Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Dekaron
You last visited: Today at 23:05

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Why everyone is unable to FULLY unpack the bot without error.

Discussion on Why everyone is unable to FULLY unpack the bot without error. within the Dekaron forum part of the MMORPGs category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Aug 2007
Posts: 93
Received Thanks: 23
Why everyone is unable to FULLY unpack the bot without error.

Update:
looks like the EIP might be in the actual exe we run to launch the the bot. after entry it calls to the gamemon.des. this isnt a problem in itself, BUT becomes a huge problem when trying to unpack it.
the launcher program doesnt use Themdia


running SEVERAL unpackers, debuggers, and dissassemblers on this **** bot I have found something.
Themdia is not the problem at all. that actually should be able to be stripped out fairly easy.
anyone thats run UnThemida on the bot has probably found that you get an OEP error and UnThemida terminates.

What I have tried:

i have run a couple OEP finders as well as tried to force OEP in the unpacking.
i have found a varience of OEP depending on which find method I was using. all the OEP end up having various offset errors. (most at FFFF 038FB039)
in the version I did unpack (but did not unhook anything) that address comes up with "FFFF ??? Unknown Command" every time.

What I have Found:
every working solution is found by trying to repro the problem.
I was able to figure out WHY this is a problem, but I do not know how to get around it without manually unpacking with a MUP (i tried but I am unable to locate the ACTUAL entry point for OEP)

problem with this **** bot is that the OEP is outside of the PE headers. that is why any of our unpacking utilities are having problems, or giving errors.

if anyone can find me the EP for OEP, i can manually unpack it and unhook all the needless **** in it.
Im PRETTY sure the entry point is located in the "launcher" program.
Fugltlve is offline  
Old 09/27/2007, 20:58   #2
 
elite*gold: 0
Join Date: Sep 2007
Posts: 8
Received Thanks: 0
heh .... we unpack it . isn't it ? Yes Ep is in the launch program use Artmoney and u can see it
lordpipas is offline  
Old 09/27/2007, 21:20   #3
 
elite*gold: 0
Join Date: Aug 2007
Posts: 93
Received Thanks: 23
Quote:
Originally Posted by lordpipas View Post
heh .... we unpack it . isn't it ? Yes Ep is in the launch program use Artmoney and u can see it
yep. i got the EIP address for OEP, its just that i havent found a utility that will allow me to unpack gamemon.des correctly with the EIP outside of the PE header.
Fugltlve is offline  
Old 09/28/2007, 08:05   #4
 
elite*gold: 0
Join Date: Sep 2007
Posts: 8
Received Thanks: 0
so ..what the problem ?
lordpipas is offline  
Old 09/28/2007, 16:20   #5
 
elite*gold: 0
Join Date: Aug 2007
Posts: 93
Received Thanks: 23
Quote:
Originally Posted by lordpipas View Post
so ..what the problem ?
i havent found a utility that will allow me to unpack gamemon.des correctly with the EIP outside of the PE header, and im not sure how to remove themida by using MUP
Fugltlve is offline  
Old 09/28/2007, 16:55   #6
 
elite*gold: 0
Join Date: Sep 2007
Posts: 8
Received Thanks: 0
wm qUp ? its work ....why not ?
lordpipas is offline  
Old 09/28/2007, 17:53   #7
 
elite*gold: 0
Join Date: Aug 2007
Posts: 93
Received Thanks: 23
Quote:
Originally Posted by lordpipas View Post
wm qUp ? its work ....why not ?
i can unpack it just fine with qunpack. BUT you cant unhook anything and you get an error that the OEP is outside the PE header. so it unpacks incorrectly as the EP isnt in the unpack.
I researched this a little bit and found that if the OEP is ouside of the PE header you need to unpack the program manually via MUP in order to unpack with the entry point.
i can unpack manually (although id rather not cause its a horrid process) but i dont know how to strip out Themida before i unpack it
Fugltlve is offline  
Old 09/28/2007, 20:13   #8
 
elite*gold: 0
Join Date: Sep 2007
Posts: 8
Received Thanks: 0
em....GameMons insnt .exe file its source file ... and nothing more ... so u dont must have EP ....
lordpipas is offline  
Old 09/28/2007, 20:27   #9
 
elite*gold: 0
Join Date: Aug 2007
Posts: 93
Received Thanks: 23
Quote:
Originally Posted by lordpipas View Post
em....GameMons insnt .exe file its source file ... and nothing more ... so u dont must have EP ....
wont run unpacked without the EP for some reason. if i unpack with qunp, not unhook anything, the unpack file size is massive (56000k) compared to the packed 2000k. if i unhook everything as it should be, unpacked size is 2004k but wont initialize or test. just gives me the OEP error
Fugltlve is offline  
Old 09/28/2007, 20:57   #10
 
elite*gold: 0
Join Date: May 2006
Posts: 73
Received Thanks: 8
its normal that themida packs file to a file size which is hundretfold so largly like the normal file
luckyjol is offline  
Old 09/28/2007, 22:28   #11
 
elite*gold: 0
Join Date: Aug 2007
Posts: 93
Received Thanks: 23
Quote:
Originally Posted by luckyjol View Post
its normal that themida packs file to a file size which is hundretfold so largly like the normal file
ok. so the original file the at 56000k with everything still hooked can be used?
Fugltlve is offline  
Old 09/28/2007, 22:33   #12
 
elite*gold: 0
Join Date: May 2006
Posts: 73
Received Thanks: 8
i am not sure i have no oep to test it but i read it in another forum from a guy called "sd333221" he is also registered to epvp
luckyjol is offline  
Old 09/29/2007, 10:11   #13
 
elite*gold: 0
Join Date: Sep 2007
Posts: 8
Received Thanks: 0
yes it can be
lordpipas is offline  
Old 09/29/2007, 20:37   #14
 
elite*gold: 0
Join Date: Aug 2007
Posts: 93
Received Thanks: 23
Quote:
Originally Posted by lordpipas View Post
yes it can be
thanks lord. i can start working on it again.

on that note. found the 3 call stacks that 1) request auth 2) recieve auth 3) deny on failed auth

looking for a way to put a bypass in. gonna try playing around with adding a EIP after the call stacks and see what happens
Fugltlve is offline  
Old 09/29/2007, 20:55   #15
 
elite*gold: 0
Join Date: Sep 2007
Posts: 8
Received Thanks: 0
Crashing may be i doing something wrong ....
lordpipas is offline  
Reply


Similar Threads Similar Threads
CD Key Unable to connect
05/05/2010 - Diablo 2 - 5 Replies
Hab mir gestern CDKeys von 'nem Online-Shop geholt leider scheinen nur 4 von den 6 zu funktionieren und zwar kommt bei den zwei nicht funktionierenden Keys die Meldung "Unable to Connect - The CD Key you used to install this application was intended for another product. Please reinstall this application using the correct cd key.". Ich hab die beiden Keys schon als Classic identifiziert (u.a. weil battlenet.eu das sagt und weil die alle LoD Keys funktionieren und eben ein Classic Key). Ich...
unable to get addresses
07/31/2009 - Grand Chase - 6 Replies
im having problems finding addresses for any of the grand chase hacks when i try to use the to search for the one hit KO only 3 adresses appear and 2 of them have no values, http://img24.imageshack.us/img24/5990/ihitkoerror .th.jpg if i try to enter the address from 1 hit ko it gives me '??' as the value. when i try to upload the CT from zid engine it tells me "this table was made with a newer version of moonlight engine and isn't supported. Download the latest version from the...
help me ...unable to login...
04/25/2007 - Silkroad Online - 1 Replies
have a little problem... when i want to start bot:Unable to login,please check your username and password!?!?! what should i do? plz help me thx :D <hr>Append on Apr 24 2007, 19:02<hr> sry i dont put the dll on :P sry for the question:D but now when i open sro it close in 1second!?
COTOBO Error "Unable to inject...."
07/26/2006 - Conquer Online 2 - 1 Replies
PLEASE กกกกกกกกก FIX the error "Unable to inject dll..." do a COTOBO for win98 users... PLEASE กกกกกกก
POS-Unable to Zone
02/12/2006 - Final Fantasy XI - 6 Replies
I tried closing POS.exe and it still dosn't work... I know it can't be fleehack because this time I wasn't using it and it didn't work. :? I'm using english version of POS please help! text2schild.php?smilienummer=1&text=10 cookies for anyone who can solve this!' border='0' alt='10 cookies for anyone who can solve this!' />



All times are GMT +1. The time now is 23:06.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.