your welcome.
maybe i will add some things later.
argh i really should learn for my exams, but i really dont want to :D
maybe i will add some things later.
argh i really should learn for my exams, but i really dont want to :D
ahh saw the problem .... have 64 bit but the game is installed with x86 so when i dl the for x86 it worked thx :pQuote:
download the redistributable package.
a link can be found in the first post
and no there is no way to remove the hackshield.
i dont know any way, to remove it completly.
CreateMutex JNZ -> JMP
CreateProcess InheritHandles -> FALSE
CreateMUtexA (ClientCHeck):
006352A2 . 68 2033BC00 PUSH Maestia_.00BC3320 ; /MutexName = "Global\C886B01D-2DDD-466e-B6D7-43E0DC18F895"
006352A7 . 6A 00 PUSH 0 ; |InitialOwner = FALSE
006352A9 . 6A 00 PUSH 0 ; |pSecurity = NULL
006352AB . FF15 B482A500 CALL DWORD PTR DS:[<&KERNEL32.CreateMute>; \CreateMutexA
006352B1 . 8945 E4 MOV DWORD PTR SS:[EBP-1C],EAX
006352B4 . 837D E4 00 CMP DWORD PTR SS:[EBP-1C],0
006352B8 0F85 3D010000 JNZ Maestia_.006353FB ;this JNZ -> JMP
CreateMutexW (ClientCheck):
007E0054 |. 68 FCD4AE00 PUSH Maestia_.00AED4FC ; /MutexName = "Homage"
007E0059 |. 50 PUSH EAX ; |InitialOwner
007E005A |. 50 PUSH EAX ; |pSecurity
007E005B |. FF15 9C82A500 CALL DWORD PTR DS:[<&KERNEL32.CreateMute>; \CreateMutexW
007E0061 |. 8BD8 MOV EBX,EAX
007E0063 |. FF15 C881A500 CALL DWORD PTR DS:[<&KERNEL32.GetLastErr>; [GetLastError
007E0069 |. 3D B7000000 CMP EAX,0B7
007E006E |. 75 30 JNZ SHORT Maestia_.007E00A0 ;this JNZ -> JMP
CreateProcessA (ClientCheck):
00635AFA . 51 PUSH ECX ; /pProcessInfo
00635AFB . 8D95 1CFEFFFF LEA EDX,DWORD PTR SS:[EBP-1E4] ; |
00635B01 . 52 PUSH EDX ; |pStartupInfo
00635B02 . 8B45 08 MOV EAX,DWORD PTR SS:[EBP+8] ; |
00635B05 . 50 PUSH EAX ; |CurrentDir
00635B06 . 6A 00 PUSH 0 ; |pEnvironment = NULL
00635B08 . 6A 00 PUSH 0 ; |CreationFlags = 0
00635B0A . 6A 01 PUSH 1 ; |InheritHandles = TRUE
00635B0C . 6A 00 PUSH 0 ; |pThreadSecurity = NULL
00635B0E . 6A 00 PUSH 0 ; |pProcessSecurity = NULL
00635B10 . 8D8D 8CFBFFFF LEA ECX,DWORD PTR SS:[EBP-474] ; |
00635B16 . 51 PUSH ECX ; |CommandLine
00635B17 . 6A 00 PUSH 0 ; |ModuleFileName = NULL
00635B19 . FF15 7C83A500 CALL DWORD PTR DS:[<&KERNEL32.CreateProc>; \CreateProcessA
CreateProcessA (ClientCheck):
006368D9 . 50 PUSH EAX ; /pProcessInfo
006368DA . 8D8D 1CFEFFFF LEA ECX,DWORD PTR SS:[EBP-1E4] ; |
006368E0 . 51 PUSH ECX ; |pStartupInfo
006368E1 . 8B55 08 MOV EDX,DWORD PTR SS:[EBP+8] ; |
006368E4 . 52 PUSH EDX ; |CurrentDir
006368E5 . 6A 00 PUSH 0 ; |pEnvironment = NULL
006368E7 . 6A 00 PUSH 0 ; |CreationFlags = 0
006368E9 . 6A 01 PUSH 1 ; |InheritHandles = TRUE
006368EB . 6A 00 PUSH 0 ; |pThreadSecurity = NULL
006368ED . 6A 00 PUSH 0 ; |pProcessSecurity = NULL
006368EF . 8D85 7CF7FFFF LEA EAX,DWORD PTR SS:[EBP-884] ; |
006368F5 . 50 PUSH EAX ; |CommandLine
006368F6 . 6A 00 PUSH 0 ; |ModuleFileName = NULL
006368F8 . FF15 7C83A500 CALL DWORD PTR DS:[<&KERNEL32.CreateProc>; \CreateProcessA