RF client patcher file : C:\Users\Ru\Downloads\REPACK AOP FIX TIME\OldSchool\rf15-v0.2.1\RFO 1.5b\RFOnline\RF_Online.bin size : 10153352 bytes sha1 : CE3FCF163A042ADE290485885238565A6693C46C known: looks like RF Online V1.5 Defcon1 - Cocked Pistol (GamesCampus GC15b, PE 2013-03-13) - RF 1.5 [MODIFIED: sha1 is not the clean original] (all patch sites are recognized, so the offsets are trusted; the bin is just already patched or a variant)
Patch status: hackshield OFF @ 0x3DFC65, 0x3DFC99, 0x3DFCB0, 0x4C6B3C
- AhnLab HackShield Pro. Unlike the other builds here this one does NOT get skipped - it gets RUN and then overruled. HackShield init is called from dozens of sites, at boot and again after login, and each one resolves a function pointer; skipping init leaves every one of those pointers null and the next HS call anywhere dereferences null. So the orchestration at RVA 0x3E0490 still runs to completion (its resolvers load the real HackShield/<locale>/ehsvc.dll and fill the pointers), and only its VERDICT is forced: its three "mov eax,[ebp-8]" return-value loads become "xor eax,eax; nop", so it always reports success to the four callers that check it. The fourth site is a separate post-login notification (0x4C773C) that fires through a pointer HackShield never resolved because its kernel driver is dead; it is fire-and-forget - its caller discards the result and it only formats an error text - so it returns success immediately instead. 1 = ON (stock); 0 = OFF (run HackShield, ignore its verdict). LEAVE THE REAL ehsvc.dll IN PLACE: this patch needs it, and a no-op stub DLL does not work (HackShield functions return pointers the client then dereferences, not just status codes). hsdialog OFF @ 0x3E07E1
- The "HS Err 8" boot dialog. HackShield puts up a modal box on EVERY launch and the client stops there until somebody clicks OK - harmless, but it makes an unattended or scripted launch impossible. The error is AhnLab reporting its own dead kernel driver; it cannot be satisfied, only hidden. This jumps over the MessageBoxA block in the code-0x204 arm of the error dispatcher (RVA 0x3E13E1 -> the arm's own existing exit at 0x3E1402), which is a pure display path: the box's return value is destroyed by an "xor eax,eax" before anything reads it, and nothing before the patch point is touched, so the dispatcher's verdict is byte-identical either way. The log line "HackShield Err 204" is written BEFORE this point and is preserved. 1 = ON (dialog shown, stock); 0 = OFF (suppressed). Independent of the hackshield patch above - you can take either or both. movie OFF @ 0x1A29C6
- The two Bink intro movies (about 11 and 27 seconds). This uses the client's OWN skip path rather than breaking the movie: there is one shared blocking play loop, and inside it a test for the Escape key. Turning that test into two no-ops makes the loop take the Escape arm on its first pass, exactly as if you held Escape as the movie opened - the client logs "Pressed Escape", marks the movie finished and runs its normal teardown into the login screen. NOTE THAT DELETING OR RENAMING THE .bik FILES IS NOT THE SAME THING AND WILL BREAK THE CLIENT: a movie that fails to OPEN is fatal to this build, and it rebuilds the title sequence forever, which looks exactly like a hung server. This patch leaves the files alone and the movie still opens. 1 = ON (intros play, stock); 0 = OFF (skipped).
Notes for RF 1.5:
- HackShield: take BOTH -HackShield 0 and -HsDialog 0. The first makes the client stop caring that AhnLab failed; the second removes the "HS Err 8" box it puts up on every launch, which the client otherwise waits at until somebody clicks OK. That error is AhnLab reporting its own long-dead kernel driver and cannot be satisfied, only hidden. The client still writes "HackShield Err 204" to its NetLog either way, which is deliberate - it is the checkpoint that says HackShield got exactly as far as expected.
- Leave the real HackShield<locale>\ehsvc.dll where it is. A stubbed-out DLL does NOT work on this build: the client calls HackShield functions that must return POINTERS it then dereferences, not just status codes.
- The AhnLab logo splash on the way in is NOT removable by this patcher, and that is not an oversight. It is drawn by ehsvc.dll itself - confirmed by resolving the window back to its module in a running client - out of encrypted resources inside a packed DLL that has to stay loaded and real for the reason in the line above. There is no file you can edit to stop it. It lasts a few seconds and costs nothing else; the boot is still unattended.
- Intro movies: use -Movie 0. DO NOT delete or rename the .bik files instead - this client treats a movie that fails to OPEN as fatal and rebuilds the title sequence forever, which looks exactly like a hung server. The patch does not touch your files; it makes the client skip the movie the same way holding Escape does.
- FireGuard: config, not a patch. This build reads USEFG from DataTable<locale>\FG_CB.ini ONLY, and a MISSING file means ON. rflauncher.exe detects it and offers to switch it off.
- Screen mode: use -Windowed 0|1 and -Resolution. This build reads bFullScreen and the resolution from R3Engine.ini once at startup, never writes that file, and has no in-game toggle, so a bad value leaves you with a client that will not start and no way back except the ini. The Screen mode block above checks yours against what this display actually accepts and says what to do; the failure it is looking for is a window that opens and closes with the NetLog stopping at "Base Init End~".
- Server port: as with every RF client, it arrives through the launcher handoff, not the bin. See -Port below.
This client is already set up for a private server (the recommended patches are all applied).
Screen mode: file : C:\Users\Ru\Downloads\REPACK AOP FIX TIME\OldSchool\rf15-v0.2.1\RFO 1.5b\RFOnline\R3Engine.ini bFullScreen : TRUE resolution : 1920 x 1080 this display: 1920 x 1080 @ 60 Hz, 32 bpp fullscreen is ON and 1920x1080 @ 60 Hz is an available mode - good.
Read-only status only (no patch flags given). Pass e.g. -HackShield 0 to change something.
[2026-10-05T23:40:17] [32mINFO [0m client entered world {"session": 2, "name": "SIGMA", "serial": 3000, "index": 10037, "in_world": 1} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "1F/03", "body": "00"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "02/0A", "body": "00"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "3A/03", "body": ""} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "0D/11", "body": "f800"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "0D/1E", "body": "00"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "0D/20", "body": "00"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "0D/1F", "body": "00"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "0D/1E", "body": "00"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "0D/20", "body": "00"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "0D/15", "body": "0000"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "0D/1E", "body": "00"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "0D/20", "body": "00"} [2026-10-05T23:40:17] [32mINFO [0m recv {"session": 2, "op": "19/3B", "body": "0000030000"} [2026-10-05T23:40:24] [32mINFO [0m election phase {"phase": 5, "name": "class_order"} [2026-10-05T23:40:44] [32mINFO [0m tcpnet: session 2 read error: read tcp 127.0.0.1:27810->127.0.0.1:1224: wsarecv: An existing connection was forcibly closed by the remote host. [2026-10-05T23:40:44] [32mINFO [0m client disconnected {"session": 2, "remote": "127.0.0.1:1224", "connected_for": 39.704}
this is what i have