Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Dekaron
You last visited: Today at 03:47

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



How to remove y0da+ASProtect??

Discussion on How to remove y0da+ASProtect?? within the Dekaron forum part of the MMORPGs category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Sep 2008
Posts: 18
Received Thanks: 1
my google skills sucks .

any help would be apreciated

anyone?? please?
bruyeria is offline  
Old 09/29/2008, 17:29   #2
 
elite*gold: 0
Join Date: Oct 2007
Posts: 196
Received Thanks: 188
In order to remove those packers you need to be good with assembler.
Lucky us, somebody who is good with assembler released a script to do this work.
Well I used that script and here you have the unpacked dekaron.exe from 4.1 patch. ( )

Code:
dbh

var a
var b
var c
var d
var e
var test
var rva

run
eoe checkme
eob checkme

checkme:
mov b,eip
add b,2
mov b,[b]
cmp b,00058F64
je checklast
esto

checklast:
mov a,ebp
sub a,10
mov a,[a]
cmp a,400000
je found
esto

found:
eob end
eoe end
mov c,[40003C]
add c,100
add c,400000
mov c,[c]
bprm 401000,c
esto

end:
mov a,[eip]
and a,0000FF
cmp a,C3
jne exit
mov test,[esp]
and test,F00000
shr test,14
cmp test,9
jae loop
jmp exit

loop:
eob exit
eoe exit
esto

exit:
sti
mov d,eip
sub d,9
mov eip,d
mov e,[ebp-8]
mov [eip],e
mov d,eip
sub d,1
mov eip,d
mov [eip],#68#
mov d,eip
sub d,2
mov eip,d
mov [eip],#6A60#
dpe "dump.exe",eip
cmt eip,"OEP! Stolen bytes fixed & dumped. Fix IAT with ImpREC!"
mov rva,eip
sub rva,400000
log rva,"RVA of OEP: "
ret

retry:
ret
p.s.If you want to do it yourselfe fix the dump this script is doing with Imprec.
xhugox is offline  
Thanks
1 User
Old 09/29/2008, 18:32   #3
 
elite*gold: 0
Join Date: Aug 2008
Posts: 1,122
Received Thanks: 215
+#2 reported at 29.09.2008 18:32 gmt+2 cause double posts

Please use the next time the edit button please.

Thanks
Hagman94 is offline  
Old 09/29/2008, 19:43   #4



 
Mastershouter's Avatar
 
elite*gold: 21
Join Date: Nov 2006
Posts: 2,526
Received Thanks: 1,222
+merged
Mastershouter is offline  
Old 06/13/2009, 14:58   #5
 
elite*gold: 0
Join Date: Mar 2008
Posts: 6
Received Thanks: 1
Quote:
Originally Posted by xhugox View Post
In order to remove those packers you need to be good with assembler.
Lucky us, somebody who is good with assembler released a script to do this work.
Well I used that script and here you have the unpacked dekaron.exe from 4.1 patch. ( )
The file could not be found. Please check the download link.
is what i get when following that link

im trying to understand the great works of Nebular a tut on y0da+ASProtect would be nice

im not looking for a hand feed but a hand pointing in the right direction

heres where i started this quest of knowledge
Expedition CRC

anyone with a link on that topic pls pm it to me

my eyes are sore from reading double posts flames and posts in the wrong topics if your having the same problem and interested in understanding Nebulars achievements in this aspect friend me and we can learn together by sending relative links with useful information

aquiring the necessary apps isnt hard for me pirate/hacker/////

just so you know who i am

i dont agree with 1 click hacks reason:
it destroys the game.

i do agree with hacking games reason:
its a challenge when you work for it and when it works you feel good.

grinding to make the hack work is like grinding for gold reason:
the rewards are yours to enjoy.

i know i praised Nebular @ the beginning in the middle and now @ the end
keniffca is offline  
Old 06/13/2009, 15:39   #6
 
elite*gold: 0
Join Date: Oct 2007
Posts: 196
Received Thanks: 188
Nebular reversed the game's crc function and wrote his own function in C which loads files from the harddrive into memory and calculates their crc.
Then he implemented his function into a new memory section (I think it is called .epvp) and changed some pointers which point at the original crc function. (Note; use IDA to see the pointer pointing to the function the new memory section)
Since he changed the pointer which pointed to the original CRC function to point to his own function, his function gets all parameters, the normal crc function would get and the function's return value is also obtained by a function which sends it to the server.

About the new no-crc; I have no idea, never looked into it...

p.s. 2Moons is using UPX atm, just have a look at the memory sections.
xhugox is offline  
Thanks
1 User
Reply


Similar Threads Similar Threads
SeaEmu ASProtect help!
08/28/2010 - SRO Private Server - 4 Replies
Hi! I've a problem with SeaEmu. When i open it for the first time, it's ok. But when I try to open on the second time, don't open but it appear on the task manager (ctrl+alt+supr). Sometimes, it's show me ERROR saying: UNREGISTERED VERSION This program has been protected by unregistered version of ASProtect Software Protection System IT'S NOT LICENSED FOR DISTRIBUTION! This message will not appear on programs protected by a registered version of ASProtect. I hope you'll can help...
SIR BRIAN E2 UNG ASprotect v3.
01/13/2010 - Grand Chase - 2 Replies
sir brian e2 ba ung Asprotect v3 na hnahanap nyo? part1: http://www.megaupload.com/?d=XKVSYLI2 part2: http://www.megaupload.com/?d=1YO1ENQZ part3: http://www.megaupload.com/?d=85UZPVQ1 part4: http://www.megaupload.com/?d=14M7KTAJ
(Testing) ASProtect Extrator
01/12/2010 - Grand Chase Hacks, Bots, Cheats & Exploits - 9 Replies
Look at this I've Extract Main.exe Here are the info 23:48:43 - open main.exe.. 23:48:46 - starting c:\program files\level up games\grand chase\main.exe.. Victim ImageBase - 00400000 Victim EntryPoint - 00001000 23:48:54 - unhandled break at 01a91b85.. 23:49:26 - asprotect detected.. 23:49:26 - loading modules.. 23:49:27 - hooking modules..
ASProtect encrypted .dll unpacking for private srv
07/06/2006 - Lineage 2 - 0 Replies
More and more private server admins are starting to use ASProtect for packing network.dll and engine.dll files, so it's impossible to use OOG l2walker for these servers unless we'll find some way to unpack Asprotected files. PEtools shows that BeyondC4 private server's engine.dll is asprotect (aspr). Here is the link of BeyondC4 private server engine.dll, I need to find protocol version/token: http://rapidshare.de/files/25095982/Engine...rotec t.rar.html Please anyone help, if you know...



All times are GMT +1. The time now is 03:50.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.