Log in

View Full Version : BitArts


NchantA
January 28th, 2001, 05:21
i was wondering if anyone had any material, urls or something to say on softlocx protections.

NchantA

Kilby
January 28th, 2001, 15:55
I havn't looked at softlocx but I have spent a few hours with Cruncher 2.

If Cruncher 2 is an example of their idea of security then their other products should be pretty easy.

Kilby...

NchantA
January 29th, 2001, 11:49
hey guys, im particularly looking for info on softlocx

i am not 100% sure that the program im having trouble with is softlocx but thats what im guessing...

kirb can u send me your tut plz? any help is appreciated

NchantA

Kilby
January 29th, 2001, 13:31
Hi NchantA,

I have attempted to send the doc (& test file) to Tsehp, but his mailbox is down.

So from the previous message here ArthaXerXes is posting it on his new system The Nexus.

I ain't got the URL on me at the moment, so either ArthaXerXes can post the URL, or Tsehp can pass on another mail address, so he can post the tut on the RCE site.

If nothing happens in the next 24 hours I will make alternate arrangements.

Kilby...

LaptoniC
January 30th, 2001, 18:28
Your essay good however softlocx needs patching after unpack.There is levels for license you should patch .I couldnt managed to find it but you can try Pic2html http://home4.inet.tele.dk/palsbo/download2.html I have found one softlocx unpacker by Chafe but it didnt worked on this.
Regards

Kilby
January 31st, 2001, 05:02
Oops posted the reply in a new threas, called copylocx.

Kilby...

Kilby
January 31st, 2001, 05:54
Hmmm, just had a look at that prog,

The exe is packed with a (I assume) older vesion of cruncher, so atleast my weekend wasn't totally wasted.

+SplAj
January 31st, 2001, 07:58
Gentlemen,

This exe is packed with crunch, BUT the protection is by .......................

Softguard6.ocx from Russell Anderson
(1997 home made protection)

This parasite is installed in your Windows directory

Nothing to do with Softlocx 4 or 5

+SplAj

Kilby
January 31st, 2001, 09:20
I'm in work at the momentand the only thing I have with any form of dissassembler is hiew.

In reality I'm trying to get a bit of experiance of dumping wrapped files, and as I had a very easy success with Cruncher, so I thought I would build on that victory.

Kilby...

NchantA
January 31st, 2001, 09:21
"I have found one softlocx unpacker by Chafe but it didnt worked on this."

could send me (nchanta@nchanta.com) or give a url where i could get this softlocx unpacker plz?

its worth a try (hi r!sc) ;D

NchantA

btw thanks for clearing that up splaj+

+SplAj
January 31st, 2001, 09:57
www.exetools.com

unlocx5 in unpacker section ?

I managed to manually unpack all BA softs
- take care the IT is dESTROYEd when you dump. So catch the IT while its mapped then
dump that section. Rebuild after

The Owl
January 31st, 2001, 17:27
now that several more knowledgable people on softlocx have shown up here, i'd
like to pose a problem which i can't solve as i don't have the time for it. for some
reason, the latest 6.022pre version is detected by the softlocx wrapper which i
think is more like an accident (my bug ;-)) than any conscious effort on their part
(6.021 is ok). i'd really appreciate if someone took the time and told me what
check fails (or rather succeeds) so that i could fix it. note that the issue is about
detecting winice, it has nothing to do with the icedump tracer which is fooled by
another thing i didn't yet emulate (int 1a/02, the last pre release actually has code
for emulation, so you could test it too once the real detection issues is solved).
thanks for your help in advance.

NchantA
February 1st, 2001, 00:50
yo +splaj, but i couldnt find the unlocx on exetools under unpackers...

aswell as being so stupid i cant dump this thing, i also accidentaly played with my system clock, and now its bloody expired...

any ideas hehe

NchantA

NchantA
February 1st, 2001, 00:57
um nm about unlocx i found (good ol google) but its still bloody expired ;D

Solomon
February 1st, 2001, 04:07
Here is a cracking tutorial for BitArts Fusion v1.0 by lazarus:
http://www.qwikpages.com/backstreets/krobar/serial/ser88.txt

+SplAj
February 1st, 2001, 04:34
To re-enable B-A trial

1) find 'netdet.ini' in your Win folder
delete any section that says :-

[Routing.extent{CRITICAL ENTRY}]
NetDatKCR for the targets name and delete this. See a load of binary. Thats it.

After doing BOTH of the above. Restart the app and the trial begins.......

Hint.
Use TRW2000 AFTER the registration window has loaded and set a BPX TerminateProcess. Then
tarce in to the real exe from the 'insXX.tmp' (mutant) and search for the real IT being built

Big clue there is more than just kernel32.dll
andd the destroyed IT has the FIRST letter of
the API name remaining only (eg RegQuery.. become R..........)

Dump this section when built in memory. Then dump at OEiP . Replace crap section with good dump and thets it. You still have to patch the unregistered flags though

Use DEDE by DaFixer as it's Delphi NOT ASM as they claim.

Should have kept my mouth shut as i'm fed up with this old stuff.....

BTW.1 the unpacker needs bug fixing if you use WinNT or 2K. The PE header is only ok for Win98.

BTW.2 NchantA, was that your serial for ColorPilot4.04 ??? tell me how you got the reg window to appear. I had to use DEDE to get the TFORMS and switch the about window for the Reg window, plus my reg key is 1 char different to yours

SplAj