downloadbrowsewarrantyVoider's WTF

Download crackmeWTF.zip, 10 kb (password: crackmes.de)
Browse contents of crackmeWTF.zip

This one does a really weird thing I haven´t seen in any other crackme, will you find out what it is?

It´s a lot less scary than it looks. At some point you should scream "HEUREKA!"...

Tested on XP and W2k. Please don´t use on other OS versions!

Have fun, write a keygen!
WV

Difficulty: 3 - Getting harder
Platform: Windows 2000/XP only
Language: C/C++

Published: 22. Aug, 2005
Downloads: 855

Rating

Waiting for at least 3 votes
(we have only 1).

Rate this crackme:

Send a message to warrantyVoider »

View profile of warrantyVoider »

Solutions

Solution by jE!, published 27. aug, 2005; download (32 kb), password: crackmes.de or browse.

jE! has not rated this crackme yet.

Solution by psych1c, published 25. aug, 2005; download (62 kb), password: crackmes.de or browse.

psych1c has not rated this crackme yet.

Submit your solution »

Discussion and comments

TQN
22. Aug 2005
Hi warrantyVoider !
Did you test and sure that all explorer.exe in Win2k/XP will have the string "This program xxx" at addess 0x100004E. I think I can hardcode this string in my keygen, and this way is shorter than using Toolhelp API/PSAPI to read explorer's memory.
warrantyVoider
Author
22. Aug 2005
Hi TQN,
of course, feel free to hardcode this string. It seems to be identical in W2K and XP. Also it seems this string does not get changed in international versions of Windows. (Hardcoded in the compiler I guess.). Greetings, WV

ps: While the string is identical, the image base is not. Under W2K explorer.exe loads at 0x400000, under XP it´s 0x1000000.
jE!
27. Aug 2005
weep, strange, i missed fact of other submittion, & written quite identical solve..
aniway submitted..

You may leave your comment, thoughts and discuss this crackme with other reversers here.
Acting childish will not be tolerated.
HTML and such will be left as-is, so don't try.