"McAfee VirusScan v4.0.1"
|
This tutorial is coming from... |
|
|
ReFleXZ
'99
Url:
Http://ReFleXZ99.cjb.net |
|
About the essay... |
|
Written by:
MiZ
Date: 10th
February 1999
Tools required:
Difficult
level:
|
|
Introduction... |
|
McAfee is one of the best virus scan programs available on the market.You are able to scan your mail,files,files while running,copying...It's simply great program.So if you want to use it,then please BUY it,it's worth paying.And if you want to use this essay just to save yourself from paying more money,then please GET OUT OF HERE!!! |
|
About the protection... |
|
Type
of protection: |
|
The Essay... |
|
So first off,move your time few years ahead.Press Ctrl+D to get into Softice,set breakpoint on MessageBoxA,press Ctrl+D again to get out of Softice.Start McAfee VirusScan,press Scan button,a nag appears and we have to options,either we can Purchase the software or Cancel.Press Cancel button,and ice breaks,press F12,press enter and you should be here:
:0040F950
FF1500ED4300
Call [User32!MessageBoxA] Now scroll up a bit until you see:
:0040F8EB
85C0
test eax, eax <---If
EAX 0 then Now we have to NOP th jumps at addresses :0040F8ED and :0040F8F4,and it won't exit anymore or display message box.Next we have to remove the nag.Now set breakpoint on GetSystemTime in ice.Press again Scan button,ice breaks,now keep pressing F12 until the nag shows up,then press on Purchase button,and keep pressing F12 until you're in SCAN32 code,here:
:0040F8E1
50
push eax Now scroll up until you see:
:0040F8A4
8BE8
mov ebp, eax
Now
we need to make jump at :0040F8A8 to jump always.
:00406130
E8FB1C0000
call 00407E30 See that at line :00406137 there's a jump that jumps over the call to the nag,so you have to change it to jump always.
We
have three more left.After you've patched the SCAN32.EXE and
VShwin32.EXE,when you start McAfee VirusScan Central,it detects that
we manipulated the .EXE:s.So set once again that breakpoint on MessageBoxA.
:0040725E
FF1510884200
Call [User32!MessageBoxA] Now scroll up until you see:
:00407229
8BF0
mov esi, eax We need to chnage this jump at :0040722D to jmp 00407278.But even after you change it,it will still exit.So it's after this jump again some check.So when you jump from jump at :0040722D,you'll jump here:
:00407278
33F6
xor esi, esi Now you'll have to nop this jump above as well as the test eax,eax.
When
you press Scan button,message appears sayin that validation code of
bla bla...please reinstall.
:0042A941
894C241C
mov dword ptr [esp+1C], ecx Now scroll up until you see:
:0042A8DB
BEF88F4300
mov esi, 00438FF8 Now you need to change jne to jmp and you're done.
Now
when you click on Schedule button it,displays a message saying that
the file bla bla...please reinstall.
:00401F3E
FF15B0074200
Call [User32!MessageBoxA] Now scroll up until you see:
:00401E80
57
push edi You need to change jump at :00401E86 to jmp 00401F68 , and it will always start. The Crack: Open file SCAN32.EXE in your favourite hexeditor and search for bytes: 242C83C41885C07410 replace with 242C83C41840484048 837C2438037509 replace with 837C2438039090 85ED0F84BA000000 replace with 85EDE9BB00000090 8F430083FD017575 replace with 8F430083FD01EB75 In Vshwin32.exe: B1C000085C0740E replace with B1C000085C0EB0E In VSCAN40.EXE 8BF085F674498D44 replace with 8BF085F6EB498D44 85C00F8536FFFFFF replace with 4048404840484048 In AVCONSOL.EXE: 00000F84DC0000 replace with 0000E9DD00000090
Job done. |
|
Final notes... |
|
Greetz and thanx: McCodEMaN,Bjanes,The Sandman,CrackZ,+ORC,Jeff,Eternal Bliss.....and all otherz.... |
|
Disclaimer... |
|
This tutorial is written for EDUCATIONAL purposes only.
|
Copyright © 1999 by ReFleXZ '99
All rights reserved