Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 11-06-2006, 00:22
SystemeD SystemeD is offline
Friend
 
Join Date: Dec 2004
Posts: 68
Rept. Given: 8
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
SystemeD Reputation: 1
Armadillo 4.44 problem

Hi all,
I'm dealing with a VB app packed with Armadillo 4.44. More precisely Armadillo Protection Finder says:
Code:
!- Protected Armadillo Protection system (Professional)
!- <Protection Options>
Standard protection or Minimum protection
Enable Strategic Code Splicing
!- <Backup Key Options>
Variable Backup Keys
!- <Compression Options>
Best/Slowest Compression
!- <Other Options>
Disable Monitoring Thread
!- Version 4.44
ArmaGUI and dilloDie successfully unpacks it and I have my VB app running. The problem is that it looks for ArmAccess.dll and also patching all calls I can't have my app registered. The strange thing is that I successfully remove all nag screens and whatever but limitations are still there. Moreover I noticed that in the code there are big regions full of nop. I wonder if full code is someway stolen and how can I recover it?

Thanks in advance!
Reply With Quote
  #2  
Old 11-06-2006, 10:15
TmC TmC is offline
VIP
 
Join Date: Aug 2004
Posts: 328
Rept. Given: 1
Rept. Rcvd 15 Times in 9 Posts
Thanks Given: 2
Thanks Rcvd at 22 Times in 16 Posts
TmC Reputation: 15
try to set a bp o GetEnvironmentVariableA and see what variables the program loads to see if is is registered.
The rest is un to you wheather you want to patch or to find a code cave where to put your variables in (PUSH VarValue, PUSH VarName, CALL SetEnvironmentVariableA, JMP ModuleEntryPoint and setting entry point to first instruction in code cave).

Usually limitations are placed by requiring a variable, see if it is in registered state(let's say USERNAME is not DEFAULT, KEYCREATED is not empty etc) and if not take countermeasures such as enabling limitation.

By the way, can you tell, or pm the program you are talking about?
Reply With Quote
  #3  
Old 11-06-2006, 18:03
SystemeD SystemeD is offline
Friend
 
Join Date: Dec 2004
Posts: 68
Rept. Given: 8
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
SystemeD Reputation: 1
Thank you very much for your reply I'm gonna try what you said!

I don't know if posting target's name is against the rules, so you have PM!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Armadillo 8.6 unpacking problem eAGLe_eYe General Discussion 8 03-11-2013 22:43
Armadillo 3.75b Problem TmC General Discussion 5 12-20-2005 10:55
Hide DS2.7 with Armadillo >3.xx Problem peek General Discussion 8 03-11-2004 02:14


All times are GMT +8. The time now is 10:06.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )