Post subject: 6519 Bomb Diffused. Posted: Wed Dec 09, 2009 1:13 pm
1337 Beta Collector
Joined Sun Jan 11, 2009 3:29 am
Posts 2314
Favourite OS Maemo 5 PR1.3
Okay. Replaced tokens.dat and pkeyconfig from Windows 2000 VM... Check. Booted up VM. Check. (Date: Dec 02 2007) Got to the desktop with no activation reminder. Good. Restart 6519. Changed BIOS date to today (Dec 9 2009, 8:11 PM GMT+8) Started VM. No activation nags. Winkey+E, Alt, Halp>About Windows. No bomb. Task Manager. No bomb.
Do I win a cake?
DISCLAIMER: No (other) system files were harmed in the making of lulz.
_________________ Program run condition: collect keys. Deadline: 2 days.
Post subject: Re: 6519 Bomb Diffused. Posted: Wed Dec 09, 2009 1:27 pm
1337 Beta Collector
Joined Sun Jan 11, 2009 3:29 am
Posts 2314
Favourite OS Maemo 5 PR1.3
angelwolf71885 wrote:
nice.. but im worryed how this might be used by the bad guys
because activashion is dissabled
This is what people wanted all along, a debomber for 6519. BTW, major side effect: control.exe is [censored]. Oops. Time to open up WinLogon in IDA. Too bad Win.OCM aint here anymore.
_________________ Program run condition: collect keys. Deadline: 2 days.
Post subject: Re: 6519 Bomb Diffused. Posted: Wed Dec 09, 2009 1:28 pm
Guru Beta Collector
Joined Sat Jan 26, 2008 11:57 pm
Posts 901
Location Florida
Favourite OS Windows 7
PortalCake wrote:
angelwolf71885 wrote:
nice.. but im worryed how this might be used by the bad guys
because activashion is dissabled
This is what people wanted all along, a debomber for 6519. BTW, major side effect: control.exe is [censored]. Oops. Time to open up WinLogon in IDA. Too bad Win.OCM aint here anymore.
yah but if you do the same thing to 7600 no real cd key needed
Post subject: Re: 6519 Bomb Diffused. Posted: Wed Dec 09, 2009 2:25 pm
1337 Beta Collector
Joined Sun Sep 27, 2009 7:55 pm
Posts 1003
yeah, I saw Windows OCManage here yesterday
_________________ Someone once said, "there's no pattern to whether or not Windows releases are good", you're right. It's all your personal opinion. Enough said.
Post subject: Re: 6519 Bomb Diffused. Posted: Wed Dec 09, 2009 4:11 pm
Site Moderator
Joined Thu Oct 23, 2008 3:25 am
Posts 2616
Location Earth.
Favourite OS Real Life
Why not see what calls are getting 'lost' in the current control.exe, and then re-route them to the current calls that are found (and suitaable to use) EDIT: Or someone codes a replacement Control Panel that uses regestry keys for almost all of the dirty work? (shouldn't be too hard, i use reg keys on some locked down systems at school, enables aero, changes color, messes with background, all under restricted privlages)
Post subject: Re: 6519 Bomb Diffused. Posted: Thu Dec 10, 2009 1:58 pm
1337 Beta Collector
Joined Sun Jan 11, 2009 3:29 am
Posts 2314
Favourite OS Maemo 5 PR1.3
pizzaboy192 wrote:
Why not see what calls are getting 'lost' in the current control.exe, and then re-route them to the current calls that are found (and suitaable to use) EDIT: Or someone codes a replacement Control Panel that uses regestry keys for almost all of the dirty work? (shouldn't be too hard, i use reg keys on some locked down systems at school, enables aero, changes color, messes with background, all under restricted privlages)
Hmm... I'm mucking around in IDA atm. (BTW, the VM's been on for ~5 hours eating CPU cycles and it hasn't BSODed. If it did, it would have sent a really painfully screeching sound.) There seems to be a bit of code that checks a file (dunno what it is, tho.) and if it returns a certain value, it halts control.exe's execution (leaving you with either a blank CPL or none at all.)
BTW, Win2k's contol.exe does not work on Win7. I took tokens and pkeyconfig from Vista SP2, Ultimate. Chose Win2k because it's simple and boots quick.
NOTE: if you want to do this yourself, make sure to NTFS COMPRESS tokens.dat . I can't stress it enough. And yes, took me about a month to figure it out. And around 40 reinstalls of 6519.
Offtopic Comment
EDIT: Wish Win.OCM would come back. Shame that one of the best members left. Stop flaming. And DO NOT mention names.
_________________ Program run condition: collect keys. Deadline: 2 days.
Post subject: Re: 6519 Bomb Diffused. Posted: Sun Dec 27, 2009 2:29 am
Guru Beta Collector
Joined Sat Nov 15, 2008 9:47 pm
Posts 925
Nice work, PortalCake.
With Windows 7 Toolkit i fixed this build up, and got hidden desktop wallpaper, i was surprised that those were even in 6519
Also Superbar looks quite nice and i found (vista) drivers for graphic card, sound card and internet, which working great. I tried even to install DiRT 2 which runs quite well
Till i got how i can copy those files in i just searched for a long time and found it out finally, i restarted the system and the control panel was empty after restarting also "Display" and "Personalize" don't work when i right click on desktop. Also the enabled aero before restart was gone...
Some pics:
Overall pretty good work debombing it
Last edited by SLAYERMAGGOT on Sun Dec 27, 2009 1:57 pm, edited 1 time in total.
Post subject: Re: 6519 Bomb Diffused. Posted: Sun Dec 27, 2009 2:40 am
1337 Beta Collector
Joined Sun Jan 11, 2009 3:29 am
Posts 2314
Favourite OS Maemo 5 PR1.3
I have aero working 100%. BTW, debombing each of these builds manually sucks. Head on to my forums (http://phobos.co.tv) so that we'd make a universal debomber for Win6 and above. (system driver, perhaps)
_________________ Program run condition: collect keys. Deadline: 2 days.
Post subject: Re: 6519 Bomb Diffused. Posted: Wed Apr 06, 2011 9:05 am
Amateur Beta Collector
Joined Mon Dec 27, 2010 8:58 am
Posts 146
Favourite OS Win 7 RTM SP1/Win 8 RTM
PortalCake wrote:
Okay. Replaced tokens.dat and pkeyconfig from Windows 2000 VM... Check. Booted up VM. Check. (Date: Dec 02 2007) Got to the desktop with no activation reminder. Good. Restart 6519. Changed BIOS date to today (Dec 9 2009, 8:11 PM GMT+8) Started VM. No activation nags. Winkey+E, Alt, Halp>About Windows. No bomb. Task Manager. No bomb.
Do I win a cake?
DISCLAIMER: No (other) system files were harmed in the making of lulz.
Any chance you could upload these tokens.dat and pkeyconfig for us here who does not have windows 2000? Or is there another way to get it to work?
Post subject: Re: 6519 Bomb Diffused. Posted: Wed Apr 06, 2011 10:41 am
Amateur Beta Collector
Joined Mon Mar 21, 2011 2:41 am
Posts 109
Favourite OS SEGA OS
win2000 doesn't have those files, I think only late vista builds got them (not sure which builds)
he ment that he booted OS in virtual machine installed on win2000 you need files from either vista RTM or SP1 as early win7 was probably based on something among those versions of vista
Users browsing this forum: MSUser2013 and 5 guests
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum
All views expressed in these forums are those of the author and do not necessarily represent the views of the BetaArchive site owner.