DBK32.sys and DBK32.dll

Find a Bug? Have a Problem? Like to Suggest a Feature? Do it Here

Moderators: g3nuin3, SpeedWing, WhiteHat, mezzo

DBK32.sys and DBK32.dll

Postby Faulrn » Tue Jul 18, 2006 1:06 pm

These 2 files (taken from cheatengine) are detected by most games. Not just nProtected games. CE is one of the largest Memory editors to date and it is only natural that it is targetted first.

Modifying or totally replacing them with your own would extend its life by quite a bit, in terms of being undetected by most games.
I'm a lama :)
Faulrn
I Have A Few Questions
 
Posts: 7
Joined: Tue Jul 18, 2006 12:20 pm
Location: Melbourne, AUS

Postby L. Spiro » Tue Jul 18, 2006 1:37 pm

In the cases where these are detected, they can simply be removed completely.

As I did not want to depend on these files for my own work, I only use them in two minor cases:
  • Stealth Mode, which doesn’t fully work.
  • Removing debugging protections when attaching the debugger.

If you never need these two features, just remove those files.

Soon my own kernel-mode driver will replace these files and being as unknown as my software is (despite the fact that I have tons of contacts directly inside the industry) it will go back into being undetected.

My driver will also not be detectable by name, as it will have a new name each time you run Memory Hacking Software.


L. Spiro
User avatar
L. Spiro
L. Spiro
 
Posts: 3129
Joined: Mon Jul 17, 2006 10:14 pm
Location: Tokyo, Japan

Postby Faulrn » Tue Jul 18, 2006 1:45 pm

Hrmmm. So if i remove those 2 files would i be able to do a pointer search? because i would like to see what access some address'.
I'm a lama :)
Faulrn
I Have A Few Questions
 
Posts: 7
Joined: Tue Jul 18, 2006 12:20 pm
Location: Melbourne, AUS

Postby L. Spiro » Tue Jul 18, 2006 1:50 pm

Removing those files does not cripple any other functionality aside from the ones above.
If your game is not allowing you to attach because of those files, you will have to remove them and then try again, but there is no guarantee that the game will have nothing else to use for protection.
In other words, after removing those files, it may then find some other reason to prevent you from attaching.

It’s up to the game.


L. Spiro
User avatar
L. Spiro
L. Spiro
 
Posts: 3129
Joined: Mon Jul 17, 2006 10:14 pm
Location: Tokyo, Japan

Postby IcameIsawIcheated » Sat Jul 22, 2006 5:32 am

Everytime I opened my game process, I would get the erro that that .dll couldn't be loaded. I have deleted them both now. Don't need any of those features for the game I'm hacking at the moment.
IcameIsawIcheated
Hackleberry Fin
 
Posts: 21
Joined: Thu Jul 20, 2006 6:16 am

Postby L. Spiro » Sun Jul 23, 2006 4:07 pm

3.0.0.8 has those files removed and replaced with my own kernel-mode driver, however with less functionality for the moment.


L. Spiro
User avatar
L. Spiro
L. Spiro
 
Posts: 3129
Joined: Mon Jul 17, 2006 10:14 pm
Location: Tokyo, Japan


Return to Bugs/Problems/Suggestions

Who is online

Users browsing this forum: No registered users and 0 guests