Bypass Play.exe

08/11/2007 02:47 darksonic#1
There are two ways to bypass play.exe and start soul.exe without autopatching
Method #1:
The first and easiest method is to use the blacknull parameter, to do this find Eudemon's shortcut on the desktop or the start menu programs and rightclick it>properties:
[Only registered and activated users can see links. Click Here To Register...]

now add the word "blacknull" (not quotes) at the end of the path under "Target":
[Only registered and activated users can see links. Click Here To Register...]

now all you have to do is click on the shortcut normally and the game will open right away.

Method #2:
If for whatever reason the first method does not work (using a cam that doesnt allow you to specify parameters) , you could use this method to bypass the play.exe
First you need ollydbg:
[Only registered and activated users can see links. Click Here To Register...]
look to the left menu and download it from the link

after you extracted ollydbg, open it (OLLYDBG.EXE) and go to file>open then select soul.exe from your eduemons' directory and click "open":
[Only registered and activated users can see links. Click Here To Register...]

now wait for the application to load unless it says "paused" at the buttom right and then rightclick in the middle of the program and choose "Search for">"All referenced text strings":
[Only registered and activated users can see links. Click Here To Register...]

a new window will popup when search is completed, now rightclick in the middle and select "Search for text":
[Only registered and activated users can see links. Click Here To Register...]

now type in "blacknull" (no qoutes), uncheck "Case sensitive" and check "Entire Scope" and click "OK". You will find one word that matches in all References, rightclick it and select "Follow in Disassembler":
[Only registered and activated users can see links. Click Here To Register...]

now look down from "blacknull" in the new window and look for the value:
JNZ SHORT 00587392, thats the 2nd JNZ value from "blacknull". Now rightclick this value and select "Assemble":
[Only registered and activated users can see links. Click Here To Register...]

change "JNZ" to "JE" (notice the space after JNZ or JE keep it!). Thus we have changed Jump if not equal to Jump if equal which is the opposite of what was originally (ie if u add blacknull at the end or try to open it with play.exe its gonna give you the message "please run Play.exe"!)
[Only registered and activated users can see links. Click Here To Register...]

now close the assembling window by clicking "X" or "Cancel" then rightclick on the middle of the program and go to "Copy to Executable">"All Modifications" and select "Copy All" in the small window that appears:
[Only registered and activated users can see links. Click Here To Register...]

a new window will appear with your modifications, now rightclick on the new window and select "Save to file":
[Only registered and activated users can see links. Click Here To Register...]

now save the modified executable to eudemons' directory, usually as soul2.exe (do not overwrite the original!):
[Only registered and activated users can see links. Click Here To Register...]
close ollydbg


now whenever you want to open eudemons quickly, without autopatch or you want to use a program that doesn't allow you to specify parameters for soul.exe, just open soul2.exe and it should open right way..
08/11/2007 04:17 shwayarcher#2
ooh nice job...better for ppl who cant auto patch and good for when the autopatch server is down +k
08/13/2007 06:14 rookiehacker#3
more than that....does anyone have a copy of eudemons before exphack was stopped? we should see which side they fixed things on...probably server but we should check it out
08/13/2007 23:29 darksonic#4
Quote:
Originally posted by rookiehacker@Aug 13 2007, 00:14
more than that....does anyone have a copy of eudemons before exphack was stopped? we should see which side they fixed things on...probably server but we should check it out
we need to know at which patch it was fixed and at which patch before it was a soul.exe released ;), because we can access the patches on the ftp server:
ftp://64.151.79.165/1066.exe but we need to know the exact patch # because directory listing is not allowed
09/05/2007 07:43 funhacker#5
Quote:
Originally Posted by rookiehacker View Post
more than that....does anyone have a copy of eudemons before exphack was stopped? we should see which side they fixed things on...probably server but we should check it out
it would of been server sided like with ep you now cant have more time in the OTG then wat you already have [my assumption] still worth checking
03/03/2008 18:10 smikisssss#6
speed hack would work :) need downgraded client who has ?