How to find the real serial 

AutoConnect 1.01

a Cracking tutorial By Nemesis] TNT


This reading material is not intended to violate Copyrights
and/or it is law, but educational purposes only. I hold no
responsibility ( by all means and in any shape whatsoever )
of the mis-used of this material.

About The Program

AutoConnect will automatically hit the Reconnect button for you when your ISP disconnects you from your Dial Up Connection.

If you have any comments or suggestions regarding AutoConnect, please send them to

Please visit for the latest version of AutoConnect, as well as other great programs.


Homepage :
Size : 76.0kb

Tool: numega Softice 4.5 [can be download at

HOW TO GET VALID SERIAL NUMBER for your name By Using [Softice]

lets get started run  AutoConnect  now enter your name and  fake serial click register button message box say Sorry, you have entered an incorrect registration code! ok now do this ctrl D bring softice , now we should put breakpoint like this bpx hmemcpy and enter press F5 to get out off softice, type your fake serial in the edit click register now you are back in softice, now lets search for real serial ;-) ok press F5 1 time F12 9 times until we land at this address below, now press F10 to go down .

* Reference To: USER32.GetDlgItemTextA, Ord:0104h

:00401C7A FF15F4504000 Call dword ptr [004050F4]

:00401C80 8D8500FEFFFF lea eax, dword ptr [ebp+FFFFFE00] <---we land here

:00401C86 50 push eax

:00401C87 8D8D00FFFFFF lea ecx, dword ptr [ebp+FFFFFF00]

:00401C8D 51 push ecx

:00401C8E E8CC030000 call 0040205F  <---trace this call

:00401C93 83C408 add esp, 00000008

:00401C96 85C0 test eax, eax

:00401C98 7440 je 00401CDA

:00401C9A 8D9500FEFFFF lea edx, dword ptr [ebp+FFFFFE00]

:00401CA0 52 push edx

:00401CA1 8D8500FFFFFF lea eax, dword ptr [ebp+FFFFFF00]

:00401CA7 50 push eax

* Referenced by a CALL at Addresses:

|:00401C8E , :00402032

when you trace the call you will land here

:0040205F 55 push ebp

:00402060 8BEC mov ebp, esp

:00402062 81EC04010000 sub esp, 00000104

:00402068 C745FC00000000 mov [ebp-04], 00000000

:0040206F 8D85FCFEFFFF lea eax, dword ptr [ebp+FFFFFEFC]

:00402075 50 push eax

:00402076 8B4D08 mov ecx, dword ptr [ebp+08]

:00402079 51 push ecx

:0040207A E8B5000000 call 00402134

:0040207F 83C408 add esp, 00000008

:00402082 8D95FCFEFFFF lea edx, dword ptr [ebp+FFFFFEFC]

:00402088 52 push edx

:00402089 8B450C mov eax, dword ptr [ebp+0C]

:0040208C 50 push eax

:0040208D E87E040000 call 00402510 <--type d eax for real serial

:00402092 83C408 add esp, 00000008

:00402095 85C0 test eax, eax

:00402097 7507 jne 004020A0

:00402099 C745FC01000000 mov [ebp-04], 00000001

now remember the serial you have fond enter it and is registered !

easy or ??? the program is registered  ;-) hope you find it useful ?


Special Thanks go to All [TNT MEMBERS] Keep it Real guys.

