Thread: Bypassing xtrap

Page 1 of 3 123 LastLast
Results 1 to 15 of 32
  1. #1
    kmanev073's Avatar
    Join Date
    Feb 2011
    Gender
    male
    Location
    Bulgaria
    Posts
    2,400
    Reputation
    97
    Thanks
    2,537
    My Mood
    Cool

    Bypassing xtrap

    Hello guys,
    Since I started trying to bypass the XCrap I was thinking: So if we use normal bypass we get hack tool... so we know that it is not coused by xtrap bcs it is not running... it is not the crossfire.exe... the only one left is HGWC ! so if we suspend it before cf starts and add fake xtrapva.dll cf will load with it and we wont get detected file changing... I am not at home for this and next week so i wanted to disscuss with you... is XTrap bypass with no problems still possable ?

  2. The Following User Says Thank You to kmanev073 For This Useful Post:

    zerograve00 (09-08-2012)

  3. #2
    NanoGold's Avatar
    Join Date
    May 2012
    Gender
    male
    Posts
    56
    Reputation
    10
    Thanks
    23
    My Mood
    Paranoid
    I tried this before ,I Suspend HGWC after the game starts crossfire and it gives hack tool detected.. i think that hack tool is server sided error

  4. #3
    kmanev073's Avatar
    Join Date
    Feb 2011
    Gender
    male
    Location
    Bulgaria
    Posts
    2,400
    Reputation
    97
    Thanks
    2,537
    My Mood
    Cool
    @NanoGold you should release hgwc after replacing

  5. #4
    Avene's Avatar
    Join Date
    Jul 2012
    Gender
    male
    Posts
    134
    Reputation
    152
    Thanks
    2,052
    My Mood
    Relaxed
    Quote Originally Posted by NanoGold View Post
    I tried this before ,I Suspend HGWC after the game starts crossfire and it gives hack tool detected.. i think that hack tool is server sided error
    I'm pretty damn sure you need to remove crc checks for hgwc in crossfire.exe.

    You better ask HL.BOT about this but doubt he will answer you.

  6. #5
    kmanev073's Avatar
    Join Date
    Feb 2011
    Gender
    male
    Location
    Bulgaria
    Posts
    2,400
    Reputation
    97
    Thanks
    2,537
    My Mood
    Cool
    Quote Originally Posted by Avene View Post
    I'm pretty damn sure you need to remove crc checks for hgwc in crossfire.exe.

    You better ask HL.BOT about this but doubt he will answer you.
    he will maybe say he is busy but why guys always want to ask him ?!? there are plenty of other good and skilled guys

    + i think i tried in the past and it didnt detect file change but i didnt login :S i dont remember it was long time ago...

  7. #6
    Avene's Avatar
    Join Date
    Jul 2012
    Gender
    male
    Posts
    134
    Reputation
    152
    Thanks
    2,052
    My Mood
    Relaxed
    I dumped @Code64 's Code64 Hack [4-CF] v0.2 & i see XTrapVa.dll inside:

    Code:
    65612094   8B5D 08          MOV EBX,DWORD PTR SS:[EBP+8]
    65612097   68 58816165      PUSH Code64Dump.65618158                     ; ASCII "XTrapVa.dll"
    6561209C   53               PUSH EBX
    6561209D   FF15 B4806165    CALL DWORD PTR DS:[656180B4]             ; msvcr100.strstr
    656120A3   83C4 08          ADD ESP,8
    656120A6   85C0             TEST EAX,EAX
    656120A8   74 52            JE SHORT Code64Dump.656120FC
    656120AA   56               PUSH ESI
    656120AB   57               PUSH EDI
    656120AC   68 64816165      PUSH Code64Dump.65618164                     ; ASCII "LoadLibraryA"
    656120B1   68 74816165      PUSH Code64Dump.65618174                     ; ASCII "kernel32.dll"
    656120B6   FF15 08806165    CALL DWORD PTR DS:[65618008]             ; kernel32.GetModuleHandleA
    656120BC   50               PUSH EAX
    65612140   68 94816165      PUSH Code64Dump.65618194                     ; ASCII "XtrapVa.dll"
    65612145   FFD6             CALL ESI
    65612147   85C0             TEST EAX,EAX
    65612149   74 19            JE SHORT Code64Dump.65612164
    6561214B   E8 F0510000      CALL Code64Dump.65617340
    65612150   53               PUSH EBX
    65612151   E8 AAFEFFFF      CALL Code64Dump.65612000
    65612156   83C4 04          ADD ESP,4
    65612159   5E               POP ESI
    6561215A   B8 01000000      MOV EAX,1
    6561215F   5B               POP EBX
    65612160   5D               POP EBP
    65612161   C2 0C00          RETN 0C
    65612164   57               PUSH EDI
    65612165   68 64816165      PUSH Code64Dump.65618164                     ; ASCII "LoadLibraryA"
    6561216A   68 74816165      PUSH Code64Dump.65618174                     ; ASCII "kernel32.dll"
    6561216F   FFD6             CALL ESI
    65612171   50               PUSH EAX
    65612172   FF15 40806165    CALL DWORD PTR DS:[65618040]             ; apphelp.7210FFF6
    65612178   8B3D 10806165    MOV EDI,DWORD PTR DS:[65618010]          ; kernel32.VirtualProtect
    6561217E   8D70 02          LEA ESI,DWORD PTR DS:[EAX+2]
    65612181   8B06             MOV EAX,DWORD PTR DS:[ESI]
    65612183   8D55 0C          LEA EDX,DWORD PTR SS:[EBP+C]
    65612186   52               PUSH EDX
    65612187   6A 40            PUSH 40
    Like hackshield, patching some bytes in EHSvc.dll can make your base undetected.

  8. #7
    Hexicidal's Avatar
    Join Date
    Oct 2010
    Gender
    male
    Location
    What?
    Posts
    3,619
    Reputation
    -405
    Thanks
    6,106
    My Mood
    Busy
    Are you using MakeCall function ?

  9. #8
    giniyat101's Avatar
    Join Date
    Sep 2011
    Gender
    male
    Location
    Not telling.
    Posts
    1,935
    Reputation
    130
    Thanks
    1,380
    My Mood
    Dead
    why do u ask some questions ending with "is possible?" instead of trying yourself?


     



    [img]https://i43.photobucke*****m/albums/e367/DeteSting/Steam-update.gif[/img]

  10. #9
    BACKD00R's Avatar
    Join Date
    Jan 2010
    Gender
    male
    Location
    Brazil
    Posts
    10,711
    Reputation
    1814
    Thanks
    31,902
    My Mood
    Aggressive
    Quote Originally Posted by Avene View Post
    I dumped @Code64 's Code64 Hack [4-CF] v0.2 & i see XTrapVa.dll inside:

    Code:
    65612094   8B5D 08          MOV EBX,DWORD PTR SS:[EBP+8]
    65612097   68 58816165      PUSH Code64Dump.65618158                     ; ASCII "XTrapVa.dll"
    6561209C   53               PUSH EBX
    6561209D   FF15 B4806165    CALL DWORD PTR DS:[656180B4]             ; msvcr100.strstr
    656120A3   83C4 08          ADD ESP,8
    656120A6   85C0             TEST EAX,EAX
    656120A8   74 52            JE SHORT Code64Dump.656120FC
    656120AA   56               PUSH ESI
    656120AB   57               PUSH EDI
    656120AC   68 64816165      PUSH Code64Dump.65618164                     ; ASCII "LoadLibraryA"
    656120B1   68 74816165      PUSH Code64Dump.65618174                     ; ASCII "kernel32.dll"
    656120B6   FF15 08806165    CALL DWORD PTR DS:[65618008]             ; kernel32.GetModuleHandleA
    656120BC   50               PUSH EAX
    65612140   68 94816165      PUSH Code64Dump.65618194                     ; ASCII "XtrapVa.dll"
    65612145   FFD6             CALL ESI
    65612147   85C0             TEST EAX,EAX
    65612149   74 19            JE SHORT Code64Dump.65612164
    6561214B   E8 F0510000      CALL Code64Dump.65617340
    65612150   53               PUSH EBX
    65612151   E8 AAFEFFFF      CALL Code64Dump.65612000
    65612156   83C4 04          ADD ESP,4
    65612159   5E               POP ESI
    6561215A   B8 01000000      MOV EAX,1
    6561215F   5B               POP EBX
    65612160   5D               POP EBP
    65612161   C2 0C00          RETN 0C
    65612164   57               PUSH EDI
    65612165   68 64816165      PUSH Code64Dump.65618164                     ; ASCII "LoadLibraryA"
    6561216A   68 74816165      PUSH Code64Dump.65618174                     ; ASCII "kernel32.dll"
    6561216F   FFD6             CALL ESI
    65612171   50               PUSH EAX
    65612172   FF15 40806165    CALL DWORD PTR DS:[65618040]             ; apphelp.7210FFF6
    65612178   8B3D 10806165    MOV EDI,DWORD PTR DS:[65618010]          ; kernel32.VirtualProtect
    6561217E   8D70 02          LEA ESI,DWORD PTR DS:[EAX+2]
    65612181   8B06             MOV EAX,DWORD PTR DS:[ESI]
    65612183   8D55 0C          LEA EDX,DWORD PTR SS:[EBP+C]
    65612186   52               PUSH EDX
    65612187   6A 40            PUSH 40
    Like hackshield, patching some bytes in EHSvc.dll can make your base undetected.
    This code is not a bypass!



     

    Skype : BACKD00R-MPGH

     

    • Contributor: October, 31th 2011
    • CA BR Minion: January, 03th 2012
    • CF AL Minion: April, 07th 2012
    • CA Minion: April, 15th 2012
    • CF Minion: July, 03th 2012
    • PB Minion: January, 25th 2013
    • AVA Minion : February, 02th 2013
    • Arctic Combat minion: April, 03th 2013
    • Warface Minion: April, 03th 2013

    • Minion + : July 08th 2012
    • Moderator : January 21th 2013
    • Global Moderator : August 1st 2013







  11. #10
    Glenox's Avatar
    Join Date
    Jun 2012
    Gender
    male
    Location
    C:\WINDOWS\system32\Glenox.exe
    Posts
    539
    Reputation
    10
    Thanks
    2,372
    My Mood
    Bored
    try to bypass the x-trap and HGWC

    only crossfire.exe run with out x-trap and HGWC!!!
    Coming Soon,

  12. #11
    Andrea1234567890's Avatar
    Join Date
    Aug 2011
    Gender
    male
    Posts
    1
    Reputation
    10
    Thanks
    0
    There are some method:

    XTrap & HGWC still a****** Hooking APIs - Unlimited time
    HGWC still alive + suspend: 10 min + Hooking API
    HGWC still alive + suspend: 10 min + 2 Hooking APIs

    You can patch HGWC without suspend and can work 10 min.
    To make it work for unlimited time, you must search the connection between XTrap -> Keep alive.
    I've already did it for S4League but It's boring to do alawys detouring functions, I want search addys on XTrapVa.dll like time ago :C
    I've never played crossfire but exist a method to remove HGWC and playing. I must see the game :C

    EDIT: I'm downloading it to see C:
    EDIT2: Yes, my bypass work :c
    Last edited by Andrea1234567890; 09-06-2012 at 03:25 AM.

  13. #12
    kmanev073's Avatar
    Join Date
    Feb 2011
    Gender
    male
    Location
    Bulgaria
    Posts
    2,400
    Reputation
    97
    Thanks
    2,537
    My Mood
    Cool
    Quote Originally Posted by giniyat101 View Post
    why do u ask some questions ending with "is possible?" instead of trying yourself?
    bcs i am not at home for 1 week and could not w8

    ---------- Post added at 01:54 PM ---------- Previous post was at 01:52 PM ----------

    PS... so if i find the ip that xtrap sends packets to... and start pinging it with CMD and start the game with no xtrap we could possably make some bypass correct ?

  14. #13
    [WPGH]Infinity's Avatar
    Join Date
    Sep 2012
    Gender
    male
    Posts
    0
    Reputation
    10
    Thanks
    2
    My Mood
    Yeehaw
    kmanev073 signature:

    On 27.09.2011 one great man with nickname kmanev073 siad: You don't need to be pro to be one from the best but you can't be the best if you are not pro so Never say Never ! Dont give up ! And live untill you are able !

    "siad", yeah should be an awsome man.

  15. The Following User Says Thank You to [WPGH]Infinity For This Useful Post:

    kmanev073 (09-06-2012)

  16. #14
    kmanev073's Avatar
    Join Date
    Feb 2011
    Gender
    male
    Location
    Bulgaria
    Posts
    2,400
    Reputation
    97
    Thanks
    2,537
    My Mood
    Cool
    Quote Originally Posted by [WPGH]Infinity View Post
    kmanev073 signature:

    On 27.09.2011 one great man with nickname kmanev073 siad: You don't need to be pro to be one from the best but you can't be the best if you are not pro so Never say Never ! Dont give up ! And live untill you are able !

    "siad", yeah should be an awsome man.
    whats wrong ?!? i was in the bed tying to sleep and... just... said that hehe

    PS ehehehheee i have written it wrong

    ---------- Post added at 09:53 PM ---------- Previous post was at 09:52 PM ----------

    PS 2 fixed it thanks for telling me... now please on topic

  17. The Following User Says Thank You to kmanev073 For This Useful Post:

    [WPGH]Infinity (09-07-2012)

  18. #15
    justinsswagga's Avatar
    Join Date
    Aug 2012
    Gender
    male
    Posts
    49
    Reputation
    10
    Thanks
    148
    My Mood
    Confused
    I can't dump crossfire.

Page 1 of 3 123 LastLast

Similar Threads

  1. Bypassing Xtrap
    By wiggieles in forum General Hacking
    Replies: 0
    Last Post: 11-09-2008, 08:09 AM
  2. bypass xtrap
    By dude123 in forum WolfTeam General
    Replies: 6
    Last Post: 02-29-2008, 01:19 AM
  3. Bypassed Xtrap
    By apezwijn in forum WolfTeam Hacks
    Replies: 7
    Last Post: 10-20-2007, 12:22 AM
  4. How to bypass Xtrap ? Then Use Actool instead of KoxP !
    By kcetinkaya in forum Knight Online Hacks
    Replies: 2
    Last Post: 07-18-2007, 07:01 PM