OllyDBG & CO

04/13/2009 06:24 akizz#196
With u value dont work, im try with "JMP SHORT 0046880B" and now running direct, but thanks for help dear. ;)
04/14/2009 11:17 NovaCygni#197
Correct me if im wrong but if people had grasped the teachings of the first few pages of this thread they should already know how to continue this work, I see alot of "Help plx" requests for things already covered in this thread! Any nub can follow a guide to "Change this line to xyz, and that line to xyz"...
04/15/2009 04:29 batmanbatman#198
Quote:
Originally Posted by NovaCygni View Post
Correct me if im wrong but if people had grasped the teachings of the first few pages of this thread they should already know how to continue this work, I see alot of "Help plx" requests for things already covered in this thread! Any nub can follow a guide to "Change this line to xyz, and that line to xyz"...
most of them ask for being allowed to use free items to socket fan/talis:p
04/16/2009 19:49 killermanx0#199
any1 knows how to up the fps limit like _fobos_ did? i know where to look but not what to change.
04/16/2009 20:05 _fobos_#200
Quote:
Originally Posted by killermanx0 View Post
any1 knows how to up the fps limit like _fobos_ did? i know where to look but not what to change.
open CO in olly -> search for all intermodular calls -> type in Sleep -> double click first one u find -> look for next 2 lines.

1:
00482E95 8D51 19 LEA EDX,DWORD PTR DS:[ECX+19]

into:

00482E95 8D51 14 LEA EDX,DWORD PTR DS:[ECX+14]

2:
00482E9E 83C1 19 ADD ECX,19

into:

00482E9E 83C1 14 ADD ECX,14

to remove the lock you patch the JNB
04/16/2009 22:51 killermanx0#201
Quote:
Originally Posted by _fobos_ View Post
open CO in olly -> search for all intermodular calls -> type in Sleep -> double click first one u find -> look for next 2 lines.

1:
00482E95 8D51 19 LEA EDX,DWORD PTR DS:[ECX+19]

into:

00482E95 8D51 14 LEA EDX,DWORD PTR DS:[ECX+14]

2:
00482E9E 83C1 19 ADD ECX,19

into:

00482E9E 83C1 14 ADD ECX,14

to remove the lock you patch the JNB

thnx alot bro ;)
04/27/2009 02:03 killermanx0#202
srry for the doublepost but i got a request.
can any1 restrict the quiz search from internet explorer to mozilla firefox or any other browser?
i know the place in the conquer exe file but i dont know how to lead it to a other browser. it would help allot since internet explorer laggs with much ppl and often cant load the search.
05/02/2009 17:06 high6#203
Btw if you want to remove the "Please login later" shit do this.

Search for -> All intermodular calls
Find "GetTickCount" and check them for the following code.
Code:
00434C1A      |.  FFD7               CALL EDI                                                 ; [GetTickCount
00434C1C      |.  2B05 3C815D00      SUB EAX,DWORD PTR DS:[5D813C]
00434C22      |.  3D 10270000        CMP EAX,2710
Thing you are looking for is the CMP EAX,2710.
Patch the JBE right above "CALL EDI" to a JMP.
05/08/2009 12:52 medooo#204
hello all ,,,
can any one help me to make conquer.exe non-dc ?
& how to make it work with the speed hack !
help pls if u know how
05/08/2009 22:44 ookamocka#205
ok my question is sort of unrelated to everything and more of just a ollyDBG problem... when i run Conquer.exe through ollyDBG, i always get the same problem, it creates the conquer task and puts it at the bottom, but i can't see the window or get the window to appear, so i'm stuck with not being able to run Conquer.exe through ollyDBG . . .
05/09/2009 04:38 ookamocka#206
nvm, i figured out that there's an attach option... so thats that... but now i have a new question... or err.. request

i'm trying to find how to jump on top of where somebody already is... so i searched for the "100023=You can't stop here!" i.e. "PUSH 186B7"... and playing around with it for a little while... i ended up finding nothing really...

Code:
004C617E     EB 2B          JMP SHORT Conquer_.004C61AB
004C6180     FF15 7C805700  CALL DWORD PTR DS:[<&GraphicData.GameDat>;  GraphicD.GameDataSetQuery
004C6186     8B10           MOV EDX,DWORD PTR DS:[EAX]
004C6188     6A 00          PUSH 0
004C618A     6A 00          PUSH 0
004C618C     68 0000FF00    PUSH 0FF0000
004C6191     68 D5070000    PUSH 7D5
004C6196     68 B7860100    PUSH 186B7
004C619B   > 8BC8           MOV ECX,EAX
004C619D   . FF52 3C        CALL DWORD PTR DS:[EDX+3C]
004C61A0   . 50             PUSH EAX
004C61A1   . B9 A0855D00    MOV ECX,Conquer_.005D85A0
004C61A6   . E8 9D47FDFF    CALL Conquer_.0049A948
004C61AB   > 5F             POP EDI
004C61AC   . 5E             POP ESI
004C61AD   . 5B             POP EBX
004C61AE   . C9             LEAVE
i've tried just about everything to make my char jump on the spot of another player (and i also randomly tried to jump on places you can't actually jump on)... but the most i managed to do, was to remove the message, and thats by replacing 004C6186 with the line 004C617E... i'm pretty sure NOP'ing it would have the same affect though so err w/e... but ne way... i tried redirecting the 004C617E to a bunch of places, with no success, it'd just crash when u attempt to jump... only thing else i can think of... is to CALL the jump function some how... but i'm not even sure what the jump function or w/e is :(...

like i know if u try to bypass the gate jumping your char will jump there and warp back... but for when i got the message to not come up for jumping in a place you can't jump the message doesn't come up, and u don't jump at all . . .

any help plz? :)
05/09/2009 11:30 IAmHawtness#207
Quote:
Originally Posted by ookamocka View Post
any help plz? :)
Code:
004C60F6  |. 8B4D FC        MOV ECX,DWORD PTR SS:[EBP-4]
004C60F9  |. 85C9           TEST ECX,ECX
004C60FB  |. 74 0E          JE SHORT Conquer.004C610B
004C60FD  |. E8 78C20000    CALL Conquer.004D237A
004C6102  |. 83E0 20        AND EAX,20
004C6105  |. 33C9           XOR ECX,ECX
Change into:

Code:
004C60F6  |. 8B4D FC        MOV ECX,DWORD PTR SS:[EBP-4]
004C60F9  |. 85C9           TEST ECX,ECX
004C60FB  |. 74 0E          [B]JMP SHORT Conquer.004C610B[/B]
004C60FD  |. E8 78C20000    CALL Conquer.004D237A
004C6102  |. 83E0 20        AND EAX,20
004C6105  |. 33C9           XOR ECX,ECX
However, it's still pretty hard actually jumping on top of the players, you need to click somewhere around their right food or so :p.
05/09/2009 17:36 ookamocka#208
Quote:
Originally Posted by IAmHawtness View Post
Code:
004C60F6  |. 8B4D FC        MOV ECX,DWORD PTR SS:[EBP-4]
004C60F9  |. 85C9           TEST ECX,ECX
004C60FB  |. 74 0E          JE SHORT Conquer.004C610B
004C60FD  |. E8 78C20000    CALL Conquer.004D237A
004C6102  |. 83E0 20        AND EAX,20
004C6105  |. 33C9           XOR ECX,ECX
Change into:

Code:
004C60F6  |. 8B4D FC        MOV ECX,DWORD PTR SS:[EBP-4]
004C60F9  |. 85C9           TEST ECX,ECX
004C60FB  |. 74 0E          [B]JMP SHORT Conquer.004C610B[/B]
004C60FD  |. E8 78C20000    CALL Conquer.004D237A
004C6102  |. 83E0 20        AND EAX,20
004C6105  |. 33C9           XOR ECX,ECX
However, it's still pretty hard actually jumping on top of the players, you need to click somewhere around their right food or so :p.
oh man your amazing :) lol... ya thats np on still needing to click on right at their feet or whatever... because i'm using it for a bot, so i don't have to worry about randomizing the variables to avoid obstacles, i can just jump right on to players in the way ^_^... so again, ty soooo much for that one... i spent an hour yesterday trying to find it lol

also, if u don't mind, how exactly did u find it? did u just search for PUSH 186B7 and just kept going above it and JMP the first JE/JNZ/JNE/etc. into JMP and seeing if it worked, and if it didn't work do the next one above it? if u did then i feel like an idiot cuz i got all the way to

Code:
004C6109   . 74 75          JE SHORT Conquer_.004C6180
doing that, and it didn't work, so i gave up on trying that approach... lol just 1 more and i would of had it >.<

thx for the insight... and if u don't feel like publicizing how u found it, send me a PM plz ^_^

again, i'm very greatfull for this ;)
05/09/2009 18:21 IAmHawtness#209
Quote:
Originally Posted by ookamocka View Post
also, if u don't mind, how exactly did u find it? did u just search for PUSH 186B7 and just kept going above it and JMP the first JE/JNZ/JNE/etc. into JMP and seeing if it worked, and if it didn't work do the next one above it? if u did then i feel like an idiot cuz i got all the way to
I loaded Conquer.exe in ollydbg, right clicked -> Search for -> All commands -> PUSH 186B7.

I found two "PUSH 186B7" instructions - one at 004C6196, one at 0050B66A

Then I had Conquer opened with Cheat Engine attached to it (I always use Cheat Engine for these kind of things)

I used Cheat Engine to set a breakpoint at both the "PUSH 186B7" instructions and tried jumping on a player in CO, and found out which one of them caused the "You can't jump here" (or whatever) error.

Then I just started tracing back.

Code:
[B]004C6180  |> FF15 7C805700  CALL DWORD PTR DS:[<&GraphicData.GameDat>;  GraphicD.GameDataSetQuery[/B]
004C6186  |. 8B10           MOV EDX,DWORD PTR DS:[EAX]
004C6188  |. 6A 00          PUSH 0
004C618A  |. 6A 00          PUSH 0
004C618C  |. 68 0000FF00    PUSH 0FF0000
004C6191  |. 68 D5070000    PUSH 7D5
004C6196  |. 68 B7860100    PUSH 186B7
^ See that command there?
If you click on that and press Find references to -> Selected command (hotkey Ctrl+R) you'll see the addresses that jumps there.

Then you'll find the JE Conquer.004C6180, and 3 instructions below that is the JE Conquer.004C610B instruction, which needs to be JMP'd :).

It's a lot easier doing these kinds of things if you combine Cheat Engine and ollydbg, really :p.
05/21/2009 01:42 silverstreak#210
OK new EXE, 5127 patch, most changes can be made, however I havent been able to find the "TQ_CONQUER" for multi? Any ideas?

LOL nevermind - PUSH 4AE "FTW? I THINK SO!"