How to find serial for:

Rusty VB Crackme 1.0

Version 1.0 by Rusty

Written by tnHuAn


Introduction

Ok, now I'm very sad, I meet an accident, and i must go to the hospital. In hospital not have any PC, so I borrow a laptop from my friend. Yeah! this is a very good laptop: PIII 550 , 128 MB RAM with DVD, with this laptop, I can't setup SoftICe and some cracking tool : Hiew , W32dasm, and SmartCheck... Well, and I ask my friend give me a Crack CD, this is my CD, in this CD I write all about Cracking: tools, tutotrials, Crackmes,... Yep... My heath not good, so I can't do cracking in long time, and I have idea, I will choose a VB Crackme, coz a VB Crackme will easier to crack, I will use SmartCheck and it will give me some serial....And I choose a crackme : Rusty VB Crackme 1.0 ( I think : Version 1.0 usually easy ). But I wrong, With this crackme, SmartCheck can't help me anything, and I hate it, I must use SoftICe for this crackme...You know, to crack a VB Crackme, easiest is use SmartCheck, but now I use SoftIce, and It not simple...

Tools required

Target's URL

    http://www.crackmes.prv.pl

 

Essay

Ok, first of all: this crackme is a VB Crackme, so I use smartCheck, but I can't find anything with SmartCheck, so I must use SoftICe....

Run this crackme, enter some fake name and serial . I use :

Press Ctr+D to pop up SoftICe, set a breakpoint at Hmemcpy, and Click : Register it! You will kicked into SoftICe, press F5 , then Press F12 until you in MSVBVM50.Dll code, then trace the code using F10, keep tracing until you are in the program code, you will see: this crackme packed by UPX, but it not important, you don't need unpack it... Now continue tracing until you see this code :

015F:00402634 85C0 TEST EAX,EAX

015F:00402636 0F84B7000000 JZ 004026F3 (NO JUMP)

015F:0040263C 8D85E4FEFFFF LEA EAX,[EBP-011C]

015F:00402642 8D4DDC LEA ECX,[EBP-24]

015F:00402645 50 PUSH EAX

015F:00402646 51 PUSH ECX

015F:00402647 C785ECFEFFFF01000000MOV DWORD PTR [EBP-0114],00000001

015F:00402651 89BDE4FEFFFF MOV [EBP-011C],EDI

015F:00402657 FFD3 CALL EBX

015F:00402659 50 PUSH EAX

015F:0040265A 8D55CC LEA EDX,[EBP-34]

015F:0040265D 8D85D4FEFFFF LEA EAX,[EBP-012C]

015F:00402663 52 PUSH EDX

015F:00402664 50 PUSH EAX

015F:00402665 FF155C414000 CALL [MSVBVM50!rtcMidCharVar]

015F:0040266B 8D8DD4FEFFFF LEA ECX,[EBP-012C]

015F:00402671 8D95F8FEFFFF LEA EDX,[EBP-0108]

015F:00402677 51 PUSH ECX

015F:00402678 52 PUSH EDX

015F:00402679 FF1594414000 CALL [MSVBVM50!__vbaStrVarVal]

015F:0040267F 50 PUSH EAX

015F:00402680 FF1524414000 CALL [MSVBVM50!rtcAnsiValueBstr]

015F:00402686 668985ACFEFFFF MOV [EBP-0154],AX

015F:0040268D 8D459C LEA EAX,[EBP-64]

015F:00402690 8D8DA4FEFFFF LEA ECX,[EBP-015C]

015F:00402696 50 PUSH EAX

015F:00402697 8D95C4FEFFFF LEA EDX,[EBP-013C]

015F:0040269D 51 PUSH ECX

015F:0040269E 52 PUSH EDX

015F:0040269F 89BDA4FEFFFF MOV [EBP-015C],EDI

015F:004026A5 FF15BC414000 CALL [MSVBVM50!__vbaVarAdd]

015F:004026AB 8BD0 MOV EDX,EAX

015F:004026AD 8D4D9C LEA ECX,[EBP-64]

015F:004026B0 FFD6 CALL ESI

015F:004026B2 8D8DF8FEFFFF LEA ECX,[EBP-0108]

015F:004026B8 FF15E0414000 CALL [MSVBVM50!__vbaFreeStr]

015F:004026BE 8D85D4FEFFFF LEA EAX,[EBP-012C]

015F:004026C4 8D8DE4FEFFFF LEA ECX,[EBP-011C]

015F:004026CA 50 PUSH EAX

015F:004026CB 51 PUSH ECX

015F:004026CC 57 PUSH EDI

015F:004026CD FF151C414000 CALL [MSVBVM50!__vbaFreeVarList]

015F:004026D3 83C40C ADD ESP,0C

015F:004026D6 8D956CFEFFFF LEA EDX,[EBP-0194]

015F:004026DC 8D857CFEFFFF LEA EAX,[EBP-0184]

015F:004026E2 8D4DDC LEA ECX,[EBP-24]

015F:004026E5 52 PUSH EDX

015F:004026E6 50 PUSH EAX

015F:004026E7 51 PUSH ECX

015F:004026E8 FF15D4414000 CALL [MSVBVM50!__vbaVarForNext]

015F:004026EE E941FFFFFF JMP 00402634 (JUMP )

Give me your idea about this code, it look like a loop, huh??? yeah, this loop will get each character in your name, and it will calculate, and make a serial .... If you want keygen, this code very important for you... But with my health now , I can only find correct serial, so this code not important with me.... Continue trace, until you see this code :

015F:00402752 8D95E4FEFFFF LEA EDX,[EBP-011C]

015F:00402758 8D8DFCFEFFFF LEA ECX,[EBP-0104]

015F:0040275E FFD6 CALL ESI

015F:00402760 8D8DFCFEFFFF LEA ECX,[EBP-0104]<--- Here : type d ecx

015F:00402766 8D95E4FEFFFF LEA EDX,[EBP-011C]

015F:0040276C 51 PUSH ECX

015F:0040276D 52 PUSH EDX

015F:0040276E C785BCFEFFFF01000000MOV DWORD PTR [EBP-0144],00000001

Yeah!!!, when the highlight at : 00402760 , you type : d ecx, and you will see :

20 00 35 00 32 00 37 00 34 00 37 00 32 00 30 00      .5.2.7.4.7.2.0

Do you remember ? Visual Basic not use normal character, it use WideChar ( w.i.d.e. .c.h.a.r ), so I think my correct serial is : 5274720. Test it please , in this crackme , type:

But when I click button: Register it !, he he he what I get : not a good message ,  I GET A BAD MESSAGE ....  

  So I think : I wrong, well I try again, but I can't find anything important.. So I try reverse my serial

5274720 ----> 0274725

And I test is again :

Yeh!!, It Work Good!!!!!, And I get a good message. So to register this crackme: here is correct information:

Ok, Now crackme cracked, and I think it enought for today, now I must sleep, hope I meet some good dream...

BYE...
 

Final Notes

Ok, if you want to comment me something , please email : tnhuan19@hotmail.com

My Greetz Goes to:


All member of Tres2000: McCodEMaN, Sphinx, ....

All member of HAH, and Eddile in Digital Insight

Acid_Cool_178 ( Crack my crackme#6), BiSHoP, a_evil, tKc,....

When ever there is a door,
there is an entrance.
And behind an entrance can no secret hide,
when a cracker takes his knowledge for a ride
                                                                               McCodEMaN



ObDuh

The information in this essay is for educational purpose only!
You are only allow to crack, reverse engineer, modify code and debugg programs that you legaly bought and then for personal use only!!
To ignore this warning is a criminell act and can result in lawful actions!

So please note!
I take no responebility for how you use the information in this essay, i take NO responebility for what might happen to you or your computer!
You use this information on your own risk!!

What i mean is: Please buy the software!








Essay written by tnHuAn ŠTRES2000. All Rights Reserved.