Quote:
Originally Posted by The-mann
Bro, i want to say nice work until now, i couldnt really understand everything or whats your real objective but i'd like to give you some lead for G4megu4rd problem.
First of all, i have seen that G4megu4rd uses a certain "Au~Kb~Hook~.dll"; Well, i have tried to move this out from the game folder and what happens is that the patching client starts but if you press "start game", just at the point where G4megu4rd would start, it stops working, and i mean the game doesnt work. Well from this i got the conclusion that, that dll is the point where the G4megu4rd is hooked to the game.
In my opinion there is a possibility that if you remove a few (or more) lines from that dll file , maybe you could make the game jump over the point where the G4megu4rd, hooks to it, and i guess that if you do that, it won't be a problem h00king wpe pro to it or doing other things freely.
Another thing is that i have found with some programs which detect hidden processes that when the game starts there are some processes named "Game~mon~.des and G~ame~gu~ard~.des"(remove the "~" things, as well as for the earlier name of the .dll); Well those files are located in the G4megu4rd folder in the game; Again, in my opinion there are some things happening in there ( like it makes the process invisible or hooking things), having a look inside that thing could reveal new things.
I know i have said these things in another topic of mine and Avati. said that it could be a problem if they patch it up so we would need to find new ways on each patch ( or something like that ). Well i guess that you dont need it for so long time so i think it would be useful.
Also when the game starts there is a service created named "NP~P~TNT~2"( or at least the program said so) which is deleted after the game is shut down... well since it stays on while you play the game i think it plays the "watcher" which triggers the shutdown when you try to hack something , i would recommend watching for that thing too.
And last i will say sorry that i only give leads or ideas, i can't work these on my own because i only know few things about programming, but i'm trying to help in my way... and also i hope i have helped with something.
|
only changing some lines, its more then that, the gamestarts when gameguard says all is right<- try to simulate this.
first gameguard start, and its not a dll
its gameguard.des,
it checks if all gameguard files are there and patches them. If all goes right, it starts the game and gamemon.des , again not a dll, gamemon.des hides himself and archlord.exe
and while gamemon.des is active u can't use wpe or other sniffer/debugger, why? becouse the
debugport of archlord is already in use, gameguard "hook" his self in archlord so no other programms can hook it.
it would be easyly to stop gamemon.des blocking the debugport, but the problem is, gamemon&archlord are hidden ><