votan
July 8th, 2002, 10:03
first of all, hi all forum members..
i have dealt with a win32 program protected by hardlock envelope.. this program is a vb one, at the start it behaves as p-code,then turns native code.. anyway.. i read M4V3RiCk HL-API hardlock essay.. it is really helpful tut. then I tried to de-envelope the program.. in envelope I found Hl-login,Hl-Avail and Hl,version services.. i emulated these services.. envelope decrypted encrypted sections and filled some imports from kernel...then the program crashed in .protect section when it called some imports from kernel: getmodulefilenamea,virtualqueryex etc... the error message is related to page error (virtualqueryex) instead of a envelope error..
I have some Qs about that: maybe some of among u had some experiences.. is my decryption without right dongle successful ? maybe envelope read some decryption key from dongle... another Q is that Crackz wrote at the beginning of Maverick's tut about envelope mechanisms. He said that after decryption there is also import trashing.. is this the reason for the crash???
tnx everyone right now...
i have dealt with a win32 program protected by hardlock envelope.. this program is a vb one, at the start it behaves as p-code,then turns native code.. anyway.. i read M4V3RiCk HL-API hardlock essay.. it is really helpful tut. then I tried to de-envelope the program.. in envelope I found Hl-login,Hl-Avail and Hl,version services.. i emulated these services.. envelope decrypted encrypted sections and filled some imports from kernel...then the program crashed in .protect section when it called some imports from kernel: getmodulefilenamea,virtualqueryex etc... the error message is related to page error (virtualqueryex) instead of a envelope error..
I have some Qs about that: maybe some of among u had some experiences.. is my decryption without right dongle successful ? maybe envelope read some decryption key from dongle... another Q is that Crackz wrote at the beginning of Maverick's tut about envelope mechanisms. He said that after decryption there is also import trashing.. is this the reason for the crash???
tnx everyone right now...