Tuesday, August 31, 2010

Jonita UPDATED 31082010 [Ammo, Grade, Point Hack]

Download Link : Click Here

credit    : jonita@nyit-nyit.net


Fitur:
- Infinite ammo [Always ON]
- Grade+Point Hack [F12]

Enjoy it

Saturday, August 28, 2010

PBT 1.3 [Grenade, Minimize, Wallshot]


Download Link : Click Here


No Password, enjoy leech



1. Start Launcher
2. Pada saat hackshield sedang loading, klik I3ExecInject
3. Centang Cheat atau tekan Hotkey cheat di Trainer
4. Enjoy !

Friday, August 27, 2010

Hackshield Bypass Source

Nih kalo agan dah buat wallhack atau sejenisnya
pasang code ini di Project kalian biar gk kedetek HackSHit

///////////////////////BEGIN PATCH/////////////


DWORD OldProtection;
void MEMwrite(void *adr, void *ptr, int size)
{
        VirtualProtect(adr,size,PAGE_EXECUTE_READWRITE, &OldProtection);
        memcpy(adr,ptr,size);
        VirtualProtect(adr,size,OldProtection, &OldProtection);
}

void NewDetourhs(long Address,int Size,int Size2)
{
long EhSvc = (long)GetModuleHandleA("EhSvc.dll");
DWORD OldProtect;
VirtualProtect((void*)(EhSvc+Address),Size,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(EhSvc+Address) = Size2;
//*(int*)(EhSvc+Address) = Size;
}

void CopyModules(void)
{

        long EhSvc = (long)GetModuleHandleA("EhSvc.dll");

        //self crc checks
        MEMwrite((void *)(EhSvc+0x0FF28),(void*)(PBYTE)"\xB8\x01\x00\x00\x00",5);

        //anti asm scan game client
        MEMwrite((void *)(EhSvc+0x1BC28),(void*)(PBYTE)"\x90\x90",2);//

        ////unhook dip & sss 8
        MEMwrite((void *)(EhSvc+0x650A5),(void*)(PBYTE)"\xEB",1);//
        MEMwrite((void *)(EhSvc+0x650CF),(void*)(PBYTE)"\xEB",1);//

        //dll jump code check
        MEMwrite((void *)(EhSvc+0x66931),(void*)(PBYTE)"\xEB",1);//
        MEMwrite((void *)(EhSvc+0x66B79),(void*)(PBYTE)"\xEB",1);//

        //anti restore page
        MEMwrite((void *)(EhSvc+0x5F80E),(void*)(PBYTE)"\xEB",1);//
        MEMwrite((void *)(EhSvc+0x5F784),(void*)(PBYTE)"\xEB",1);//

        //processscan, main eagle process detect callback, for cheat engine
        MEMwrite((void *)(EhSvc+0x54A14),(void*)(PBYTE)"\xE9\x7E\x0A\x00\x00",5);//

        // nano detect objects
        MEMwrite((void *)(EhSvc+0x2411B),(void*)(PBYTE)"\xEB",1);//
        MEMwrite((void *)(EhSvc+0x24265),(void*)(PBYTE)"\xEB",1);//
        MEMwrite((void *)(EhSvc+0x2435F),(void*)(PBYTE)"\x31",1);//
        MEMwrite((void *)(EhSvc+0x22556),(void*)(PBYTE)"\x31",1);//
        MEMwrite((void *)(EhSvc+0x26171),(void*)(PBYTE)"\x31",1);//
        MEMwrite((void *)(EhSvc+0x25618),(void*)(PBYTE)"\xEB",1);//
        MEMwrite((void *)(EhSvc+0x2572C),(void*)(PBYTE)"\xEB",1);//
        MEMwrite((void *)(EhSvc+0x25ADB),(void*)(PBYTE)"\xEB",1);//

        int EhPtr = 0x0D0F40;
        NewDetourhs((EhPtr-0x44),0x8,4);//
        NewDetourhs((EhPtr-0x40),0x8,4);//
        NewDetourhs((EhPtr-0x20),0x8,4);//

        NewDetourhs(0x0D13F8,0x8,4);//
        NewDetourhs(0x0CD5F8,0x8,4);//
        NewDetourhs(0x0C7570,0x8,4);//
        NewDetourhs(0x0C7754,0x8,4);//
        NewDetourhs(0x0CED40,0x8,4);//
        NewDetourhs(0x0C7739,0x8,4);//
        NewDetourhs(0x0D2E08,0x8,4);//
        NewDetourhs(0x0C7758,0x8,4);//
        NewDetourhs(0x0C62F8,0x8,4);//
        NewDetourhs(0x0C7715,0x8,4);//
        NewDetourhs(0x0D0F40,0x8,4);//
        NewDetourhs(0x0C7719,0x8,4);//
        NewDetourhs(0x0D2E40,0x8,4);//
        NewDetourhs(0x0C62F8,0x8,4);//
        NewDetourhs(0x0CD8FC,0x8,4);//
        NewDetourhs(0x0CD5F8,0x8,4);//
        NewDetourhs(0x0D3DF1,0x8,4);//

}
void Loop(void)
{
for(;;)
{
long EhSvc = (long)GetModuleHandleA("EhSvc.dll");
if(EhSvc!=0)
{
CopyModules();
}
Sleep(20);
}
}

/////////////////////END PATCH///////////////////////

Lalu buat fungsi untuk memanggil Anti HS
pasang di : DLL_Attach_Process
CreateThread(NULL, NULL, (LPTHREAD_START_ROUTINE)Loop, NULL, NULL, NULL);

Setelah itu compile

================================

jangan ngejunk, khusus yang udah tau C++ D3D HACK

Friday, August 20, 2010

PBQuickWallhack 2.0 Preview


Kalo gambar kekecilan, klik aja fotonya :D

Wednesday, August 18, 2010

PB Destroy Complete Trainer 1.0

Link Download : Click Here

no password

work on other computer ! tested

updated 16 agustus

Tidak direkomendasikan mengaktifkan Mode Wallshot, karena dapat menyebabkan DC !

Sunday, August 15, 2010

Unpacking Yodas Protector 1.03.3

Watch Online Tutorial : Click Here
Download Archives : Unpackme, Complete Tutorial Click Here


C:\Yodas Protector Unpacking.swf
Build 2 successfully completed
Created at: Sat Aug 14 08:28:53 2010
Flash player required: v6.0 or above
Size: 1654 KB
Total frames in main movie: 5160
Playback frame rate: 20
Approximate playback time: 258 seconds

Annotated text transcript:

Unpacking Yoda's Protector 1.03.3
Tools :

-OllyDBG
-OllyDump
-IsDebugPresent (If you need)
-LordPE
-TargetFile

This Tutorial is writen by Richard Irfan Yusan

richardyusan@rocketmail.com
The TargetFile ;-)
yoda's Protector 1.03.3 -> Ashkbiz Danehkar
Entryopy : PACKED
EP Check : PACKED
Load the target file to OllyDBG
Set your Exceptions Settings like this
make sure this checkbox is checked
If User32.dll already loaded into memory, set your ollydbg events setting back to normal
Uncheck !
Right Click > Go To > Expression

Or

CTRL + G
Type "BlockInput"
Fill with NOPs
Place Breakpoint here
F2
Now, we must fix IsDebuggerPresent

there are two method :

1.Manual Fix : Continue watching
2. Using IsDebuggerPresent OllyDBG plugin , you can skip this step
MOV EAX,0
GetCurrentProcessId

Case sensitive
Yoda uses CreateToolhelp32Snapshot to retrieve all running processes. Then , yoda search for process that started unpackme and it checks does that proces has same PID as unpackme itself. If not, yoda terminates that process which is OllyDbg.exe in our case. If we patch CreateToolhelp32Snapshot API, we will get Invalid_Handle exception. But there is another very easy way how to trick yoda. Yoda uses GetCurrentProcessId API to retrieve it's own PID. We can make yoda think that it is ollydbg.exe if we set that API to retireve olly's PID. How we can do that? By injecting simple patch.
00000730 is OllyDBG PID
730 mean ollydbg pid
Run Debugged Program

F9
We land at this breakpoint :D
Run Debugged Program Again

F9
Set Memory BP on access
OEP
CTRL+A to analyze this code
UnPackMe file run without error :D
;-)
Entropy : NOT PACKED
EPCheck : NOT PACKED
And UnPackMe Unpacked succesfully !

My Blog :
richardyusan.wordpress.com





PBQuickWallhack 2.0 ! Release !

Friday, August 13, 2010

PointBlank Trainer +2 Fixed



Link Download : Click Here

Password : Enjoy ! No password

Work On Other Computer, Tested ! 100% WORK !!!

Wednesday, August 11, 2010

[Share] Unpacking UPX 3.05w - All Version

Video online Klik Disini

Download files beserta Unpackme

Klik Disini
C:\UPX_3.05w_UnpackMe\UPX_3.05w(Unpacking) Indonesian.swf
Build 1 successfully completed
Created at: Mon Aug 09 21:18:02 2010
Flash player required: v6.0 or above
Size: 1395 KB
Total frames in main movie: 4960
Playback frame rate: 20
Approximate playback time: 248 seconds

Annotated text transcript:

Reversing for Noobs / Newbies
Unpacking UPX 3.05w
Tools :

-OllyDBG
-LordPE
-ImportREC
-PackedFile

Tutorial made by Richard Irfan Yusan
-http://www.richardyusan.wordpress.com
-http://www.facebook.com/richard.yusan
Entropy : (Packed)
EP Check : (Packed)
Click This
Follow in Dump
Pilih 4 Bytes

38 07 91 7C
Set BreakPoint > Hardware, on access > Dword
Run Debugged Program
(F9)
Jalankan lagi
(F9)
Set Breakpoint di sini
Magic Jump ini akan membawa kita dimana OEP Berada
Karena kita sudah tidak membutuhkan HWBP ( Hardware Breakpoint ), kita buang saja breakpointnya
Delete
Restart Debugged Process
(CTRL+F2)
Tekan F8
Original Entry Point (OEP)
;-)
Gunakan LordPE untuk full dumping TargetFile
File belum berjalan dengan sempurna :( yang perlu kita lakukan hanyalah membetulkan IAT-nya
File juga belum ter-unpack :(
;-)
Pilih hanya 4 bytes saja

1128
Coba kita langsung jalankan Auto Search tanpa mengubah value OEP
Error ! :(
Coba kita gunakan OEP yang telah
ditemukan di OllyDBG

1128
Success ! ;-)
Tak ada imports yang invalid
pilih file yang telah di dumping
File telah ter-unpack !
Not Packed :D
File berjalan dengan sempurna
Gunakan RebuildPE agar ukuran file semakin kecil
SELESAI....

Array Of Bytes ( Updated 11 Agustus )

Ammo Unlimited (array of byte)
89 90 64 03 00 00

Granat Unlimited (array of byte)
6A 00 8B 55 E8 8B 02 8B 4D E8



Tutor bisa dilihat di n3, snutz, forum lain

bahan : PH, CE

Monday, August 9, 2010

Unpacking ASPack 2.12 Indonesian Version by RCD

Klik Disini untuk melihat video onlinenya

Unpacking nya sangat mudah

download files unpackme & tutor lebih lengkap

click here

Saturday, August 7, 2010

PointBlank Trainer +4 Working 100% Check This Out

Penggunaan :

- Suspend PointBlank.exe pas lagi loading Hackshield menggunakan Process Hacker atau program sejenisnya

- Jalankan Trainer

NB : Untuk Alt + Tab No DC masih memiliki beberapa bug, disarankan Gak usah pake


- Check Kotaknya, yang ALT+Tab No DC disarankan gk di centang


Baca lanjut untuk download



- Tutup Trainer, Resume Process PointBlank.exe



Pengen Bukti Work ?


Check This Out



Liat Ammo nya 136 ?? What


liat lagi neh SS berikutnya, ammonya makin nambah


WKWKKWW Ammonya jadi 173 ???


Good


Sekarang Granatnya


Pada Detik 02:20, Ammo Granat cuma 1, Liat Mission Noticenya, masih lom selesai :D



Download Link : Click Here


Clue Password : (Nama nick)

Thursday, August 5, 2010

Alt+Tab No DC 5 Agustus !!!

Credit : Black Rain n3
clue password >>> Lihat Disini

Download Link : Click Here

Penggunaan : replace semua file dengan file yang ada di archive

-PointBlank.exe
-I3BaseDx.dll
-PointBlank.i3exec

Worked & Tested

Tuesday, August 3, 2010

Cheat XShot : Unlimited Ammo

Cheat XShot : Unlimited Ammo, gunakan RCD Engine 1.4.......:D

Credit : RCD





Monday, August 2, 2010

RCD Engine 1.4 for XSHOT

Download link : Click Here

Password : (Clue:nama nick)

tutor : check semua setting di Tab Extra > Attach ke Mat.exe > Happy Cheating

engine ini gk kedetect !