Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-18-2005, 06:11
Newbie_Cracker's Avatar
Newbie_Cracker Newbie_Cracker is offline
VIP
 
Join Date: Jan 2005
Posts: 227
Rept. Given: 72
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 50
Thanks Rcvd at 25 Times in 18 Posts
Newbie_Cracker Reputation: 26
How to unpack ExeSafeGuard ?

Hi friends.
Tonight I packed win98 Notepad.exe with ExeSafeGuard v1.03 to test its power. Its stub is too polymorphic, so I couldn't find any constant signatures between many packed files for PEiD.
Next, I decided to unpack it.



It beated me. It crashed OllyDbg (by DebugOutputString bug). I used modified OllyDbg, but it didn't run. I put BP on GetCurrentProcess and saw it uses ntdll.ZwQueryInformationProcess to detect debugger. I forced GetCurrentProcess to return 0 in EAX to disable this trick (It works on SDProtector ). OllyDbg began to load modules and then....
Notepad.exe is crashed !

ExeSafeGuard creates second process to run the target ( like SDprotector and Armadillo). I guess it uses WaitForDebugEvent too, because OllyDbg couldn't attach to second process (even first process). But putting BP on 2nd instruction (for fooling int3 check on APIs) of CreateProcessA, CreateThread, WriteProcessMemory, and WaitForDebugEvent didn't help me. Crash occured before any breaking !

Is there anybody who knows what should I do with this packer?? (Descriptions of its author is acceptable too )
Please don't say the only choice is SoftIce to defeat it !!

ps : I attached packed Notepad.exe with v1.03.
Here is the ExeSafeGuard v1.03

htpp://forum.exetools.com/showpost.php?p=38593&postcount=8

Regards.
Attached Files
File Type: rar NOTEPAD_Packed.rar (59.7 KB, 11 views)

Last edited by Newbie_Cracker; 08-20-2005 at 07:28.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 14:58.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )