Summarize the shelling method of Themida/winlicense (TM/WL).
1, look at the shell version, this method can be manually, because the shell version number is written in the program inside, after extracting the breakpoint can be viewed, here is a generic script, I will no longer wordy, follow the script, the use of the method is very simple, directly run the script. (The script I have also passed in the resource, can be obtained at the end of the article)
2, for the Ver 1.1.0.0-2.1.0.0 themida/winlicense Shell software, manual off simply unthinkable, there is also a general foreign script, can take off most of the shell, a small part even if not, change the corresponding configuration or change part of the script content can also be removed smoothly. The specific steps also have nothing to say, the script after the run dump, and then repair it.
3, for a small part with the SDK or more abnormal encryption, if it is not able to shell, you can also use patch hwid way, that is, every machine does not have to run the registration code directly, of course, this is only for Winlicense,themida is only to add shell.
Original from http://www.jiamikong.com/doc/3723
Summarize the shelling method of themida/winlicense shell software