Go Back   MegaGames Forum > MGF Helping Zone - Support Forums > Tutorial Submissions

 
 
Thread Tools Display Modes
A Simple NO-CD Cracking Tutorial
Old 09-04-2005   #1
Creativity
Light Gamer
 
Creativity's Avatar
 
Creativity is offline
Join Date: May 2005
Location: Chennai, India.
Posts: 203
Creativity is on a distinguished road
Rep Power: 5
Send a message via Yahoo to Creativity
Post A Simple NO-CD Cracking Tutorial

Use this tute only for cracking the EXEs of the CDs that you own...
This tutorial is for Educational purpose only.

Author: Creativity
Target Program: Ballance 2.0.0.1 (But the splash page displays v1.13)
Application type: Microsoft Visual C++ application (Use PEiD to find it out)

Tools required:
W32Dasm 8.93 or above.
Olly Debugger 1.10 (Debugging + Patching the game)
PEiD / ClonyXXL / ProtectionID

How to crack:
This is my first cracking tutorial... so please report me or forgive me for my mistakes that I made, I'm a newbie in cracking...

CLONY XXL STEPS:
Step 01: Insert the disc into the drive then click Scan in clony XXL.
Oh great the game doesnot contain any CD protection.

PEiD STEPS:
Step 01: Click on "..." and open the target "Player.exe" in the bin folder in the game's installation directory.
Step 02: Oh cool the game doesn't contain any protection like Securom, safeDisc etc and it is not protected with any Exe protectors. We are lucky... and our cracking burden is reduced.

W32DASM STEPS:
Step 01: Start the game without the CD... oh no... a window with title "Attention" and It says "Place the CD-ROM into the Drive and Start the Game again"
Step 02: Load up W32Dasm and disassemble the file "Player.exe" in the Bin folder...
Step 03: Since the error message "Place the CD-ROM into the drive and start the game again" loads up in the runtime, so it is not possible to search with the string.
Step 04: In W32Dasm click on "String Data references" button in the toolbar. Search for "Attention" thats the title of error message window.An alternate method is by using the menu "Search->Find Text" then type your text,"Attention" in the text box. Click on "Find next".
Step 05: It will take us to the line that displays the following

* Possible StringData Ref from Data Obj ->"Attention"

Step 06: Scroll a little below and you can find these lines.

* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0040121B(C)


It says that the jump to this error message is from the address 0040121B and it also indicates what type of jump it is.
(C)-Conditional Jump (JNE's and JE's) and
(U)-Unconditional Jump (JMP)

So our jump is a conditional jump... (ie) it is checked for specific condition and then jumped.okay now that we've got the address where the game checks,Note it down in a piece of paper... Next is to Patch it out... close W32Dasm.

Note: There are two dialog with title "Attention", If you are not sure of which one is the dialog that points to CD-Check then run the target in a debugger to find out the correct Error string.

OLLY DEBUGGER STEPS:
i've added a screen shot of Olly and with the three important windows marked...

My interface and yours might differ because I've added new plugins and changed the color of the interface.

Step 01: Open the target file "Player.exe" in OllyDebugger
Step 02: Ollydebugger has many windows, we have to open the CPU window to debug the process. Click on the "C" icon in the toolbar... It will display the decompiled code. Maximize the window.
Step 03: Now Right click in the window and Select "Goto->Expression" and enter the address that you noted in W32Dasm... In this case it is 0040121B and then Click "OK"
Step 04: Ok now we have successfully landed in our checking area 0040121B. We need to bypass the check so that we can run the game without the CD and with the CD. This is really important, because the game must be able to run with a CD and without a CD, in that way we must crack it.

Original code:
00401219 . 84C0 TEST AL,AL
0040121B 75 46 JNZ SHORT Player.00401263

What does this code do ?
To know what it does follow the steps, Select the line 00401219 and then right click Select "Breakpoint->Run to selection" Now look at the information window, the sliced one that is just below the code window slice. We'll find that registerAL=00 if the CD is not inserted and AL=01 when the CD is inserted. so the next line is JNZ(Jump if Not Zero) if the AL value is 0 it will not jump, So it'll jump only when the CD is inserted (ie.)when AL becomes 01, so this is a conditional Jump. We have to change it to unconditional jump, It must jump always. So we have to modify it. So follow the steps below.

Step 05: Double Click on the line 0040121B or Click on the line and press Spacebar a window with title "Assemble at 0040121B" will pop up, now change "JNZ SHORT 00401263-->JMP SHORT 00401263", I've only changed the first three characters in the line.
Step 06: So we have patched the game in the memory, to patch the executable, Right click in the code window and select "Copy to executable-> All modifications" and click "Copy All", Now a dump window(D in the title) will popup displaying all the modifications that we made. Now Right click in the Dump window and select "Save file" then save the file with some other name, example Player_cracked.exe...

Patched code:
00401219 . 84C0 TEST AL,AL
0040121B EB 46 JMP SHORT Player.00401263

Final Notes:
So we've successfully cracked the game Ballance 2.0.0.1 (V1.13 according to the splash page), Now the game will run when the CD is inserted and also when the CD is not in the drive. There are manys ways to crack this... one method is this one. Every program has its own weakness. Finding the weakness is the solution.

Greets:
To all NO-CD crackers in the world. And all the members of Lethal Injection team and Members in this MGForums.

Last edited by Creativity; 09-04-2005 at 02:01 PM.
 
 
Old 09-06-2005   #2
CloneDevil
Newbie
 
CloneDevil is offline
Join Date: Dec 2004
Posts: 13
CloneDevil is on a distinguished road
Rep Power: 0
CLonyXXL !!!!!!!!!!
Please use DiscScanX + A-Ray Scanner
 
 
Old 09-21-2005   #3
Kaho
Newbie
 
Kaho is offline
Join Date: Sep 2005
Posts: 2
Kaho is on a distinguished road
Rep Power: 0
I might be doign somethign wrong Iam trying to learn how to Crack Warcraft exes and its not going over so well Maybe you could help me. Or somebody? I have the disk and all but I have so many and converted them into slimmer cases which are on my bookshelf and everytime i would go thru them when i want to play I dont have much time after my mom gets done rearaging my room. Iam a lil cluttered and at the end of playing before i got to work my games are all over my desk and my mom just puts them back wherever they may be. Iam getting tired of looking thru 5 shelves of dvds/games for ps2 xbox and PC. Thanks

Last edited by Kaho; 09-21-2005 at 03:12 PM.
 
 
Breakthrough !
Old 09-24-2005   #4
Creativity
Light Gamer
 
Creativity's Avatar
 
Creativity is offline
Join Date: May 2005
Location: Chennai, India.
Posts: 203
Creativity is on a distinguished road
Rep Power: 5
Send a message via Yahoo to Creativity
Breakthrough !

Try to breakthrough into the porgram using Breakpoints like
BPX MessageBoxA -> This will break when messagebox is called or when error messages are displayed.
BPX GetDriveTypeA -> This will make a break when the target scans for your drive type.

or just search for CMP EAX,05 or CMP EAX,03 then try changing 05<=>03 and also check whether conditional jumps(JNZ, JE) are present below this statement and try reversing them or change them to unconditional jump(JMP).

If you still can't find a solution then read tutorials in http://biw.rult.at/
I learned tutorials at this site and they were really helpful.

Last edited by Creativity; 09-24-2005 at 01:01 PM.
 
 
Old 03-13-2006   #5
Creativity
Light Gamer
 
Creativity's Avatar
 
Creativity is offline
Join Date: May 2005
Location: Chennai, India.
Posts: 203
Creativity is on a distinguished road
Rep Power: 5
Send a message via Yahoo to Creativity
Use some nice tools like FileMon and RegMon from sysinternals... these tools log which file/regvalue the game accesses... so you can easily crack it..

Some old games use regvalue to store the location of the install source, so if you change this regvalue and copy all the files from the CD it gets working without the CD.

Someother games lookout for a certain files and if the anyone of the files are not found, they popup with message "Insert the Correct CD-ROM" or similar messages !

I hope this info will be helpful !

BPX GetDriveTypeA
Checks for the type of drive you have... (ie) whether it is a floppy,HDD or CD etc
03 = HDD
05 = CDD

Since many ppl requested me for the tools.. i've uploaded them in www.filelodge.com

Links for the tools :
Download Olly Debugger
Download PEiD 0.93

Enjoy

Bye,
Creativity

Last edited by Creativity; 04-14-2006 at 12:54 PM.
 
 
Old 03-14-2006   #6
echo prime
Skilled Gamer
 
echo prime's Avatar
 
echo prime is offline
Join Date: Feb 2006
Posts: 1,228
echo prime is on a distinguished road
Rep Power: 5
Dude! What's wrong with you? Why are you posting like this??
__________________
:
 
 
Old 03-16-2006   #7
Creativity
Light Gamer
 
Creativity's Avatar
 
Creativity is offline
Join Date: May 2005
Location: Chennai, India.
Posts: 203
Creativity is on a distinguished road
Rep Power: 5
Send a message via Yahoo to Creativity
Quote:
Originally Posted by echo prime
Dude! What's wrong with you? Why are you posting like this??
What is wrong ?
What has to be done... what is wrong in my post ???
 
 
Old 03-17-2006   #8
Amargeddemon
Professional Gamer
 
Amargeddemon's Avatar
 
Amargeddemon is offline
Join Date: Feb 2005
Location: New Zealand (the darker side of sheep tamers)
Posts: 4,809
Amargeddemon will become famous soon enough
Rep Power: 9
Send a message via MSN to Amargeddemon
Quote:
What is wrong ?
What has to be done... what is wrong in my post ???
What echo means is use the "edit" button
__________________


For Cracks and Patches Check - GBW, GCW ,
MG

Smile it costs nothing - quoted from a true genius (R.I.P My Friend)

Reach me on Bebo: AsylumReject


[SIGPIC][/SIGPIC]
 
 
Old 03-18-2006   #9
echo prime
Skilled Gamer
 
echo prime's Avatar
 
echo prime is offline
Join Date: Feb 2006
Posts: 1,228
echo prime is on a distinguished road
Rep Power: 5
Yes. Posting more than once simultaneously (multiple posting) is against forum rules. I was not talking about the content.
__________________
:
 
 
Old 03-18-2006   #10
Creativity
Light Gamer
 
Creativity's Avatar
 
Creativity is offline
Join Date: May 2005
Location: Chennai, India.
Posts: 203
Creativity is on a distinguished road
Rep Power: 5
Send a message via Yahoo to Creativity
Sorry Pals... sorry for those posts... is there anyway to delete the previous post ??

Bye,
Creativity
 
 
Old 03-18-2006   #11
echo prime
Skilled Gamer
 
echo prime's Avatar
 
echo prime is offline
Join Date: Feb 2006
Posts: 1,228
echo prime is on a distinguished road
Rep Power: 5
Nope. No way of doing that. Just be careful next time. Cheers.
__________________
:
 
 
Old 03-18-2006   #12
NorthViking
 
NorthViking's Avatar
 
NorthViking is offline
Join Date: Aug 2002
Location: Sweden
Posts: 12,200
NorthViking is a glorious beacon of lightNorthViking is a glorious beacon of lightNorthViking is a glorious beacon of lightNorthViking is a glorious beacon of lightNorthViking is a glorious beacon of light
Rep Power: 24
Send a message via ICQ to NorthViking Send a message via MSN to NorthViking Send a message via Yahoo to NorthViking
Sometimes you want to update new info by making a new post.

However the edit button is recommended and should be used, otherwise.
__________________


cheers !!

Aka molle
MegaGames Game Fixes
MegaGames Patches
MegaGames PC Cheats
MegaGames Console Cheats
MegaGames Trainers
MegaGames Demos
MegaGames Freeware
EGF Useful Tutorials

Please read the
rules !

R.I.P Rocol, I will always remember you, my dear friend.

Last edited by NorthViking; 03-18-2006 at 01:31 PM.
 
 
Old 03-18-2006   #13
Rocol
 
Rocol's Avatar
 
Rocol is offline
Join Date: Aug 2002
Location: England
Posts: 8,482
Rocol will become famous soon enoughRocol will become famous soon enough
Rep Power: 17
Send a message via ICQ to Rocol Send a message via Yahoo to Rocol
Sorted, compatible posts merged. As said, if you wish to add information to and existing post, please use the edit button where possible
__________________
Smile ... it costs nothing

MGF Forum Rules
 
 
Old 04-05-2006   #14
vikrant1986
Newbie
 
vikrant1986 is offline
Join Date: Apr 2006
Posts: 1
vikrant1986 is on a distinguished road
Rep Power: 0
hi creativtyy u r a great i have tird ur tutorial & it works . but the problemn is that how can i create a no cd fix for a patch ie i want to crack rome total war v 1.2 since its necessary for the realism total war .
 
 
Old 04-05-2006   #15
STi FlyBy
 
STi FlyBy's Avatar
 
STi FlyBy is offline
Join Date: Dec 2005
Location: NY, USA
Posts: 6,922
STi FlyBy will become famous soon enoughSTi FlyBy will become famous soon enough
Rep Power: 11
Quote:
Originally Posted by vikrant1986
hi creativtyy u r a great i have tird ur tutorial & it works . but the problemn is that how can i create a no cd fix for a patch ie i want to crack rome total war v 1.2 since its necessary for the realism total war .
What a patch does is it modifies lines of code in files that have been known to cause bugs/errors. If you go into the .exe file for your game and modify it properly, it will work.
__________________


Read the rules!

http://www.cardomain.com/ride/2952983/

"A.A. is for quitters ..."

"Never trust anything that bleeds for a week and lives ..."

"Smile, it costs nothing ..." - the words of a kind man, Rocol
 
 
Old 04-07-2006   #16
mammu
Skilled Gamer
 
mammu's Avatar
 
mammu is offline
Join Date: Apr 2005
Location: India, Pune
Posts: 1,677
mammu is on a distinguished road
Rep Power: 6
Send a message via Yahoo to mammu
Creativity can we make no-DVD crack with your method and does it works also for protected DVD games like popt2t?
 
 
Old 04-08-2006   #17
echo prime
Skilled Gamer
 
echo prime's Avatar
 
echo prime is offline
Join Date: Feb 2006
Posts: 1,228
echo prime is on a distinguished road
Rep Power: 5
Quote:
Creativity can we make no-DVD crack with your method and does it works also for protected DVD games like popt2t?
Definitely no...
__________________
:
 
 
Old 04-08-2006   #18
STi FlyBy
 
STi FlyBy's Avatar
 
STi FlyBy is offline
Join Date: Dec 2005
Location: NY, USA
Posts: 6,922
STi FlyBy will become famous soon enoughSTi FlyBy will become famous soon enough
Rep Power: 11
Quote:
Originally Posted by echo prime
Definitely no...
Well RELOADED released a way to get around Starforce. I haven't had time to put some time into it (plus, I don't have any of those games), but if you do a search, you may be able to find that.
__________________


Read the rules!

http://www.cardomain.com/ride/2952983/

"A.A. is for quitters ..."

"Never trust anything that bleeds for a week and lives ..."

"Smile, it costs nothing ..." - the words of a kind man, Rocol
 
 
Old 04-09-2006   #19
mammu
Skilled Gamer
 
mammu's Avatar
 
mammu is offline
Join Date: Apr 2005
Location: India, Pune
Posts: 1,677
mammu is on a distinguished road
Rep Power: 6
Send a message via Yahoo to mammu
I will search and try.
__________________
The Pain may pause...
...But it never goes away.


Never argue with idiots. First they bring you to their level and then beat you with their experience!

WorldNewsForum.Net
 
 
someone help me wit bfme2
Old 04-12-2006   #20
narutoboi
Newbie
 
narutoboi is offline
Join Date: Apr 2006
Posts: 3
narutoboi is on a distinguished road
Rep Power: 0
someone help me wit bfme2

someone plz help me wit bfme2....

Last edited by narutoboi; 04-12-2006 at 11:12 PM.
 
 
Old 04-12-2006   #21
STi FlyBy
 
STi FlyBy's Avatar
 
STi FlyBy is offline
Join Date: Dec 2005
Location: NY, USA
Posts: 6,922
STi FlyBy will become famous soon enoughSTi FlyBy will become famous soon enough
Rep Power: 11
Quote:
Originally Posted by narutoboi
someone plz help me wit bfme2....i install the game...now it ask me for the
cd....??? im a newbie.....*wonder if dis is illegal?*
any pro...who can exlpain to me in a way dat i understand...like list
der step....

MUCH MUCH APPRECIATION!!!!

d.t.
What happens when you put the original disc in the drive and try to play it?
__________________


Read the rules!

http://www.cardomain.com/ride/2952983/

"A.A. is for quitters ..."

"Never trust anything that bleeds for a week and lives ..."

"Smile, it costs nothing ..." - the words of a kind man, Rocol
 
 
Old 04-12-2006   #22
Amargeddemon
Professional Gamer
 
Amargeddemon's Avatar
 
Amargeddemon is offline
Join Date: Feb 2005
Location: New Zealand (the darker side of sheep tamers)
Posts: 4,809
Amargeddemon will become famous soon enough
Rep Power: 9
Send a message via MSN to Amargeddemon
Do you even have the original disk mate?
__________________


For Cracks and Patches Check - GBW, GCW ,
MG

Smile it costs nothing - quoted from a true genius (R.I.P My Friend)

Reach me on Bebo: AsylumReject


[SIGPIC][/SIGPIC]
 
 
Old 04-12-2006   #23
narutoboi
Newbie
 
narutoboi is offline
Join Date: Apr 2006
Posts: 3
narutoboi is on a distinguished road
Rep Power: 0
not really helpful....i dl der game from torrent portal...im tire of dl-ing movie so i dl load game....but now i need cd key...and der cd..

D.T.

Last edited by narutoboi; 04-12-2006 at 11:16 PM.
 
 
Old 04-12-2006   #24
STi FlyBy
 
STi FlyBy's Avatar
 
STi FlyBy is offline
Join Date: Dec 2005
Location: NY, USA
Posts: 6,922
STi FlyBy will become famous soon enoughSTi FlyBy will become famous soon enough
Rep Power: 11
Quote:
Originally Posted by narutoboi
not really helpful....i dl der game from torrent portal...im tire of dl-ing movie so i dl load game....but now i need cd key...and der cd..

D.T.
There's your problem. If you want a game to work, buy a copy. Please don't talk about this in such a thread, because warez gets closed. :nono:

:warez:
__________________


Read the rules!

http://www.cardomain.com/ride/2952983/

"A.A. is for quitters ..."

"Never trust anything that bleeds for a week and lives ..."

"Smile, it costs nothing ..." - the words of a kind man, Rocol
 
 
Old 04-12-2006   #25
Amargeddemon
Professional Gamer
 
Amargeddemon's Avatar
 
Amargeddemon is offline
Join Date: Feb 2005
Location: New Zealand (the darker side of sheep tamers)
Posts: 4,809
Amargeddemon will become famous soon enough
Rep Power: 9
Send a message via MSN to Amargeddemon
MATE .......(READ THE RULES) and BUY the game......
to answer your question about legality yes this conversation is ILLEGAL
__________________


For Cracks and Patches Check - GBW, GCW ,
MG

Smile it costs nothing - quoted from a true genius (R.I.P My Friend)

Reach me on Bebo: AsylumReject


[SIGPIC][/SIGPIC]
 
 
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
New xbox backup tutorial CyBeR XxX Microsoft 44 07-01-2008 09:42 PM
A Simple Game Hacking Tutorial Creativity Software 32 12-26-2007 08:05 AM
Simple (professional) Website Logo DaMoMo Software 0 10-03-2004 08:55 AM
A German Cracking Tutorial ???? [CU]shooter No-DVD/CD Fixes & Patches 4 12-08-2003 12:18 AM
An Ultimative Cracking Tool??? Catch No-DVD/CD Fixes & Patches 14 12-07-2003 06:06 AM



All times are GMT -7. The time now is 04:25 AM.

vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
All logos and trademarks in this site are property of their respective owner. ©1998 - 2009 MegaGames. All rights reserved.
top of page