|
|
|
|
|
|
"This CrackMe maybe not so hard to crack. |
|
|
|
that pops up with some text in it. Press the ok and you'll see the window only with 'About' button, so here is nothing interesting. You can now close the crackme. Now, how to disable the Nag??...first you must know how to Nag is Load the crackme again. Sice now breaks on execution of windows You can pach this crackme on few different ways, but I'll explain only two! That jump will jump over all other parameters and the call and you'll land at the line 401023! Load the Hiew, press "F4" and choice "Hex" mode! Now, we must find the line 40100C. So press "ALT+F1" untils "Local" is enabled, and you'll see same addresses like in Sice. Press "F5"(Goto) and type ".40100C"! You'll now see where in file the code we are looking for is stored. You'll see: 6A 30 68 79.... We must change only two bytes, so we'll only change first instruction("push 30"), all other will stay same! How to jump from 40100C to 401023??...take any HEX calculator(that can be one Hope you have another one, uncracked copy of the crackme, if not download 015F:0040101E E8|DA|01|00|00 CALL USER32!MessageBoxA Press "F3" to edit the file and put 5 nops("90 90 90 90 90") instead of "E8 DA 01 00 00"! If you still have some problems or questions you can mail us: ReFleXZ@fcmail.com |
|
My thanks and gratitude goes to:- The Sandman for his great site(the best site for newbies) full of knowledge and for Torn@do, Carpathia, Zobel, MisterE, VisionZ, DecoderZ, Rhytm, noos, Ordoc... If I miss someone plz forgive me, and if you think that you must be on this list tell me! |
|
|