Log in

View Full Version : norton antivirus 2003


bytexus
February 16th, 2003, 17:03
The new version of nav Comes whith a new protection (i say). First i see the progs runs with no nags(i sayd to myself goobye vbox) but when i look at proces list i see two processes rundll32.exe. So we have a vboxed aplication(4.6.2).The main executable is not crypted with VBOX (i think) "main.exe". But the other thing that i've noticed is that the nav uses some dll "crypt32.dll"and reads some interesting values from registry. I think it uses some encryption algoritm(rsa????). I tried softice but you can breakpoint only api's(if i put a breakpoint on some memory adress a nav window will pop up), finaly i make the program run(by changeing only a jump) but the programs doesn't load the plugins->so it doesn't work. I've found the call that loads the plugins but thi was my end. I trace into some calls until i reach into a call from ole32.dll. When the prog stil is in the trial time this the cal from ole32.dll returns some (good) values in the registers.When the trials expires the call returns other values(bad) in the registers. I replaced the values with the good one but i got a crash(probably those values were on stack also).
I don't know what else i could try to do because i can't crack-it.
I must say i am a newbie and don't have too much experience.
thanks.

JMI
February 16th, 2003, 19:38
bytexus:

It seem I could simply cut and paste most of one of my recent post on this Forum for your benefit, except the software concerned is different. This is your first post and, as with the other recent one, it is obvious you did not look around much, and clearly didn't read the FAQ. Had you done so your would have realized that you needed to search before posting your question to determine whether, and to what extent your question had been asked and/or answered before.

Had you done that, using the search button at the top of every Forum, and simply entered "vbox" you would have found some useful information, from no less an illuminary than our own resident unpaxing God, +Slpa/\, and others, which might assist you.

Read those threads, then think some more, and then follow the posting guidelines with some description of your system and the tools you are using and more about what you tried after you did your search. Then you will probably find those here willing to help.

Regards.