Binary 38801, Latest binary.

06/06/2013 19:54 capel0#1
This is latest binary unpacked.

Has R6002 error.

Hasn't any modification.

Code:
https://mega.co.nz/#!BEV0jb6J!MPcP3xCGenYIGQXAzsVPeHiEx4wSCVHYDf9vBKpCPTs


Can anyone to remove hackshield and CRC check?
06/06/2013 19:55 TheMarv :<#2
#report

Seriously? xD
06/06/2013 19:56 capel0#3
Quote:
Originally Posted by TheMarv :< View Post
#report

Seriously? xD
Try it!
06/06/2013 19:58 TheMarv :<#4
The link doesn't even work....
06/06/2013 20:02 capel0#5
Now works!
06/06/2013 20:04 TheMarv :<#6
Virustotal: [Only registered and activated users can see links. Click Here To Register...]
06/06/2013 20:23 .Awesoome'#7
Why do you release crashed Binarys ? There is no reason..
06/06/2013 20:26 capel0#8
Quote:
Originally Posted by .Awesoome' View Post
Why do you release crashed Binarys ? There is no reason..
I dont know how to fix R6002.

I said has not modifications
06/06/2013 21:09 .Captor#9
Here a 'Fix' for the CRC Check

PHP Code:
This difference file is created by The Interactive Disassembler

metin2client_38801
.exe
002C0188
70 00
002C0189
E6 00
002C018A
65 00
002C018B
00 00
002C018C
67 00
002C018D
94 00
002C018E
D8 00
002C018F
87 00
002C0100
D8 00
002C0191
0B 00
002C0192
00 00
002C0193
00 00
002C0194
00 00
002C0195
00 00
002C0196
00 00
002C0197
00 00
002C0198
60 00
002C0199
E6 00
002C019A
65 00
002C019B
00 00
002C019C
03 00
002C019D
C4 00
002C019E
89 00
002C019F
49 00
002C01A0
00 00
002C01A1
05 00
002C01A2
08 00
002C01A3
00 00
002C01A4
00 00
002C01A5
00 00
002C01A6
00 00
002C01A7
00 00
002C01A8
54 00
002C01A9
E6 00
002C01AA
65 00
002C01AB
00 00
002C01AC
6E 00
002C01AD
5A 00
002C01AE
A8 00
002C01AF
D6 00
002C01B0
00 00
002C01B1
D0 00
002C01B2
3E 00
002C01B3
04 00
002C01B4
00 00
002C01B5
00 00
002C01B6
00 00
002C01B7
00 00
002C01B8
44 00
002C01B9
E6 00
002C01BA
65 00
002C01BB
00 00
002C01BC
CA 00
002C01BD
C6 00
002C01BE
07 00
002C01BF
93 00
002C01C0
00 00
002C01C1
1C 00
002C01C2
BF 00
002C01C3
03 00
002C01C4
00 00
002C01C5
00 00
002C01C6
00 00
002C01C7
00 00 
The fix isn't the best, but it works. :)
I try to fix the Hshield ;)
06/07/2013 00:45 balika01#10
rebuilded binary: [Only registered and activated users can see links. Click Here To Register...]
disable crc:
Code:
000C356D: E8 90
000C356E: 3E 90
000C356F: CC 90
000C3570: FF 90
000C3571: FF 90
000C3572: 84 90
000C3573: C0 90
000C3574: 0F 90
000C3575: 84 90
000C3576: 01 90
000C3577: 02 90
000C3578: 00 90
000C3579: 00 90
(because my laptop died, i unable to test this binary on win7, on xp works perfectly and this should works in win7 too ;))
06/07/2013 00:50 deco016#11
no bug with invetory?
06/07/2013 08:23 .Captor#12
Quote:
Originally Posted by balika01 View Post
rebuilded binary: [Only registered and activated users can see links. Click Here To Register...]
disable crc:
Code:
000C356D: E8 90
000C356E: 3E 90
000C356F: CC 90
000C3570: FF 90
000C3571: FF 90
000C3572: 84 90
000C3573: C0 90
000C3574: 0F 90
000C3575: 84 90
000C3576: 01 90
000C3577: 02 90
000C3578: 00 90
000C3579: 00 90
(because my laptop died, i unable to test this binary on win7, on xp works perfectly and this should works in win7 too ;))
Can you make a dif for disable the hshield? :) i try'ed it but i failed... -.- sorry for bad english :P
06/07/2013 08:29 Mi4uric3#13
Quote:
Originally Posted by .Captor View Post
Can you make a dif for disable the hshield? :) i try'ed it but i failed... -.- sorry for bad english :P
Whats so hard about it?
Delete the Hackshield folder and then find the places where the messageboxes appear and make the last jump before the messagebox call always jump over it.
06/07/2013 08:43 .Captor#14
Quote:
Originally Posted by Mi4uric3 View Post
Whats so hard about it?
Delete the Hackshield folder and then find the places where the messageboxes appear and make the last jump before the messagebox call always jump over it.
Ich habe es jetzt auf eigene art gemacht (mit OllyDBG) und es funktioniert soweit auch, nur beim Beenden des Clienten bekomme ich eine Meldung vom HACK_SHIELD (Auch ohne Ordner) "UNINITIALIZE_ERROR(errorCode=3) :D
06/07/2013 10:03 Mi4uric3#15
Quote:
Originally Posted by .Captor View Post
Ich habe es jetzt auf eigene art gemacht (mit OllyDBG) und es funktioniert soweit auch, nur beim Beenden des Clienten bekomme ich eine Meldung vom HACK_SHIELD (Auch ohne Ordner) "UNINITIALIZE_ERROR(errorCode=3) :D
Dann patchst du diese Messagebox halt auch..? :p