|
|
|
|
|
by pieter1976
3710 days ago
|
|
The malware looks for processes with with a specific DLL loaded in it and then will replace two specific bytes with other instructions, which essentially trick the process into thinking an important check has been done. It replaced a JNZ with NOP NOP. The BAE Systems blog post has lots of techincal detail: http://baesystemsai.blogspot.co.uk/2016/04/two-bytes-to-951m... |
|
That's some good old-fashioned straightforward DRM cracking right there, I'm getting flashbacks from the 90s.