Welcome to Cracking Tutorial #113! Hiya guys, Hmm from Tuts #105-110 it seemed I forgot to replace Tutor #numbers in Welcome Screen. So excuse me please :) Well, here is another tut113.tKC... Oh yes, there might be a while before next tutors coming, I'm moving to another town. Take care while I'm off ;) Let's rave! ...or crack babes? :) You'll need the following tools: (I use these tools, I assume you'll use 'em, but it doesn't mean that you'll need to use all those tools, so be sure to get them handy for the examples in this tutorial!) SoftICE v4.05 W32Dasm v8.93 Hacker's View v6.55 SmartCheck v6.03 ProcDump32 v1.6.2 TRW2000 v1.22 IDA v4.04 Windows Commander v4.51 (I use it coz of easier to multitask) Delphi, VB, C++, or TASM to code a keygen or a patch.. Don't ask me where to download all these tools since you had a chance to get them when you used my older tutorials. Here are a few good sites where you can grab tools from: http://protools.cjb.net http://w3.to/protools http://www.crackstore.com or ask any crackers to get you these tools! Are you ready?! OK! ;) SERIAL NUMBER IS FISHY - DECLINE YOUR PATCH'ITCH'ING. Audio Companion v1.11 A Cracking Tutorial by ASTAGA [D4C/C4A] DISCLAIMER This reading material is not intended to violate Copyrights and/or it is law, but educational purposes only. I hold no responsibility ( by all means and in any shape whatsoever ) of the mis-used of this material. ABOUT THE PROGRAM This program consists of three parts: one to read from the computer's CD-ROM unit digitally (CD Ripper), a wav to MP3/WMA encoder, a MP3 to wav decoder and a maximizer (Batch Processor) and a sound recorder allowing you to record music via your com puter's sound card (Audio Splitter). WHERE TO DOWNLOAD Author : Roni Music, Malmoe-Sweden Copyright : Roni Music Homepage : http://www.ronimusic.com URL : http://www.ronimusic.com/audiocom.htm Size : KB as of ,2000 HOW TO GET VALID SERIAL NUMBER by using SoftIce Note: When registering, you must supply your user ID. The user ID is the code displayed at the top of the window. If you don't see it, you'll have to download the latest version from our web site. After ordering, you'll receive a personal password based on this user ID. This entitles you to use the software on your computer. In this tute my ID=2DEAD6E2 1. Run AUDIOCOM.EXE, click HELP/PASSWORD submenu, in the registration dialog box type these below information : Password : 73881050PSWD Do not click OK button yet 2. Fire up SoftIce by pressing [ CTRL + D ], set a breakpoint as follow : bpx GetDlgItemTextA [enter] Press X or F5 to return to the main program 3. Now it's time to click OK button... you'll return back into SoftIce! In within SoftIce press F11, F5, F11 once until you see these below snippet codes : ______________________________________________________________ 015F:00404C62 FF15E0624200 CALL [USER32!GetDlgItemTextA] 015F:00404C68 E873FDFFFF CALL 004049E0 <== break here 015F:00404C6D 85C0 TEST EAX,EAX 015F:00404C6F 7456 JZ 00404CC7 ==> *** ... ... 015F:00404CC4 C21000 RET 0010 015F:00404CC7 8D442404 LEA EAX,[ESP+04] <== *** 015F:00404CCB 68880B4300 PUSH 00430B88 015F:00404CD0 50 PUSH EAX 015F:00404CD1 B9784E4400 MOV ECX,00444E78 015F:00404CD6 E8250A0000 CALL 00405700 015F:00404CDB 8D4C2404 LEA ECX,[ESP+04] 015F:00404CDF 51 PUSH ECX 015F:00404CE0 E88BFCFFFF CALL 00404970 015F:00404CE5 83C404 ADD ESP,04 ===> d eax 015F:00404CE8 8D542404 LEA EDX,[ESP+04] _____________________AUDIOCOM!.text+3C61___________________ Break due to BPX #015F:00404C62 Press F10 8 times - stop at 015F:00404CE5 - and display EAX register : : d eax [enter] ==> at virtual address 0167:0067F640 did you see 119AD111 ? Write it down, this could be a potential password. Look at 2 lines below there is your prog ID. 4. Disable all breakpoints by typing BD * [enter] Press F5 or X to return to the main program 5. Repeat registration procedure and keyed-in 119AD111 as your S/N . Click OK/REGISTER button ..... ouchh! the screen splash and classic message " thank you .... " . 6. Where the hell is my registration code is stored ?? The correct registration code is stored in the AUDIOCOM.INI as follows : [Init] Always on Top=0 Window Xpos=10 Window Ypos=10 Password=119AD111 Screen=0 Used Before=1 7. How can I practise with my own user name ? - I strongly recommended you not to do this! FAQ ABOUT ME continued ... * When and how did you start cracking .... ? Dunno exactly ( but I made my own tracks over DIGGER game long time ago ). I interested in cracking after I saw early tKC release ( before he founded PC96 ), UCF, ChiangMai, BlackSquad ron (G-Rom,theBritish,Prometheus) thru very expensive compuserve.com BBS account. After that I found and read good ol' Assembler Language tutorial by Hugo Perez, The Cracking Manual by Cyborg, Uncle Joe's handbook, TKC tute #1-8 , ED!SON tute, Intro to Win95 Cracking by eXact/oRP (aka siceboy), tutes from FLU[X], romeo[D4C], and MEXELITE/CbD. * What did you hate(s) in cracking ... ? Packed program! and to be honest Delphi based program. * Do you keygen ... ? NO and never! I will not let you register the program using your own name. Three years ago I talked with Ian D. Mead and took an empathy how much the Auhor(s) lost their potential income due to keygen. ( I cracked his crippleware MEDIT - embryo of UltraEdit ... he was just remind me .. whatta wise man ) But keygen is LeetZ!?! yes and no, it depends on your point of view. * What is your wish(es) : A : Drink beer and teasing girl with TKC, Marquis de Soiree, G-ROM, Saltine, ThatDude, Quantico, Lost Soul, ByteRipper, Aqua(dude), Prome'I bring Fire' theus, TheBritish, Egis, AliBaba, romeo-JUANDA, Odin, CyberLatin, Carpathia, Bunter, DJPaul etc. * No more FAQ please. E N D N O T E S Distributing your serial number is illegal and is no different than distributing illegal copies of the registered software. Violation of this rule may result in temporary or permanent revocation of this license and cancellation of the serial number; the original licensee will also be held responsible for damages, physical and estimated. Do not distribute your crack release based on this tutorial, because you become a LAMER(s)! ( tHATDUDE (PC97) defined LAMER(s) is the guy who sits in front of personal computer, using Hex Editor, ripping off other group(s) crack release, repacking (distro) them under his name. Adopted from newsgroup alt.cracks, alt.crackers - February 1997 ) More about LAMER(s): lamer /n./ [prob. originated in skateboarder slang] Synonym for luser, not used much by hackers but common among warez d00dz, crackers, and phreakers. Oppose elite. Has the same connota tions of self-conscious elitism that use of luser does among hackers. < SOURCE: http://sagan.earthspace.net/jargon/jargon_27.html > Never attribute to malice that which is adequately explained by stupidity ASTAGA [D4C/C4A] tute-audiocom11.zip [EOF] 11/12/00 5:33:03 PM SERIAL NUMBER IS FISHY - DECLINE PATCH'ITCH'ING AutoShutdown v3.7 A Cracking Tutorial by ASTAGA [D4C/C4A] DISCLAIMER This reading material is not intended to violate Copyrights and/or it is law, but educational purposes only. I hold no responsibility ( by all means and in any shape whatsoever ) of the mis-used of this material. READ End Notes in the below section of this material. ABOUT THE PROGRAM A Windows 32-bit utility to automatically shutdown your system. An icon resides in the system tray for ease of use. You may set up this utility to shutdown after a period of inactivity or at a specified time each day. AutoShutdown has many features, including the ability to automat ically detect when your system is inactive. You may disable the auto features and still use the other functionality of AutoShut down. Since AutoShutdown installs itself in the background, it can be configured to perform actions at a set date and time, during a period of inactivity or when a hot key is pressed. WHERE TO DOWNLOAD Author : Don Metzler Copyright : Barefoot Productions, Inc. Homepage : http://www.barefootinc.com URL : http://www.barefootinc.com/files/autoshut.zip Size : 1.5 MB as of August 17, 2000 HOW TO GET VALID SERIAL NUMBER by using SoftIce 1. Run AUTOSHUTDOWN.EXE, click on the REGISTRATION tab, , in the registration dialog box type these below informations : Name : Pirates Order Code : 738810509 Do not click OK button yet You have noticed that the OK button was dimmed/grayed, so let the cursor remain in the Reg Code field box . Do not click OK button yet 2. Fire up SoftIce by pressing [ CTRL + D ], set a breakpoint as follow : BPX GetDlgItemTextA [enter] and F5 to return to the main program 3. Now press BACKSPACE once ( i mean delete the " 9 "! )... you'll return back into SoftIce! In within SoftIce press F11, F5, F11, then you'll break and see these below codes : __________________________________________________________________ 015F:00495C5C FF15B4174000 CALL [USER32!GetDlgItemTextA] 015F:00495C62 EB10 JMP 00495C74 015F:00495C64 FF7510 PUSH DWORD PTR [EBP+10] 015F:00495C67 8B10 MOV EDX,[EAX] ......... ......... ____________________ AUTOSHUTDOWN!.data+00078C5C _________________ Clear previous breakpoint because you just need to reach the main program's codes only. : bc * [enter] Do a search string as follow : : s 0 l ffffffffffff ff d7 85 c0 0f 84 B3 00 00 [enter] Pattern found at 0167:004671A1 (004671A1) Set a new breakpoint at this location : : bpx 0167:004671A1 [enter] Press X to let SoftIce break in this location 4. If nothing goes wrong you'll break again in SoftIce and see these below snippet codes : __________________________________________________________________ 015F:0046719E FF750C PUSH DWORD PTR [EBP+0C] 015F:004671A1 FFD7 CALL EDI <== break HERE 015F:004671A3 85C0 TEST EAX,EAX 015F:004671A5 0F84B3000000 JZ 0046725E 015F:004671AB 8B7D0C MOV EDI,[EBP+0C] 015F:004671AE 57 PUSH EDI ==> D EDI 015F:004671AF 53 PUSH EBX 015F:004671B0 E875FFFFFF CALL 0046712A 015F:004671B5 59 POP ECX ==> D ECX/EDX 015F:004671B6 85C0 TEST EAX,EAX 015F:004671B8 59 POP ECX 015F:004671B9 0F85AB000000 JNZ 0046726A ==> D ECX 015F:004671BF 8D45C0 LEA EAX,[EBP-40] 015F:004671C2 68B86A4200 PUSH 00426AB8 015F:004671C7 50 PUSH EAX 015F:004671C8 E8838D0100 CALL 0047FF50 015F:004671CD 8D45C0 LEA EAX,[EBP-40] 015F:004671D0 68C06A4200 PUSH 00426AC0 015F:004671D5 50 PUSH EAX 015F:004671D6 E8858D0100 CALL 0047FF60 === 015F:004671DB 8D45C0 LEA EAX,[EBP-40] 015F:004671DE 53 PUSH EBX 015F:004671DF 50 PUSH EAX 015F:004671E0 E87B8D0100 CALL 0047FF60 015F:004671E5 6AFF PUSH FF 015F:004671E7 8D85C0FEFFFF LEA EAX,[EBP-0140] 015F:004671ED 6A00 PUSH 00 015F:004671EF 50 PUSH EAX 015F:004671F0 8D45C0 LEA EAX,[EBP-40] 015F:004671F3 50 PUSH EAX ==> D EAX 015F:004671F4 E876000000 CALL 0046726F 015F:004671F9 83C428 ADD ESP,28 ==> D EAX 015F:004671FC 8D85C0FEFFFF LEA EAX,[EBP-0140] 015F:00467202 57 PUSH EDI 015F:00467203 50 PUSH EAX ... ... ... 015F:00467230 7538 JNZ 0046726A ## ==> 00467232 56 PUSH ESI 015F:00467233 8D85C0FEFFFF LEA EAX,[EBP-0140] 015F:00467239 6A01 PUSH 01 015F:0046723B 50 PUSH EAX 015F:0046723C 53 PUSH EBX 015F:0046723D E82D000000 CALL 0046726F 015F:00467242 6A01 PUSH 01 ==> D EAX HERE 015F:00467244 8D85C0FEFFFF LEA EAX,[EBP-0140] 015F:0046724A 57 PUSH EDI 015F:0046724B 50 PUSH EAX 015F:0046724C E861000000 CALL 004672B2 015F:00467251 83C41C ADD ESP,1C 015F:00467254 85C0 TEST EAX,EAX 015F:00467256 750D JNZ 00467265 015F:00467258 46 INC ESI 015F:00467259 83FE10 CMP ESI,10 015F:0046725C 7ED4 JLE 00467232 (JUMP ) ==> ## 015F:0046725E 33C0 XOR EAX,EAX ______________________ AUTOSHUTDOWN!.data+0004A19E _______________ Well at this stage this gonna be long ( but interesting ) tracing, just be patience and always watch your Data Window; keep on going pressing F10 key and stop in the location as explained in the below. Let's dance. 015F:004671A1 d edi [enter] ==> your fake code at 0167:7AB108 015F:004671B5 d ecx [enter] ==> see that part of generated code d edx [enter] ==> your name at 0167:7AB008 015F:004671DB d ecx [enter] ==> what is ASD42... at 0167:426AC4 015F:004671DB d ecx [enter] ==> ASDS42-PIRATESORDER at 0167:7AAFAC 015F:004671ED d eax [enter] ==> ASDS42-PIRATESORDER at 0167:7AAFAC 015F:004671F9 d eax [enter] ==> AS3E-637-138-2FFA at 0167:7AAEAC kewl, this one looks like a serial number. Write it down! 5. Disable all breakpoints by typing BD * [enter] Press F5 or X to return to the main program 6. Repeat registration procedure and keyed-in AS3E-637-138-2FFA as your S/N . Did you see that OK button got cleared ? No ????? 7. Hahahah ... GOTCHA! RESTART your tracing, press F10 from last memory location ( 015F:004671F9 ). 015F:0046721B d ecx [enter] ==> your last potential reg code changed into AS3E-441-031-E880 at 0167: 7ADE74. 015F:00467239 d eax [enter] ==> AS3E-441-031-E880 at new virtual address 0167:7ADE64 . 015F:00467242 d eax [enter] ==> kewl, new potential reg. code AS3E-763-031-211X-1FB5 at 0167: 0167:007ADE64 . Write it Down. This time I won't cheat you .... just verify these below snippet codes : EAX=007ADE64 EBX=007ADFC0..EDX=00354246 ESI=00000001 EDI=007AE0C0 EBP=007ADFA4..EIP=00467242 o d I s z a p c CS=015F DS=0167 SS=0167..ES=0167 FS=1B37 GS=0000 -----------------------------byte--------------PROT---(0)-- 0167:007ADE64 41 53.....32 31 31 AS3E-763-031-211 0167:007ADE74 32 58.....17 01 00 2X-1FB5..n...... 0167:007ADE84 00 00.....17 19 1C .....G....>..... 8. Disable all breakpoints by typing BD * [enter] Press F5 or X to return to the main program 9. Repeat registration procedure and keyed-in AS3E-763-031-211X-1FB5 as your S/N . Did you see that OK button got cleared ? YES! Click it .... you're registered. 10. In main program click HELP/HELP CONTENTS submenu, click on REGISTERING subhelp menu and read that Register Form. This program offers you more than 1 user license even site licenses. Iam so curious about this and drives me to return back into SoftIce. 11. Let's trace again, this time start from 015F:00467242 , just press F10 .... wait, do D EAX at 015F:00467242 and BELIEVE ME stay always there! 015F:0046725C ==> jump/loop to 015F:00467232 keep on pressing that damn F10 until you jump passed 015F:0046723D. Look at the Data Window your AS3E-763-031- 211X-1FB5 changed into AS3E-763-031-211X- 3F6B! Watch for the last prefix! Press again F10 , you'll loop again and after jump passed 015F:0046723D ( stop at 015F:00467242 ) the last prefix changed into 5F21. I do it for 10 times ( you can do it several times ) and stop after I got last prefix 1D66 and 3D1C. 12. Next, I keyed-in AS3E-763-031-211X-1D66 as the serial number, yes, they're accepted! I clicked HELP/ABOUT submenu .... it was registered for 750 users. 13. Where the hell is my registration code is stored ?? The correct registration code is stored in the registry as follows : REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Barefoot Productions\AutoShutdown\ Registered] "Name"="PIRATES ORDER" "Code"="AS3E-763-031-2112X-7ED7" ==> 100 users license 14. How can I practise with my own user name ? - I strongly recommended you not to do this! FAQ ABOUT ME : * Does ASTAGA has a meaning ? A : Yes. It's an Arabic word meaning " oh my God ... " an expression for surprise or even disgusting situation/condition. Note : ASTAGA was also my handle name / call sign in CB and/or ham radio in the past 1976. * Why do you always put " Pirates Order " as your user name and 'Red Rackham' as your company name ?? A : First, it is to avoid you to use your own name during improper/illegal registering shareware program. Second, it was inspired by old TV Serial " Democratic Order of Pirates International " . Don't you realize that all what we have done is about piracy ? ... * Why do you always put " 73881050 " as your fake code ? A : First, it was adopted from my local CB's Ten Code ( Citizen Band ) listing 10-73 (=nice talk with you Pal ... ); 10-88 (=cherio/ciao ... ); and 10-50 (=stop transmitting/break/clear the channel). Second, I feel it's a nice combination in fishing S/N and in most cases reg code consist of 8 chararacters. * Do you hate patching ... or dead listing approach ? A : Not really! First, it's depend on the program as long as they're caught in SoftIce. Second, making a dead listing consumed my harddisk space and I lost my patience during they're disassembled. However, i love reading TKC tutes #1-9 and FLU[X] from where i learn patching; for you newbies download those 2 amazing tutes also crack tute pack called romeo[D4C] and KLEE8084 from Sandman's web site. * to be continued ..... E N D N O T E S Distributing your serial number is illegal and is no different than distributing illegal copies of the registered software. Violation of this rule may result in temporary or permanent revocation of this license and cancellation of the serial number; the original licensee will also be held responsible for damages, physical and estimated. Do not distribute your crack release based on this tutorial, because you become a LAMER(s)! ( tHATDUDE (PC97) defined LAMER(s) is the guy who sits in front of personal computer, using Hex Editor, ripping off other group(s) crack release, repacking (distro) them under his name. Adopted from newsgroup alt.cracks, alt.crackers - February 1997 ) More about LAMER(s): lamer /n./ [prob. originated in skateboarder slang] Synonym for luser, not used much by hackers but common among warez d00dz, crackers, and phreakers. Oppose elite. Has the same connota tions of self-conscious elitism that use of luser does among hackers. < SOURCE: http://sagan.earthspace.net/jargon/jargon_27.html > Never attribute to malice that which is adequately explained by stupidity ASTAGA [D4C/C4A] tute-autoshutdown37.zip [EOF] First Edited : 08/18/00 1:38:24 AM Revised/Updated : 11/15/00 1:14:41 PM Open the app ANR.EXE (audio notes recorder v2.00) in w32dasm.. and go to SDR... look for the error msg you get when you try to register with fake serial (innuendo/22446688) you see the message (xcemico blabla:)... double click, scroll up, now you'll see the complete message! scroll up untill you see a reference, trace into it, and you'll come here: :0043C441 0F84CD000000 je 0043C514 lets change it into 0F85 (jne).. launch hiew.. load the app, go to the offset.. and change this data, press F9 to update and F10 to quit. launc the exe.. try to register.. nice! it works!.. now.. let's go to about.. "registered to: &name-you-filled-in" let's close the app, and restart it.. go to about.. damn.. "unregistered"... so.. that doesn't stop us.... go (again) to SDR in w32dasm and search "unregistered"... double click on it.. close the window.. scroll up untill you see a reference, go to that location in the code... scroll up untill you see a call, trace into that call (use your bar at top), and note the offset open the app again in hiew, go to the offset you just noted, and press F3 (edit) -> F2 (type commands): mov eax,1 ret F9 F10 start app again.. register (if needed), go to "about and see it's regged" ;) g'luck Audio.Notes.Recorder.v2.0.Cracked-CiA << the CiA release! g'luck innuendo - innuendo@crackersinaction.com for comments! another one.. we MUST be flying! and now.. another tut on smartcheck (my favorites!) Vb Crash Shield v1.0.11 (www.ImronCorp.com/vbcrash.htm) In my last tutorial i gave you a way on HOW to get 2 valid serials for ONE program, you know that isn't always possible (or at least, NOW you know). In this program, we have "Unregistered User" which uses a bad serial, but.. it's possible to find a serial FOR it, and also to find a serial for the name YOU entered in ONE run.. so.. let's go! launch smartcheck (you've seen it was smartcheck in the hex view of the file!), open the file and run it, try to register with your name (i got this -debugfile- from another CiA cracker/coder, so it will be "darks" we use instead of innu.. high ds ;) after you tried to register the app with a bad serial, and you got that errormessage, close it, and return to smartcheck. Be sure you "show all events" and here we go! you'll see something like: - mnu_h(2)_Click frmAbout (Form) created -frmAbout_Load OnError(long:-1) .... "UnRegistered User " (length = 80.. filled with spaces...) so.. scroll whole this part down and at the bottom OF THIS PART you start tracing upwards... if you click out some events, (config s'check so it shows numbers in front of each line), you'll see at line 7957: "Invalid Registration#".. wasn't that the errormessage you got?? lets scroll up, the serial will show up in some minutes ;) If we show only the code we want "show specific events & errors" and go to the end of cmd, then select "view all events", and scroll up.. at a moment you'll see (at location 7683): - __vbaVarCat(VARIANT:String:"UnR", VARIANT:Single:6256) returns DWORD: 65F330 sounds interesting, doesn't it?? click on it! the line under this one is __vbaVarTstEq(VARIANT:Const String:"", VARIANT:String:"UnR6256") returns DWORD:0 << the serial for unregistered?? YES! (so the program gives a fake serial every time it starts as long its unregged;) now, we want a serial for the name we entered.. looking at the first serial we found it will prolly be something like "dar****" where **** = number... DarkShadow entered "darks" as name, so so i'll show you... go to "view specific events and errors", go to the cmd_abt(0)_Click (cmd = command button), and scroll down, at the bottom you'll set s'check to view "all events" you'll see a MsgBox(..) with some __vba*** shit above it, "unsuccess.." all shit! at one place you see __vbaVarTstEq(VARIANT:CONST STRING:"",VARIANT:STRING:"dar5493") returns DWORD:0 looks like the serial for darks.. doesn't it? try it.. and yes, it works! CiA rls: Vb.Crash.Shield.v1.0.11.Serial.Only-CiA g'luck innuendo - innuendo@crackersinaction.com for comments! another one.. we MUST be flying! DongJong's NEWBIE TUTORIAL DongJong's How to get a PERSONAL SERIAL for Visi Font Pro v3.0 Tools to use ~~~~~~~~~~~~ SmartCheck 6.xx Where to get Tools ~~~~~~~~~~~~~~~~~~ http://cracking.home.ml.org http://surt.to/HarvestR http://crackstore.com http://www.pepsoft.com Where to get the program ~~~~~~~~~~~~~~~~~~~~~~~~ Visi Font Pro 3.0 http://www.dcmsoftware.bizland.com/visipro.zip Program description ~~~~~~~~~~~~~~~~~~~ Visi Font Pro 3.0 is the simpliest and fastest way to view, manipulate, catalog, and print fonts installed on your computer. All your installed fonts will automatically be loaded into the program and then displayed on the screen. Procedures ~~~~~~~~~~ Start SmartCheck (SC) and open Visipro.exe, run the program by pressing F5, as usual, you need to click only the "ACKNOWLEDGE" button when SC is running and gives you option buttons to click to, until we came when SC now loads the program. A $9.95 value after the 30 day demo :> Okey! lets go on, after clicking those SC acknowledge button, the program will load, and whoa! a yellow bannered registration information and counting days you have used their program, you won't really missed registering it or you won't miss cracking it :> he he :> funny analogy :> then choose the Option --> Register menu, it ask for your name and code, there enter any name and serial number you like. Okey, here's the short of it (enter any serial just follow my tut) : Name: Albert Alexander Lay Serial Number: 1434 Then after filling on the details click on UNLOCK, and a not so nice message will greet you saying "Registration not successful. Re-enter data or contact DCM software". Just click CANCEL go on and just click on and exit the program, press on the error the "Acknowledge" button and SC stops tracing for us to begin hunting that code :> Ok, so now let's look on the left side of SmartCheck, as usual there are many to choose from which is which, as always this tutorial will simplify the matter for you newbies out there, it's a busy life anyway :> so choose the [+]Command1_Click, after you've click on it, there'll be a long line of Mid(s) and Chr(s) along it when you continue to browse way down below it, but never mind, just go near the end of this menu... along the way you'll encounter: Mid$(LPBSTR:0070F2D4,long:1,long:1,String:"2" Chr(Integer:54) Mid$(LPBSTR:0070F2D4,long:2,long:1,String:"6" Chr(Integer:52) --- Snip for brevity's sake --- As we are going to that direction anyway :> we are almost there :> just go way straight to the end of it, there you'll see []LTrim$(String:"26442883...")now click on it and watch right pane of SC, waddya seeeeeeee :> well... [-]-- String string 004474D0 | | |--- = "2644288343573770" Hmm... if you try that out... he he... Smile! as it works! Well, that's it, you've made it! Start Visipro.exe, and click on the Registration menu and use this info: Name: Albert Alexander Lay Unlock Code: 2644288343573770 Click OK and what you got? It simply says "Registration was successful. Thank you for purchasing Visi Font Pro" kewl :> Click OK and the next time you load Visi Font Pro, click on about menu and see your name on it :> NINDOT KA-AYO! The registration details is place in the registry directory : HKEY_CURRENT_USER\Software\VB and VBA Program Settings\Visi Font Pro\Install just delete the Registerd User Registration Number value to revert to the unregisterd state of the program, follow my tut and get your own name and serial for this font software :> Maayung Gabi-i sa tanan! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Greetings goes to these people: tkc- i would like to thank tKC for his tutors. MsJessca- for hosting the tuts and inspiring tkc :> Albert Alexander Lay- KeWl DuDe! for the computer and Internet, goodluck ;) Ms. KJF- hello 7372122 :-) BJ! Fely! Yo-yo! I Love You! ;) All cracking groups and cracking fanatics and newbies galores! Have fun :> keep on rockin' ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ My good friend Albert Alexander Lay has a mobile phone +639179356877 I'd like to have some international friends all over the world, please text me via that mobile number, please state your full name, age, sex and the place (from where are you), will text you via INTERNET! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Hanggang sa Muli... MABUHAY! Another Tutor by DongJong ;-) sutra@goplay.com I really hope you've enjoyed this tutorial as much as I did! Don't miss Tutor #114 soon! ;) Credits goto: BrSrK for Splash Logo. ASTAGA for providing 2 tut in this version. innu3ndo for providing 2 tut in this version. DongJong for providing a tut in this version. To ALL the crackers: You are welcome to send me your tutors to publish them .. see below for my email address! *** 95 chars per line in textfile please! *** And all the tutors can be found at: http://www.crackersinaction.com (or on IRC, ask CiA ops for urls!) Greetz goto all my friends! You can find me on IRC or email me at tkc@reaper.org Coded by The Keyboard Caper - tKC The Founder of PhRoZeN CReW/Crackers in Action 2000 Compiled with Delphi 5 on 25 November 2000 Cracking Tutorial #113 is dedicated to iNNU3NDo... u deserved it ;)