
unPECompact v1.43
TRW2000 vs Numega SoftIce
Written by McCodEMaN
Introduction |
Tools required |
Target's URL |
My target was notepad.exe
Essay |
First Approach: Using SoftIce!
Load the packad exe in Softice symbol loader and it will break here....
:0040AC76 9C
PUSHFD
:0040AC77 60
PUSHAD
:0040AC78 E802000000 CALL
0040AC7F <--Step into
:0040AC7D 33C0
XOR EAX, EAX this
Call.
:0040AC7F 8BC4
MOV EAX, ESP
:0040AC81 83C004
ADD EAX, 04
Step into the call at :0040AC78 (F8), if you don't the program executes!
Next, you'll be looping....looping and so on...so here is what we'll do:
Scroll down the softice window until you see......
:0040E487 61
POPAD
:0040E488 9D
POPFD
:0040E489 50
PUSH EAX <--Bpx here!
:0040E48A 68CC104000
PUSH 004010CC <--Entry point!
:0040E48F C20400
RET 0004 <--Edit here!
When you see this code place a breakpoint on PUSH EAX and press F5 to break at that location.
At :0040E48A PUSH 004010CC you'll find the programs entry point, write that down.
In my case it's 004010CC - 400000 = 10CC
Ok, now you can step down to 0040E48F RET 0004 and create a infinite
loop like this.....
a eip [ENTER] and jmp eip [ENTER] and [Esc]!
Now you can clear your breakpoint and leave softice (F5), next run ProcDump and set options like this:
Under Structure:
-Recompute Object Size
Under Import:
-Rebuild new import table
You can now select your task and make a full dump, then name it and save.
Run the PE Editor and open your dumped file, then enter the correct PE Entry point (10CC).
Second Approach: Using TRW2000!
Here is some useful knowledge about TRW2000!
Start up TRW2000 and click on [Browse] to select your packed exe, then hit [Load] and TRW breaks
so that you'll end up here....
:0040AC76 PUSHF
:0040AC77 PUSHA
:0040AC78 CALL 0040AC7F <--Enter
here!
Step into the first call using F8 and then scroll down with F10 until you reach this code:
:0040E1E3 SAR
EAX, 02
:0040E1E6 REP MOVSD
:0040E1E8 ADD
ECX, EAX
:0040E1EA AND
ECX, BYTE +03
:0040E1ED REP MOVSB <--Stop
here!
Mark the line: 0040E1ED REP MOVSB and scroll down the TRW window until you see.....
:0040E487 POPA
:0040E488 POPF
:0040E489 PUSH EAX
<--Bpx here!
:0040E48A PUSH DWORD
10CC <--Entry point!
:0040E48F RET
04
Place a breakpoint on PUSH EAX by typing:
bpx 0040e489,
then press F5 to make TRW break at this location!
Back in TRW go down to: 0040E48A PUSH DWORD 004010CC
Clear your breakpoint and place a new at the entry point.
bc *
bpx 004010CC
Then hit F5 and when TRW breaks clear all breakpoints (bc *)!
Now we are going to dump this unpacked exe from memory, in TRW type this:
makepe (reg. user) or pedump (unreg. user) then press [ENTER].
TRW will now dump the file from memory as I said and create an exe named:
newpe.exe(reg. user) or dump1.exe(unreg. user)
and save them into the target folder.
All that's left is to give our dump more stability by using a PE program!
Final Notes |