How to remove nags in Hypersnap 3.07
by Freak [TOL]
TARGET: HypersnapDX 3.07
URL : http://www.hyperionics.com
Required Tools: W32Dasm 8.9 (http://cracking.home.ml.org)
Hex Workshop (or any other Hex Editor)
Ok, first start the prog up and see what it does. Started it? Good. Now we know that it has two kinds of nags:
1. Startup Nagscreen
2. Puts an unregistered Box on you image.
First we start with the unregisteredbox. We load hsdx.exe into W32dasm. Then click on Refs and choose String Data References. We see the text that'll put into the box.
We doubleclick on "Snapped with Hypersnap-DX"...
You'll reach this piece of code:
* Referenced by a CALL at Addresses:
|:0040173D , :00407FED , :0040864A , :0040E25B , :0040E55C <<---Very Interesting....
|:0040EE27
|
:0040748E 55 push ebp
:0040748F 8BEC mov ebp, esp
:00407491 83EC48 sub esp, 00000048
:00407494 53 push ebx
:00407495 56 push esi
:00407496 33DB xor ebx, ebx
:00407498 57 push edi
:00407499 8D4DD8 lea ecx, dword ptr [ebp-28]
:0040749C 895DFC mov dword ptr [ebp-04], ebx
:0040749F 895DF8 mov dword ptr [ebp-08], ebx
:004074A2 E82E220100 call 004196D5
:004074A7 8B4D08 mov ecx, dword ptr [ebp+08]
:004074AA A184D94600 mov eax, dword ptr [0046D984]
:004074AF 3BCB cmp ecx, ebx
:004074B1 7508 jne 004074BB
:004074B3 3BC3 cmp eax, ebx
:004074B5 0F842B020000 je 004076E6
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004074B1(C)
|
:004074BB 3BCB cmp ecx, ebx
:004074BD 7413 je 004074D2
:004074BF 8B01 mov eax, dword ptr [ecx]
:004074C1 8D55CC lea edx, dword ptr [ebp-34]
:004074C4 52 push edx
:004074C5 FF5004 call [eax+04]
:004074C8 8BF0 mov esi, eax
:004074CA 8D7DD8 lea edi, dword ptr [ebp-28]
:004074CD A5 movsd
:004074CE A5 movsd
:004074CF A5 movsd
:004074D0 EB0F jmp 004074E1
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004074BD(C)
|
:004074D2 8D4DDC lea ecx, dword ptr [ebp-24]
:004074D5 51 push ecx
:004074D6 8D4DD8 lea ecx, dword ptr [ebp-28]
:004074D9 51 push ecx
:004074DA 8BC8 mov ecx, eax
:004074DC E871C70000 call 00413C52
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004074D0(U)
|
:004074E1 53 push ebx
* Reference To: GDI32.CreateCompatibleDC, Ord:001Fh
|
:004074E2 FF1548184900 Call dword ptr [00491848]
:004074E8 8BD8 mov ebx, eax
:004074EA A184D94600 mov eax, dword ptr [0046D984]
:004074EF 33FF xor edi, edi
:004074F1 895DF4 mov dword ptr [ebp-0C], ebx
:004074F4 3BC7 cmp eax, edi
:004074F6 7440 je 00407538
:004074F8 57 push edi
:004074F9 8D4DF8 lea ecx, dword ptr [ebp-08]
:004074FC 57 push edi
:004074FD 51 push ecx
:004074FE 57 push edi
:004074FF FF30 push dword ptr [eax]
:00407501 57 push edi
* Reference To: GDI32.CreateDIBSection, Ord:0024h
|
:00407502 FF158C184900 Call dword ptr [0049188C]
:00407508 3BC7 cmp eax, edi
:0040750A 8945FC mov dword ptr [ebp-04], eax
:0040750D 741B je 0040752A
:0040750F 8B0D84D94600 mov ecx, dword ptr [0046D984]
:00407515 8B7108 mov esi, dword ptr [ecx+08]
:00407518 E84DBF0000 call 0041346A
:0040751D 50 push eax
:0040751E 56 push esi
:0040751F FF75F8 push [ebp-08]
:00407522 E8B9DE0100 call 004253E0
:00407527 83C40C add esp, 0000000C
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0040750D(C)
|
:0040752A 397DFC cmp dword ptr [ebp-04], edi
:0040752D 7509 jne 00407538
:0040752F 397D08 cmp dword ptr [ebp+08], edi
:00407532 0F84AE010000 je 004076E6
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:004074F6(C), :0040752D(C)
|
:00407538 8B45FC mov eax, dword ptr [ebp-04]
:0040753B 3BC7 cmp eax, edi
:0040753D 7508 jne 00407547
:0040753F 8B4508 mov eax, dword ptr [ebp+08]
:00407542 8B4034 mov eax, dword ptr [eax+34]
:00407545 8B00 mov eax, dword ptr [eax]
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0040753D(C)
|
* Reference To: GDI32.SelectObject, Ord:014Ah
|
:00407547 8B3538184900 mov esi, dword ptr [00491838]
:0040754D 50 push eax
:0040754E 53 push ebx
:0040754F FFD6 call esi
:00407551 8945F0 mov dword ptr [ebp-10], eax
:00407554 A140D64600 mov eax, dword ptr [0046D640]
:00407559 3BC7 cmp eax, edi
:0040755B 7413 je 00407570
:0040755D 57 push edi
:0040755E 50 push eax
:0040755F 53 push ebx
* Reference To: GDI32.SelectPalette, Ord:014Bh
|
:00407560 FF1568184900 Call dword ptr [00491868]
:00407566 53 push ebx
:00407567 8945EC mov dword ptr [ebp-14], eax
* Reference To: GDI32.RealizePalette, Ord:0137h
|
:0040756A FF1564184900 Call dword ptr [00491864]
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0040755B(C)
|
:00407570 FF35A05E4800 push dword ptr [00485EA0]
:00407576 53 push ebx
:00407577 FFD6 call esi
:00407579 A3A05E4800 mov dword ptr [00485EA0], eax
:0040757E 8D45E4 lea eax, dword ptr [ebp-1C]
* Possible StringData Ref from Data Obj ->" Snapped with HyperSnap-DX " <<<--Nagtext
|
:00407581 BF5C574600 mov edi, 0046575C
:00407586 50 push eax
:00407587 57 push edi
:00407588 E863E20100 call 004257F0
:0040758D 59 pop ecx
:0040758E 50 push eax
:0040758F 57 push edi
:00407590 53 push ebx
* Reference To: GDI32.GetTextExtentPoint32A, Ord:0105h
|
:00407591 FF1574184900 Call dword ptr [00491874]
:00407597 8B45D8 mov eax, dword ptr [ebp-28]
:0040759A 3B45E4 cmp eax, dword ptr [ebp-1C]
:0040759D 0F8ECC000000 jle 0040766F
:004075A3 8B45E8 mov eax, dword ptr [ebp-18]
:004075A6 8D0440 lea eax, dword ptr [eax+2*eax]
:004075A9 3945DC cmp dword ptr [ebp-24], eax
:004075AC 0F8EBD000000 jle 0040766F
:004075B2 57 push edi
:004075B3 E838E20100 call 004257F0
:004075B8 59 pop ecx
* Possible StringData Ref from Data Obj ->" http://www.hyperionics.com " <<<--Nagtext
|
:004075B9 BE3C574600 mov esi, 0046573C
:004075BE 56 push esi
:004075BF 8BF8 mov edi, eax
:004075C1 E82AE20100 call 004257F0
:004075C6 3BC7 cmp eax, edi
:004075C8 59 pop ecx
:004075C9 7607 jbe 004075D2
:004075CB 56 push esi
:004075CC E81FE20100 call 004257F0
:004075D1 59 pop ecx
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004075C9(C)
|
:004075D2 8B45E8 mov eax, dword ptr [ebp-18]
:004075D5 8B4DE4 mov ecx, dword ptr [ebp-1C]
* Reference To: GDI32.GetStockObject, Ord:00FAh
|
:004075D8 8B3D6C184900 mov edi, dword ptr [0049186C]
:004075DE 03C8 add ecx, eax
:004075E0 8D1440 lea edx, dword ptr [eax+2*eax]
:004075E3 8945C8 mov dword ptr [ebp-38], eax
:004075E6 8945CC mov dword ptr [ebp-34], eax
:004075E9 894DD0 mov dword ptr [ebp-30], ecx
:004075EC 8955D4 mov dword ptr [ebp-2C], edx
:004075EF 83C0FE add eax, FFFFFFFE
:004075F2 83C102 add ecx, 00000002
:004075F5 83C202 add edx, 00000002
:004075F8 6A04 push 00000004
:004075FA 8945B8 mov dword ptr [ebp-48], eax
:004075FD 894DC0 mov dword ptr [ebp-40], ecx
:00407600 8945BC mov dword ptr [ebp-44], eax
:00407603 8955C4 mov dword ptr [ebp-3C], edx
:00407606 FFD7 call edi
:00407608 50 push eax
:00407609 8D45B8 lea eax, dword ptr [ebp-48]
:0040760C 50 push eax
:0040760D 53 push ebx
* Reference To: USER32.FillRect, Ord:00CCh
|
:0040760E 8B1D641C4900 mov ebx, dword ptr [00491C64]
:00407614 FFD3 call ebx
:00407616 6A00 push 00000000
:00407618 FFD7 call edi
:0040761A 8B7DF4 mov edi, dword ptr [ebp-0C]
:0040761D 50 push eax
:0040761E 8D45C8 lea eax, dword ptr [ebp-38]
:00407621 50 push eax
:00407622 57 push edi
:00407623 FFD3 call ebx
:00407625 6A00 push 00000000
:00407627 57 push edi
* Reference To: GDI32.SetTextColor, Ord:0172h
|
:00407628 FF1580184900 Call dword ptr [00491880]
:0040762E 68FFFFFF00 push 00FFFFFF
:00407633 57 push edi
* Reference To: GDI32.SetBkColor, Ord:0150h
|
:00407634 FF157C184900 Call dword ptr [0049187C]
:0040763A 8D45C8 lea eax, dword ptr [ebp-38]
:0040763D 6A00 push 00000000
:0040763F 50 push eax
:00407640 6AFF push FFFFFFFF
* Possible StringData Ref from Data Obj ->" Snapped with HyperSnap-DX " <<<---Nagtext
|
:00407642 685C574600 push 0046575C
:00407647 57 push edi
* Reference To: USER32.DrawTextA, Ord:00AAh
|
:00407648 FF15181D4900 Call dword ptr [00491D18]
:0040764E 56 push esi
:0040764F E89CE10100 call 004257F0
:00407654 59 pop ecx
:00407655 50 push eax
:00407656 8B45E8 mov eax, dword ptr [ebp-18]
:00407659 03C0 add eax, eax
:0040765B 56 push esi
:0040765C 50 push eax
:0040765D FF75C8 push [ebp-38]
:00407660 57 push edi
* Reference To: GDI32.TextOutA, Ord:0183h
|
:00407661 FF1578184900 Call dword ptr [00491878]
* Reference To: GDI32.SelectObject, Ord:014Ah
|
:00407667 8B3538184900 mov esi, dword ptr [00491838]
:0040766D 8BDF mov ebx, edi
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:0040759D(C), :004075AC(C)
|
:0040766F FF75F0 push [ebp-10]
:00407672 53 push ebx
:00407673 FFD6 call esi
:00407675 FF35A05E4800 push dword ptr [00485EA0]
:0040767B 53 push ebx
:0040767C FFD6 call esi
:0040767E 33FF xor edi, edi
:00407680 A3A05E4800 mov dword ptr [00485EA0], eax
:00407685 393D40D64600 cmp dword ptr [0046D640], edi
:0040768B 740B je 00407698
:0040768D 57 push edi
:0040768E FF75EC push [ebp-14]
:00407691 53 push ebx
* Reference To: GDI32.SelectPalette, Ord:014Bh
|
:00407692 FF1568184900 Call dword ptr [00491868]
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0040768B(C)
|
:00407698 53 push ebx
* Reference To: GDI32.DeleteDC, Ord:0043h
|
:00407699 FF155C184900 Call dword ptr [0049185C]
:0040769F 397DFC cmp dword ptr [ebp-04], edi
:004076A2 7436 je 004076DA
:004076A4 8B0D84D94600 mov ecx, dword ptr [0046D984]
:004076AA 8B7108 mov esi, dword ptr [ecx+08]
:004076AD E8B8BD0000 call 0041346A
:004076B2 50 push eax
:004076B3 FF75F8 push [ebp-08]
:004076B6 56 push esi
:004076B7 E824DD0100 call 004253E0
:004076BC 83C40C add esp, 0000000C
:004076BF FF75FC push [ebp-04]
* Reference To: GDI32.DeleteObject, Ord:0046h
|
:004076C2 FF1550184900 Call dword ptr [00491850]
:004076C8 8B4D08 mov ecx, dword ptr [ebp+08]
:004076CB 3BCF cmp ecx, edi
:004076CD 740B je 004076DA
:004076CF FF3584D94600 push dword ptr [0046D984]
:004076D5 E84D0A0100 call 00418127
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:004076A2(C), :004076CD(C)
|
:004076DA 8B0D3CD54600 mov ecx, dword ptr [0046D53C]
:004076E0 57 push edi
:004076E1 E868050100 call 00417C4E
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:004074B5(C), :00407532(C)
|
:004076E6 5F pop edi
:004076E7 5E pop esi
:004076E8 5B pop ebx
:004076E9 C9 leave
:004076EA C3 ret <<<--- Return from where it's called.....
We see that that is the routine to place the nagbox on your picture and after completing it it returns to from where it was called. We see in the header (I marked it) that this routine is called very often. Do you remember the nagscreen? It'll place the box when you save,copy,print etc... a picture. Well we could nop out all the calls, but that would be a lot of 90's. But we know that when the routine is finished, it'll return (hex:C3). So if we put an ret at the beginning it won't generate the boxes. So let's make it. Scroll back to this piece of code:
* Referenced by a CALL at Addresses:
|:0040173D , :00407FED , :0040864A , :0040E25B , :0040E55C
|:0040EE27
|
:0040748E 55 push ebp <<<---- We'll replace this ;-)
:0040748F 8BEC mov ebp, esp
:00407491 83EC48 sub esp, 00000048
:00407494 53 push ebx
:00407495 56 push esi
:00407496 33DB xor ebx, ebx
:00407498 57 push edi
:00407499 8D4DD8 lea ecx, dword ptr [ebp-28]
:0040749C 895DFC mov dword ptr [ebp-04], ebx
:0040749F 895DF8 mov dword ptr [ebp-08], ebx
:004074A2 E82E220100 call 004196D5
:004074A7 8B4D08 mov ecx, dword ptr [ebp+08]
:004074AA A184D94600 mov eax, dword ptr [0046D984]
:004074AF 3BCB cmp ecx, ebx
:004074B1 7508 jne 004074BB
:004074B3 3BC3 cmp eax, ebx
:004074B5 0F842B020000 je 004076E6
Get sure that the blueline is on :0040748E 55 push ebp
Look down to see at which offset it is.Ah we see @Offset 0000688Eh
So we've got all we need to know. Open HSDX.EXE in your Hex Editor and go to Offset 688Eh (the h only stands for HEX) and replace the 55 with C3. Save the file (make a backup) and run it. Shoot a picture and save it and etc... And what? Kewl!! No more nagboxes on your images. ;-)))
Ok, you've done the first part, but there's still the startup nagbox:
Hmm, while looking in the stringtable, we figure out that there's no text from the startupnag, so we've got to take a different approach: We'll use the debugmode. Click on DEBUG and then on LOAD PROCESS.White after everything is loaded and press F9 . HypersnapDX will be executed. The StartupNag appears. Then after finishing all the loading of Hypersnap press F7 (Step Into) then terminate the process (click on terminate). Back in W32Dasm you're in this piece of code:
* Referenced by a CALL at Address:
|:004106FF <<<<--- Here is the nag called from.
|
:004105F9 55 push ebp
:004105FA 8BEC mov ebp, esp
:004105FC B800100000 mov eax, 00001000
:00410601 E82A680100 call 00426E30
:00410606 833D845E480000 cmp dword ptr [00485E84], 00000000
:0041060D 53 push ebx
:0041060E 56 push esi
:0041060F 57 push edi
:00410610 0F85AB000000 jne 004106C1
:00410616 8D4510 lea eax, dword ptr [ebp+10]
:00410619 50 push eax
:0041061A 8D8500F0FFFF lea eax, dword ptr [ebp+FFFFF000]
:00410620 FF750C push [ebp+0C]
:00410623 50 push eax
:00410624 E827770100 call 00427D50
:00410629 8B7D08 mov edi, dword ptr [ebp+08]
:0041062C 83C40C add esp, 0000000C
:0041062F 85FF test edi, edi
:00410631 BB00010000 mov ebx, 00000100
:00410636 7435 je 0041066D
:00410638 57 push edi
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:00410660(U)
|
:00410639 8BCF mov ecx, edi
:0041063B E896D60000 call 0041DCD6
:00410640 8BF0 mov esi, eax
:00410642 85F6 test esi, esi
:00410644 741C je 00410662
:00410646 859EE0000000 test dword ptr [esi+000000E0], ebx
:0041064C 7411 je 0041065F
:0041064E 8B8698000000 mov eax, dword ptr [esi+00000098]
:00410654 8D8E98000000 lea ecx, dword ptr [esi+00000098]
:0041065A 6A00 push 00000000
:0041065C FF5010 call [eax+10]
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0041064C(C)
|
:0041065F 56 push esi
:00410660 EBD7 jmp 00410639
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:00410644(C)
|
:00410662 85FF test edi, edi
:00410664 7407 je 0041066D
:00410666 8B4734 mov eax, dword ptr [edi+34]
:00410669 8B00 mov eax, dword ptr [eax]
:0041066B EB02 jmp 0041066F
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:00410636(C), :00410664(C)
|
:0041066D 33C0 xor eax, eax
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0041066B(U)
|
:0041066F 6840200100 push 00012040
:00410674 8D8D00F0FFFF lea ecx, dword ptr [ebp+FFFFF000]
:0041067A 6870CD4600 push 0046CD70
:0041067F 51 push ecx
:00410680 50 push eax
* Reference To: USER32.MessageBoxA, Ord:0195h
|
:00410681 FF15801D4900 Call dword ptr [00491D80]
:00410687 85FF test edi, edi
:00410689 7436 je 004106C1
:0041068B 57 push edi
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004106AE(U)
|
:0041068C 8BCF mov ecx, edi
:0041068E E843D60000 call 0041DCD6
:00410693 8BF0 mov esi, eax
:00410695 85F6 test esi, esi
:00410697 7428 je 004106C1
:00410699 859EE0000000 test dword ptr [esi+000000E0], ebx
:0041069F 740C je 004106AD
:004106A1 8BCE mov ecx, esi
:004106A3 E8A8730000 call 00417A50
:004106A8 83F801 cmp eax, 00000001
:004106AB 7403 je 004106B0
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0041069F(C)
|
:004106AD 56 push esi
:004106AE EBDC jmp 0041068C
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004106AB(C)
|
:004106B0 8B8698000000 mov eax, dword ptr [esi+00000098]
:004106B6 8D8E98000000 lea ecx, dword ptr [esi+00000098]
:004106BC 6A01 push 00000001
:004106BE FF5010 call [eax+10]
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:00410610(C), :00410689(U), :00410697(C)
|
:004106C1 5F pop edi
:004106C2 5E pop esi
:004106C3 5B pop ebx
:004106C4 C9 leave
:004106C5 C3 ret
After examining all the code, we'll find out that it operates as same as the other one, expect that it's called only one time. Replace the first push ebp with ret (55->C3). Operate as same as above to make the changes with the Hex-Editor. Startup HyperSnap-DX...
KEEEWWL no more nagscreen.
That's all Folks.......
(PS: I included a patch if you can't figure it out)
If you got some questions, comments or what the hell then write me: rampster@metronet.de
| BACK |