Tuesday, August 31, 2010
Jonita UPDATED 31082010 [Ammo, Grade, Point Hack]
credit : jonita@nyit-nyit.net
Fitur:
- Infinite ammo [Always ON]
- Grade+Point Hack [F12]
Enjoy it
Saturday, August 28, 2010
PBT 1.3 [Grenade, Minimize, Wallshot]
Download Link : Click Here
No Password, enjoy leech
1. Start Launcher
2. Pada saat hackshield sedang loading, klik I3ExecInject
3. Centang Cheat atau tekan Hotkey cheat di Trainer
4. Enjoy !
Friday, August 27, 2010
Hackshield Bypass Source
pasang code ini di Project kalian biar gk kedetek HackSHit
///////////////////////BEGIN PATCH/////////////
DWORD OldProtection;
void MEMwrite(void *adr, void *ptr, int size)
{
VirtualProtect(adr,size,PAGE_EXECUTE_READWRITE, &OldProtection);
memcpy(adr,ptr,size);
VirtualProtect(adr,size,OldProtection, &OldProtection);
}
void NewDetourhs(long Address,int Size,int Size2)
{
long EhSvc = (long)GetModuleHandleA("EhSvc.dll");
DWORD OldProtect;
VirtualProtect((void*)(EhSvc+Address),Size,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(EhSvc+Address) = Size2;
//*(int*)(EhSvc+Address) = Size;
}
void CopyModules(void)
{
long EhSvc = (long)GetModuleHandleA("EhSvc.dll");
//self crc checks
MEMwrite((void *)(EhSvc+0x0FF28),(void*)(PBYTE)"\xB8\x01\x00\x00\x00",5);
//anti asm scan game client
MEMwrite((void *)(EhSvc+0x1BC28),(void*)(PBYTE)"\x90\x90",2);//
////unhook dip & sss 8
MEMwrite((void *)(EhSvc+0x650A5),(void*)(PBYTE)"\xEB",1);//
MEMwrite((void *)(EhSvc+0x650CF),(void*)(PBYTE)"\xEB",1);//
//dll jump code check
MEMwrite((void *)(EhSvc+0x66931),(void*)(PBYTE)"\xEB",1);//
MEMwrite((void *)(EhSvc+0x66B79),(void*)(PBYTE)"\xEB",1);//
//anti restore page
MEMwrite((void *)(EhSvc+0x5F80E),(void*)(PBYTE)"\xEB",1);//
MEMwrite((void *)(EhSvc+0x5F784),(void*)(PBYTE)"\xEB",1);//
//processscan, main eagle process detect callback, for cheat engine
MEMwrite((void *)(EhSvc+0x54A14),(void*)(PBYTE)"\xE9\x7E\x0A\x00\x00",5);//
// nano detect objects
MEMwrite((void *)(EhSvc+0x2411B),(void*)(PBYTE)"\xEB",1);//
MEMwrite((void *)(EhSvc+0x24265),(void*)(PBYTE)"\xEB",1);//
MEMwrite((void *)(EhSvc+0x2435F),(void*)(PBYTE)"\x31",1);//
MEMwrite((void *)(EhSvc+0x22556),(void*)(PBYTE)"\x31",1);//
MEMwrite((void *)(EhSvc+0x26171),(void*)(PBYTE)"\x31",1);//
MEMwrite((void *)(EhSvc+0x25618),(void*)(PBYTE)"\xEB",1);//
MEMwrite((void *)(EhSvc+0x2572C),(void*)(PBYTE)"\xEB",1);//
MEMwrite((void *)(EhSvc+0x25ADB),(void*)(PBYTE)"\xEB",1);//
int EhPtr = 0x0D0F40;
NewDetourhs((EhPtr-0x44),0x8,4);//
NewDetourhs((EhPtr-0x40),0x8,4);//
NewDetourhs((EhPtr-0x20),0x8,4);//
NewDetourhs(0x0D13F8,0x8,4);//
NewDetourhs(0x0CD5F8,0x8,4);//
NewDetourhs(0x0C7570,0x8,4);//
NewDetourhs(0x0C7754,0x8,4);//
NewDetourhs(0x0CED40,0x8,4);//
NewDetourhs(0x0C7739,0x8,4);//
NewDetourhs(0x0D2E08,0x8,4);//
NewDetourhs(0x0C7758,0x8,4);//
NewDetourhs(0x0C62F8,0x8,4);//
NewDetourhs(0x0C7715,0x8,4);//
NewDetourhs(0x0D0F40,0x8,4);//
NewDetourhs(0x0C7719,0x8,4);//
NewDetourhs(0x0D2E40,0x8,4);//
NewDetourhs(0x0C62F8,0x8,4);//
NewDetourhs(0x0CD8FC,0x8,4);//
NewDetourhs(0x0CD5F8,0x8,4);//
NewDetourhs(0x0D3DF1,0x8,4);//
}
void Loop(void)
{
for(;;)
{
long EhSvc = (long)GetModuleHandleA("EhSvc.dll");
if(EhSvc!=0)
{
CopyModules();
}
Sleep(20);
}
}
/////////////////////END PATCH///////////////////////
Lalu buat fungsi untuk memanggil Anti HS
pasang di : DLL_Attach_Process
CreateThread(NULL, NULL, (LPTHREAD_START_ROUTINE)Loop, NULL, NULL, NULL);
Setelah itu compile
================================
jangan ngejunk, khusus yang udah tau C++ D3D HACK
Wednesday, August 18, 2010
PB Destroy Complete Trainer 1.0
Link Download : Click Here
no password
work on other computer ! tested
updated 16 agustus
Tidak direkomendasikan mengaktifkan Mode Wallshot, karena dapat menyebabkan DC !
Sunday, August 15, 2010
Unpacking Yodas Protector 1.03.3
Watch Online Tutorial : Click Here
Download Archives : Unpackme, Complete Tutorial Click Here
C:\Yodas Protector Unpacking.swf
Build 2 successfully completed
Created at: Sat Aug 14 08:28:53 2010
Flash player required: v6.0 or above
Size: 1654 KB
Total frames in main movie: 5160
Playback frame rate: 20
Approximate playback time: 258 seconds
Annotated text transcript:
Unpacking Yoda's Protector 1.03.3
Tools :
-OllyDBG
-OllyDump
-IsDebugPresent (If you need)
-LordPE
-TargetFile
This Tutorial is writen by Richard Irfan Yusan
richardyusan@rocketmail.com
The TargetFile ;-)
yoda's Protector 1.03.3 -> Ashkbiz Danehkar
Entryopy : PACKED
EP Check : PACKED
Load the target file to OllyDBG
Set your Exceptions Settings like this
make sure this checkbox is checked
If User32.dll already loaded into memory, set your ollydbg events setting back to normal
Uncheck !
Right Click > Go To > Expression
Or
CTRL + G
Type "BlockInput"
Fill with NOPs
Place Breakpoint here
F2
Now, we must fix IsDebuggerPresent
there are two method :
1.Manual Fix : Continue watching
2. Using IsDebuggerPresent OllyDBG plugin , you can skip this step
MOV EAX,0
GetCurrentProcessId
Case sensitive
Yoda uses CreateToolhelp32Snapshot to retrieve all running processes. Then , yoda search for process that started unpackme and it checks does that proces has same PID as unpackme itself. If not, yoda terminates that process which is OllyDbg.exe in our case. If we patch CreateToolhelp32Snapshot API, we will get Invalid_Handle exception. But there is another very easy way how to trick yoda. Yoda uses GetCurrentProcessId API to retrieve it's own PID. We can make yoda think that it is ollydbg.exe if we set that API to retireve olly's PID. How we can do that? By injecting simple patch.
00000730 is OllyDBG PID
730 mean ollydbg pid
Run Debugged Program
F9
We land at this breakpoint :D
Run Debugged Program Again
F9
Set Memory BP on access
OEP
CTRL+A to analyze this code
UnPackMe file run without error :D
;-)
Entropy : NOT PACKED
EPCheck : NOT PACKED
And UnPackMe Unpacked succesfully !
My Blog :
richardyusan.wordpress.com
Friday, August 13, 2010
PointBlank Trainer +2 Fixed
Link Download : Click Here
Password : Enjoy ! No password
Work On Other Computer, Tested ! 100% WORK !!!
Wednesday, August 11, 2010
[Share] Unpacking UPX 3.05w - All Version
Download files beserta Unpackme
Klik Disini
C:\UPX_3.05w_UnpackMe\UPX_3.05w(Unpacking) Indonesian.swf
Build 1 successfully completed
Created at: Mon Aug 09 21:18:02 2010
Flash player required: v6.0 or above
Size: 1395 KB
Total frames in main movie: 4960
Playback frame rate: 20
Approximate playback time: 248 seconds
Annotated text transcript:
Reversing for Noobs / Newbies
Unpacking UPX 3.05w
Tools :
-OllyDBG
-LordPE
-ImportREC
-PackedFile
Tutorial made by Richard Irfan Yusan
-http://www.richardyusan.wordpress.com
-http://www.facebook.com/richard.yusan
Entropy : (Packed)
EP Check : (Packed)
Click This
Follow in Dump
Pilih 4 Bytes
38 07 91 7C
Set BreakPoint > Hardware, on access > Dword
Run Debugged Program
(F9)
Jalankan lagi
(F9)
Set Breakpoint di sini
Magic Jump ini akan membawa kita dimana OEP Berada
Karena kita sudah tidak membutuhkan HWBP ( Hardware Breakpoint ), kita buang saja breakpointnya
Delete
Restart Debugged Process
(CTRL+F2)
Tekan F8
Original Entry Point (OEP)
;-)
Gunakan LordPE untuk full dumping TargetFile
File belum berjalan dengan sempurna :( yang perlu kita lakukan hanyalah membetulkan IAT-nya
File juga belum ter-unpack :(
;-)
Pilih hanya 4 bytes saja
1128
Coba kita langsung jalankan Auto Search tanpa mengubah value OEP
Error ! :(
Coba kita gunakan OEP yang telah
ditemukan di OllyDBG
1128
Success ! ;-)
Tak ada imports yang invalid
pilih file yang telah di dumping
File telah ter-unpack !
Not Packed :D
File berjalan dengan sempurna
Gunakan RebuildPE agar ukuran file semakin kecil
SELESAI....
Array Of Bytes ( Updated 11 Agustus )
Ammo Unlimited (array of byte)
89 90 64 03 00 00
Granat Unlimited (array of byte)
6A 00 8B 55 E8 8B 02 8B 4D E8
Tutor bisa dilihat di n3, snutz, forum lain
bahan : PH, CE
Monday, August 9, 2010
Unpacking ASPack 2.12 Indonesian Version by RCD
Unpacking nya sangat mudah
download files unpackme & tutor lebih lengkap
click here
Saturday, August 7, 2010
PointBlank Trainer +4 Working 100% Check This Out
- Suspend PointBlank.exe pas lagi loading Hackshield menggunakan Process Hacker atau program sejenisnya
- Jalankan Trainer
NB : Untuk Alt + Tab No DC masih memiliki beberapa bug, disarankan Gak usah pake
- Check Kotaknya, yang ALT+Tab No DC disarankan gk di centang
Baca lanjut untuk download
- Tutup Trainer, Resume Process PointBlank.exe
Pengen Bukti Work ?
Check This Out
Liat Ammo nya 136 ?? What
liat lagi neh SS berikutnya, ammonya makin nambah
Good
Sekarang Granatnya
Pada Detik 02:20, Ammo Granat cuma 1, Liat Mission Noticenya, masih lom selesai :D
Download Link : Click Here
Clue Password : (Nama nick)
Thursday, August 5, 2010
Alt+Tab No DC 5 Agustus !!!
clue password >>> Lihat Disini
Download Link : Click Here
Penggunaan : replace semua file dengan file yang ada di archive
-PointBlank.exe
-I3BaseDx.dll
-PointBlank.i3exec
Worked & Tested
Tuesday, August 3, 2010
Cheat XShot : Unlimited Ammo
Credit : RCD
Monday, August 2, 2010
RCD Engine 1.4 for XSHOT
Password : (Clue:nama nick)
tutor : check semua setting di Tab Extra > Attach ke Mat.exe > Happy Cheating
engine ini gk kedetect !
