Jump to content
Tuts 4 You

DNGuard HVM v3.9.6.2


0x59

Recommended Posts

  • 2 weeks later...
  • 10 months later...
Hadits follower

i have tried two way to skip trial pass but i have failed both , one when i get msg trial expiration at preparemethod , i have setted a static method so i get back the last method code line but when i back i see assembly all types get crashed like assembly get dispose after the trial msg appear , 

and another way i have tried i have removed .hvm section completely but it will corrupt file not work , actually i am not good at asm language , so i cant systemfiledatatime check . 

i have fixed yck project for latest clr library 4.8.9195.0 built by: NET481REL1LAST_B  => 64bit works excellent , i can get CORINFO_METHOD_INFO , no need dbghelper.dll  , 

at trial edition just need startup methodhandle hooks no need full modulhandle hook . 

  • Like 1
Link to comment
Share on other sites

whoknows
Posted (edited)

2024-05-10_200943.png.2ba422d4112d373e02680b8b72807d91.png

 

native dumped

2024-05-10_201305.png.b1facbafada653dd0fe1138269adc096.png

 

[edit] - doh, the same dropped to %temp% by default.

HVMRun64.rar

Edited by whoknows
  • Like 1
Link to comment
Share on other sites

collins
13 hours ago, Hadits follower said:

我尝试了两种方法来跳过试用通过,但我都失败了,一种是当我在preparemethod处收到msg试用到期时,我设置了一个静态方法,这样我就可以返回最后一个方法代码行,但是当我回来时,我看到程序集所有类型都得到了出现试用消息后,像程序集得到处置一样崩溃, 

我尝试过的另一种方法是完全删除 .hvm 部分,但它会损坏文件而无法工作,实际上我不擅长 asm 语言,所以我无法检查系统文件数据时间。 

我已经修复了la test clr 库 4.8.9195.0的 yck 项目,构建方式为: NET481REL1LAST_B   => 64 位,效果非常好,我可以获得 CORINFO_METHOD_INFO ,不需要 dbghelper.dll , 

在试用版中只需要启动方法句柄挂钩,不需要完整的模块句柄挂钩。 

can you share your fixed yck project?

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...