also be used as a TRW lesson.
Some basic TRW commands/keys can be found in my A beginners quick guide to TRW.
You can find that essay in the essay database, but there is also a link under the TRW approach in this essay.



Tools required


TRW 2000 1.22
Numega SoftIce
ProcDump 1.6
PECompact 1.43

Target's URL

My target was notepad.exe



Essay



First Approach: Using SoftIce!

Load the packad exe in Softice symbol loader and it will break here....


:0040AC76   9C           PUSHFD
:0040AC77   60           PUSHAD
:0040AC78   E802000000     CALL    0040AC7F <--Step into
:0040AC7D   33C0            XOR    EAX, EAX    this Call.
:0040AC7F   8BC4            MOV    EAX, ESP
:0040AC81   83C004          ADD    EAX, 04

Step into the call at :0040AC78 (F8), if you don't the program executes!

Next, you'll be looping....looping and so on...so here is what we'll do:
Scroll down the softice window until you see......


:0040E487   61              POPAD
:0040E488   9D              POPFD
:0040E489   50               PUSH   EAX <--Bpx here!
:0040E48A   68CC104000       PUSH   004010CC <--Entry point!
:0040E48F   C20400            RET   0004 <--Edit here!


When you see this code place a breakpoint on PUSH EAX and press F5 to break at that location.
At :0040E48A    PUSH    004010CC you'll find the programs entry point, write that down.

In my case it's 004010CC - 400000 = 10CC

Ok, now you can step down to 0040E48F    RET    0004 and create a infinite loop like this.....


               a eip [ENTER]  and  jmp eip [ENTER] and [Esc]!


Now you can clear your breakpoint and leave softice (F5), next run ProcDump and set options like this:



Under Structure:

-Recompute Object Size


Under Import:

-Rebuild new import table



You can now select your task and make a full dump, then name it and save.

Run the PE Editor and open your dumped file, then enter the correct PE Entry point (10CC).





Second Approach: Using TRW2000!

Here is some useful knowledge about TRW2000!



Start up TRW2000 and click on [Browse] to select your packed exe, then hit [Load] and TRW breaks so that you'll end up here....


:0040AC76   PUSHF
:0040AC77   PUSHA
:0040AC78   CALL   0040AC7F <--Enter here!
 

Step into the first call using F8 and then scroll down with F10 until you reach this code:


:0040E1E3     SAR    EAX, 02
:0040E1E6   REP MOVSD
:0040E1E8     ADD    ECX, EAX
:0040E1EA     AND    ECX, BYTE +03
:0040E1ED   REP MOVSB <--Stop here!


Mark the line: 0040E1ED    REP    MOVSB and scroll down the TRW window until you see.....



:0040E487   POPA
:0040E488   POPF
:0040E489   PUSH   EAX <--Bpx here!
:0040E48A   PUSH   DWORD 10CC <--Entry point!
:0040E48F    RET   04
 


Place a breakpoint on PUSH EAX by typing:       bpx 0040e489, then press F5 to make TRW break at this location!

Back in TRW go down to: 0040E48A     PUSH    DWORD  004010CC
Clear your breakpoint and place a new at the entry point.

bc *
bpx 004010CC


Then hit F5 and when TRW breaks clear all breakpoints (bc *)!
Now we are going to dump this unpacked exe from memory, in TRW type this:

       makepe (reg. user) or pedump (unreg. user) then press [ENTER].

TRW will now dump the file from memory as I said and create an exe named:

      newpe.exe(reg. user) or dump1.exe(unreg. user)

and save them into the target folder.


All that's left is to give our dump more stability by using a PE program!




----{ We have a tie but the game will continue! }----



Final Notes



I would like to thank:

attiTude, tKC, Razzia, MrX, members of TRES2000 and my beloved Jen!




When ever there is a door,
there is an entrance.
And behind an entrance can no secret hide,
when a cracker takes his knowledge for a ride



ObDuh

The information in this essay is for educational purpose only!
You are only allow to crack, reverse engineer, modify code and debugg programs that you legaly bought and then for personal use only!!
To ignore this warning is a criminell act and can result in lawful actions!

So please note!
I take no responebility for how you use the information in this essay, i take NO responebility for what might happen to you or your computer!
You use this information on your own risk!!

What i mean is: Please buy the software!








Essay written by McCodEMaN ŠTRES2000. All Rights Reserved.