| View previous topic :: View next topic | 
	
	
		| Author | Message | 
	
		| Dark Byte Site Admin
 
  Reputation: 470 
 Joined: 09 May 2003
 Posts: 25807
 Location: The netherlands
 
 | 
			
				|  Posted: Mon Jul 19, 2004 6:23 am    Post subject: |   |  
				| 
 |  
				| Yes, that's him |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| emperor Master Cheater
 
 ![]() Reputation: 0 
 Joined: 16 May 2003
 Posts: 470
 Location: Germany
 
 | 
			
				|  Posted: Mon Jul 19, 2004 6:25 am    Post subject: |   |  
				| 
 |  
				| Good.Well I attached it to an email, rar, highest compression Level. And btw...why did you send me the Beta..? |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| Dark Byte Site Admin
 
  Reputation: 470 
 Joined: 09 May 2003
 Posts: 25807
 Location: The netherlands
 
 | 
			
				|  Posted: Mon Jul 19, 2004 6:30 am    Post subject: |   |  
				| 
 |  
				| I thought you might want to check it out too.  (e.g: with nprotect and the network version) |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| emperor Master Cheater
 
 ![]() Reputation: 0 
 Joined: 16 May 2003
 Posts: 470
 Location: Germany
 
 | 
			
				|  Posted: Mon Jul 19, 2004 6:32 am    Post subject: |   |  
				| 
 |  
				| This does not bypass nProtect. I tried it on both my 32Bit and 64Bit Windows OS. I selected to use CE kernel routines and I selected the stealth function but it was still no use. |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| Dark Byte Site Admin
 
  Reputation: 470 
 Joined: 09 May 2003
 Posts: 25807
 Location: The netherlands
 
 | 
			
				|  Posted: Mon Jul 19, 2004 6:55 am    Post subject: |   |  
				| 
 |  
				| It could be that the driver failed to load. The easiest way to check is by selecting the cheat engine process ,use the read/write processmemory kernel routines and add add address C0000000 to the list.
 If that address can be read (so no ??) the driver does it's work else there was a problem with loading the driver.
 
 (Best to only try this on the 32-bit version)
 
 Edit: Actually, selecting a process with the kernel mode routines on can not ever fail! Unless it is reprogrammed (wich is possible because I used the same name, but that's not really required anymore for ce, and i've changed it now)
 If the normal OpenProcess method fails it creates a random value (thats never 0) posing as processhandle. (and CE will only say that it failed to open if it gets a 0 as processhandle)
 |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| emperor Master Cheater
 
 ![]() Reputation: 0 
 Joined: 16 May 2003
 Posts: 470
 Location: Germany
 
 | 
			
				|  Posted: Mon Jul 19, 2004 8:33 am    Post subject: |   |  
				| 
 |  
				| Server edition gives me following error message: Openprocess failed:5
 And the client's screenshot is attached. The server runs on a 32bit win xp sp2 (on the 64bit vers the C0000000 returned ?? value and therefore it doens't work there correctly). On the 32bit the C0000000 works but still i cannot open the process..
 The screenshot was taken when after I chose the CE server and added C0000000 to the list and then tried to open the game's process.
 |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| Dark Byte Site Admin
 
  Reputation: 470 
 Joined: 09 May 2003
 Posts: 25807
 Location: The netherlands
 
 | 
			
				|  Posted: Mon Jul 19, 2004 8:44 am    Post subject: |   |  
				| 
 |  
				| My bet is that this is caused because the dbk32.dll exports the functions with the EXACT name as they are exported in the kernel32.dll 
 I'm pretty sure, because my own OpenProcess function doesn't give a error 5 (5=access denied)
 |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| emperor Master Cheater
 
 ![]() Reputation: 0 
 Joined: 16 May 2003
 Posts: 470
 Location: Germany
 
 | 
			
				|  Posted: Mon Jul 19, 2004 8:50 am    Post subject: |   |  
				| 
 |  
				| Translated into normal English: "All we have to do is wait" ...correct? |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| Dark Byte Site Admin
 
  Reputation: 470 
 Joined: 09 May 2003
 Posts: 25807
 Location: The netherlands
 
 | 
			
				|  Posted: Mon Jul 19, 2004 8:59 am    Post subject: |   |  
				| 
 |  
				| Other people yes, you can just redownload the file again (link was in the first e-mail I sent you) 
 i've renamed the function names, hope this one works
 |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| emperor Master Cheater
 
 ![]() Reputation: 0 
 Joined: 16 May 2003
 Posts: 470
 Location: Germany
 
 | 
			
				|  Posted: Mon Jul 19, 2004 9:39 am    Post subject: |   |  
				| 
 |  
				| Nice indeed, selecting the process works. Just that somehow after doing an unknown initial value scan the next scan gives an error. Strange enough, if the next scan is done within seconds after the first scan it sometimes seems to work...just that i cannot get that fast to another computer and back. Well also another possible source for problems would be that I used a client on wine. Therefore in order to do further testing I'll go borrow a notebook. Really nice job bypassing nProtect btw...thank you. edit:Lol...if i connect computer 1<->notebook it's obvious that i have no online connection so i cannot try it LOL! Guess i am screwed
     edit: After getting another network card I can say following: Dark Byte is greatest and it's yet another proof that Cheat Engine is the greatest Cheating Tool on this planet. I don't bevieve a compareable powerful tool exists...Thank you Dark Byte you are greatest.
 |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| mrchuseau Newbie cheater
 
 ![]() Reputation: 0 
 Joined: 15 May 2004
 Posts: 23
 
 
 | 
			
				|  Posted: Wed Jul 21, 2004 9:50 am    Post subject: Where have ce gone ? |   |  
				| 
 |  
				| where is the beta ? i have tried your links but no one take me to the beta
 and i ve used a web scaning tool but i only find ce3beta
 where have you hided the ce 4.4 beta ?
 or are you preparing to launch the complete ce 4.4 ?
 |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| emperor Master Cheater
 
 ![]() Reputation: 0 
 Joined: 16 May 2003
 Posts: 470
 Location: Germany
 
 | 
			
				|  Posted: Thu Jul 22, 2004 5:25 am    Post subject: Re: Where have ce gone ? |   |  
				| 
 |  
				|  	  | mrchuseau wrote: |  	  | where is the beta ? i have tried your links but no one take me to the beta
 and i ve used a web scaning tool but i only find ce3beta
 where have you hided the ce 4.4 beta ?
 or are you preparing to launch the complete ce 4.4 ?
 | 
 You could've hardly found it as Dark Byte said that the link was in an E-Mail he sent to me.
 |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| the_brilliance Advanced Cheater
 
 ![]() Reputation: 0 
 Joined: 15 Nov 2003
 Posts: 82
 
 
 | 
			
				|  Posted: Thu Jul 22, 2004 6:23 am    Post subject: |   |  
				| 
 |  
				| God, you people are funny. 
 Im gone for a couple of days and all this happens.
 
 By the way Xeus, Nice idea for hex editing CE.
 |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| stomperz Expert Cheater
 
 ![]() Reputation: 0 
 Joined: 18 Jul 2004
 Posts: 193
 Location: USA Chicago
 
 | 
			
				|  Posted: Thu Jul 22, 2004 4:35 pm    Post subject: |   |  
				| 
 |  
				| Hello All... First Post Here! 
 I'm been working on Darkeden uses nprotect also. ( Mu is too many leeching idiots )
 
 I use CE and don't have any problems, ( editing money, health, etc ... only server side though
  )the only problem is when I try to attach the debugger it crashes the game. 
 The IDA disassembly is tough to trace through but I'm working on it.
 
 Anyone else able to attached the debugger without detection?
 
 BTW: I've only donated to programmers a few time in the last 20 yrs but this program deserves it.
 My hat is off to you on an excellent job!!
 
 Dark Byte check your Paypal.
   |  | 
	
		| Back to top |  | 
	
		|  | 
	
		| emperor Master Cheater
 
 ![]() Reputation: 0 
 Joined: 16 May 2003
 Posts: 470
 Location: Germany
 
 | 
			
				|  Posted: Sat Jul 24, 2004 11:55 am    Post subject: |   |  
				| 
 |  
				| Maybe somebody knows...is it possible to use the memory editing of CE to just somehow kill nProtect while it's running? Without ramdomly editing its ram so that it ends up with a "produced an error and has to be closed" message. Ideas would be nice..thanks. |  | 
	
		| Back to top |  | 
	
		|  | 
	
		|  |