Go Back   UnKnoWnCheaTs - Multiplayer Game Hacks and Cheats > Anti-Cheat Software & Programming > Anti-Cheat Bypass

- Sponsored Advertisement -
http://www.myfpscheats.com/

Welcome to the UnKnoWnCheaTs - Multiplayer Game Hacks and Cheats.
You have to register before you can post and see and access any of the advanced forum features, please click the register link to proceed to the registration form. To start viewing threads or posts, select a forum that you want to visit from the selection below.
Anti-Cheat Bypass
punkbuster vac gameguard esl xray screenshot detection undetected source code tutorial
You are Unregistered, please register to gain Full access.    
Reply
 
Thread Tools

VAC2 bypassing
Old 07-21-2009, 02:24 AM   #1
Nov
The Legendary Cheater

Nov's Avatar

Join Date: Nov 2008
Location: Sweden
Posts: 486
Reputation: 17501
Rep Power: 224
Nov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UC
Points: 13,971, Level: 15
Points: 13,971, Level: 15 Points: 13,971, Level: 15 Points: 13,971, Level: 15
Activity: 1.2%
Activity: 1.2% Activity: 1.2% Activity: 1.2%
Last Achievements
VAC2 bypassing

So here we go..



This will cripple VAC2 completely, making it unable to detect your hacks.

I will make this in 2 parts, first explanation and step-by-step, then full working source-code.

--------------
Step-by-step tutorial and explanation

Inject your DLL to Steam.exe (this is where VAC2 now resides, not like VAC1 which was inside the actual game)

When a game is started, VAC2 module is generated and loaded into Steam.exe.
To check for this event, let's do this:
PHP Code:
BOOL CheckForVAC2()
{
    
HANDLE hSnapShot CreateToolhelp32SnapshotTH32CS_SNAPMODULE);
    
MODULEENTRY32 mModule32 = { sizeofMODULEENTRY32 ) };

    if( 
Module32FirsthSnapShot, &mModule32 ) )
    {
        
bool meNext false;
        if( 
oModule32Next != )
            
meNext oModule32NexthSnapShot, &mModule32 );
        else
            
meNext Module32NexthSnapShot, &mModule32 );

        while( 
meNext )
        {
            if( 
strstr( (char*)mModule32.szModule".tmp" ) )
            {
                if( 
stricmp( (char*)mModule32.szModuleszVac2Module ) )
                {
                    
strcpyszVac2Module, (char*)mModule32.szModule );

                    
dwVac2Base = (DWORD)mModule32.modBaseAddr;
                    if( 
dwVac2Base == )
                        
dwOldVac2Base 0;

                    
dwVac2Size mModule32.modBaseSize;//mModule32.dwSize;
                
}

                
CloseHandle hSnapShot );
                return 
TRUE;
            }

            if( 
oModule32Next != )
                
meNext oModule32NexthSnapShot, &mModule32 );
            else
                
meNext Module32NexthSnapShot, &mModule32 );
        }
    }

    
CloseHandlehSnapShot );
    return 
FALSE;

The file-extension of VAC2 module is always .tmp so this is a safe method of finding it.

Then once we've found that it's loaded we hook API-functions used by VAC2, use detours or IAT/EAT hooking..
Hook Module32Next (kernel32.dll) and ReadProcessMemory (kernel32.dll)

In our Module32Next hook we do this:
PHP Code:
BOOL WINAPI hModule32NextHANDLE hSnapshotLPMODULEENTRY32 lpme )
{
    
ZeroMemorylpme->szModuleMAX_MODULE_NAME32 ); //Let's remove module-name from the struct so they surely don't get any
    
lpme->modBaseAddr 0;
    
lpme->modBaseSize 0;
    
lpme->hModule NULL;
    
lpme->th32ModuleID 0;
    
lpme->th32ProcessID 0;
    
SetLastErrorERROR_NO_MORE_FILES ); //Tells them there's no more modules
    
return FALSE//Failed.

    
BOOL bReturn oModule32NexthSnapshotlpme );

    return 
bReturn;

Then VAC2 thinks that it has gone thru the whole list of loaded modules (DLL's) in the process and found no hacks.

Now in our ReadProcessMemory hook we simply return 0:
PHP Code:
BOOL WINAPI hReadProcessMemoryHANDLE hProcessLPCVOID lpBaseAddressLPVOID lpBufferSIZE_T nSizeSIZE_T *lpNumberOfBytesRead )
{
    return 
0//Same thing as returning FALSE

Because, as MSDN (http://msdn.microsoft.com/en-us/libr...53(VS.85).aspx) tells us:
"If the function fails, the return value is 0 (zero)."

Then VAC2 thinks it can't read memory.

If this causes your game quitting etc, an alternative (and better) method is to let it perform the read, but modify the bytes in the return buffer so that they are "clean"..
Say you changed a EB (Jump) to a 90 (NOP) in the game, for example to do radar-hack, then VAC2 will notice this if they read that memory.
BUT if you let it read, then take the original bytes (from cache or from original game-module on harddrive (just read file)) then VAC2 will see there is nothing wrong with this memory and think it is real


Most people now only make their hacks "VAC2-proof" by unlinking module from PEB and hiding etc.
Much better is to attack VAC2 directly, kill it and bypass it, such as my tip above..



---------------------
Fully working source code

Ok, this is from my private VAC2 disabler and has been stripped some, but it's working fine.
PHP Code:
//n! yo

#define WIN32_LEAN_AND_MEAN
#include <Windows.h>

#include <TlHelp32.h>

#include "Detours.h"
#pragma comment(lib, "Detours.lib")

HMODULE hMod;

typedef BOOL WINAPI *tReadProcessMemory ) ( HANDLELPCVOIDLPVOIDSIZE_TSIZE_T* );
tReadProcessMemory oReadProcessMemory NULL;
BOOL WINAPI hReadProcessMemoryHANDLE hProcessLPCVOID lpBaseAddressLPVOID lpBufferSIZE_T nSizeSIZE_T *lpNumberOfBytesRead )
{
    return 
0;
}

typedef BOOL WINAPI *tModule32Next ) ( HANDLELPMODULEENTRY32 );
tModule32Next oModule32Next NULL;
BOOL WINAPI hModule32NextHANDLE hSnapshotLPMODULEENTRY32 lpme )
{
    
ZeroMemorylpme->szModuleMAX_MODULE_NAME32 ); //Let's remove module-name from the struct so they surely don't get any
    
lpme->modBaseAddr 0;
    
lpme->modBaseSize 0;
    
lpme->hModule NULL;
    
lpme->th32ModuleID 0;
    
lpme->th32ProcessID 0;
    
SetLastErrorERROR_NO_MORE_FILES ); //Tells them there's no more modules
    
return FALSE//Failed.

    
return oModule32NexthSnapshotlpme );
}

DWORD MainThreadLPVOID lpArgs )
{
    
//////////////////////////////////////////////////////////////////////////
    // Hook shit
    //
    
oReadProcessMemory = ( tReadProcessMemory )DetourFunction( (PBYTE)ReadProcessMemory, (PBYTE)hReadProcessMemory );
    
//WriteLog( "ReadProcessMemory hooked, original: %p, hook: %p", oReadProcessMemory, hReadProcessMemory );

    
Sleep1000 );

    
oModule32Next = ( tModule32Next )DetourFunction( (PBYTE)Module32Next, (PBYTE)hModule32Next );
    
//WriteLog( "Module32Next hooked, original: %p, hook: %p", oModule32Next, hModule32Next );

    
return 0;
}

BOOL WINAPI DllMainHMODULE hModuleDWORD dwReasonLPVOID lpReserved )
{
    if( 
dwReason == DLL_PROCESS_ATTACH )
    {
        
//////////////////////////////////////////////////////////////////////////
        // Initialize
        
hMod hModule;
        
DisableThreadLibraryCallshMod );

        
//////////////////////////////////////////////////////////////////////////
        // Start our main thread
        
DWORD dwThreadID;
        
HANDLE hThread CreateThreadNULLNULL, (LPTHREAD_START_ROUTINE)MainThreadNULLNULL, &dwThreadID );
    }

    return 
true;



----------
And last, a little tip some of you might not know..
This is usefull when hooking functions

First, in your includes:
PHP Code:
#include <intrin.h>
#pragma intrinsic(_ReturnAddress) 
Then use like this in your hooked function:
PHP Code:
WriteLog"Function returns to %p"_ReturnAddress() ); 
Then you see where the function returns to.
Can be usefull eg. to see if return is inside VAC2-module..



Good luck and have fun hacking


Best regards,
Nov.
__________________
Moo. ‾\(º_˚ )/‾
Nov is online now

Reply With Quote


Old 07-21-2009, 08:08 AM   #2
« Alkies Bitch »

Turv's Avatar

Join Date: Nov 2004
Posts: 1,460
Reputation: 12882
Rep Power: 246
Turv 's rep takes up 1 gig of server spaceTurv 's rep takes up 1 gig of server spaceTurv 's rep takes up 1 gig of server spaceTurv 's rep takes up 1 gig of server spaceTurv 's rep takes up 1 gig of server spaceTurv 's rep takes up 1 gig of server spaceTurv 's rep takes up 1 gig of server spaceTurv 's rep takes up 1 gig of server spaceTurv 's rep takes up 1 gig of server spaceTurv 's rep takes up 1 gig of server spaceTurv 's rep takes up 1 gig of server space
Last Achievements
Quote:
Originally Posted by Nov View Post
Most people now only make their hacks "VAC2-proof" by unlinking module from PEB and hiding etc.
Does this method still actually work? I remember all the crappy Payhack sites using this method i was hoping it would have been detected by now to put alot of them out of business lol.

Anyhow, Its very rare we see an actual tutorial on bypass an anti-cheat so props to you Nov, and a welldeserved +Rep.

Thanks for posting!
__________________


Turv is offline

Reply With Quote

Old 07-21-2009, 08:20 AM   #3
Super Moderator

Kiwinz's Avatar

Join Date: Jan 2008
Location: New Zealand
Posts: 2,550
Reputation: 73932
Rep Power: 840
Kiwinz has a huge epeen!Kiwinz has a huge epeen!Kiwinz has a huge epeen!Kiwinz has a huge epeen!Kiwinz has a huge epeen!Kiwinz has a huge epeen!Kiwinz has a huge epeen!Kiwinz has a huge epeen!Kiwinz has a huge epeen!Kiwinz has a huge epeen!Kiwinz has a huge epeen!
Points: 47,215, Level: 32
Points: 47,215, Level: 32 Points: 47,215, Level: 32 Points: 47,215, Level: 32
Activity: 25.9%
Activity: 25.9% Activity: 25.9% Activity: 25.9%
Last Achievements
Rep for the Tut
Nice Read
__________________



"Those who seek revenge must dig two graves, one for his enemy and another for himself."


On the internet I will - in no shape or form - take personal offence to peoples comments, idea's or views, I assume the people who I reply to won't either.
Kiwinz is online now

Reply With Quote

Old 07-21-2009, 09:35 AM   #4


Vossy's Avatar

Join Date: Jun 2008
Location: Estonia
Posts: 123
Reputation: 2561
Rep Power: 0
Vossy is a legend in the cheating communityVossy is a legend in the cheating communityVossy is a legend in the cheating communityVossy is a legend in the cheating communityVossy is a legend in the cheating communityVossy is a legend in the cheating communityVossy is a legend in the cheating communityVossy is a legend in the cheating communityVossy is a legend in the cheating communityVossy is a legend in the cheating communityVossy is a legend in the cheating community
Quote:
Originally Posted by Nov View Post
If this causes your game quitting etc, an alternative (and better) method is to let it perform the read, but modify the bytes in the return buffer so that they are "clean"..
Same concept actually applies to other anticheats too, like Punkbuster. Only difference is that they don't use same function for reading memory. Tip: memcpy_t
Good work.
Vossy is offline

Reply With Quote

Old 07-27-2009, 04:24 PM   #5
n00bie

kingdeking's Avatar

Join Date: Jul 2009
Posts: 7
Reputation: 10
Rep Power: 31
kingdeking has made posts that are generally average in quality
are you sure your hooks work properly. When trying to pop a MessageBox whenever ReadProcMemHook is called, nothing happens? No MessageBox appears. I am injecting the DLL into Steam :/
kingdeking is offline

Reply With Quote

Old 07-27-2009, 08:43 PM   #6
Hanoi's pimp

Jugga's Avatar

Join Date: May 2009
Location: United Kingdom
Posts: 357
Reputation: 8106
Rep Power: 122
Jugga DEFINES UNKNOWNCHEATSJugga DEFINES UNKNOWNCHEATSJugga DEFINES UNKNOWNCHEATSJugga DEFINES UNKNOWNCHEATSJugga DEFINES UNKNOWNCHEATSJugga DEFINES UNKNOWNCHEATSJugga DEFINES UNKNOWNCHEATSJugga DEFINES UNKNOWNCHEATSJugga DEFINES UNKNOWNCHEATSJugga DEFINES UNKNOWNCHEATSJugga DEFINES UNKNOWNCHEATS
Recognitions:
Members who have contributed financial support towards UnKnoWnCheaTs. Donation (2)
Points: 7,398, Level: 9
Points: 7,398, Level: 9 Points: 7,398, Level: 9 Points: 7,398, Level: 9
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Last Achievements
Quote:
Originally Posted by kingdeking View Post
are you sure your hooks work properly. When trying to pop a MessageBox whenever ReadProcMemHook is called, nothing happens? No MessageBox appears. I am injecting the DLL into Steam :/
If im right u hav to inject it into the game like CSS because that wat vac scans... not steam ^^ as steam is jus an application to download and launch from
__________________
Jugga is online now

Reply With Quote

Old 07-28-2009, 10:18 AM   #7
n00bie

kingdeking's Avatar

Join Date: Jul 2009
Posts: 7
Reputation: 10
Rep Power: 31
kingdeking has made posts that are generally average in quality
even if vac2 was not located in steam, the MessaeBox should appear as ReadProcessMemory is hooked and RPM should be called by steam.

also:
Quote:
Inject your DLL to Steam.exe (this is where VAC2 now resides, not like VAC1 which was inside the actual game)
kingdeking is offline

Reply With Quote

Old 07-31-2009, 09:05 PM   #8
Nov
The Legendary Cheater

Nov's Avatar

Threadstarter
Join Date: Nov 2008
Location: Sweden
Posts: 486
Reputation: 17501
Rep Power: 224
Nov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UC
Points: 13,971, Level: 15
Points: 13,971, Level: 15 Points: 13,971, Level: 15 Points: 13,971, Level: 15
Activity: 1.2%
Activity: 1.2% Activity: 1.2% Activity: 1.2%
Last Achievements
Quote:
Originally Posted by kingdeking View Post
even if vac2 was not located in steam, the MessaeBox should appear as ReadProcessMemory is hooked and RPM should be called by steam.
Not sure why Steam itself would call RPM since it only needs to do internal memory-reading?
__________________
Moo. ‾\(º_˚ )/‾
Nov is online now

Reply With Quote

Old 08-01-2009, 07:09 AM   #9
Affiliate VIP

zoomgod's Avatar

Join Date: Aug 2007
Posts: 2,491
Reputation: 73953
Rep Power: 843
zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!
Recognitions:
Members who have contributed financial support towards UnKnoWnCheaTs. Donation (2)
The UC Member of the Month award is a prestigious award given to a single community member on a monthly basis. Based on a vote by UnKnoWnCheaTs staff, the award is given to the forum member that has shown exemplary achievement and potential in the UnKnoWnCheaTs community, and has shown great commitment to upholding the principles upon which UnKnoWnCheaTs stands for. A member who has been awarded the Member of the Month award has been distinguished as an asset to the UnKnoWnCheaTs community. Member of the Month
Points: 46,850, Level: 32
Points: 46,850, Level: 32 Points: 46,850, Level: 32 Points: 46,850, Level: 32
Activity: 43.5%
Activity: 43.5% Activity: 43.5% Activity: 43.5%
Last Achievements
Quote:
Originally Posted by Nov View Post
Not sure why Steam itself would call RPM since it only needs to do internal memory-reading?
Because if it's no longer in the game's process it can't with a simple pointer. 0x400000 address for example would be relative to steams process not the games.
__________________
I'm like a virus, you can delete me but I am never really gone.
Links die, searching does not. (Fravia : searchlores.org)
Solving problems requires effort not a college degree.
zoomgod is offline

Reply With Quote

Old 08-01-2009, 11:48 AM   #10
Nov
The Legendary Cheater

Nov's Avatar

Threadstarter
Join Date: Nov 2008
Location: Sweden
Posts: 486
Reputation: 17501
Rep Power: 224
Nov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UC
Points: 13,971, Level: 15
Points: 13,971, Level: 15 Points: 13,971, Level: 15 Points: 13,971, Level: 15
Activity: 1.2%
Activity: 1.2% Activity: 1.2% Activity: 1.2%
Last Achievements
Quote:
Originally Posted by zoomgod View Post
Because if it's no longer in the game's process it can't with a simple pointer. 0x400000 address for example would be relative to steams process not the games.
Steam is always in it's own process.. maybe I've wrote something you guys have missinterpreted :X
__________________
Moo. ‾\(º_˚ )/‾
Nov is online now

Reply With Quote

Old 08-01-2009, 04:28 PM   #11
Retired Admin

learn_more's Avatar

Join Date: Sep 2006
Posts: 5,249
Reputation: 93628
Rep Power: 1106
learn_more has a huge epeen!learn_more has a huge epeen!learn_more has a huge epeen!learn_more has a huge epeen!learn_more has a huge epeen!learn_more has a huge epeen!learn_more has a huge epeen!learn_more has a huge epeen!learn_more has a huge epeen!learn_more has a huge epeen!learn_more has a huge epeen!
Recognitions:
Members who have contributed financial support towards UnKnoWnCheaTs. Donation (2)
sieg heil Nazi
Points: 70,490, Level: 39
Points: 70,490, Level: 39 Points: 70,490, Level: 39 Points: 70,490, Level: 39
Activity: 24.7%
Activity: 24.7% Activity: 24.7% Activity: 24.7%
Last Achievements
Award-Showcase
Quote:
Originally Posted by Nov View Post
Steam is always in it's own process.. maybe I've wrote something you guys have missinterpreted :X
but the game aint in steam process, and that needs to be checked for cheats, not steam :P
__________________
learn_more is offline

Reply With Quote

Old 08-01-2009, 05:37 PM   #12
Nov
The Legendary Cheater

Nov's Avatar

Threadstarter
Join Date: Nov 2008
Location: Sweden
Posts: 486
Reputation: 17501
Rep Power: 224
Nov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UCNov Will always be a legend at UC
Points: 13,971, Level: 15
Points: 13,971, Level: 15 Points: 13,971, Level: 15 Points: 13,971, Level: 15
Activity: 1.2%
Activity: 1.2% Activity: 1.2% Activity: 1.2%
Last Achievements
Yes.. Reason why it didn't trigger for him as I meant was because Steam don't use RPM, only VAC does.. so his MessageBox will only come when VAC scans (when a game is loaded & connected to VAC server)
__________________
Moo. ‾\(º_˚ )/‾
Nov is online now

Reply With Quote

Old 08-02-2009, 01:29 AM   #13
Affiliate VIP

zoomgod's Avatar

Join Date: Aug 2007
Posts: 2,491
Reputation: 73953
Rep Power: 843
zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!zoomgod has a huge epeen!
Recognitions:
Members who have contributed financial support towards UnKnoWnCheaTs. Donation (2)
The UC Member of the Month award is a prestigious award given to a single community member on a monthly basis. Based on a vote by UnKnoWnCheaTs staff, the award is given to the forum member that has shown exemplary achievement and potential in the UnKnoWnCheaTs community, and has shown great commitment to upholding the principles upon which UnKnoWnCheaTs stands for. A member who has been awarded the Member of the Month award has been distinguished as an asset to the UnKnoWnCheaTs community. Member of the Month
Points: 46,850, Level: 32
Points: 46,850, Level: 32 Points: 46,850, Level: 32 Points: 46,850, Level: 32
Activity: 43.5%
Activity: 43.5% Activity: 43.5% Activity: 43.5%
Last Achievements
Just a terminology confusion, if VAC2 is loaded in steam process that is a single process not two. I thought by your comment you were unsure why they used RPM to scan for cheats.

It's all good, nice post
__________________
I'm like a virus, you can delete me but I am never really gone.
Links die, searching does not. (Fravia : searchlores.org)
Solving problems requires effort not a college degree.
zoomgod is offline

Reply With Quote

Old 08-08-2009, 01:14 AM   #14
Level 3

fatboy88's Avatar

Join Date: May 2005
Posts: 1,103
Reputation: 38964
Rep Power: 494
fatboy88 has a huge epeen!fatboy88 has a huge epeen!fatboy88 has a huge epeen!fatboy88 has a huge epeen!fatboy88 has a huge epeen!fatboy88 has a huge epeen!fatboy88 has a huge epeen!fatboy88 has a huge epeen!fatboy88 has a huge epeen!fatboy88 has a huge epeen!fatboy88 has a huge epeen!
Recognitions:
The UC Member of the Month award is a prestigious award given to a single community member on a monthly basis. Based on a vote by UnKnoWnCheaTs staff, the award is given to the forum member that has shown exemplary achievement and potential in the UnKnoWnCheaTs community, and has shown great commitment to upholding the principles upon which UnKnoWnCheaTs stands for. A member who has been awarded the Member of the Month award has been distinguished as an asset to the UnKnoWnCheaTs community. Member of the Month
Points: 27,267, Level: 24
Points: 27,267, Level: 24 Points: 27,267, Level: 24 Points: 27,267, Level: 24
Activity: 9.9%
Activity: 9.9% Activity: 9.9% Activity: 9.9%
Last Achievements
Nice job sir Mrk <3
__________________


My greatest fear is a Windows Vista Update! D:

ȜǷ-ɲآɳᶨ4 Hack:http://img42.imageshack.us/img42/473/20090203132330.png
fatboy88 is online now

Reply With Quote

Old 08-24-2009, 06:15 PM   #15
h4x0!2

mencore's Avatar

Join Date: Jul 2009
Location: Finland
Posts: 102
Reputation: 3058
Rep Power: 64
mencore is a legend in the cheating communitymencore is a legend in the cheating communitymencore is a legend in the cheating communitymencore is a legend in the cheating communitymencore is a legend in the cheating communitymencore is a legend in the cheating communitymencore is a legend in the cheating communitymencore is a legend in the cheating communitymencore is a legend in the cheating communitymencore is a legend in the cheating communitymencore is a legend in the cheating community
Points: 3,785, Level: 6
Points: 3,785, Level: 6 Points: 3,785, Level: 6 Points: 3,785, Level: 6
Activity: 6.9%
Activity: 6.9% Activity: 6.9% Activity: 6.9%
Last Achievements
Excellent work mister!
mencore is offline

Reply With Quote

Old 12-05-2009, 10:43 PM   #16
Level ∞ Coder

CyberDwak's Avatar

Join Date: Oct 2009
Posts: 584
Reputation: 17985
Rep Power: 219
CyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UC
Recognitions:
Members who have contributed financial support towards UnKnoWnCheaTs. Donation (12)
Awarded to members who have donated 10 times or more. Gratuity (1)
Points: 12,456, Level: 14
Points: 12,456, Level: 14 Points: 12,456, Level: 14 Points: 12,456, Level: 14
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Last Achievements
wow...

Does this still work?

btw +rep!
CyberDwak is offline

Reply With Quote

Old 12-05-2009, 11:25 PM   #17
Level 3

DjOsiris's Avatar

Join Date: Aug 2003
Location: In Your Worst Nigtmares
Posts: 39
Reputation: 125
Rep Power: 105
DjOsiris is in the shadow of all hacking legendsDjOsiris is in the shadow of all hacking legends
Last Achievements
Quote:
Originally Posted by CyberDwak View Post
wow...

Does this still work?

btw +rep!
Since VAC has not been updated since this post was created I would think so. I pose a question for the forum about sinJect .. Is the method of injection it uses detected by VAC?
DjOsiris is offline

Reply With Quote

Old 12-13-2009, 09:19 PM   #18
UnKnoWnCheaTeR

Heim Werker's Avatar

Join Date: Dec 2007
Location: Deutsches Reich
Posts: 1,020
Reputation: 60587
Rep Power: 676
Heim Werker has a huge epeen!Heim Werker has a huge epeen!Heim Werker has a huge epeen!Heim Werker has a huge epeen!Heim Werker has a huge epeen!Heim Werker has a huge epeen!Heim Werker has a huge epeen!Heim Werker has a huge epeen!Heim Werker has a huge epeen!Heim Werker has a huge epeen!Heim Werker has a huge epeen!
Snake Champion Troll Rampage Champion Pathfinder Champion Electric Soldier Porygon Champion 2 Ball Pool Champion Boris The Bandit Champion All Ball Champion
Recognitions:
The UC Member of the Month award is a prestigious award given to a single community member on a monthly basis. Based on a vote by UnKnoWnCheaTs staff, the award is given to the forum member that has shown exemplary achievement and potential in the UnKnoWnCheaTs community, and has shown great commitment to upholding the principles upon which UnKnoWnCheaTs stands for. A member who has been awarded the Member of the Month award has been distinguished as an asset to the UnKnoWnCheaTs community. Member of the Month
Points: 40,036, Level: 30
Points: 40,036, Level: 30 Points: 40,036, Level: 30 Points: 40,036, Level: 30
Activity: 8.2%
Activity: 8.2% Activity: 8.2% Activity: 8.2%
Last Achievements
nice job thanks for posting.
Heim Werker is offline

Reply With Quote

Old 12-13-2009, 11:35 PM   #19
Level ∞ Coder

CyberDwak's Avatar

Join Date: Oct 2009
Posts: 584
Reputation: 17985
Rep Power: 219
CyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UCCyberDwak Will always be a legend at UC
Recognitions:
Members who have contributed financial support towards UnKnoWnCheaTs. Donation (12)
Awarded to members who have donated 10 times or more. Gratuity (1)
Points: 12,456, Level: 14
Points: 12,456, Level: 14 Points: 12,456, Level: 14 Points: 12,456, Level: 14
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Last Achievements
Ok, im using this( injected into steam )
and im hiding my module from PIB and im only useing undetected methods of making my hacks lol so I better not get detected. xD


EDIT:

Hmm...

When i add my logs The ReadProcessMemory calls like 500 times, and ERROR_NO_MORE_FILES only calls twice in a 10 Min game.

If this fine? should it be like this?

Last edited by CyberDwak; 12-14-2009 at 05:45 PM.
CyberDwak is offline

Reply With Quote

Old 12-18-2009, 12:38 AM   #20
My household appliance is on drugs. Horrible.

s0beit's Avatar

Join Date: Oct 2005
Location: ALWAYS WON NEVER DEFEAT
Posts: 812
Reputation: 70378
Rep Power: 796
s0beit has a huge epeen!s0beit has a huge epeen!s0beit has a huge epeen!s0beit has a huge epeen!s0beit has a huge epeen!s0beit has a huge epeen!s0beit has a huge epeen!s0beit has a huge epeen!s0beit has a huge epeen!s0beit has a huge epeen!s0beit has a huge epeen!
Recognitions:
Members who have contributed financial support towards UnKnoWnCheaTs. Donation (1)
Points: 46,529, Level: 32
Points: 46,529, Level: 32 Points: 46,529, Level: 32 Points: 46,529, Level: 32
Activity: 2.2%
Activity: 2.2% Activity: 2.2% Activity: 2.2%
Last Achievements
This will not cripple vac2 completely, and its very dangerous to just return "error" result codes when dealing with any anticheat, you should spoof the values so they are correct, and you should never detour ReadProcessMemory because odds are that data is checked too.

Also, Module32Next hook won't protect you.
__________________
s0beit is offline

Reply With Quote
Reply  

  • Submit Thread to Digg
  • Submit Thread to del.icio.us
  • Submit Thread to StumbleUpon
  • Submit Thread to Google
  • Submit Thread to Facebook
  • Submit Thread to My Yahoo!
  • Submit Thread to MySpace
  • Submit Thread to Twitter
  • Submit Thread to Reddit



Tags
bypassing, vac2
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT +1. The time now is 06:55 AM.