Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #31  
Old 07-05-2004, 04:17
mtw mtw is offline
Friend
 
Join Date: Feb 2003
Posts: 73
Rept. Given: 0
Rept. Rcvd 2 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
mtw Reputation: 2
here is delphi src for the dll and the compiled dll
Attached Files
File Type: rar special_dll.rar (10.2 KB, 22 views)
Reply With Quote
  #32  
Old 07-05-2004, 07:43
BetaMaster BetaMaster is offline
Friend
 
Join Date: Dec 2002
Posts: 77
Rept. Given: 6
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
BetaMaster Reputation: 3
@Crk, I used your patch, created a dumped and fixed the stolen bytes and the planted infinite jump, but how can you verify that this is a working dump or not, for me it crashes at 1328e, [ModName: msvbvm60.dll
ModVer: 6.0.92.37 Offset: 0001328e], is this normal?

also I have used the external signature faker (special.dll) by mtw (btw, thanks again mtw), but that leads no where!!

have any of you got another a "valid" result?

Last edited by BetaMaster; 07-05-2004 at 07:50.
Reply With Quote
  #33  
Old 07-05-2004, 12:55
mtw mtw is offline
Friend
 
Join Date: Feb 2003
Posts: 73
Rept. Given: 0
Rept. Rcvd 2 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
mtw Reputation: 2
[QUOTE=BetaMaster]@Crk, I used your patch, created a dumped and fixed the stolen bytes and the planted infinite jump, but how can you verify that this is a working dump or not, for me it crashes at 1328e, [ModName: msvbvm60.dll
ModVer: 6.0.92.37 Offset: 0001328e], is this normal?

also I have used the external signature faker (special.dll) by mtw (btw, thanks again mtw), but that leads no where!!

That DLL is only to bypass the security checks after the ThunRTMain call, like I said this DLL just helps you out after dump so you can find the procedure for the reg check (which btw uses a machine specific key with the HKLM\Software\Classes\CLSID\"machine depend key"\InprocServer32\InprocServer32) .. if you want to crack software noone said it will be "just find a hard key and patch it" you must read on protections, and assembly, I told you how to bypass the sec's checks, and I also said after this for "YOU" to find the reg procedure, this isnt a "show me how to crack" forum, there is enough information in this thread to get a good dump, IAT rebuilt, and security bypasses so your only job is to find the reg procedure. If it is crashing then your dump is no good. Remember Crk's dumper is for full version not the demo (download) version. Look at my other posts for the OEP and stolen bytes for the download (demo) ..
Reply With Quote
  #34  
Old 07-05-2004, 15:11
Crk
 
Posts: n/a
does this .dll has to be placed in the Tweak-Xp directory or system32 ?

maybe we'll have to share with you the installer for full version.. to finally check if this method you used works with the full version ..... also which method you used to dump the DEMO version?? most be the same technique for full version since is the same VB app. + same protector used on the exe to have a working dump.

BetaMaster if you already have full version ... maybe you have a place to upload it so mtw will get it. if not i could upload it somewhere if someone share some FTP or space to upload it to....

btw Betamaster i told you it crash for me too always at the same location.. but i believe the dump is ok.. that most be part of the integrity check program does ...let's wait for mtw comment about it.



Regards

Last edited by Crk; 07-05-2004 at 15:21.
Reply With Quote
  #35  
Old 07-05-2004, 17:27
BetaMaster BetaMaster is offline
Friend
 
Join Date: Dec 2002
Posts: 77
Rept. Given: 6
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
BetaMaster Reputation: 3
@mtw, I really appreciated your comments in this thread, but when I read your comments, it's like that you tell us that you have worked every thing, I am not having that impression by illusions, and secondly, this is a discussion and I suppose you had some discussions before.I also like to remind you that I didn't ask for your help to bypass the registration routines or the demo limitations, actually I have a full version and a key.

@Crk, the crash that is supposed to be after a crc invalidation is in kernel32.dll, just try to change the txp3.val or make a little change to the file tweak-xp.exe and see it. I guess there is something wrong with the dump.

any help is really appreciated.
Reply With Quote
  #36  
Old 07-05-2004, 21:43
mtw mtw is offline
Friend
 
Join Date: Feb 2003
Posts: 73
Rept. Given: 0
Rept. Rcvd 2 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
mtw Reputation: 2
Quote:
Originally Posted by BetaMaster
@mtw, I really appreciated your comments in this thread, but when I read your comments, it's like that you tell us that you have worked every thing, I am not having that impression by illusions, and secondly, this is a discussion and I suppose you had some discussions before.I also like to remind you that I didn't ask for your help to bypass the registration routines or the demo limitations, actually I have a full version and a key.
Quote:
Originally Posted by BetaMaster
and I also hope that mtw share with us a working solution to this proggy, not that I like the program itself, but rather to show it tp TotalIdea.I think they deserve it.
If you didnt ask for a solution to bypass it then why make this comment, sorry for my reply's, Im done with this thread. And yes I do have a fully working dumped DEMO copy.
Reply With Quote
  #37  
Old 07-06-2004, 06:01
Crk
 
Posts: n/a
Place for Full version --> hxxp://forum.andr.net/viewtopic.php?t=42283
Reply With Quote
  #38  
Old 07-06-2004, 06:03
BetaMaster BetaMaster is offline
Friend
 
Join Date: Dec 2002
Posts: 77
Rept. Given: 6
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
BetaMaster Reputation: 3
you're a strange guy, you want to help, but words don't come out off your mouth "enough", as if you're afraid to uncover critical information.I guess if that was the general case, then this forum would have never seen the light, and people who have some knowledge now, wouldn't have aquired that knowledge in the first place.

I really liked some help on this topic, as I don't consider myself unpacker at all (perhaps only some simple packers like upx, aspack, pecompact, thinstall, and some cases of asprotect and svkp), not to mention of course that I don't see any tool to disassemble vb6, or any intermediate/advanced tutorial on the subject.

I am sorry that you felt that way towards me, and I apologize if I hurt your feelings. I was just trying to learn something I don't know from someone who seemed to know better than me.

Thanks again, and peace.
Reply With Quote
  #39  
Old 07-06-2004, 06:11
Crk
 
Posts: n/a
relax guys .. we all are here to learn from each other something new every day...

keep the knowledge and sharing spirit alive!

Regards
Reply With Quote
  #40  
Old 07-07-2004, 05:53
mtw mtw is offline
Friend
 
Join Date: Feb 2003
Posts: 73
Rept. Given: 0
Rept. Rcvd 2 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
mtw Reputation: 2
@Crk: LOL. I am relaxed all the time, if you get frustrated just by a thread, then there is no point in going through miles of code in a debugger, as this is more frustrating.

@BetaMaster: No I dont have feelings to get hurt, and no Im not hiding anything, I just told you how to get past the protection check.

Now for dumping the Demo version:
Get rid of S-ice and fire up olly.
You know the drill, hide the debugger, and at all times dont use F9 use Shift+F9 to run the app.

Now when its loaded goto MemoryMap and Press F2 on the Resources section and Press "Shift+F9"
When it breaks set goto options a set Break On new DLL load. Press Shift+F9 and watch the DLL's second Shift+F9 you will see it loads the VB runtime DLL.
Now select the runtime DLL and select "View Names". Find the ThunRTMain, and double click it, you will be back in the CPU window. Select the PUSH EBP and press F2. Remove the "Break on new DLL load". Then Shift+F9.

When you break your in the veryfirst call from this app, the initialization of the VB "Native Code" app, which is the ThunRTMain.

Before you go on look at the second line in your stack window. "Picture include so you know what Im talking about".You'll see a line like this
0012FFC0 00401A68 ASCII "VB5!6&*"
that 401A68 (or whatever yours is) is the push 00401A68 before the call to ThunRTMain. This is the first line from the stolen bytes (all those NOPS "90h" at the OEP. The second line (of the NOPS) is the call to ThunRTMain (second line of stolen bytes). Now in the CPU window Press CTRL-G and put in 401364 for the address to jmp to. you'll be looking at an NOP. Press Ctrl+A.

Now you will see all the MSVBVM60 calls, where that first 90 is, is your OEP, now that address I said to look at in the stack window (mine 00401A68) starts here so highlight that first 90h and press space bar enter

Push (your address) (like I said mine was 00401A68), and then
Call (the address for the first JMP before the NOP's) (mine is 40135E)
That is the call to ThunRTMain.
Now you can fire up LordPE, CorrectImageSize and dump it.
Fire up ImpRec and put your OEP here (mine is 00001364),
select IAT AutoSearch then GetImports.

You will notice it gets them all except for 1 which is DLLFunctionCall.
Make this one DLLFunctionCall then fix your dump.

Now you can do traces etc with that dll, now memory might change from machine to machine, like all apps do. I run XP SP1 so you know.

Now load the dumped.exe into olly and set a bp on the DLLFunctionCall, you'll see the veryfirst call is to the special.dll, but if its not there it makes an exception. So from here you can see what the protection does (not the registration code) but the checks for the modified.exe
Attached Images
File Type: jpg Clipboard01.jpg (21.2 KB, 25 views)

Last edited by mtw; 07-07-2004 at 05:56.
Reply With Quote
  #41  
Old 07-07-2004, 23:51
BetaMaster BetaMaster is offline
Friend
 
Join Date: Dec 2002
Posts: 77
Rept. Given: 6
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
BetaMaster Reputation: 3
now that you told the complete story, it worked and 100%.

Thanks a lot mtw, much appreciated.
Reply With Quote
  #42  
Old 07-08-2004, 10:37
Crk
 
Posts: n/a
since i don't run Olly by now.. maybe i'll get some free time to start using and learning Olly very soon ..... please someone attach here working Dumped file .. i hate SVKP and its debugger detection crap
thanksssssss mtw for all info. given!
Reply With Quote
  #43  
Old 07-08-2004, 12:49
BetaMaster BetaMaster is offline
Friend
 
Join Date: Dec 2002
Posts: 77
Rept. Given: 6
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
BetaMaster Reputation: 3
keep this for discussion, give me a place to upload it to you.I unpacked the 2 builds, the retail and the demo.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 02:09.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )