Use BlackLegend Logger.
HS CallBack
HS CallBack2
HS SuperScan
HS SuperScan2
HS Detection
HS CrashOnDetect
HS Anti-Shield
HS HackCheck
HS HackCheck2
HS LoadOnGameStart
HS KillProcess
I'm Dump Ehsvc.dll,.
i want to find address bypass Hakshield,
see here i found :
HSCallBack1 C3 =
10001000 53 PUSH EBX
10001001 55 PUSH EBP
10001002 8B6C24 0C MOV EBP,DWORD PTR SS:[ESP+C]
10001006 8B5C24 10 MOV EBX,DWORD PTR SS:[ESP+10]
1000100A 8B4C24 14 MOV ECX,DWORD PTR SS:[ESP+14]
1000100E 8B4424 18 MOV EAX,DWORD PTR SS:[ESP+18]
10001012 8B5424 1C MOV EDX,DWORD PTR SS:[ESP+1C] ; ntdll.7C90E900
10001016 F0:0FC74D 00 LOCK CMPXCHG8B QWORD PTR SS:[EBP] ; LOCK prefix
1000101B 5D POP EBP ; ntdll.7C950010
1000101C 5B POP EBX ; ntdll.7C950010
1000101D C3 RETN
1000101E 90 NOP
1000101F 90 NOP
10001020 53 PUSH EBX
10001021 55 PUSH EBP
10001022 8B6C24 14 MOV EBP,DWORD PTR SS:[ESP+14]
10001026 56 PUSH ESI
10001027 57 PUSH EDI
10001028 8B7C24 14 MOV EDI,DWORD PTR SS:[ESP+14]
1000102C 8B37 MOV ESI,DWORD PTR DS:[EDI]
1000102E 8B5F 04 MOV EBX,DWORD PTR DS:[EDI+4]
10001031 8B4424 18 MOV EAX,DWORD PTR SS:[ESP+18]
where address HSCallBack1 and more?
thank.
sory bad english.
Use BlackLegend Logger.
all depending on Google and must of all application infected with viruses