Welcome to Cracking Tutorial #104! Hiya guys, Well, here is another tut104.tKC... Let's rave! ...or crack babes? :) You'll need the following tools: (I use these tools, I assume you'll use 'em, but it doesn't mean that you'll need to use all those tools, so be sure to get them handy for the examples in this tutorial!) SoftICE v4.05 W32Dasm v8.93 Hacker's View v6.55 SmartCheck v6.03 ProcDump32 v1.6.2 TRW2000 v1.22 IDA v4.04 Windows Commander v4.51 (I use it coz of easier to multitask) Delphi, VB, C++, or TASM to code a keygen or a patch.. Don't ask me where to download all these tools since you had a chance to get them when you used my older tutorials. Here are a few good sites where you can grab tools from: http://protools.cjb.net http://w3.to/protools http://www.crackstore.com or ask any crackers to get you these tools! Are you ready?! OK! ;) WHY PATCHING WHILE SERIAL NUMBER IS FISHY ButtonWiz v7.6 A Cracking Tutorial by ASTAGA [D4C/C4A] DISCLAIMER This reading material is not intended to violate Copyrights and/or it is law, but educational purposes only. I hold no responsibility ( by all means and in any shape whatsoever ) of the mis-used of this material. ABOUT THE PROGRAM ButtonWiz was designed to help you easily create stylish buttons for your web pages. It includes hundreds of pre-made styles and you can create your own in your favorite graphics program. WHERE TO DOWNLOAD Author : Joel Ryan Joel Ryan Software Homepage : http://www.joelryan.com URL : Size : KB as of ,2000 HOW TO GET VALID SERIAL NUMBER by using SoftIce At first sight ( during installation ) I didn't noticed that this is a VB6 based program. I just realized within SoftICe, but, hell .... it's VB! and I got lazy to edit my WINICE.DAT to enable exporting msvbvm60.dll. I remind you that not to follow my experience, you betta quit and edit your WINICE.DAT first before continuing cracking this program. Secondly, I have a feeling that serial number will be genera ted based on installation date ( mine is Nov 03,2000 ). So, different result in serial number may occur on your side. 1. Run BUTTONWIZ.EXE, click ENTER LICENSE button, in the registration dialog box type these below informations : Lic. Number : 73881050 Do not click OK button yet 2. Fire up SoftIce by pressing [ CTRL + D ], set a breakpoint as follow : BPX MultiByteToWideChar [enter] and F5 to return to the main program 3. Now it's time to click OK button... you'll return back into SoftIce! In within SoftIce press F11 once until you see and break at : ______________________________________________________________ 015F:6607CD84 FFD7 CALL EDI <== break here 015F:6607CD86 8BF0 MOV ESI,EAX 015F:6607CD88 4E DEC ESI 015F:6607CD89 56 PUSH ESI 015F:6607CD8A 53 PUSH EBX 015F:6607CD8B FF15E8190066 CALL [660019E8] 015F:6607CD91 8B4D0C MOV ECX,[EBP+0C] 015F:6607CD94 3BC3 CMP EAX,EBX _____________________MSVBVM60!.text+0007BD84___________________ Break due to BPX KERNEL32!MultiByteToWideChar Break due to G (ET=416.17 microseconds) Press F10 5 times - stop at 015F:6607CD91 - and display EAX register : : d eax [enter] ==> your fake code appear in the Data Window @0167:00426940. Remember they're in wide format like this : 0167:00426940 37 ... 7.3.8.8.1.0.5.0. 0167:00426950 00 ... ..p............. Create a new breakpoint as follow : : bpm 0167:00426940 [enter] Press F5 3 times , if nothing goes wrong you'll break at these below snippet codes : ______________________________________________________________ 015F:653C045E F366A7 REPZ CMPSW 015F:653C0461 7405 JZ 653C0468 <== break here 015F:653C0463 1BC0 SBB EAX,EAX 015F:653C0465 83D8FF SBB EAX,-01 015F:653C0468 85C0 TEST EAX,EAX 015F:653C046A 7F45 JG 653C04B1 ____________________OLEAUT32!.text+0007F45E___________________ Break due to BPX KERNEL32!MultiByteToWideChar Break due to BPMB #0167:00426940 RW DR3 Break due to BPMB #0167:00426940 RW DR3 Display EDI register now : : D EDI [enter] ==> look at the data window, did you see 5725 at virtual address 0167:00425592 ? Write down ! One/two lines below is your installation date information. 0167:00425582 00 00 .. 00 35 00 ..............5. 0167:00425592 37 00 .. A0 14 00 7.2.5.....$..... 0167:004255A2 00 00 .. 00 32 00 ..1.1.-.0.3.-.2. 0167:004255B2 30 00 .. 00 14 00 0.0.0........... 4. Disable all breakpoints by typing BC * [enter] Press F5 or X to return to the main program 5. Repeat registration procedure and keyed-in 5725 as your S/N Click OK/REGISTER button... ouchh! the screen splash and classic message "thank you...". END NOTES This program is sold as shareware, so you can try before you buy. This is convenient for you, saves expenses by dispensing with all that packaging, and cuts out the middle person. So it is cheap, but it is not free. If you like the program, and you will, be sure to register and pay. To keep shareware prices low, users must do the right thing: Register, pay up, and smile/grin at yourself in the mirror. Do not distribute your crack release based on this tutorial, because you become a LAMER(s)! ( tHATDUDE (PC97) defined LAMER(s) is the guy who sits in front of personal computer, using Hex Editor, ripping off other group(s) crack release, repacking (distro) them under his name. Adopted from newsgroup alt.cracks, alt.crackers - February 1997 ) More about LAMER(s): lamer /n./ [prob. originated in skateboarder slang] Synonym for luser, not used much by hackers but common among warez d00dz, crackers, and phreakers. Oppose elite. Has the same connota tions of self-conscious elitism that use of luser does among hackers. < SOURCE: http://sagan.earthspace.net/jargon/jargon_27.html > _ Never attribute to malice that which is adequately explained by stupidity _ ASTAGA [D4C/C4A] tute-buttonwiz76.zip [EOF] 11/3/00 5:33:03 PM WHY PATCHING WHILE SERIAL NUMBER IS FISHY IMon v1.1.2 A Cracking Tutorial by ASTAGA [D4C/C4A] ABOUT THE PROGRAM IMon is a utility program designed to keep track of the number of times you connect to the Internet via your telephone line each month and the duration of those connects. It provides summary information on a month-by-month basis as well as call-connect activity on a per-call detail. This is especially important if your Internet provider charges you a premium when you exceed a fixed number of hours per month of usage. BACKGROUND INFORMATION Program Name: IMon.exe Platforms: Windows 95/98/NT Free trial period: 30 days Registration cost: $15 US$. Current version: 1.1.2 Version date: 16-Feb-2000 (c)Copyright 2000 - Donth Technology Group Web site: www.donth.com Author : Joseph L. Donth HOW TO FISH SERIAL NUMBER by USING SOFTICE 1. Run the program, click REGISTER button and keyed-in fake reg code = 73881050 Do not click OK button yet. 2. Load SoftIce and create a new breakpoint : bpx hmemcpy Press F5 3. Click OK button now, and you'll break in SoftIce again. Press F11 once and press F12 several times until you see this below snippet codes. __________________________________________________________________ 015F:0044B9E6 E8D5FFFDFF CALL 0042B9C0 <== break here 015F:0044B9EB 8B55D8 MOV EDX,[EBP-28] 015F:0044B9EE 8B45F8 MOV EAX,[EBP-08] <== d edx 015F:0044B9F1 E83280FBFF CALL 00403A28 ........ ........ ________________________IMON!CODE+0004A9E6_____________________ Break due to BPX KERNEL!HMEMCPY Break due to G : bd * [enter] : BPX 015F:0044B9E6 [enter] : Press F10 2 times and display EDX register, your fake reg code appear in the Data Window at virtual address 0167:010EFDB0 . : BPM 0167:0167:010EFDB0 [enter] : Press X or F5 You'll break again in SoftIce and see these below snippet codes : _________________________________________________________________ 015F:00403D89 8B0E MOV ECX,[ESI] break 015F:00403D8B 8B1F MOV EBX,[EDI] <== here 015F:00403D8D 39D9 CMP ECX,EBX <=== ? EBX 015F:00403D8F 7558 JNZ 00403EED ..... ..... __________________________ IMON!CODE+2D89 ______________________ Break due to BPMB #0167:010EFDB0 RW DR3 Press F10 once : ? ecx [enter] : 38383337 0943207223 "8837" ==> part of your fake code : ? ebx [enter] : 31363130 0825635120 "1610" ==> part of the real code : d esi [enter] ===> your fake code at : d edi [enter] ===> did you see 0161-5448-4631-1864 at 0167:010EA318 . Write down this potential reg code. Scroll up one line above you will see your own product ID ( in my case is 5559-4526-8001-2164 ) . : bd * : F5 to return to registration dialog box 4. Repeat registration procedures, and keyed-in 0161-5448-4631-1864 as your registration code. You're registered. 5. Where the hell is my registration info is stored ?? - The correct registration code is stored in the HKCR and HKLM registry as follows ( before it's registered ) : REGEDIT4 [HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{006DFDA0-7C07-11D3 -AA01-EB99EABD0004}] [HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{006DFDA0-7C07-11D3 -AA01-EB99EABD0004}\ProgID] @="008FFC" [HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{006DFDA0-7C07-11D3 -AA01-EB99EABD0004}\Mask] @="72AD999A" 6. How can I practise with another registration key ? - I strongly recommended you not to do this ! END NOTES This program is sold as shareware, so you can try before you buy. This is convenient for you, saves expenses by dispensing with all that packaging, and cuts out the middle person. So it is cheap, but it is not free. If you like the program, and you will, be sure to register and pay. To keep shareware prices low, users must do the right thing: Register, pay up, and smile/grin at yourself in the mirror. Do not distribute your crack release based on this tutorial, because you become a LAMER(s)! ( tHATDUDE (PC97) defined LAMER(s) is the guy who sits in front of personal computer, using Hex Editor, ripping off other group(s) crack release, repacking (distro) them under his name. Adopted from newsgroup alt.cracks, alt.crackers - February 1997 ) More about LAMER(s): lamer /n./ [prob. originated in skateboarder slang] Synonym for luser, not used much by hackers but common among warez d00dz, crackers, and phreakers. Oppose elite. Has the same connota tions of self-conscious elitism that use of luser does among hackers. < SOURCE: http://sagan.earthspace.net/jargon/jargon_27.html > _ Never attribute to malice that which is adequately explained by stupidity _ ASTAGA [D4C/C4A] tute-imon112.zip [EOF] 10/31/00 6:32:06 PM WHY PATCHING WHILE SERIAL NUMBER IS FISHY InfoClip v1.1.0 A Cracking Tutorial by ASTAGA [D4C/C4A] ABOUT THE PROGRAM InfoClip is a flexible, convenient utility program that enables you to save selected text into user-defined project categories. It was designed to work with your Web browser to enable you to save text from Web pages into related text files -- simply and easily. InfoClip provides a fast, easy way for you to gather selected blocks of text as they're copied (with Ctrl-C or Ctrl-X) from any application -- without the need for tediously switching to a text editor, creating a file, inserting the text, saving the file and switching back. With InfoClip, the blocks of text are automatically collected and saved together in the InfoClip content files that you specify. InfoClip's features include: * A button for toggling the program between active and suspended states, allowing you to easily control InfoClip's cut/copy monitoring activity. * A choice of visual dividers (None, a Blank Line, Custom or Date/Time) for clearly showing separation between blocks of saved text. * An Auto-Save option which lets you specify whether InfoClip, while in the active state, will ask you each time where you want to save the block of text or will automatically save it for you. * Easy creation of your own content files with names that have meaning to you. BACKGROUND INFORMATION Program Name: InfoClip.exe Platforms: Windows 95/98/NT Free trial period: 30 days Registration cost: $15 US$. Current version: 1.1.0 Version date: 18-Jan-2000 (c)Copyright 2000 - Donth Technology Group Web site: www.donth.com Author : Joseph L. Donth HOW TO FISH SERIAL NUMBER by USING SOFTICE 1. Run the program, click REGISTER button and keyed-in fake reg code = 73881050 Do not click OK button yet. 2. Load SoftIce and create a new breakpoint : bpx hmemcpy Press F5 3. Click OK button now, and you'll break in SoftIce again. Press F11 once and press F12 several times until you see this below snippet codes. __________________________________________________________________ 015F:0044BF7E E8F9EDFDFF CALL 0042AD7C <== break here 015F:0044BF83 8B55D8 MOV EDX,[EBP-28] 015F:0044BF86 8B45F8 MOV EAX,[EBP-08] <== d edx 015F:0044BF89 E8167AFBFF CALL 004039A4 015F:0044BF8E C645F701 MOV BYTE PTR [EBP-09],01 ........ ........ ________________________INFOCLIP!CODE+0004AF7E_____________________ Break due to BPX KERNEL!HMEMCPY Break due to G : bd * [enter] : BPX 015F:0044BF7E [enter] : Press F10 2 times and display EDX register, your fake reg code appear in the Data Window at virtual address 0167:00BCBEF0 . : BPM 0167:0167:00BCBEF0 [enter] : Press X or F5 You'll break again in SoftIce and see these below snippet codes : _________________________________________________________________ 015F:00403D05 8B0E MOV ECX,[ESI] break 015F:00403D07 8B1F MOV EBX,[EDI] <== here 015F:00403D09 39D9 CMP ECX,EBX <=== ? EBX 015F:00403D0B 7558 JNZ 00403EED ..... ..... __________________________ INFOCLIP!CODE+2D05 ___________________ Break due to BPMB #0167:00BCBEF0 RW DR3 Press F10 once : ? ecx [enter] : 38383337 0943207223 "8837" ==> part of your fake code : ? ebx [enter] : 33363130 0859189552 "3610" ==> part of the real code : d esi [enter] ===> your fake code at : d edi [enter] ===> did you see 0163-2526-5556-8145 at 0167:00BCAB24 . Write down this potential reg code. Scroll up one line above you will see your own product ID ( in my case is 5550-9687-1223-8379 ) . : bd * : F5 to return to registration dialog box 4. Repeat registration procedures, and keyed-in 0163-2526-5556-8145 as your registration code. You're registered. 5. Where the hell is my registration info is stored ?? - The correct registration code is stored in the HKCR and HKLM registry as follows ( before it's registered ) : 6. How can I practise with another registration key ? - I strongly recommended you not to do this ! END NOTES This program is sold as shareware, so you can try before you buy. This is convenient for you, saves expenses by dispensing with all that packaging, and cuts out the middle person. So it is cheap, but it is not free. If you like the program, and you will, be sure to register and pay. To keep shareware prices low, users must do the right thing: Register, pay up, and smile/grin at yourself in the mirror. Do not distribute your crack release based on this tutorial, because you become a LAMER(s)! ( tHATDUDE (PC97) defined LAMER(s) is the guy who sits in front of personal computer, using Hex Editor, ripping off other group(s) crack release, repacking (distro) them under his name. Adopted from newsgroup alt.cracks, alt.crackers - February 1997 ) More about LAMER(s): lamer /n./ [prob. originated in skateboarder slang] Synonym for luser, not used much by hackers but common among warez d00dz, crackers, and phreakers. Oppose elite. Has the same connota tions of self-conscious elitism that use of luser does among hackers. < SOURCE: http://sagan.earthspace.net/jargon/jargon_27.html > _ Never attribute to malice that which is adequately explained by stupidity _ ASTAGA [D4C/C4A] tute-InfoClip110.zip [EOF] 10/31/00 6:32:06 PM WHY PATCHING WHILE SERIAL NUMBER IS FISHY RegRun II v2.51 A Cracking Tutorial by ASTAGA [D4C/C4A] DISCLAIMER This reading material is not intended to violate Copyrights and/or it is law, but educational purposes only. I hold no responsibility ( by all means and in any shape whatsoever ) of the mis-used of this material. ABOUT THE PROGRAM RegRun II is an integrated suite of utilities that give you the full control under Windows startup and guard you from trojan programs. WHERE TO DOWNLOAD Author : Greatis Software Homepage : http://www.greatis.com/regrun2.htm URL : http://www.greatis.com/regrun250.exe Size : 902 KB as of September 09,2000 HOW TO GET VALID SERIAL NUMBER by using SoftIce 1. Run REGRUN2.EXE, in the registration dialog box type these below informations : Name : Erap Last : Singson E-Mail : jueteng@impeachment.ph Code : 73881050 Do not click OK button yet 2. Fire up SoftIce by pressing [ CTRL + D ], set a breakpoint as follow : BPX hmemcpy [enter] and F5 to return to the main program 3. Now it's time to click OK button... you'll return back into SoftIce! In within SoftIce press F11, F5, F11, then F12 11 times until you see and break at : ________________________________________________________________ 015F:0043007A 0400 ADD AL,00 <==== break here 015F:0043007C 8D55E4 LEA EDX,[EBP-1C] 015F:0043007F 52 PUSH EDX 015F:00430080 8D45E0 LEA EAX,[EBP-20] ________________________________________________________________ Clear previous breakpoint and follow these below steps : bc * [enter] BPX 015F:0043007A [enter] s 0 l ffffffffffffffffff e8 84 43 08 00 [enter] SoftIce will response : Pattern found at 0030:0043078F (0043078F) bpx 0030:0043078F [enter] Press X or F5 to return to registration dialog box 4. Click OK/REGISTER button. If nothing goes wrong you'll return into SoftIce and break at : ______________________________________________________________ 015F:0043078F E884430800 CALL 004B4B18 <== break here 015F:00430794 8BD0 MOV EDX,EAX <== d edx 015F:00430796 FF8554FFF INC DWORD PTR [EBP-00AC] 015F:0043079C 8D45F8 LEA EAX,[EBP-08] 015F:0043079F E820440800 CALL 004B4BC4 015F:004307A4 FF8D54FFFF DEC DWORD PTR [EBP-00AC] 015F:004307AA 8D4580 LEA EAX,[EBP-80] 015F:004307AD BA02000000 MOV EDX,00000002 015F:004307B2 E8DD430800 CALL 004B4B94 015F:004307B7 66C78548FF MOV WORD PTR [EBP-00B8],00F8 015F:004307C0 BAD4C34C00 MOV EDX,004CC3D4 _________________________REGRUN2!.text+0002F789_________________ Break due to BPX #015F:0043078F Press F10 once, and display EDX register : d edx [enter] Look at the Data Window, did you see 759888 at virtual address 0167:00CB81A8 ?? Write down this suspicious reg code. 5. Disable all breakpoints by typing BD * [enter] Press X or F5 to return to registration dialog box 6. Repeat registration procedure and keyed-in 759888 as your S/N Click OK/REGISTER button... ouchh! the screen splash and there is no classic message "thank you for regis......"??? Just quit the application, re-run again the program, click HELP/ABOUT submenu. Simply, YOU'RE REGISTERED now... as a matter of fact it's ILLEGAL REGISTRATION! END NOTES This program is sold as shareware, so you can try before you buy. This is convenient for you, saves expenses by dispensing with all that packaging, and cuts out the middle person. So it is cheap, but it is not free. If you like the program, and you will, be sure to register and pay. To keep shareware prices low, users must do the right thing: Register, pay up, and smile/grin at yourself in the mirror. Do not distribute your crack release based on this tutorial, because you become a LAMER(s)! ( tHATDUDE (PC97) defined LAMER(s) is the guy who sits in front of personal computer, using Hex Editor, ripping off other group(s) crack release, repacking (distro) them under his name. Adopted from newsgroup alt.cracks, alt.crackers - February 1997 ) More about LAMER(s): lamer /n./ [prob. originated in skateboarder slang] Synonym for luser, not used much by hackers but common among warez d00dz, crackers, and phreakers. Oppose elite. Has the same connota tions of self-conscious elitism that use of luser does among hackers. < SOURCE: http://sagan.earthspace.net/jargon/jargon_27.html > _ Never attribute to malice that which is adequately explained by stupidity _ ASTAGA [D4C/C4A] tute-regrun251.zip [EOF] 10/31/00 3:42:43 AM WHY PATCHING WHILE SERIAL NUMBER IS FISHY ScanDiskManagerc - v1.1 A Cracking Tutorial by ASTAGA [D4C/C4A] DISCLAIMER This reading material is not intended to violate Copyrights and/or it is law, but educational purposes only. I hold no responsibility ( by all means and in any shape whatsoever ) of the mis-used of this material. ABOUT THE PROGRAM Have you ever turned off your computer under Window 95 without using the Windows shutdown/restart command? Once the computer starts up you are greeted with the blue screen of ScanDisk. ScanDisk wastes valuable time when the user knows there is nothing wrong with their computer. This program will disable (with the option of re-enabling ) ScanDisk. Just remember, ScanDisk is a very useful program, it keeps your hard drive from developing bad blocks, etc. If you use this program please run Scandisk from within Windows every once and a while. WHERE TO DOWNLOAD Author : Random Solutions Homepage : http://www.ics.uci.edu/~dmyers/software/ URL : http://sunsite.uakom.sk/pub/simtelnet/win95/util/sdm11.zip Size : ? - as of October 18,2000 Release : HOW TO GET VALID SERIAL NUMBER by using SoftIce 1. Run ScanDiskMan.exe, In the registration dialog box type these below informations : Name : Pirates Order Reg KEY : 73881050 Do not click OK button yet 2. Fire up SoftIce by pressing [ CTRL + D ], create a new breakpoint in this regard is HMEMCPY : BPX HMEMCPY [enter] and F5 to return to the main program 3. Now it's time to click OK button... you'll return back into SoftIce. In within SoftIce press F11, F5,and F11 once again. F12 seven times until you see the main progs code and landed at : 015F:0040199D FFD6 CALL ESI 015F:0040199F 8D7C2414 LEA EDI,[ESP+14] <== break here 015F:004019A3 83C9FF OR ECX,-01 <== d edi 015F:004019A6 33C0 XOR EAX,EAX 015F:004019A8 F2AE REPNZ SCASB 015F:004019AA F7D1 NOT ECX <== d edi 015F:004019AC 49 DEC ECX 015F:004019AD 83F903 CMP ECX,03 015F:004019B0 7725 JA 004019D7 __________________SCANDISKMAN!.text+099D__________________________ BD or BC 00 [enter] BPX 015F:0040199D {enter] Press F10 once ( at 015F:004019A3 ) in the command line type : d edi [enter] ==> your fake code and user name appear in the DAta Window. Look at several lines below, what are those numbers/characters are ? Press F10 stop at 015F:004019AA display EDI register, you'll see your fake reg code at virtual address 0167:0063F28D . STAY in this location and watch how the real code being copied /processed. Press F10 again and follow jump instruction at 015F:004019B0, you'll break at : __________________________________________________________________ 015F:004019D7 33C0 XOR EAX,EAX <== break here 015F:004019D9 8A4C0414 MOV CL,[EAX+ESP+14] 015F:004019DD 884C0410 MOV [EAX+ESP+10],CL 015F:004019E1 884C043C MOV [EAX+ESP+3C],CL 015F:004019E5 40 INC EAX 015F:004019E6 83F803 CMP EAX,03 015F:004019E9 7CEE JL 004019D9 ... ... 015F:00401A08 83C404 ADD ESP,04 015F:00401A0B 83FE03 CMP ESI,03 015F:00401A0E 7E1D JLE 00401A2D 015F:00401A10 33C9 XOR ECX,ECX 015F:00401A12 0FBE540C2B MOVSX EDX,BYTE PTR [ECX+ESP+2B] <== ret loop 015F:00401A17 03D0 ADD EDX,EAX 015F:00401A19 41 INC ECX 015F:00401A1A 8D541453 LEA EDX,[EDX+ESP+53] 015F:00401A1E 8A540AFF MOV DL,[ECX+EDX-01] 015F:00401A22 88540C3E MOV [ECX+ESP+3E],DL 015F:00401A26 8D5103 LEA EDX,[ECX+03] 015F:00401A29 3BD6 CMP EDX,ESI 015F:00401A2B 7CE5 JL 00401A12 ==> loop 015F:00401A2D 8D742414 LEA ESI,[ESP+14] _______________________SCANDISKMAN!.text+09D7_____________________ Press F10 until loop process at 015F:00401A2B to 015F:00401A12 completely finished. Did you notice 7380391927818518 between virtual address of 0167:0063F29D and 0167:0063F2AD ??? WRITE it DOWN. Here is what you see in the Data Window : 0167:0063F28D 00 00 00 .... 72 61 74 ...........Pirat 0167:0063F29D 65 73 20 .... 00 00 37 es Order.......7 <== real 0167:0063F2AD 33 38 30 .... 31 38 00 380391927818518. <== code 0167:0063F2BD 00 00 00 .... 35 38 39 ...3141592653589 0167:0063F2CD 37 39 33 .... 38 33 32 7932384626433832 4. Disable current existing breakpoint, press F5 to return to the registration dialog box. Keyed-in 7380391927818518 as your reg.code , click OK button and you're registered. Restart the program as their requested. 5. Where the hell is my registration info is stored ?? - The correct registration code is stored in the registry as follows : REGEDIT4 [HKEY_LOCAL_MACHINE\Software\ScanDiskManager] "ScanDisk"="2" If you delete value "2" with i.e "0" this program returned UNREGISTERED. 11. How can I practise with another registration key ? - I strongly recommended you not to do this ! END NOTES This program is sold as shareware, so you can try before you buy. This is convenient for you, saves expenses by dispensing with all that packaging, and cuts out the middle person. So it is cheap, but it is not free. If you like the program, and you will, be sure to register and pay. To keep shareware prices low, users must do the right thing: Register, pay up, and smile/grin at yourself in the mirror. Do not distribute your crack release based on this tutorial, because you become a LAMER(s)! ( tHATDUDE (PC97) defined LAMER(s) is the guy who sits in front of personal computer, using Hex Editor, ripping off other group(s) crack release, repacking (distro) them under his name. Adopted from newsgroup alt.cracks, alt.crackers - February 1997 ) More about LAMER(s): lamer /n./ [prob. originated in skateboarder slang] Synonym for luser, not used much by hackers but common among warez d00dz, crackers, and phreakers. Oppose elite. Has the same connota tions of self-conscious elitism that use of luser does among hackers. < SOURCE: http://sagan.earthspace.net/jargon/jargon_27.html > _ Never attribute to malice that which is adequately explained by stupidity _ ASTAGA [D4C/C4A] tute-SCANDISKMANAGER11.zip [EOF] 10/20/00 9:51:44 AM (All of the names above belong to their respective companies) I really hope you've enjoyed this tutorial as much as I did! Don't miss Tutor #107 soon! ;) Credits goto: IC_666 for Splash Logo. ASTAGA for providing 5 tuts in this version. To ALL the crackers: You are welcome to send me your tutors to publish them .. see below for my email address! *** 95 chars per line in textfile please! *** And all the tutors can be found at: http://www.crackersinaction.com (or on IRC, ask CiA ops for urls!) Greetz goto all my friends! You can find me on IRC or email me at tkc@reaper.org Coded by The Keyboard Caper - tKC The Founder of PhRoZeN CReW/Crackers in Action 2000 Compiled with Delphi 5 on 12 November 2000 Cracking Tutorial #106 is dedicated to CiA, all new and old members, for the support they gave me all the years!