------------ HOW TO FIND REAL SERIAL NUMBER BY USING SOFTICE --------------- Program : Tickle Ver 2.4 File Size : 1.17MB Web-site : http://www.worldlynx.net/pgerhart/ Cracked By : Ex3cutor Email : Ex3cutor@hotmail.com About the program : The application is Tickle.exe and it runs in the Tray Area of the Task Bar. Tickle keeps a winsock channel alive. Most Internet Service Providers (ISP) monitor your connection for activity. If you leave the line quiet for too long they will break the connection, forcing you to redial. Tickle will keep some 'heartbeat' activity so the ISP will not hang-up on you. Plus, the new 'randomize' features will have any server convinced you are actually surfing - not just mindlessly pinging the same address once a minute. Double-click on the little hand in the Tray Area of the Task Bar to expose Tickle's main window. ******************** START SEARCHING FOR THE REAL LICENCE KEY ***************************** 1) Start Tickle Ver 2.4 Go to 'File' --> 'Register...' to show the registration box. Key in as follows : Name : Executor TNT Code : 12345678 2) Do NOT click 'Valide My Codes'! Fire up SoftIce by pressing "Ctrl D" and set a breakpoint as follow : bpx hmemcpy [Enter] then press F5 to return back to the program 3) Now, click 'Valide My Codes' to go back to SoftIce. Within SoftIce, press F5 once ! then, type bc * [Enter] to clear our breakpoint Then, press F11 once followed by F12 8 times to reach to the following codes : 00404185 6A32 push 00000032 00404187 8B4DFC mov ecx, dword ptr [ebp-04] 0040418A 83C164 add ecx, 00000064 0040418D 51 push ecx 0040418E 8B5508 mov edx, dword ptr [ebp+08] 00404191 52 push edx If nothing goes wrong, you'll stop at 00404185 6A32 push 00000032 4) Now set another break point as follows : bpx 402D38 [Enter] Press F5 once We'll then step into the following codes : 00402D38 E845740000 Call 0040A182 00402D3D 898574FFFFFF mov dword ptr [ebp+FFFFFF74], eax 00402D43 8D4D84 lea ecx, dword ptr [ebp-7C] 00402D46 51 push ecx 00402D47 8B8D78FFFFFF mov ecx, dword ptr [ebp+FFFFFF78] 00402D4D E858020000 call 00402FAA 00402D52 898570FFFFFF mov dword ptr [ebp+FFFFFF70], eax 00402D58 C645FC01 mov [ebp-04], 01 00402D5C 8D4D84 lea ecx, dword ptr [ebp-7C] 00402D5F E8DC050000 call 00403340 00402D64 85C0 test eax, eax 00402D66 0F8580000000 jne 00402DEC 00402D6C 8D55E8 lea edx, dword ptr [ebp-18] 00402D6F 52 push edx 00402D70 8D4584 lea eax, dword ptr [ebp-7C] 00402D73 50 push eax 00402D74 E807060000 call 00403380 00402D79 25FF000000 and eax, 000000FF 00402D7E 85C0 test eax, eax 00402D80 746A je 00402DEC If nothing goes wrong, you'll stop at 00402D38 E845740000 Call 0040A182 5) Now press F10 17 times to stop at 00402D79 25FF000000 and eax, 000000FF Type d edx [Enter] What did you see ? Our REAL code is there !!! (which is E51B4C5C in this case !) 6) Exit SoftIce and enter this REAL code (E51B4C5C). You'll then be welcomed by a "Thank-you" message ! Enjoy :)