PDA

View Full Version : icesword public version



cristian02
26th March 2006, 13:12
i ve yet post a private chinese version of icesword now the public one in english is available
noone has see my post but with icesword you can write into gme o gameguard memory while the game is running it detects all hidden processes and allows a lot of tip

bye

bandog_lover
26th March 2006, 13:57
is this a bypass?

aljovan82
26th March 2006, 14:22
this is nice info, thank you, very usefull to bypass and manupulate something in gunbound.gme

popoy
26th March 2006, 14:37
like what? is this progy same as moose injector?

Mooblar
26th March 2006, 15:11
When I use this program, I get 'A required resource is unavailable' so I'm not sure (Yes im aware the file isn't approved yet.)

gunzhax
26th March 2006, 16:15
No if I'm correct this is used with Ollydbg and you would debug the .gme's while it's running.

xswat
26th March 2006, 23:26
and from there you could get a unpacked gme and experiment with it ;)

SunBeam
27th March 2006, 00:22
You can't do all he says. You can only view processes, not edit memory and can see drivers, although you can't unload them...

jesterlol
27th March 2006, 00:50
You can't do all he says. You can only view processes, not edit memory...

sunbeam: read/write memory it's true :O you can also dump entire preoces

http://members.lycos.nl/lordor69/icesword.JPG

SunBeam
27th March 2006, 01:19
Lol. I can say one word : patched. And one more thing : IceSword uses kernel drivers. You should see how your computer reacts when they patch this :D :D...

I bet if you open IceSword it will reboot ur PC...if they patch this...

jesterlol
27th March 2006, 02:02
huhauha sure... like Cheat Engine

cristian02
27th March 2006, 05:54
Lol. I can say one word : patched. And one more thing : IceSword uses kernel drivers. You should see how your computer reacts when they patch this :D :D...

I bet if you open IceSword it will reboot ur PC...if they patch this...


YOU RE WRONG SUNBEAN IT S RARE BUT YOU RE WRONG

YOU CAN PLAY WITHOUT GAMEMON YOU CAN KILL NPSCAN.DES NPGGNT ALL THAT YOU WANT OF COURSE THE GAME STOPS BECAUSE OF CHECKS GME/GAMEGUARD
BUT DOESN T REBOOT
ICE SWORD WAS PRIVATE AND SOLD IN CHINA FOR TWENTY DOLLARS

IT S A VERY VERY GOOD AND USEFULL TOOL

xswat
27th March 2006, 06:19
bleh... any1 can kill the processes. not much point tho...

wapak2
27th March 2006, 06:53
File: icesword_en1[1].12.rar
Status: MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found, this is suspicious. Normally programs aren't packed and don't force the sandbox into lengthy emulation. Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.)
MD5 01d8f8a45cc0c25134a98002f295f3c2
Packers detected: ASPACK
Scanner results
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
UNA Found nothing
VirusBuster Found nothing
VBA32 Found nothing
File is clean --> Approved. Use at own risk.

SunBeam
27th March 2006, 07:53
@cristian02 : READ AGAIN - I said IF :P

aljovan82
27th March 2006, 08:04
YOU RE WRONG SUNBEAN IT S RARE BUT YOU RE WRONG

YOU CAN PLAY WITHOUT GAMEMON YOU CAN KILL NPSCAN.DES NPGGNT ALL THAT YOU WANT OF COURSE THE GAME STOPS BECAUSE OF CHECKS GME/GAMEGUARD
BUT DOESN T REBOOT
ICE SWORD WAS PRIVATE AND SOLD IN CHINA FOR TWENTY DOLLARS

IT S A VERY VERY GOOD AND USEFULL TOOL

yes you can kill the GG but the problem is the checking packets, if your in server list you will encounter problems like cannot connect to server list at all.. you always receive errors check your internet connection .. and faking the packets isn't easy because its encrypted..

cristian02
27th March 2006, 14:53
here
http://itmanagement.earthweb.com/columns/executive_tech/article.php/3512621

SunBeam
27th March 2006, 16:35
* read this to the end before replying*

Cristian, stop that. This program has nothing to do with GunBound. Indeed it has some features that would allow one person to view the hidden .gme, since the author itself says it has rootkit detection capabilities.

As for the dumping part, it works in the same manner as LordPE. Still dumps memory, but the dumped .exe won't work. So you still need to fix the missing APIs in the IAT.

About the patching thing - IceSword also has a kernel driver [if you didn't notice the BIG .sys file]. Once iNCA learns of this tool, they will patch this. CE also has a kernel driver, remember ? Well, the only way to stop a kernel driver from functioning [as in the same way to stop it] is by rebooting your PC.

That's what's gonna happen to IceSword in the near future [unless iNCA is too dumb to learn of this, although I highly doubt it]

* end of story *