
How to make a keygen for:
Folkos CrackMe #6
Version 6 by Folkos
Written by tnHuAn
|
Introduction |
Hmm, today, my modem is dead, so I must repair it, and I can't online , can't chat, ... So I sad, and I must do something in free time, yes I crack in free time. Well, today, I make 2 keygen , and this tutorial will show you how to make a keygen for FolKos Crackme #6, next tutorial will show you how to make a keygen for Bombe Crackme 4. I will use Visual Basic to code this keygen, coz I missing Visual Basic, long time I don't code anything in VB , I only in Delphi and MASM... Now let 's go...
|
Tools required |
|
Target's URL |
I can't remember where I downloaded it, but I sure you can find the URL of TNP Group at :
|
Essay |
First of all, I want to tell with you: this crackme have a simple SoftIce Detection, so If you load SoftIce, and run this crackme: not happen, this crackme won't show anything. Well, this tutorial with have 2 part : Remove softIce dectection, and make keygen .
1) Remove SoftIce Dectection:
When you load SoftIce, and run this crackme, crackme will don't run, so use Frogsice, and run this crackme again, oh... Crackme run normally. Now view log file of Frogsice, you will see Frogsice tell you: Code 0B. Ok, code 0B mean : this crackme use MeltIce... MeltIce is a one of easiest SoftIce Protection, Ok, now close Frogsice, and press Ctrl+D to pop up SoftIce, set a breakpoint at CreateFileA, and press F5 to exit SoftIce, then run this crackme again, you will kicked into SoftIce, press F5 then press F11, you will see : at 0040115C, you will see a jump... Ok , load Hiew, then open this crackme in Hiew, then choose Decode mode, and press F5 , goto 0040115C, and change this line to Nop. Now, you can run this crackme without Frogsice...
2) Make a Keygen:
Ok, continue : making a keygen. Now you run this crackme, type some fake Name and Serial, set a breakpoint at GetdlgitemtTextA, the Click check button... Wow, you will kicked into softice, press F11 once, you will see this code :
0040127E 745F JZ 004012DF (NO JUMP)
00401280 BB04000000 MOV EBX,00000004
00401285 2BC3 SUB EAX,EBX
00401287 8BD8 MOV EBX,EAX
00401289 53 PUSH EBX
0040128A 6A00 PUSH 00
0040128C 6A00 PUSH 00
0040128E 68B90B0000 PUSH 00000BB9
00401293 FF7508 PUSH DWORD PTR [EBP+08]
00401296 E873000000 CALL USER32!GetDlgItemInt
0040129B 5B POP EBX
0040129C A30C324000 MOV [0040320C],EAX
004012A1 BF0C314000 MOV EDI,0040310C
004012A6 03FB ADD EDI,EBX
004012A8 B904000000 MOV ECX,00000004
004012AD BE0C324000 MOV ESI,0040320C
004012B2 F3A6 REPZ CMPSB
004012B4 7529 JNZ 004012DF (JUMP )
Ok, now at when the hightlight at 004012B2, you type : d esi, d edi, you will see some character in you name, and the hexa value of serial... Here is the calculation :
Ok, now you can make a keygen easily:
And now, correct serial is Decimal of Y. Ex : name = tnhuan / serial = 1851880808
If you want, you can download my keygen....Click Here
|
Final Notes |
Ok, if you want to comment me something , please email : tnhuan19@hotmail.com
All member of HAH, and Eddile in Digital Insight
Acid_Cool_178 ( Crack my crackme#6), BiSHoP, a_evil, tKc,....
|
|