Kayaker
November 8th, 2000, 01:29
I hope everyone gets the old reference 
OK, I put my foot into it. Big Time. Everyone seemed to be having so much fun with Merak Mail I decided to get into the fray. And I got frayed.
SICE detection - simple MeltIce protection
CRC check - break on CreateFileA/ReadFile. Seems to read in config.exe in 2 parts. A few calls after the 2nd Read is a CMP. Change it and you're (apparently) free to go. Interestingly there's a check if the file NAME is changed and you get the same CRC error message. This is understandable because config.exe is called by a Control Panel extension anyway and it needs to find it.
Somewhere in there I tried accessing my registry to take a look at HKLM\Software\Microsoft\Windows\CurrentVersion
(the program uses this value in it's reg check), and lo and behold I get a message saying that "Registry Editing has been disabled by your Administrator"
Oh, Oh. Now I'M the Administrator and I'd never do that to myself. So I had my suspicions and checked wininit.ini before rebooting to make sure the program wasn't going to start deleting things on startup and it looked OK.
What the heck, maybe it's a glitch I thought, I mean, this IS Windows. Reboot and I get a very polite Message Box saying "Warning you have tried a cracked program on this computer. The software people have been notified by this..."
Well, that's bull, BUT, suddenly Ping.exe appeared in my C:\ directory. Now the message won't go away and I still can't access my registry with regedit. Other files (regclean, etc.) CAN access my registry however, but TweakUI is also disabled.
Why don't you restore your registry you say? I'd love to, but my default backups seemed to have disappeared... And unfortunately I cleaned house recently of OTHER backups before defragging and never got around to making new backups.
I don't know WHERE this nasty message box may be coming from. Startup Manager (which checks Run/RunOnce/RunServices etc) doesn't show anything. StartMenu/Startup doesn't show anything. SoftIce however (oh beloved SI) shows that the Message Box (which appears just before the Icons on your Desktop appear) is created by Mprexe.exe, a standard Win98 task that always seems to be running. So I assume some little registry snippet is calling mprexe.exe and giving it that string, or maybe the string is stored elsewhere in a file. A fresh bootlog.txt doesn't show anything untowards that I can see. Bootup in SafeMode is OK - no message.
I'm just about to d/l one of those programs that allows you to change Administrator settings in Windows and hope it reverses the registry editing disabling. If it does, then I need to wipe out what's calling that Message Box.
Anyway, this is a warning to anyone who wants to "just have a little fun" with this program. I'm not complaining, I deserve it (beat me, whip me, I love it ;p and if worse comes to worse it's about time for a complete housecleaning anyway.
But if anyone has any suggestions...
BTW, I did get the program to say "Thanks for Registering", but this was only the Message Box call.
Kayaker >(

OK, I put my foot into it. Big Time. Everyone seemed to be having so much fun with Merak Mail I decided to get into the fray. And I got frayed.
SICE detection - simple MeltIce protection
CRC check - break on CreateFileA/ReadFile. Seems to read in config.exe in 2 parts. A few calls after the 2nd Read is a CMP. Change it and you're (apparently) free to go. Interestingly there's a check if the file NAME is changed and you get the same CRC error message. This is understandable because config.exe is called by a Control Panel extension anyway and it needs to find it.
Somewhere in there I tried accessing my registry to take a look at HKLM\Software\Microsoft\Windows\CurrentVersion
(the program uses this value in it's reg check), and lo and behold I get a message saying that "Registry Editing has been disabled by your Administrator"
Oh, Oh. Now I'M the Administrator and I'd never do that to myself. So I had my suspicions and checked wininit.ini before rebooting to make sure the program wasn't going to start deleting things on startup and it looked OK.
What the heck, maybe it's a glitch I thought, I mean, this IS Windows. Reboot and I get a very polite Message Box saying "Warning you have tried a cracked program on this computer. The software people have been notified by this..."
Well, that's bull, BUT, suddenly Ping.exe appeared in my C:\ directory. Now the message won't go away and I still can't access my registry with regedit. Other files (regclean, etc.) CAN access my registry however, but TweakUI is also disabled.
Why don't you restore your registry you say? I'd love to, but my default backups seemed to have disappeared... And unfortunately I cleaned house recently of OTHER backups before defragging and never got around to making new backups.
I don't know WHERE this nasty message box may be coming from. Startup Manager (which checks Run/RunOnce/RunServices etc) doesn't show anything. StartMenu/Startup doesn't show anything. SoftIce however (oh beloved SI) shows that the Message Box (which appears just before the Icons on your Desktop appear) is created by Mprexe.exe, a standard Win98 task that always seems to be running. So I assume some little registry snippet is calling mprexe.exe and giving it that string, or maybe the string is stored elsewhere in a file. A fresh bootlog.txt doesn't show anything untowards that I can see. Bootup in SafeMode is OK - no message.
I'm just about to d/l one of those programs that allows you to change Administrator settings in Windows and hope it reverses the registry editing disabling. If it does, then I need to wipe out what's calling that Message Box.
Anyway, this is a warning to anyone who wants to "just have a little fun" with this program. I'm not complaining, I deserve it (beat me, whip me, I love it ;p and if worse comes to worse it's about time for a complete housecleaning anyway.
But if anyone has any suggestions...
BTW, I did get the program to say "Thanks for Registering", but this was only the Message Box call.
Kayaker >(