Bill
Reg-Crawler (?)
Tue Dec 8 12:09:01 1998


Hi,

Here are my answers:

Q1> Where in the registry does RC keep the default program settings?

A> HKEY_Local_MachineSoftware4Developer rawler|settings

Even though I cannot make sense of the entries contain therein(?).

Q2> Where does RC store its "Days Left" counter?

ROOTRCWValue (a dword value was contained there 'b2213' i changed it jus for fun and the program read now expired)

Q3> Protections used by this program?

Nag Screen, time limit 30 days, restricted 10 bookmark limit.

I am lost as to the self modifying code - is this a reference to XORing the input?

WADSM has many string listing that look promising. (We shall see).

Q4> Any interesting files?

There is a missing registry file:

Localsoftware4Developer rawler4D

The reg key proably is stored here after the protection is passed.


QUESTION ???? I have been unable to get regmon to work on this target. What filter values did my fellow students use? File monitor worked with the 'rcrawler' filter but Regmon did not. Thankfully I had Inwatch and WXR.

Thanks!!!
Bill