Jump to content
Tuts 4 You

Recommended Posts

Posted

DNGuard HVM v3.9.6.2


This file is protected using DNGuard HVM 3.9.6.2

Protections used : 

  • HVM
  • Jit

Challenge is to unpack and post details of methods used.


 

  • 2 weeks later...
Hadits follower
Posted

protected by demo , useless

  • 10 months later...
Hadits follower
Posted (edited)

___

 

Edited by Hadits follower
  • Like 1
whoknows
Posted (edited)

2024-05-10_200943.png.2ba422d4112d373e02680b8b72807d91.png

 

native dumped

2024-05-10_201305.png.b1facbafada653dd0fe1138269adc096.png

 

[edit] - doh, the same dropped to %temp% by default.

HVMRun64.rar

Edited by whoknows
  • Like 1
collins
Posted
13 hours ago, Hadits follower said:

我尝试了两种方法来跳过试用通过,但我都失败了,一种是当我在preparemethod处收到msg试用到期时,我设置了一个静态方法,这样我就可以返回最后一个方法代码行,但是当我回来时,我看到程序集所有类型都得到了出现试用消息后,像程序集得到处置一样崩溃, 

我尝试过的另一种方法是完全删除 .hvm 部分,但它会损坏文件而无法工作,实际上我不擅长 asm 语言,所以我无法检查系统文件数据时间。 

我已经修复了la test clr 库 4.8.9195.0的 yck 项目,构建方式为: NET481REL1LAST_B   => 64 位,效果非常好,我可以获得 CORINFO_METHOD_INFO ,不需要 dbghelper.dll , 

在试用版中只需要启动方法句柄挂钩,不需要完整的模块句柄挂钩。 

can you share your fixed yck project?

  • 1 month later...
VB56390
Posted
On 5/11/2024 at 2:24 PM, collins said:

can you share your fixed yck project?

can you share your fixed yck project? +1 

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...