Reverse-Engineering Vista/Windows 7 Activation

Discussion in 'Windows 7' started by witherornot, Aug 21, 2023.

  1. witherornot

    witherornot MDL Junior Member

    Nov 18, 2020
    62
    380
    0
    #1 witherornot, Aug 21, 2023
    Last edited: Aug 28, 2023
  2. sml156

    sml156 MDL Member

    Sep 8, 2009
    202
    118
    10
    why did you you obfuscat your links -- now I'm going to have to download a deobfuscator for links where do I find that and don't obfuscat that link please
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. thetank18

    thetank18 MDL Member

    Oct 23, 2019
    102
    82
    10
    Code:
    string unobfLink = obfLink.Replace("[", "").Replace("]","");
    return unobfLink; // /s
    
     
  4. gailium119

    gailium119 MDL Addicted

    Oct 12, 2021
    838
    587
    30
    last time I checked, there ain't symbols for windows7's sppsvc.
     
  5. witherornot

    witherornot MDL Junior Member

    Nov 18, 2020
    62
    380
    0
    The sppsvc I used is from the KMS Server for Windows Server 2003. I have also been able to locate symbols for windows 7's sppsvc, but it doesn't seem to contain anything not already in the one I've deobfuscated.
     
  6. gailium119

    gailium119 MDL Addicted

    Oct 12, 2021
    838
    587
    30
    Can you locate any windows 10 sppsvc's symbols?
     
  7. witherornot

    witherornot MDL Junior Member

    Nov 18, 2020
    62
    380
    0
    My focus is not on Windows 10, so unfortunately I have not looked hard into this. However, I can say that SPP related code is (relatively) well guarded nowadays, and even in leaked private symbol dumps from Windows 10, there is no mention of sppsvc.
     
  8. gailium119

    gailium119 MDL Addicted

    Oct 12, 2021
    838
    587
    30
    Can this tool deobfuscate binaries which only have specific functions warbirded like the watermark function in explorer.exe?
     
  9. CONIGUERO

    CONIGUERO MDL Novice

    May 19, 2023
    13
    5
    0
    It only works for Vista-era warbirded binaries, and even then only if you have symbols.