Important information: this site is currently scheduled to go offline indefinitely by end of the year.

new AION .pak file format.need help!

The Original Forum. Game archives, full of resources. How to open them? Get help here.
Post Reply
titanic
beginner
Posts: 35
Joined: Wed Nov 29, 2006 9:58 pm

new AION .pak file format.need help!

Post by titanic »

The contents of this post was deleted because of possible forum rules violation.
Rheini
Moderator
Posts: 652
Joined: Wed Oct 18, 2006 9:48 pm
Location: Germany
Has thanked: 19 times
Been thanked: 46 times
Contact:

Post by Rheini »

Could you upload the game's exe and dll files?
User avatar
john_doe
VIP member
VIP member
Posts: 80
Joined: Sat Oct 21, 2006 2:25 pm
Been thanked: 1 time

Post by john_doe »

Yes, that would be good.
I checked, and the bytes used to XOR against are different for each file. I guess it's calculated via one or more values from the file header.
titanic
beginner
Posts: 35
Joined: Wed Nov 29, 2006 9:58 pm

Post by titanic »

The contents of this post was deleted because of possible forum rules violation.
Rheini
Moderator
Posts: 652
Joined: Wed Oct 18, 2006 9:48 pm
Location: Germany
Has thanked: 19 times
Been thanked: 46 times
Contact:

Post by Rheini »

Fuck. Koreans seem to like Themida ^^
Ragnarök also used it I think.
Rheini
Moderator
Posts: 652
Joined: Wed Oct 18, 2006 9:48 pm
Location: Germany
Has thanked: 19 times
Been thanked: 46 times
Contact:

Post by Rheini »

Unfortunately UnThemida can't unpack the dll :(
Mark
n00b
Posts: 16
Joined: Sat Oct 27, 2007 5:57 am
Been thanked: 1 time

Post by Mark »

Oh, hey, someone made a thread for this before I did. Awesome! Any files that you guys need that you don't have?
Rheini
Moderator
Posts: 652
Joined: Wed Oct 18, 2006 9:48 pm
Location: Germany
Has thanked: 19 times
Been thanked: 46 times
Contact:

Post by Rheini »

No we'd need someone that is able to unpack Themida.
GameZelda
advanced
Posts: 61
Joined: Wed Nov 14, 2007 5:56 pm
Been thanked: 29 times

Post by GameZelda »

john_doe wrote:Yes, that would be good.
I checked, and the bytes used to XOR against are different for each file. I guess it's calculated via one or more values from the file header.
EDIT: Solved :oops:
titanic
beginner
Posts: 35
Joined: Wed Nov 29, 2006 9:58 pm

Post by titanic »

GameZelda wrote:
john_doe wrote:Yes, that would be good.
I checked, and the bytes used to XOR against are different for each file. I guess it's calculated via one or more values from the file header.
EDIT: Solved :oops:

whats mean?
Mark
n00b
Posts: 16
Joined: Sat Oct 27, 2007 5:57 am
Been thanked: 1 time

Post by Mark »

It means this thread gets bumped.
Mark
n00b
Posts: 16
Joined: Sat Oct 27, 2007 5:57 am
Been thanked: 1 time

Post by Mark »

Who should I bribe around here to find a solution to us AION fans little predicament? :wink:
Rheini
Moderator
Posts: 652
Joined: Wed Oct 18, 2006 9:48 pm
Location: Germany
Has thanked: 19 times
Been thanked: 46 times
Contact:

Post by Rheini »

As I already said the exe seems to be protected by themida. We need an unpacked exe to figure out the encryption algorithm.
Hiam
ultra-n00b
Posts: 7
Joined: Sat Dec 08, 2007 3:56 pm

No

Post by Hiam »

What you need is not a unpacked exe. What you need is a unpacked CrySystem.dll. Also, you won't need a fully working one, what you need is to be able to read the code section. And that is pretty easy, since Themida anti codes are pretty simple.

http://geekserv.hornycat.org/~dick/CrySystem_dumped.rar

There you go, you will have all strings, all code. Just offsets is wrong.
Im myself investigating whats been happening to the first 32bytes of the compressedData. And i can say its not a simple xor, shr, shl method.
It's a dynamic value that's been tampered with more than that.

I'll be cross checking with the orginal CrySystem to see what they've added.

Many kisses
Rheini
Moderator
Posts: 652
Joined: Wed Oct 18, 2006 9:48 pm
Location: Germany
Has thanked: 19 times
Been thanked: 46 times
Contact:

Post by Rheini »

Pretty simple? Doesn't this old version of Themida/Xtreme Protector use an aggressive ring0 driver?
And what about some tools identifying Xtreme Protector (though that one section is named Themida)?
Are both protections used?
Post Reply