Posted by D0gBytes on 1/15/2000, 2:36 am
, in reply to "D0gByte's Thread"
216.110.36.120
Installed target program using InCtrl4 ( a habit ) Found no unusual registry entries in install log.
====================
NO CHANGES MADE TO c:\windows\control.ini...NO CHANGES MADE TO c:\windows\system.ini...
NO CHANGES MADE TO c:\windows\win.ini...
=====================No Hidden files were noted during install:
FILES ADDED: (19)
---by process C:\WINDOWS\TEMP\_INS0432._MP
C:\WINDOWS\UNINST.EXE
C:\PROGRAM FILES\ACOUSTICA\DEISL1.ISU
C:\PROGRAM FILES\ACOUSTICA\CHURCH.REV
C:\PROGRAM FILES\ACOUSTICA\CONCERT HALL 1.REV
C:\PROGRAM FILES\ACOUSTICA\CONCERT HALL 2.REV
C:\PROGRAM FILES\ACOUSTICA\PLATE.REV
C:\PROGRAM FILES\ACOUSTICA\ROOM 1.REV
C:\PROGRAM FILES\ACOUSTICA\ROOM 2.REV
C:\PROGRAM FILES\ACOUSTICA\ROOM 3.REV
C:\PROGRAM FILES\ACOUSTICA\STADION.REV
C:\PROGRAM FILES\ACOUSTICA\ACOUSTICA.EXE
C:\PROGRAM FILES\ACOUSTICA\HHSERVER.EXE
C:\PROGRAM FILES\ACOUSTICA\ACOUSTICA.CHM
C:\PROGRAM FILES\ACOUSTICA\_DEISREG.ISR
C:\PROGRAM FILES\ACOUSTICA\_ISREG32.DLL
C:\WINDOWS\START MENU\PROGRAMS\ACOUSTICA 2.0.LNK
==================================Running the program for the first time produced a Nag type splash screen. Options are: Evaluate, Purchase, Register. A message about the program being shareware and Day 0 of your 30 days trial period. These messages were copied for future reference.
_
Clicking "Register" produces a box where you should enter "Name" "Company" and "Key Code" and a button to click: "Register" It is noted that 3 fields are used.Clicking the "Register" button produces a message box containing "The key noes not match licence owner" This message was also copied for future use as it is likely I will use it in a string search after disassembly.
Clicking "Purchase" takes you to some info about purchasing options. Might be useful later but not interesting at the moment.
Clicking "Evaluate" allows you into the program in Shareware mode.
Clicking "Help > About" shows some company and version info but also shows an "Unregistered" message. Noted for future string search.
Following earlier log of install and looking into the registry shows that a record of "Company" "Key" "Name" are recorded at HKEY_CURRENT_USER\Software\Acon AS\Acoustica\2.0\ Somewhere in this area is a likely spot to place registration info and maybe an entry where "Days remaining in the trial period" are calculated from. This area will probably need further investigation.
Changing the system clock ahead changes the time remaining to evaluate. Changing the system clock to before the install date causes an expired condition. Returning it to today's date restores the 30 days left for evaluation.
Regmon and Filemon don't show me anything so far, that I am not aware of. After entering data in the fields to register the program, this may change.
Disassembly with W32dasm reveals some interesting strings that will probably be used during reversing the protection:
* Possible Reference to String Resource ID=09094: "Day %d of your 30 days trail period."
* Possible StringData Ref from Data Obj ->"Your license is registered. Thank "
->"you for your purchase of Acoustica "* Possible Reference to Dialog: DialogID_03E8, CONTROL_ID:00C7, "Unregistered"
* Possible StringData Ref from Data Obj ->"Unregistered"
* Possible StringData Ref from Data Obj ->"The key does not match license "
* Possible StringData Ref from Data Obj ->"The evaluation period has expired."* Possible StringData Ref from Data Obj ->"Software\Acon AS\Acoustica\2.0\"
* Possible StringData Ref from Data Obj ->"RegisterInfo"
* Possible StringData Ref from Data Obj ->"Registered to "