SERIAL NUMBER IS FISHY - DECLINE YOUR PATCH'ITCH'ING File Slicer v2.0 A Cracking Tutorial by ASTAGA [WTF/TTM] DISCLAIMER This reading material is not intended to violate Copyrights and/or it is law, but educational purposes only. I hold no responsibility ( by all means and in any shape whatsoever ) of the mis-used of this material. Read END NOTES section at the end of this file. ABOUT THE PROGRAM The long awaited updated version of File Slicer. File Slicer is a utility that breaks down any file into smaller files, then re-assembles the files back into the original. You can use it to break down any file including, ZIP files, EXE Files, and graphics. File Slicer can keep a log of files sliced and joined. You use File Slicer program to re-assemble sliced files, but best off all you don't have to have a copy of File Slicer to re-assemble the files remotely! File Slicer has an option that allows you to create a .bat file that will assemble the sliced files remotely, making it ideal for sending Sliced files over the internet or office network. It's fast and reliable and best of all it is value priced. WHERE TO DOWNLOAD Author : DCM Software Copyright : DCM Software Homepage : http://www.dcmsoftware.bizland.com/products.html URL : http://www.dcmsoftware.bizland.com/slicer.html http://members.xoom.com/websigns/slicer2.zip http://www.dcmsoftware.bizland.com/slicer2.zip Size : 590KB as of Jan 02, 2001 Rel Date : September 24, 2000 HOW TO GET VALID SERIAL NUMBER by using SoftIce This is VB5 based program. Before you apply this tute, make sure that your WINICE.DAT is containing " EXP=c:\windows\system\ msvbvm50.dll " statement. Do not cheat by using SmartCheck, because an old weapon still usable to defeat this utility program. 1. Run SLICER2.EXE, in the registration dialog box type these below informations : Name : Pirates Order Code : 73881050 Do not click OK button yet 2. Load SoftIce by pressing [ CTRL + D ], set a breakpoint as follow : BPX multibytetowidechar [enter] and F5 to return to the main program 3. Now, click OK button... you'll return back into SoftIce! In within SoftIce press F11, F5, F11 once again until you see and break at : ______________________________________________________________ 015F:7B331506 FF1590112F7B CALL [KERNEL32!MultiByteToWideChar] 015F:7B33150C 8BC5 MOV EAX,EBP <== break here 015F:7B33150E 5D POP EBP 015F:7B33150F 5F POP EDI 015F:7B331510 5E POP ESI 015F:7B331511 5B POP EBX 015F:7B331512 C20800 RET 0008 .... ______________________ MSVBVM50!.text+00040506 _______________ While you stop at 015F:7B33150C - display ESI register : : d esi [enter] did you see your name at virtual address 0167:00CA173C ??? Press F10 once - stop at 015F:7B33150E - display EAX register registers : : d eax [enter] did you see your name at virtual address 0167:00435030 ??? Several lines below are your fake code and pay attention to the sequence number at virtual address 0167:00435080 upto 0167:00435090 .. write it down. Remember they're all in wide format. EAX=00435030 EBX=0000000E ESI=00CA173C EDI=FFFFFFFF EBP=00435030 EIP=7B33150E o d I s Z a P c CS=015F DS=0167 SS=0167 ES=0167 FS=3F1F GS=0000 ___________________ byte ____________ PROT___(0) ____________ 0167:00435030 50 00 69 ... 73 00 20 00 P.i.r.a.t.e.s. . 0167:00435040 4F 00 72 ... 2C 00 00 A0 O.r.d.e.r...,... 0167:00435050 0E 00 00 ... 31 00 30 00 ....7.3.8.8.1.0. 0167:00435060 35 00 00 ... 00 00 00 00 5............... 0167:00435070 00 00 00 ... 20 00 00 00 ....LPC.4... ... 0167:00435080 4B 00 55 ... 44 00 43 00 K.U.A.1.0.W.D.C. <=== 0167:00435090 4B 00 32 ... 57 00 37 00 K.2.1.E.H.9.W.7. <=== 0167:004350A0 00 00 00 ... 21 00 00 A0 ............!... 0167:004350B0 1C 00 43 ... 00 00 00 00 ..C. Never attribute to malice that which is adequately explained by stupidity ASTAGA [WTF/TTM/D4C/C4A] tute-slicer20.zip [EOF] 1/3/01 3:01:32 PM