Valek / Phrozen Crew - Cracking Tutor #03

Target : CPIE v2002 Release 1
Target URL : http://besoft.be
Tools : PEiD v0.8 or PE-Scan v3.13, De-Crunch v1.0, Numega SmartCheck v6.2
Tools URL : http://protools.cjb.net


INTRODUCTION
Welcome to my third tutor for the Phrozen Crew. This tutor focuses on the Numega SmartCheck method of cracking a Visual Basic application. What SmartCheck does is, it decodes the Visual Basic application to source code at runtime! Ok, lets go for it, but remember, not ALL visual basic application will be easy to crack using SmartCheck, especially P-Code compiled application.


IDENTIFICATION

Like with all other target programs, it is an advantage to know whether or not an application is packed with a encryption/protection scheme and if so, with which one. For this reason I recommend the PEiD (PE iDentifier v0.8) coded by snaker & Qwerton or PE-Scan v3.13 by Snyper.



I also recommend that if you use PEiD that you turn on the HARDCORE scanning option number 2 ON. The reason for this is that a lot of the more advanced packers/encryptors will try and fake identifiers by using other packers/cryptors' identification strings as well as virtually no identification markings at all. This will limit those chances to allmost none!



Using either one of these identification packages (I use both since PEiD will tell me what language it was coded in too whereas PE-Scan will give me more SPECIFIC packer versions numbers), you will find out that Tweaki is protected by Bit-Arts' Crunch v2.0.0.2 protection scheme.

Now using these identification utilities, you will see that the application is NOT protected with any third party packer/encryptor. Using PEiD, you will also easily find out that this application had been coded in Visual Basic 6 - making it a perfect SmartCheck candidate...



CRACKING THE CODE

Start up SmartCheck and load CPIE into SmartCheck and run it using the triangle "RUN" button. You will be faced with a NAG screen, click on "REGISTER". Enter your desired name and any fake serial number, ie. for the name I used "Valek / Phrozen Crew" and for the serial number I used "11111-11111-11111-11111". Now click again on "REGISTER. Another NAG screen will pop up telling you that you had entered an invalid serial name/number combination. Do NOT close this NAG screen yet but rather Alt+TAB back to SmartCheck. Scroll all the way down and expand the "Click" event. If you again scroll all the way down, you will see a "CmprStr" event... Single-click on this event and write down the correct serial number on a piece of paper since SmartCheck won't let you copy/paste the serial number. Click the red "STOP" button and click "Yes" to the question whether SmartCheck should close CPIE as well.

Start up CPIE and when you get the NAG screen click on "REGISTER" and enter your name and the correct serial and click again on "REGISTER", ie. for the name I had used "Valek / Phrozen Crew" and for the serial number I now use "V2Q1O-2vPf9-nE0R1-fiCnM"

Congratulations! - You have successfully cracked CPIE!


Enjoy!

Valek / Phrozen Crew

PS: Click on the Phrozen Crew logo to visit our website or on my logo to contact me via email