What's new
RevTeam.Re - Reverse Engineering Team

Welcome Guest! Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox! Register and wait for our approve!

Qt5 C++ [How to Crack] EaseUS Data Recovery Wizard (valid license)

KarMa94

Member
Joined
Jan 16, 2025
Messages
8
Reaction score
5
Does anyone know how to debug this kind of software made with Qt? Can anyone give me a hint? Or is anyone able to crack this new version of EaseUS?

Download
Please, Log in or Register to view URLs content!

1745672141668.png


**License Key Format EXAMPLE**
G4Q7N-PL6J2-V9FZM-1W6SR-KD2YO

When you enter the correct activation serial, it connects to the server

Firebase is used for product information that is irrelevant to activation (firebasefetch.exe)
POST
Please, Log in or Register to view URLs content!




**REAL ACTIVATION URL**
Host: activation.easeus.com
Connection: Keep-Alive
Cache-Control: no-cache

Process: "C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe"

**Requests When Validating Serial**
GET
Please, Log in or Register to view URLs content!

Response
JKLm5PsKLXcTsJ47Ft-GH-2Q91Tkl-RE-WUfd7K1TsL0wXa34q

GET
Please, Log in or Register to view URLs content!

Response
367UUQ5LPZX37Ft-GH-2Q91Tkl-RE-W


**Request to Open the Program Already Activated**

GET
Please, Log in or Register to view URLs content!


Response
396QPzWjYk13Q4g-KN-2V84Zn-RT-J





**When you activate the program, this file is generated. It contains the serial, which is also saved in the registry**
"C:\Users\USER\AppData\Roaming\EaseUS\DRW\Configure.dat"
[register]
sn=G4Q7N-PL6J2-V9FZM-1W6SR-KD2YO
key=AbCdEfGhIjKlMnOpQrStUvWxYz1234567890+/
tech_expired=0

[HKEY_LOCAL_MACHINE\Software\EASEUS\DRW]
"SNExpired"=hex(3):30,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"SN"=hex(3):47,34,51,37,4E,2D,50,4C,36,4A,32,2D,56,39,46,5A,4D,2D,31,57,36,\
53,52,2D,4B,44,32,59,4F,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00
"SNKey"=hex(3):41,62,43,64,45,66,47,68,49,6A,4B,6C,4D,6E,4F,70,51,72,53,74,\
55,76,57,78,59,7A,31,32,33,34,35,36,37,38,39,30,2B,2F,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\Software\EASEUS\EaseUS Data Recovery Wizard]
"ExpiredDate"="2099-01-30"
"ExpiredDays"=hex(3):FF,FF,FF,FF,FF,FF,FF,FF




**Another file created during activation**
"C:\Program Files (x86)\EaseUS\ENS\.wpn.js"

{
"options": {
"verbosity": 3
},
"credentials": {
"appId": "xYzPQL83BBB",
"androidId": 9876543210123456789,
"securityToken": 1928374655647382910,
"GCMToken": "xyrHAbcTgKl:APA91bMfNqYt74D58qFTsWPbZY-XyuvwwL_XQRVGtK8XYzWmku5LxsdY7pUvBfqWE4zPLo0JDQsHYaOPz6bnr5mQXdRTYXzl04KJTEBAs7kfiUv7L3dbJxKg-QP4Kv9gixeGfaRzB7rQ2"
},
"keys": {
"id": 83472918374659102,
"secret": 984321657423,
"privateKey": "8LpQvZT6PnYXBOZPxN4yp_RD72R6Sr9zjhNuxCVQsa1",
"publicKey": "BAabWxkgGhdfTFhLrQcvdYQu4VY63MR8HZR2gIspdqNNyTD6ptX9kq3sVvQMNBt3yBW8KPYb4wGGur8GF7h6qKP",
"authSecret": "WwqzFNhPCduUVbWsaGFtjP"
},
"subscriptions": []
}



**IMPORTANT**
Apparently, a token is generated using local system and hardware information, and sent as a parameter to the only activation URL that actually matters:
Please, Log in or Register to view URLs content!

This request is what determines whether the program is activated. All other connections can be blocked without affecting activation.
I can modify the server response and it doesn't affect the activation process as long as a response is returned. However, if I remove the response entirely and leave it empty, the program deactivates. This suggests that the real validation is handled within the executable itself; the server call is simply a connectivity check, as usual.

"C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRW.exe"
is the process that launches the application (DRWUI.exe)

However, this one is the process that actually contains the entire user interface and all the activation information:
"C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe"

So, I’m not sure how to trace them properly. Any tips or suggestions?
 
Last edited:

unitechpkl

New member
Joined
Sep 23, 2026
Messages
2
Reaction score
0
Please, Log in or Register to view quote content!

I tried to block all four of these files using Windows Firewall (even I disconnected internet cable before running the program) , but I couldn't get it to work. The files are:

  1. DRWUI.exe
  2. DRW.exe
  3. firebasefetch.exe
  4. BUILDPE\firebasefetch.exe


@echo off
title EaseUS Data Recovery Wizard - Firewall Block
color 0A

echo ================================================
echo Blocking EaseUS Data Recovery Wizard
echo ================================================
echo.

:: Check for Administrator privileges
net session >nul 2>&1
if %errorlevel% neq 0 (
echo ERROR: Please run this BAT file as Administrator.
echo.
pause
exit /b 1
)

:: ------------------------------------------------
:: DRWUI.exe
:: ------------------------------------------------
echo Blocking DRWUI.exe...

netsh advfirewall firewall delete rule name="Block EaseUS DRWUI - Outbound" >nul 2>&1
netsh advfirewall firewall delete rule name="Block EaseUS DRWUI - Inbound" >nul 2>&1

netsh advfirewall firewall add rule name="Block EaseUS DRWUI - Outbound" dir=out action=block program="C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe" enable=yes profile=any
netsh advfirewall firewall add rule name="Block EaseUS DRWUI - Inbound" dir=in action=block program="C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe" enable=yes profile=any

:: ------------------------------------------------
:: DRW.exe
:: ------------------------------------------------
echo.
echo Blocking DRW.exe...

netsh advfirewall firewall delete rule name="Block EaseUS DRW - Outbound" >nul 2>&1
netsh advfirewall firewall delete rule name="Block EaseUS DRW - Inbound" >nul 2>&1

netsh advfirewall firewall add rule name="Block EaseUS DRW - Outbound" dir=out action=block program="C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRW.exe" enable=yes profile=any
netsh advfirewall firewall add rule name="Block EaseUS DRW - Inbound" dir=in action=block program="C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRW.exe" enable=yes profile=any

:: ------------------------------------------------
:: firebasefetch.exe - Main
:: ------------------------------------------------
echo.
echo Blocking firebasefetch.exe...

netsh advfirewall firewall delete rule name="Block EaseUS FirebaseFetch - Outbound" >nul 2>&1
netsh advfirewall firewall delete rule name="Block EaseUS FirebaseFetch - Inbound" >nul 2>&1

netsh advfirewall firewall add rule name="Block EaseUS FirebaseFetch - Outbound" dir=out action=block program="C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\firebasefetch.exe" enable=yes profile=any
netsh advfirewall firewall add rule name="Block EaseUS FirebaseFetch - Inbound" dir=in action=block program="C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\firebasefetch.exe" enable=yes profile=any

:: ------------------------------------------------
:: firebasefetch.exe - BUILDPE
:: ------------------------------------------------
echo.
echo Blocking BUILDPE firebasefetch.exe...

netsh advfirewall firewall delete rule name="Block EaseUS FirebaseFetch BUILDPE - Outbound" >nul 2>&1
netsh advfirewall firewall delete rule name="Block EaseUS FirebaseFetch BUILDPE - Inbound" >nul 2>&1

netsh advfirewall firewall add rule name="Block EaseUS FirebaseFetch BUILDPE - Outbound" dir=out action=block program="C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\BUILDPE\EaseUS-x64\firebasefetch.exe" enable=yes profile=any
netsh advfirewall firewall add rule name="Block EaseUS FirebaseFetch BUILDPE - Inbound" dir=in action=block program="C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\BUILDPE\EaseUS-x64\firebasefetch.exe" enable=yes profile=any

echo.
echo ================================================
echo FIREWALL RULES CREATED SUCCESSFULLY
echo ================================================
echo.
echo Blocked executables:
echo.
echo 1. DRWUI.exe
echo 2. DRW.exe
echo 3. firebasefetch.exe
echo 4. BUILDPE\firebasefetch.exe
echo.
echo INBOUND and OUTBOUND connections are blocked.
echo.
echo Press any key to finish...
pause >nul
```


AFTER THE PROPER HOST FILE, PATCH, AND ACTIVATOR RUN SUCCESSFULLY, WHEN I RUN THE APPLICATION (WITH THE INTERNET STILL DISCONNECTED), THE APPLICATION SHOWS AS ACTIVATED FOR ONLY ABOUT 5 SECONDS. THEN IT IMMEDIATELY REVERTS FROM ACTIVATED BACK TO TRIAL MODE.

HOSTS FILE → PATCH → ACTIVATOR → INTERNET DISCONNECTED → LAUNCH APPLICATION → ACTIVATED FOR ~5 SECONDS → REVERTS TO TRIAL
 
Top