Page 1 of 6 123 ... LastLast
Results 1 to 15 of 87
  1. #1
    AeroMan's Avatar
    Join Date
    Dec 2008
    Gender
    male
    Location
    Hell
    Posts
    3,294
    Reputation
    189
    Thanks
    3,049
    My Mood
    Busy

    Post Dumping WarRock.exe

    Hello guys,
    i have noticed that many ppl have been looking for WarRock.exe dumped.
    Now here is a good tut you guys may use.

    What do i need?
    WarRock
    Kernel Detective 1.3.1 (download unther)


    What does Kernel Detective 1.3.1 does?

    Kernel Detective is a free tool that help you detect, analyze, manually modify and fix some Windows NT kernel modifications. Kernel Detective gives you the access to the kernel directly so it's not oriented for newbies. Changing essential kernel-mode objects without enough knowledge will lead you to only one result ... BSoD !

    Supported NT versions :
    XP/Vista


    Kernel Detective gives you the ability to :
    1- Detect Hidden Processes.
    3- Detect Hidden Threads.
    2- Detect Hidden DLLs.
    3- Detect Hidden Handles.
    4- Detect Hidden Driver.
    5- Detect Hooked SSDT.
    6- Detect Hooked Shadow SSDT.
    7- Detect Hooked IDT.
    8- Detect Kernel-mode code modifications and hooks.
    9- Disassemble (Read/Write) Kernel-mode/User-mode memory.
    10- Monitor debug output on your system.


    Enumerate running processes and print important values like Process Id, Parent Process Id, ImageBase, EntryPoint, VirtualSize, PEB block address and EPROCESS block address. Special undocumented detection algorithms were implemented to detect hidden processes.

    Detect hidden and suspicious threads in system and allow user to forcely terminate them .

    Enumerate a specific running process Dynamic-Link Libraries and show every Dll ImageBase, EntryPoint, Size and Path. You can also inject or free specific module.

    Enumerate a specific running process opened handles, show every handle's object name and address and give you the ability to close the handle.

    Enumerate loaded kernel-mode drivers and show every driver ImageBase, EntryPoint, Size, Name and Path. Undocumented detection algorithms were implemented to detect hidden drivers.

    Scan the system service table (SSDT) and show every service function address and the real function address, detection algorithm improved to bypass KeServiceDescriptorTable EAT/IAT hooks.You can restore single service function address or restore the whole table.

    Scan the shadow system service table (Shadow SSDT) and show every shadow service function address and the real function address. You can restore single shadow service function address or restore the whole table

    Scan the interrupts table (IDT) and show every interrupt handler offset, selector, type, Attributes and real handler offset. This is applied to every processor in a multi-processors machines.

    Scan the important system kernel modules, detect the modifications in it's body and analyze it. For now it can detect and restore inline code modifications, EAT and IAT hooks. I'm looking for more other types of hooks next releases of Kernel Detective.

    A nice disassembler rely on OllyDbg disasm engine, thanks Oleh Yuschuk for publishing your nice disasm engine .With it you can disassemble, assemble and hex edit virtual memory of a specific process or even the kernel space memory. Kernel Detective use it's own Read/Write routines from kernel-mode and doesn't rely on any windows API. That make Kernel Detective able to R/W processes VM even if NtReadProcessMemory/NtWriteProcessMemory is hooked, also bypass the hooks on other kernel-mode important routines like KeStackAttachProcess and KeAttachProcess.

    Show the messages sent by drivers to the kernel debugger just like Dbgview by Mark Russinovich. It's doing this by hooking interrupt 0x2d wich is responsible for outputing debug messages. Hooking interrupts may cause problems on some machines so DebugView is turned off by default, to turn it on you must run Kernel Detective with "-debugv" parameter.

    How do i use this?
    1/ Open WarRock.exe
    2/ When WarRock.exe is finished loading, waiting to login, open Kernel Detective 1.3.1
    You should now have a screen like this:

    3/ Then click on the process tab (screen signed above)
    4/ Then look for WarRock.exe

    5/ Dump that to a file.

    6/ give it a name + .exe

    7/ Your done! Ready to reverse!
    8/ Thank me

    Code:
    VirusScans:
    VirusTotal
    VirScan
    I am not responsible for any problems,further actions with G1!
    This can lead to instand ban!


    Releated info:
    Program is legal, can be used to dump other programs to.
    Dumping WarRock.exe & Other games is illegal.
    Do you take the risk? (i dont)
    Its up to you



    Virusses = Unpackers
    Not really a virus.
    Last edited by AeroMan; 09-01-2010 at 04:42 AM. Reason: Do you care? Don't you fergot somthing?? You fergot to thank me, remember that! i'll keep an eye on you!

  2. The Following 158 Users Say Thank You to AeroMan For This Useful Post:

    αςε.εmόkόι (04-27-2012),6ixth (06-10-2013),aboodymgdob (01-11-2015),adamban1 (07-30-2014),aeaquarii (06-25-2015),AHUNDRED222 (12-27-2013),akosimjcreado (04-20-2013),aLcohoL_95 (07-04-2011),alkeev23 (01-26-2014),andreiiro (05-12-2012),AngerFist69 (05-01-2012),antonio00 (01-11-2013),apezwijn (10-29-2010),armour199915 (08-23-2015),avenues2 (10-22-2013),ayay456 (07-01-2014),baris09kk (05-19-2013),basilkh (06-18-2013),bayot (05-03-2012),blackbird0002 (04-09-2013),breezybutch (12-28-2013),bukachit (01-17-2013),CARUMAL (06-02-2013),centrod123 (01-09-2014),cieloem0 (10-15-2013),colddin25 (08-20-2012),Cvillian (10-23-2010),DaneCoder (06-09-2014),dayammara (12-02-2014),devicer00 (05-02-2012),doggc (07-22-2014),donatelo07 (04-10-2013),Dong'Rickz (05-13-2014),eaglech (07-28-2011),easykill92 (10-01-2011),elmar10 (08-17-2012),enonno (02-09-2016),erikhenri (04-26-2012),Estelle (05-04-2013),exstrike1234 (04-27-2012),fadeel123 (05-09-2014),farah112233 (05-19-2012),GameMakerCode (07-14-2014),Gamer0815 (07-16-2012),Gamer1204 (06-12-2012),gamernuub (09-15-2010),generalokok1 (08-04-2012),geraldelijino (01-31-2013),Ghost304 (02-06-2013),ginging (10-14-2012),hacker21b (03-08-2013),HackkinGCoDer (06-28-2014),hardcorejunk96 (09-24-2010),harukazen (01-12-2012),HeLLBoY42 (08-25-2012),hermes159 (09-08-2011),hijackthis (07-11-2011),hubvduki97 (03-23-2014),Hypnotize_ (04-26-2012),ikonsafi (09-20-2012),ikonsafi2 (01-14-2014),Ilanytjah (05-07-2012),ilubyah143 (12-18-2013),itapa (07-08-2011),iWiizz (08-01-2012),ixibanixi (04-28-2012),jackadams (02-20-2014),jade1821 (10-28-2012),jamharie (03-15-2013),jan24dirk (06-02-2013),jangox (06-10-2011),janspogi (05-02-2014),jbpogz17 (03-23-2013),jericsond (06-27-2011),Jhem (06-30-2014),jhunibanez (12-30-2012),johnix98 (05-04-2012),joshua09joshua09 (02-15-2014),jrzkietoledo (11-28-2014),jweak641 (04-04-2013),kahan (09-13-2011),karlvanz55 (03-22-2013),KenshinCoder (01-15-2013),killallbosz (01-15-2014),killer21killer (11-06-2012),kilzzwar (03-01-2013),lhander (04-05-2014),lhord (09-09-2014),lokill000 (12-27-2013),m.balzak (10-08-2010),mahmod123 (05-03-2012),makaniel1 (04-26-2012),mangker33 (09-01-2012),marnzkie2 (11-23-2012),mcgilbz1 (05-28-2012),MDassasin (10-27-2012),metalsteal (07-20-2012),Mon0ncle (05-16-2014),mrdeath108 (01-28-2013),mrgolchips (01-01-2014),mrinvictus (04-28-2012),nadz0090210 (04-17-2011),navim14 (04-09-2014),nicerob (10-02-2012),NIgga* (02-03-2014),Nightwin (01-07-2014),nunox10 (04-11-2012),OneEyedPyro (03-09-2013),paglinawan (10-21-2014),partzrevey123 (09-25-2014),paul36bone (09-16-2012),Paulamor (06-11-2014),paulcedric (11-16-2013),pockie2 (06-22-2012),pongping88 (04-14-2011),prongzi (02-07-2013),ramiwr00 (07-04-2011),rhalp (07-06-2013),RobinC (11-19-2013),ropsu678 (10-28-2010),ryski123 (09-01-2010),Ryuzaki™ (06-15-2012),sananebak (04-30-2018),sandaljebat (09-16-2012),SCAMP258 (01-31-2013),seho jeong (05-03-2012),seibay (06-29-2012),shenabriol (02-06-2013),shisui07 (01-25-2015),sn1p3rer (02-16-2011),stjoerge (07-01-2014),suarnie (04-12-2014),superhacker321 (04-21-2014),sutil (02-12-2014),SyncMaster (Hacker) (08-01-2014),tammerza (12-08-2013),TheCamels8 (09-01-2010),TheGoodB0y (08-23-2011),themen (05-03-2012),THR34DSM4K3R (01-15-2014),toomtamza (12-12-2015),tracy0091 (05-23-2015),trialsg (11-05-2014),wakamar009 (08-20-2012),warrock kr user (07-16-2012),warrock16 (12-02-2012),warvincent (07-20-2012),xBeo (12-21-2012),xceman (12-03-2011),xchancy21 (11-15-2013),yanirlu (08-16-2014),zerus123 (07-13-2013),ziad alayan (11-17-2012),ziemore (11-24-2014),zLuckrØx (03-01-2013),zoltan09 (09-18-2011),[G]a[M]e[R] (04-29-2012),[N]oSoul (03-14-2013)

  3. #2
    iRobot™'s Avatar
    Join Date
    Jun 2010
    Gender
    male
    Location
    Mpgh.net
    Posts
    2,463
    Reputation
    20
    Thanks
    322
    My Mood
    Twisted
    nice 1 bro welcome back

  4. #3
    Threadstarter
    Upcoming MPGHiean
    AeroMan's Avatar
    Join Date
    Dec 2008
    Gender
    male
    Location
    Hell
    Posts
    3,294
    Reputation
    189
    Thanks
    3,049
    My Mood
    Busy
    Quote Originally Posted by iRobot™ View Post
    nice 1 bro welcome back
    Thanks bro
    Im just back to help ppl, not to code anymore

  5. The Following User Says Thank You to AeroMan For This Useful Post:

    cristiroxx (08-30-2011)

  6. #4
    iRobot™'s Avatar
    Join Date
    Jun 2010
    Gender
    male
    Location
    Mpgh.net
    Posts
    2,463
    Reputation
    20
    Thanks
    322
    My Mood
    Twisted
    ehh well you should start again.. you where respected once and will be respected more

  7. #5
    Krypton1x's Avatar
    Join Date
    May 2010
    Gender
    male
    Location
    Tacoma
    Posts
    13,296
    Reputation
    1184
    Thanks
    1,196
    My Mood
    Brooding
    Moving to source code section and stickying.

  8. #6
    tarvi98's Avatar
    Join Date
    Mar 2010
    Gender
    male
    Location
    sinu kơrval
    Posts
    503
    Reputation
    7
    Thanks
    66
    My Mood
    Angelic
    wow! thats realy good i need to use it(K)
    IM Expert Member !
    !!


    [IMG]https://www.danasof*****m/sig/jaanus.jpg[/IMG]




    Userbars!

    [IMG]https://i297.photobucke*****m/albums/mm202/saad2919/warrock.jpg[/IMG]

    [IMG]https://i656.photobucke*****m/albums/uu288/enforced-scape/Windows_7_Userbar_by_ilioscio.jpg[/IMG]




  9. #7
    iRobot™'s Avatar
    Join Date
    Jun 2010
    Gender
    male
    Location
    Mpgh.net
    Posts
    2,463
    Reputation
    20
    Thanks
    322
    My Mood
    Twisted
    tony its a tutorial.. not a source code

  10. #8
    Krypton1x's Avatar
    Join Date
    May 2010
    Gender
    male
    Location
    Tacoma
    Posts
    13,296
    Reputation
    1184
    Thanks
    1,196
    My Mood
    Brooding
    Quote Originally Posted by iRobot™ View Post
    tony its a tutorial.. not a source code
    Deals with coding, getting codes for WarRock, belongs in the WarRock source code section. Ask Dave.

  11. #9
    TheCamels8's Avatar
    Join Date
    May 2010
    Gender
    male
    Location
    Israel :D
    Posts
    2,945
    Reputation
    174
    Thanks
    1,376
    My Mood
    Cheeky
    Great tutorial dude

  12. #10
    Snape's Avatar
    Join Date
    May 2008
    Gender
    male
    Location
    Hogwarts
    Posts
    13,893
    Reputation
    855
    Thanks
    3,033
    /Approved .



  13. The Following User Says Thank You to Snape For This Useful Post:

    *GuideMan* (05-28-2011)

  14. #11
    ryski123's Avatar
    Join Date
    Mar 2008
    Gender
    male
    Location
    www.mpgh.net
    Posts
    1,772
    Reputation
    81
    Thanks
    634
    My Mood
    Stressed
    Thanked even tho i wont use :P Welcome back bro
    Ryski123 MySize Rhyme

    *AeroMan's Apprentice*
    My Projects :
    Stealth No Menu
    No Menu
    Ryski123 D3D Menu
    Spammer
    Injector


    100 Posts [x]
    500 Posts [x]
    1000 Posts [x]
    2000 Posts [ ]
    Respect List! :
    AeroMan <--- My Brother you Helped me alot
    [MPGH]reaper
    [MPGH]vital
    reap3r <-- Helped me alot
    1possible <---- Awsome!
    Rave - AWSOME coder
    swiftdude <-- AWSOME coder!!! ---> Helps when needed
    thecamels8
    ropsu678 /
    Quote Originally Posted by fogest View Post


    Just because your on a hacking site doesn't mean you have to hack or like hacking.
    LOL, Why the Fuck would you be on here then?


    Press Thanks If I Helped You

  15. #12
    omghacker's Avatar
    Join Date
    Apr 2009
    Gender
    male
    Posts
    184
    Reputation
    10
    Thanks
    34
    My Mood
    Relaxed
    What is dumping? /

  16. #13
    Threadstarter
    Upcoming MPGHiean
    AeroMan's Avatar
    Join Date
    Dec 2008
    Gender
    male
    Location
    Hell
    Posts
    3,294
    Reputation
    189
    Thanks
    3,049
    My Mood
    Busy
    Its unpacking your program from themida & other packers

  17. #14
    omghacker's Avatar
    Join Date
    Apr 2009
    Gender
    male
    Posts
    184
    Reputation
    10
    Thanks
    34
    My Mood
    Relaxed
    Quote Originally Posted by AeroMan View Post
    Its unpacking your program from themida & other packers
    And what can you do with it then? :s

  18. #15
    Threadstarter
    Upcoming MPGHiean
    AeroMan's Avatar
    Join Date
    Dec 2008
    Gender
    male
    Location
    Hell
    Posts
    3,294
    Reputation
    189
    Thanks
    3,049
    My Mood
    Busy
    Quote Originally Posted by omghacker View Post
    And what can you do with it then? :s
    You can look inside to find structs,addies,bytes,patterns(with masks) & Bypasses

Page 1 of 6 123 ... LastLast

Similar Threads

  1. [Release] Dumped WarRock.exe
    By Pitcher in forum WarRock Hack Source Code
    Replies: 5
    Last Post: 08-24-2011, 11:07 AM
  2. New Dumped Warrock.exe
    By TheCamels8 in forum WarRock Hack Source Code
    Replies: 8
    Last Post: 10-28-2010, 04:03 PM
  3. How to dump Warrock.exe [VID]!
    By TheCamels8 in forum WarRock Tutorials
    Replies: 4
    Last Post: 10-19-2010, 10:32 AM
  4. Dumped WarRock.exe
    By AeroMan in forum WarRock Hack Source Code
    Replies: 45
    Last Post: 08-22-2010, 10:30 PM
  5. Dumped (WarRock.exe) [20.8.2010]
    By CyberRazzer in forum WarRock Hack Source Code
    Replies: 6
    Last Post: 08-22-2010, 12:20 AM