(a) Themida and without license winlicense Shell software is not said, directly on the script shelling.
(b) Take a look at some of the minor features of different versions of Oep:
Oep features after temida2.1.x.x version (2.0.8.0,2.1.0.10,2.1.3.32, etc.)
Oep features prior to the Temida2.1 version, such as (2.0.3.0,1.8.2.0,1.885, etc.):
Temida Oep Characteristics: (2.0.3.0,)
One, for Winlicense2.1.0.10 and the following version, do not license, you can arbitrarily construct a license direct bypass. Then shelled.
Bypass process
1, first get license name, self-construct a license, then OD run program, pop-up prompt window to get the first address of jmp: firstjmpaddress.
2, the next firstjmpaddress hardware breakpoint, rerun the program, after interruption, enter in the second Jmp,enter, then search for CMP ecx,eax, under Breakpoint, run, interrupt in cmpecxeaxaddress.
3, run a few times, you will get eax,ecx different values, where eax is the correct checkword, the EAX value assigned to ECX can be. There are two different times, so there are two checkword.
4, search Kenrel.dll's first address, this machine is 7c800000, ctrl+b, input: XX 7 C. Then search for the second address of the DLL address, you can get seconddlladdress. After changing the second Checkword, the seconddlladdress changes to the first DLL address, run can be bypass.
Second, after the 2.1.x.x version of the OEP features (2.0.8.0,2.1.0.10,2.1.3.32, etc.):
Bypass process:
1, need a usable license
1th, the 2 steps are the same as above.
In the 3rd step, there is only one checkword, but this checkword value also has two checks, each assigned to ECX can be bypass.
Three, also encountered a bypass, is the need to constantly monitor the value of EAX and seconddlladdress, do not know which version belongs to. You can see the tutorial Winlicense ByPass for seconddlladdress.
The above three versions of the bypass process need to distinguish, mainly see the value of CMP ecx,eax time to identify!
Winlicense shelling Process:
Insert the bypass script into the ZHW hwid themida-winlicense 1.x-2.x Multi PRO Edition 1.2.txt to achieve bypass and shelling.
Search the/*ZHW Bypass * * section to see the inserted script.
Originally from: http://www.jiamikong.com/doc/3724
Themida and winlicense Shell software shelling tutorial