1 - KeyGen Me v0.1 2006 :

hello evryone,
here is X-CrK | CiM 'nd ProliXe solution for my keygenme:
Get the name:
004010C2 . 6A 5A PUSH 5A ; /Count = 5A (90.)
004010C4 . 68 A0304000 PUSH KeyGenMe.004030A0 ; |Buffer =
KeyGenMe.004030A0
004010C9 . 6A 6A PUSH 6A ; |ControlID = 6A (106.)
004010CB . FF75 08 PUSH DWORD PTR SS:[EBP+8] ; |hWnd
004010CE . E8 AF030000 CALL ;
if it's less then 3 chars or more then 30 => it's invalid name:
004010D3 . 83F8 03 CMP EAX,3
004010D6 . 7C 63 JL SHORT KeyGenMe.0040113B
004010D8 . 83F8 1E CMP EAX,1E
004010DB . 7F 5E JG SHORT KeyGenMe.0040113B
we do some shit with our name let see what is it
004010DD . E8 C7000000 CALL KeyGenMe.004011A9
so we take the last char on our Name (for me it's "K") add it to the
Name length (for me 5) multiply it with 0040102Bh
004011A9 /$ 8BD8 MOV EBX,EAX
004011AB |. 8BD0 MOV EDX,EAX
004011AD |. B9 A0304000 MOV ECX,KeyGenMe.004030A0
004011B2 |> 0FBE440A FF MOVSX EAX,BYTE PTR DS:[EDX+ECX-1]
004011B7 |. 03D8 ADD EBX,EAX
004011B9 |. 0FAFDE IMUL EBX,ESI
004011BC |. 4A DEC EDX
004011BD |.^75 F3 JNZ SHORT KeyGenMe.004011B2
004011BF |. 8BC3 MOV EAX,EBX
004011C1 C3 RETN
we save the result on stack
004010E2 . 50 PUSH EAX
Get the serial
004010E3 . 6A 5A PUSH 5A ; /Count = 5A (90.)
004010E5 . 68 FA304000 PUSH KeyGenMe.004030FA ; |Buffer =
KeyGenMe.004030FA
004010EA . 6A 6B PUSH 6B ; |ControlID = 6B (107.)
004010EC . FF75 08 PUSH DWORD PTR SS:[EBP+8] ; |hWnd
004010EF . E8 8E030000 CALL ;
if less then 8 ==> bad serial
004010F4 . 83F8 08 CMP EAX,8
004010F7 . 7C 42 JL SHORT KeyGenMe.0040113B
put the length on EDX
004010F9 . 8BD0 MOV EDX,EAX
push our serial and Call (Decimal to Hexa) conversion
004010FB . 68 FA304000 PUSH KeyGenMe.004030FA
00401100 . E8 9B020000 CALL KeyGenMe.004013A0
the result is on EAX after that we call some arithmetic calculation let
see
00401105 . E8 B8000000 CALL KeyGenMe.004011C2
all we do here is:
1- put our hexadecimal serial on esi
2- Xor it with 38393138
3- shl 16 the result ad put it on EAX
4- shr 16 the result and put it on EBX
5- ADD EAX and EBX
004011C2 /$ 8B35 AE314000 MOV ESI,DWORD PTR DS:[4031AE]
004011C8 |. 33C6 XOR EAX,ESI
004011CA |. 8BD8 MOV EBX,EAX
004011CC |. C1E8 10 SHR EAX,10
004011CF |. 69DB 00000100 IMUL EBX,EBX,10000 ; UNICODE
004011D5 |. 03C3 ADD EAX,EBX
004011D7 |. C705 FE314000 >MOV DWORD PTR DS:[4031FE],1
004011E1 .C3 RETN
after that we pop the result of Name's manipulation and compare it our
result
0040110A . 59 POP ECX
0040110B . 3BC1 CMP EAX,ECX
0040110D . 75 2C JNZ SHORT KeyGenMe.0040113B
you may patch this "MOV DWORD PTR DS:[4031FE],1" to "MOV DWORD PTR
DS:[4031FE],0"
so that the keygenme don't exit
here is the scenario:
1- put our hexadecimal serial on esi
2- Xor it with 38393138
3- shl 16 the result ad put it on EAX
4- shr 16 the result and put it on EBX
5- ADD EAX and EBX
6- compare EAX with ECX (where ecx is result of name manipulation)
we must have ECX=EAX so we reverse the scenario
1-ECX=EAX=EBX (where ecx is result of name manipulation)
2-shl 16 ECX
3-shr 16 EBX
4- add EBX and ECX
5-Xor it with 38393138
6-print the result on decimal format
the keygen is easy to do. I attached a KeYgen solution and source to
this article
be carefull with "IsDebuggerPresent" API .... and happy keygening
Special Thanks Fly to ::
OOPS Willingness X-CrK F4T4LDR4G0N EspioNLerAvaGe Dr_Nitro ...
Enjoy !