Project 1999

Go Back   Project 1999 > General Community > Technical Discussion

Reply
 
Thread Tools Display Modes
  #21  
Old 07-04-2014, 12:43 AM
Grimjaw Grimjaw is offline
Planar Protector

Grimjaw's Avatar

Join Date: Jun 2014
Location: https://discord.gg/ngqrDtyVe6
Posts: 1,089
Default

Quote:
Originally Posted by abacab-101 [You must be logged in to view images. Log in or Register.]
The file is obfuscated, and has two anti-cracking methods put into place; the first is the encryption and the block against .NET Reflector editing, it jumbles up the text and actively block compilers there are ways around that but I won't post that here.

The second is when it's edited a Project1999 pop-up comes up that says "this file has been corrupted, modified, and changed" as well as the DLL-2 error that pops up; the trick here is to maintain the file integrity and size; since most of the file has bullshit hex for filler (the lines upon lines of CC CC CC CC CC and 00 00 00 00 00) that must be maintained to keep the file from being rejected by the p99 client.

DLL has been cracked it's not hard at all.
so what does it do then lol? U can read pcode?
Reply With Quote
  #22  
Old 07-04-2014, 12:49 AM
abacab-101 abacab-101 is offline
Banned


Join Date: Jun 2014
Posts: 31
Default

Quote:
Originally Posted by Grimjaw [You must be logged in to view images. Log in or Register.]
so what does it do then lol? U can read pcode?
1. It's a callback
2. It causes an overflow on third-party programs, when you D/C it flags you because it sends out bad packets that the server then collects from your client; since MQ2 can't function well when the dsetup.dll is running at x100000 as opposed to the normal x0200 of eqgame.exe it disconnects the moment your character hits the world and reads the very first packet.
Reply With Quote
  #23  
Old 07-04-2014, 01:37 AM
abacab-101 abacab-101 is offline
Banned


Join Date: Jun 2014
Posts: 31
Default

P99's handle:
eqgame.exe (5556), DLL, C:\p99\dsetup.dll, 0x10000000

Normal handle:
eqgame.exe (5556), DLL, C:\everquest\dsetup.dll, 0x02000
Reply With Quote
  #24  
Old 07-04-2014, 01:38 AM
abacab-101 abacab-101 is offline
Banned


Join Date: Jun 2014
Posts: 31
Default

MQ2 reads 0x02 as that is what the client normally pushes, since p99 puts out 0x10 MQ2 cannot handle it and disconnects, thus the flagging occurs.
Reply With Quote
  #25  
Old 07-04-2014, 10:11 AM
phiren phiren is offline
Aviak


Join Date: Jul 2013
Posts: 67
Default

For the record, I don't think DSETUP.DLL is a big conspiracy to steal information on my computer.

I'm probably part of a minority of people who play on a machine where I have no control over my anti virus settings.

So -- if the devs feel that what they did is fine, and it's McAfee + other anti virus just being lame (which I completely agree with actually)... then that's fine.

I just wanted to bring it to the attention in the hopes that maybe the Devs can find an alternative.

~Phiren
Reply With Quote
  #26  
Old 07-09-2014, 02:15 AM
lvpa lvpa is offline
Large Bat


Join Date: May 2014
Posts: 11
Default

AVG just picked this up. It was odd because I hadn't done anything for like an hour, was just sitting afk, and it popped up.

Should I let AVG remove it? It's already quarantining it and not giving me the option to leave it alone; the options are quarantine or remove completely.
Reply With Quote
  #27  
Old 07-09-2014, 04:27 AM
Ambrotos Ambrotos is offline
VIP / Contributor

Ambrotos's Avatar

Join Date: Jan 2012
Posts: 2,290
Default

then you won't be able to play on the server. It isn't a virus
__________________
Reply With Quote
  #28  
Old 07-09-2014, 04:40 AM
lvpa lvpa is offline
Large Bat


Join Date: May 2014
Posts: 11
Default

Quote:
Originally Posted by Ambrotos [You must be logged in to view images. Log in or Register.]
then you won't be able to play on the server. It isn't a virus
I know; I'm saying AVG didn't give me a choice, it was either delete or quarantine; both amount to the program becoming inaccessible.
Last edited by lvpa; 07-09-2014 at 04:46 AM..
Reply With Quote
  #29  
Old 07-09-2014, 05:57 AM
Ambrotos Ambrotos is offline
VIP / Contributor

Ambrotos's Avatar

Join Date: Jan 2012
Posts: 2,290
Default

Derubael made a good post on the first page I think. Just switch scanners, and don't deal with avg.
__________________
Reply With Quote
  #30  
Old 07-09-2014, 06:07 AM
Argh Argh is offline
Planar Protector

Argh's Avatar

Join Date: Aug 2010
Posts: 1,166
Default

Malwarebytes
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 10:17 AM.


Everquest is a registered trademark of Daybreak Game Company LLC.
Project 1999 is not associated or affiliated in any way with Daybreak Game Company LLC.
Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.