Crack main 1.04A+

Joined
Aug 24, 2005
Messages
417
Reaction score
266
Programs: Olly and Hex Editor



1 - In Olly, look for mu.exe and then find the offsets below:

Code:
00602757    /75 55              jnz short 006027AE                             ; main.006027AE
00602759    |68 ECFF7F00        push 7FFFEC
0060275E    |68 10E4F707        push 7F7E410
00602763    |E8 89DE0B00        call 006C05F1                                  ; main.006C05F1
00602768    |83C4 08            add esp,8
0060276B    |68 FCF97F00        push 7FF9FC                                    ; ASCII "mu.exe"
00602770    |8D95 14FEFFFF      lea edx,dword ptr ss:[ebp-1EC]
00602776    |52                 push edx                                       ; ntdll.KiFastSystemCallRet
The first offset, replacing JNZ by JMP. This will disable the Mu.exe.

2 - Then look for "config.ini read error" and then find the offsets below:

Code:
00602A46     68 A4008000        push 8000A4                                    ; ASCII "config.ini read error",CR,LF
00602A4B     68 10E4F707        push 7F7E410
00602A50     E8 9CDB0B00        call 006C05F1                                  ; main.006C05F1
00602A55     83C4 08            add esp,8
00602A58     C785 3CF2FFFF 0000>mov dword ptr ss:[ebp-DC4],0
00602A62     8D8D 40FFFFFF      lea ecx,dword ptr ss:[ebp-C0]
00602A68     E8 D3140000        call 00603F40                                  ; main.00603F40
00602A6D     8B85 3CF2FFFF      mov eax,dword ptr ss:[ebp-DC4]
00602A73     E9 C3130000        jmp 00603E3B                                   ; main.00603E3B
00602A78     6A 01              push 1
00602A7A     E8 1BB51900        call 0079DF9A                                  ; main.0079DF9A
00602A7F     83C4 04            add esp,4
00602A82     8985 34F2FFFF      mov dword ptr ss:[ebp-DCC],eax
00602A88     83BD 34F2FFFF 00   cmp dword ptr ss:[ebp-DCC],0
00602A8F     74 19              je short 00602AAA                              ; main.00602AAA
00602A91     A1 F8F97F00        mov eax,dword ptr ds:[7FF9F8]
00602A96     50                 push eax
00602A97     8B8D 34F2FFFF      mov ecx,dword ptr ss:[ebp-DCC]
The first offset, replacing JE by JMP. This will disable the GuameGuard.

3 - Look for "gg init error":

Code:
00602AD8    /0F85 89000000      jnz 00602B67                                   ; main.00602B67
00602ADE    |68 BC008000        push 8000BC                                    ; ASCII "gg init error",CR,LF
00602AE3    |68 10E4F707        push 7F7E410
00602AE8    |E8 04DB0B00        call 006C05F1                                  ; main.006C05F1
00602AED    |83C4 08            add esp,8
00602AF0    |E8 AFCFFFFF        call 005FFAA4                                  ; main.005FFAA4
00602AF5    |833D 28E8F707 00   cmp dword ptr ds:[7F7E828],0
The first offset, replacing JNZ by JMP. This will disable the GuameGuard.

4 - Look for ResourceGuard Error:

Code:
0062E2D6    /74 47              je short 0062E31F                              ; main.0062E31F
0062E2D8    |B9 E022F807        mov ecx,7F822E0
0062E2DD    |E8 2E110300        call 0065F410                                  ; main.0065F410
0062E2E2    |8D9424 8C090000    lea edx,dword ptr ss:[esp+98C]
0062E2E9    |52                 push edx                                       ; ntdll.KiFastSystemCallRet
0062E2EA    |68 64108000        push 801064                                    ; ASCII "> ResourceGuard Error!!(%s)",CR,LF
0062E2EF    |68 10E4F707        push 7F7E410
The first offset, replacing JE by JMP. This will disable the ResourceGuard.
5 - Save all changes.

6 - Open the main.exe with the Hex Editor. Find connect.muonline.co.kr and change by your IP server.

7 - Save and make copies of the file renaming to main.exe.

Vers
 
Back