Unpacking method exhaustiv list 컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴� Analyzis work made by G-RoM. Some test were done by Beta Team of course ;). Default Options (check dox). 旼컴컴컴컴컴컴컫컴컴컴컴컴컴쩡컴컴컴컴컴컴컴컴컴컴컴쩡컴컴컴컴컴컴컴컴컴컴컴커 쿙ame � Method � Options � Section To remove after� 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿍JFNT 1.x � *unknown* � Create new import. � Last one. � � � � Do not recompute obj. � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿐NC 0.1 � Standard � Do not recompute obj. � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿓ASIUK used � HASIUK � Default � None � 쿫y Activision � /NeoLite � � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿗OUIS Cryptor � Standard � Default � Last section � � � � Do not recompute obj. � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿘anolo � Manolo � Rebuild Import Table � .manolo section � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿙eoLite x.xx � HASIUK � Default � None � � � /NeoLite � � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿛ECRYPT32 � none � � Depend on version � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿛ELOAD � Standard � Do not recompute obj. � .peload section � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿛ELOCK � none � � last one � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿛EPACK � PEPack � Rebuild Import Table � PEPACK!! section � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿛ESHiELD <0.2 � PESHiELD � Do not recompute obj. � ANAKIN98 section � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿛etite � Petite � Default � .petite section � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿛etite � Petite 2 � Create new import � .petite section � � � � U will need to fix � � � � � reloc pointer too. � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿞ecurom � Standard � Original CD required. � Better not touch ;) � � � � Do not recompute obj. � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿞hrinker 3.2 � Shrinker32 � Ignore Faults � .load object at least � � � � Rebuild Import Table � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿞hrinker 3.3 � Shrinker33 � Do not recompute obj. � None � � � � Rebuild Import Table � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿞TNPE 1.xx � Standard � Do not recompute obj. � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿟imeLock 3.x � Vbox � Create new import � WeiJunLi section � � � std/Dialog � Ignore Faults � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿣Box � Vbox Std � Create new import � WeiJunLi section � � � � Ignore Faults � � � � � Do not recompute obj. � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿣Box with TRY � Vbox � Create new import � WeiJunLi section � � dialog � Dialog � Ignore Faults � � � � � Do not recompute obj. � � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿥WPack32<1.10 � WWPACK32 I � Default � .WWP32 section � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿥WPack32 1.10 � WWPACK32 II� Default � .WWP32 section � 쳐컴컴컴컴컴컴컵컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴탠컴컴컴컴컴컴컴컴컴컴컴캑 쿥WPack32 1.11 � WWPACK32 I � Default � .WWP32 section � 읕컴컴컴컴컴컴컨컴컴컴컴컴컴좔컴컴컴컴컴컴컴컴컴컴컴좔컴컴컴컴컴컴컴컴컴컴컴켸 FOR VBOX : Validate the TRY button, THEN validate OK in ProcDump32 Application must be unwrapped totally ;). NOTA: The "Do not recompute obj" is not necessary : u can leave this option checked, it only impact on produced PE size. Indeed, cryptors leaves object size untouched. For unknown packer, try to use the Standard Unpacker prior to try the *unknown* one, the method to return to original code is used by many cryptors / packers. If it fails, or Hang up, then use the unknown unpacker AND please note the value displayed if it was successfully unpacked This address is where the return to original code is done. If you subtract from this address the IMAGEBASE, and the OBJECT LOADER RVA, u will know where to set the BPX. If u don't understand what I say Study PE Format ;). Packer/Protector tested but not working (yet ?): 컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴컴 � PECRYPT32 : Ahem... I talked much with Random and told him many tips like how my import detection work, etc... Moreover there are several MTE in the code and Some IDT manipulations which cause the loader to not be traced totally. I personnally tested trace of 10 MILLIONS of lines with an access violation error at the end. IN CONCLUSION : you can't trace it by using ProcDump... At least you can analyze a dump. The full support of PECRYPT32 will be done one day.... When I got or did a fully featured tracer or, may be if a crazy guy can try to do it with the script language ;). � PELock : It contains some code that detect debug API, support for it will come with Ring 0 Tracer. � PESHiELD 0.2 : Well I can't test it much coz it is quite incompati- ble with win98. But Support for it will come with Ring 0 Tracer too. Generally, always use specific unpackers/deprotectors because they handle perfectly the PE and restore it to its EXACT state before protection. Final Words : 컴컴컴컴컴컴� If u did a script to support a packer/protector, Send it to me. If u have a cryptor/pecryptor I don't have... send it too ;) Good Luck.