Helgame.exe OEP

Discussion on Helbreath Hacks. New ones Released. and how to work them.
Post Reply
jingjangjoe
just visiting
Posts: 8
Joined: Fri May 21, 2004 2:52 pm

Post by jingjangjoe »

Hi anyone knows what is the OEP of helgame 3.62?
if read few tutorials on unpacking ASprotect but i just cant seem to find the OEP. Kinda blur...

Any help would be great
choketokill
just visiting
Posts: 2
Joined: Sun May 02, 2004 9:29 pm

Post by choketokill »

thats becuase its not packed with that any more thay used Armadillo
KLKS
Loyal fan
Posts: 218
Joined: Sun Feb 22, 2004 2:32 pm

Post by KLKS »

i wish i could bitch slap choketokill for being such a dumbass. hb still uses aspr but its a new strain

i looked into the client with a few friends and found it uses multiple SEH tricks to do stuff, and to find the OEP is easy, for all u non technical ppl, u can stop reading and continue with other shit

get one hb client (3.51 pref) and see its OEP, now loadup 3.62 and go trough aspr, pass the stolen bytes, and when u reach ingame, dump the executable, load the dumped executable up in IDA and load 3.51 in IDA, now u gotta remember where ingame ASPR resumed the code so u can do a code compre, simentech dont change their base code so the initial startup code will be the same, now look for a sequence of code in the function (dumped code) and look for the same in 3.51, from there slowly backtrace till u find OEP, when u find it, it wont be 00's like aspr usually does, it will be filled with some messed up code.

good luck :)
jingjangjoe
just visiting
Posts: 8
Joined: Fri May 21, 2004 2:52 pm

Post by jingjangjoe »

hahah thanks dude...ill give it a wack =)
jingjangjoe
just visiting
Posts: 8
Joined: Fri May 21, 2004 2:52 pm

Post by jingjangjoe »

i checked out helgame.exe V 3.51
correct me if im wrong..is the oep for 3.51 = 004A88D7 ?
powermage
Loyal fan
Posts: 252
Joined: Fri Apr 23, 2004 6:23 am

Post by powermage »

noour not wrong if i am correct
___________________________________________________<br>HB CELESTIAL 4 EVER<br>HBNOL TO DIE<br>DAM I HABE BEEN QUACKED BY Nprotect
KLKS
Loyal fan
Posts: 218
Joined: Sun Feb 22, 2004 2:32 pm

Post by KLKS »

the helgame i have (3.51 has an OEP of 4A8947
powermage
Loyal fan
Posts: 252
Joined: Fri Apr 23, 2004 6:23 am

Post by powermage »

my OEP is 004A88D7
___________________________________________________<br>HB CELESTIAL 4 EVER<br>HBNOL TO DIE<br>DAM I HABE BEEN QUACKED BY Nprotect
jingjangjoe
just visiting
Posts: 8
Joined: Fri May 21, 2004 2:52 pm

Post by jingjangjoe »

I Tried rebuilding it in IMprec....it says that OEP does not match Memory..
powermage
Loyal fan
Posts: 252
Joined: Fri Apr 23, 2004 6:23 am

Post by powermage »

LOL
same here.... anyone know how to matcn it properly??
___________________________________________________<br>HB CELESTIAL 4 EVER<br>HBNOL TO DIE<br>DAM I HABE BEEN QUACKED BY Nprotect
jelly1
noob
Posts: 16
Joined: Wed May 05, 2004 5:01 pm

Post by jelly1 »

u need to search iat manually
jingjangjoe
just visiting
Posts: 8
Joined: Fri May 21, 2004 2:52 pm

Post by jingjangjoe »

so we put iat value instead of OEP value at imprec?
powermage
Loyal fan
Posts: 252
Joined: Fri Apr 23, 2004 6:23 am

Post by powermage »

i tried that
___________________________________________________<br>HB CELESTIAL 4 EVER<br>HBNOL TO DIE<br>DAM I HABE BEEN QUACKED BY Nprotect
jelly1
noob
Posts: 16
Joined: Wed May 05, 2004 5:01 pm

Post by jelly1 »

u need to put oep, iat address and size, all searched manually.
powermage
Loyal fan
Posts: 252
Joined: Fri Apr 23, 2004 6:23 am

Post by powermage »

lol no wonder la
___________________________________________________<br>HB CELESTIAL 4 EVER<br>HBNOL TO DIE<br>DAM I HABE BEEN QUACKED BY Nprotect
Post Reply