Sliverz
Task2
Wed Dec 16 16:07:48 1998


Greetings friends..
I think I took the longer approach to this task but I will post it for your comments and assistance.
Using NTfilemon and NTregmon, I noted that it was consistently calling cyt.ini and msffs.dll. After checking and altering the cyt.ini to no avail, I then unhid the dll and proceeded to alter. After a lot of nops and OO's I found that I could invoke the register screen by changing the two digits 2 and 7 in the string following 000000ED:g431
...ie: 17119..27..23919 etc..... By then deleting the two files, cyt.ini and msffs.dll and starting the application again, I found the difference in the new and old msffs.dll file. The unregistered dll uses 8 and 6 to replace the 2 and 7 in the registered dll. I can now toggle this application between registered and unregistered simply by altering these digits. I'm still not sure how to use this Regview but I'm sure I will learn.

Thank you all!