Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 03-19-2004, 13:48
Pompeyfan
 
Posts: n/a
I am only talking about running it in Olly now, works fine outside of Olly:

Call at:

005807AA . E8 A9DAF3FF CALL SystemCl.004BE258

Leads to:

004BE258 /$ 53 PUSH EBX
004BE259 |. 8BD8 MOV EBX,EAX
004BE25B |. 8BC3 MOV EAX,EBX
004BE25D |. 8B15 54515800 MOV EDX,DWORD PTR DS:[585154]
004BE263 |. E8 5C70F4FF CALL SystemCl.004052C4

Leads to:

004052C4 $ 31C9 XOR ECX,ECX
004052C6 . 85D2 TEST EDX,EDX
004052C8 . 74 21 JE SHORT SystemCl.004052EB
004052CA . 52 PUSH EDX
004052CB > 3A0A CMP CL,BYTE PTR DS:[EDX]

There are tons of calls to 004052C4, which then lead you to this access violation, nopping the call at 005807AA didn't help it to run in Olly, nopping the call to 004052C4 helps it run for a bit longer, the trial screen comes up, but keeps dissapearing because of access violations.
I haven't hit that code 411 error message yet, guess I haven't run the program long enough.
Reply With Quote
  #2  
Old 03-22-2004, 03:13
Pompeyfan
 
Posts: n/a
004BDF78 . 6A 00 PUSH 0 ; /Arg1 = 00000000
004BDF7A . 8D45 F0 LEA EAX,DWORD PTR SS:[EBP-10] ; |
004BDF7D . 50 PUSH EAX ; |/Arg1
004BDF7E . A1 F0505800 MOV EAX,DWORD PTR DS:[5850F0] ; ||
004BDF83 . 8945 E8 MOV DWORD PTR SS:[EBP-18],EAX ; ||
004BDF86 . C645 EC 0B MOV BYTE PTR SS:[EBP-14],0B ; ||
004BDF8A . 8D55 E8 LEA EDX,DWORD PTR SS:[EBP-18] ; ||
004BDF8D . 33C9 XOR ECX,ECX ; ||
004BDF8F . B8 70E04B00 MOV EAX,Copy_of_.004BE070 ; ||ASCII "Error 411 - CODE: %s"
004BDF94 . E8 3388F6FF CALL Copy_of_.004267CC ; |\Copy_of_.004267CC
004BDF99 . 8B45 F0 MOV EAX,DWORD PTR SS:[EBP-10] ; |
004BDF9C . 66:8B0D 88E04B>MOV CX,WORD PTR DS:[4BE088] ; |
004BDFA3 . B2 01 MOV DL,1 ; |
004BDFA5 . E8 5240F9FF CALL Copy_of_.00451FFC ; \Copy_of_.00451FFC

If you scroll up, this routine starts at:

004BDEC4 /. 55 PUSH EBP

If you search for references to this, you get:

References in Copy_of_: to 004BDEC4, item 1
Address=004BE179
Disassembly=PUSH Copy_of_.004BDEC4

Here is the routine:

004BE143 . 73 43 JNB SHORT Copy_of_.004BE188
004BE145 . 33C9 XOR ECX,ECX
004BE147 . B2 01 MOV DL,1
004BE149 . A1 58334500 MOV EAX,DWORD PTR DS:[453358]
004BE14E . E8 8D78F9FF CALL Copy_of_.004559E0
004BE153 . A3 F8F45800 MOV DWORD PTR DS:[58F4F8],EAX
004BE158 . 33D2 XOR EDX,EDX
004BE15A . A1 F8F45800 MOV EAX,DWORD PTR DS:[58F4F8]
004BE15F . E8 047AF9FF CALL Copy_of_.00455B68
004BE164 . BA 60EA0000 MOV EDX,0EA60
004BE169 . A1 F8F45800 MOV EAX,DWORD PTR DS:[58F4F8]
004BE16E . E8 057AF9FF CALL Copy_of_.00455B78
004BE173 . A1 FCF45800 MOV EAX,DWORD PTR DS:[58F4FC]
004BE178 . 50 PUSH EAX ; /Arg2 => 00000000
004BE179 . 68 C4DE4B00 PUSH Copy_of_.004BDEC4 ; |Arg1 = 004BDEC4
004BE17E . A1 F8F45800 MOV EAX,DWORD PTR DS:[58F4F8] ; |
004BE183 . E8 007AF9FF CALL Copy_of_.00455B88 ; \Copy_of_.00455B88
004BE188 > C3 RETN

Change this line to:

004BE143 . EB 43 JMP SHORT SystemCl.004BE188

No more code 411 error message!!!!
Reply With Quote
  #3  
Old 03-22-2004, 03:19
Pompeyfan
 
Posts: n/a
Also, if you change 0057FD45 from JE to JMP, you get rid of splash screen, still working on getting rid of the limit of only the first 30 files being deleted, otherwise program works fine, but wont run properly in Olly.
Quote:
After I nop'ed the call at address 005807AA, the program runs fine.
You are of course right Hobgoblin, I ended up having to change this too, it ran okay first day without this change, but following day it didn't, although if I restored a backup file made from the previous day it then would again without the nopping of the call, but then who wants to keep replacing the file everyday.
Reply With Quote
  #4  
Old 03-22-2004, 21:59
hobgoblin hobgoblin is offline
Friend
 
Join Date: Jan 2002
Posts: 124
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 2
Thanks Rcvd at 5 Times in 5 Posts
hobgoblin Reputation: 0
Hi there

I just put a ret at the beginning of the call. Nice to see different solutions. I didn't dig deep enough to check the 30 files limit, though.
regards,
hobgoblin
Reply With Quote
  #5  
Old 03-25-2004, 07:46
smartins
 
Posts: n/a
lol, nice to see my program here

Yea, there are a few hidden checks for the ASProtect shell and that 30 files limit. I don't feel angry for you guys trying to crack it I just accept it and move on. It's part of the software business.

Btw, any recomendations on the best protection system out there? I took a look at Armadillo and it looked very nice. But it does not compress exe's as well as ASProtect.

Take care,
Steven

Last edited by smartins; 03-25-2004 at 07:51.
Reply With Quote
  #6  
Old 03-25-2004, 08:22
Satyric0n
 
Posts: n/a
smartins,

You can always just use a packer with good compression (even a simple one like UPX does fine), then do your protection afterwards (Armadillo, etc). It's not uncommon to come across applications that have been packed by two or three different systems.

Regards
Reply With Quote
  #7  
Old 03-26-2004, 04:21
Pompeyfan
 
Posts: n/a
Hey what a top bloke, anyway mate, I really crack just for the fun of it, probably a lot of us do, it isn't really about stealing your software, all the best to you
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 22:06.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )