Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 03-11-2009, 16:56
ZeNiX's Avatar
ZeNiX ZeNiX is offline
Administrator
 
Join Date: Feb 2009
Posts: 735
Rept. Given: 177
Rept. Rcvd 772 Times in 259 Posts
Thanks Given: 226
Thanks Rcvd at 910 Times in 247 Posts
ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899
Patching Themida / WinLicense Banned License

I saw Nooby's tut on patching the blacklist two days ago.
So, I tried it on some custom built versions of Themida.
Up to now, I have no luck on it.

Yes, I used the banned license from admin@free8xxxxxx.
Then I get lost in the VM of jmp ESI's.

Had anyone tried it?

Maybe it is because that I am not familiar with its VM.

Also, I see people saying that Shoooo uses another method which patches the BannedID check and corrects the CRC. However, I cannot find his tut.

Can you offer any help?

I did not try it on the WinLicense, as I do not have a banned key.
But I assume that the check of the banned key is same or similar.
Right?
Reply With Quote
  #2  
Old 03-11-2009, 16:59
quosego quosego is offline
Family
 
Join Date: Feb 2009
Posts: 104
Rept. Given: 8
Rept. Rcvd 39 Times in 13 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
quosego Reputation: 39
Haven't tried it, should be interesting.. Will take a look.

However as far as I know Themida and Winlicense are both protected with the same custom winlicense.
Reply With Quote
  #3  
Old 03-25-2009, 02:34
Ember Ember is offline
Friend
 
Join Date: Feb 2009
Posts: 84
Rept. Given: 68
Rept. Rcvd 25 Times in 15 Posts
Thanks Given: 36
Thanks Rcvd at 79 Times in 33 Posts
Ember Reputation: 25
I have never seen this tutorial before? Is it a private one?
Reply With Quote
  #4  
Old 03-27-2009, 04:46
leosmi05 leosmi05 is offline
Friend
 
Join Date: Feb 2005
Posts: 26
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
leosmi05 Reputation: 0
Which one?

Could you give some examples of applications protected with Themida/WinLicense? (Small size applications are preffered) :-)

I can't run WinLicense itself, as it crashes immediatelly after starting it.
Reply With Quote
  #5  
Old 03-27-2009, 13:02
ZeNiX's Avatar
ZeNiX ZeNiX is offline
Administrator
 
Join Date: Feb 2009
Posts: 735
Rept. Given: 177
Rept. Rcvd 772 Times in 259 Posts
Thanks Given: 226
Thanks Rcvd at 910 Times in 247 Posts
ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899
Quote:
I can't run WinLicense itself, as it crashes immediatelly after starting it.
Which version of WinLicense did you use?
Maybe you used a cracked version?

All custom build versin of Themida and Winlicense are protected with Winlicense.
Reply With Quote
  #6  
Old 03-27-2009, 15:48
ZeNiX's Avatar
ZeNiX ZeNiX is offline
Administrator
 
Join Date: Feb 2009
Posts: 735
Rept. Given: 177
Rept. Rcvd 772 Times in 259 Posts
Thanks Given: 226
Thanks Rcvd at 910 Times in 247 Posts
ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899
I have tried [quosego/snd] method to bypass the banned License on.
However, the protected file will result on Application Error.
Maybe there are more checks inside Themida itself?
Attached Images
File Type: jpg TMD265.JPG (627.9 KB, 23 views)
File Type: jpg TMD2652.JPG (30.0 KB, 18 views)
Reply With Quote
  #7  
Old 03-27-2009, 22:45
Jupiter's Avatar
Jupiter Jupiter is offline
Lo*eXeTools*rd
 
Join Date: Jan 2005
Location: Moscow, Russia
Posts: 234
Rept. Given: 43
Rept. Rcvd 62 Times in 37 Posts
Thanks Given: 38
Thanks Rcvd at 191 Times in 57 Posts
Jupiter Reputation: 62
PE CheckSum Adjuster v1.33

ZeNiX
to fix Themida CRC, you can use my Hiew plugin:

PE CheckSum Adjuster v1.33

[ENG]
PE CheckSum Adjuster can modify PE file to conform PE checksum. New and original checksums are the same! This means that checksum will be intact! Useful when you need to keep original checksum, for ex. for Themida patching.

[RUS]
PE CheckSum Adjuster изменяет PE файл для соответствия контрольной сумме (поле OptionalHeader.CheckSum).
Модуль не изменяет контрольную сумму: контрольная сумма нового файла равна контрольной сумме оригинального.
Полезно, когда нужно сохранить исходную контрольную сумму файла, например для патча Themida.

Compiled HEM: CheckSumAdjust133.zip (~3Kb)

Hiew version minimal: 7.45
HEM SDK version: 0.35


Hiew External Modules
Reply With Quote
The Following 2 Users Gave Reputation+1 to Jupiter For This Useful Post:
ahmadmansoor (03-28-2009), Ember (03-28-2009)
  #8  
Old 03-28-2009, 04:22
leosmi05 leosmi05 is offline
Friend
 
Join Date: Feb 2005
Posts: 26
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
leosmi05 Reputation: 0
Quote:
Originally Posted by ZeNiX View Post
Which version of WinLicense did you use?
Maybe you used a cracked version?

All custom build versin of Themida and Winlicense are protected with Winlicense.
I wanted to analyze one file protected with Themida, so I downloaded the latest demo version of Themida and WinLicense (2.0.4.0) from Oreans.
But WinLincense crashes when you start it. How can people then try your code protector? :-)
BTW, no debugger was runnning.

Cheers!
Reply With Quote
  #9  
Old 03-28-2009, 17:20
gunterg gunterg is offline
Friend
 
Join Date: Sep 2004
Posts: 59
Rept. Given: 0
Rept. Rcvd 2 Times in 2 Posts
Thanks Given: 2
Thanks Rcvd at 3 Times in 3 Posts
gunterg Reputation: 2
What OS you had? Anyway it's very strange because since a few versions TMD/WL not use more ring0 protection.
Reply With Quote
  #10  
Old 03-29-2009, 04:41
leosmi05 leosmi05 is offline
Friend
 
Join Date: Feb 2005
Posts: 26
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
leosmi05 Reputation: 0
Question

Yep, very strange. I tried it on XP SP2.
Anyway, can anyone suggest some apps protected with TheMida v2.0.4+?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Themida/Winlicense hobferret General Discussion 1 05-10-2013 18:44


All times are GMT +8. The time now is 21:34.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )