Red faceDoes anyone know UAV address?

Posts 1–15 of 17 · Page 1 of 2
Does anyone know UAV address?
Does some "smart brain" knows the uav address please? d: All I need to know is that address. I want to release my first public ava hack since old hackers don't release it anymore D:
lol Ask ccman32 he need for Uav hack 5 Mins :v
ccman32 isn't even active on MPGH anymore. Maybe @Jabberwock or @RedHunter can provide you with the answer to this question of yours.
Quote Originally Posted by Hunter View Post
ccman32 isn't even active on MPGH anymore. Maybe @Jabberwock or @RedHunter can provide you with the answer to this question of yours.
Idk about UAV address because Im new on this game . Still learning on It .
Jabberwock's not active because he's in the military, he goes two weeks at a time and gets a week off + breaks in between and he has other things to do when he's off
Also, there's no heartbeat so do some research and you'll find out how to find current xigncode address and make a bypass from that
Quote Originally Posted by Scythen View Post
Also, there's no heartbeat so do some research and you'll find out how to find current xigncode address and make a bypass from that
what so my bypass will work again
Quote Originally Posted by antep2727 View Post
what so my bypass will work again
Update your xigncode address in your source of course, it should work.
Quote Originally Posted by Scythen View Post
Also, there's no heartbeat so do some research and you'll find out how to find current xigncode address and make a bypass from that
OHh Im taking care of that right now buddy
Quote Originally Posted by Scythen View Post
Also, there's no heartbeat so do some research and you'll find out how to find current xigncode address and make a bypass from that

0026CE40 55 PUSH EBP // Current addy for Xingcode initialization

- - - Updated - - -

UAV Starts at "ava.exe"+01C5AA10 / 3ac / 24cc / 0 / 59c type Binary length 1 / Start bit (7) You're welcome ....
Increment the zero offset by a factor of two to get the others . ( 3ac / 24cc /8 / 59c ) ( 3ac / 24cc /10 / 59c )

- - - Updated - - -

Quote Originally Posted by foxofor6 View Post
Does some "smart brain" knows the uav address please? d: All I need to know is that address. I want to release my first public ava hack since old hackers don't release it anymore D:
If you know how to use cheat engine... The table below is for reference only...

 
AVA cheat engine UAV (reference only)
<?xml version="1.0" encoding="utf-8"?>
<CheatTable CheatEngineTableVersion="16">
<CheatEntries>
<CheatEntry>
<ID>4</ID>
<Description>"super weapons "</Description>
<Color>80000008</Color>
<VariableType>4 Bytes</VariableType>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>778</Offset>
<Offset>40C</Offset>
<Offset>230</Offset>
</Offsets>
<Hotkeys>
<Hotkey>
<Action>Activate</Action>
<Keys>
<Key>97</Key>
</Keys>
<ID>0</ID>
</Hotkey>
<Hotkey>
<Action>Deactivate</Action>
<Keys>
<Key>98</Key>
</Keys>
<ID>1</ID>
</Hotkey>
<Hotkey>
<Action>Set Value</Action>
<Keys>
<Key>97</Key>
</Keys>
<Value>55</Value>
<ID>2</ID>
</Hotkey>
<Hotkey>
<Action>Set Value</Action>
<Keys>
<Key>100</Key>
</Keys>
<Value>3</Value>
<ID>3</ID>
</Hotkey>
</Hotkeys>
</CheatEntry>
<CheatEntry>
<ID>5</ID>
<Description>"unlimited ammo "</Description>
<Color>80000008</Color>
<VariableType>Byte</VariableType>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>75D</Offset>
<Offset>40C</Offset>
<Offset>230</Offset>
</Offsets>
<Hotkeys>
<Hotkey>
<Action>Toggle Activation</Action>
<Keys>
<Key>97</Key>
</Keys>
<ID>0</ID>
</Hotkey>
<Hotkey>
<Action>Deactivate</Action>
<Keys>
<Key>98</Key>
</Keys>
<ID>1</ID>
</Hotkey>
</Hotkeys>
</CheatEntry>
<CheatEntry>
<ID>7</ID>
<Description>"recoil"</Description>
<Color>80000008</Color>
<VariableType>Float</VariableType>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>894</Offset>
<Offset>40C</Offset>
<Offset>230</Offset>
</Offsets>
<Hotkeys>
<Hotkey>
<Action>Toggle Activation</Action>
<Keys>
<Key>97</Key>
</Keys>
<ID>0</ID>
</Hotkey>
<Hotkey>
<Action>Deactivate</Action>
<Keys>
<Key>98</Key>
</Keys>
<ID>1</ID>
</Hotkey>
<Hotkey>
<Action>Set Value</Action>
<Keys>
<Key>97</Key>
</Keys>
<Value>0</Value>
<ID>2</ID>
</Hotkey>
</Hotkeys>
</CheatEntry>
<CheatEntry>
<ID>8</ID>
<Description>"recoil"</Description>
<Color>80000008</Color>
<VariableType>Float</VariableType>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>890</Offset>
<Offset>40C</Offset>
<Offset>230</Offset>
</Offsets>
<Hotkeys>
<Hotkey>
<Action>Toggle Activation</Action>
<Keys>
<Key>97</Key>
</Keys>
<ID>0</ID>
</Hotkey>
<Hotkey>
<Action>Deactivate</Action>
<Keys>
<Key>98</Key>
</Keys>
<ID>1</ID>
</Hotkey>
<Hotkey>
<Action>Set Value</Action>
<Keys>
<Key>97</Key>
</Keys>
<Value>0</Value>
<ID>2</ID>
</Hotkey>
</Hotkeys>
</CheatEntry>
<CheatEntry>
<ID>9</ID>
<Description>"spread"</Description>
<Color>80000008</Color>
<VariableType>Float</VariableType>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>B58</Offset>
<Offset>40C</Offset>
<Offset>230</Offset>
</Offsets>
<Hotkeys>
<Hotkey>
<Action>Activate</Action>
<Keys>
<Key>97</Key>
</Keys>
<ID>0</ID>
</Hotkey>
<Hotkey>
<Action>Deactivate</Action>
<Keys>
<Key>98</Key>
</Keys>
<ID>1</ID>
</Hotkey>
<Hotkey>
<Action>Set Value</Action>
<Keys>
<Key>97</Key>
</Keys>
<Value>3</Value>
<ID>2</ID>
</Hotkey>
<Hotkey>
<Action>Increase Value</Action>
<Keys>
<Key>38</Key>
</Keys>
<Value>.5</Value>
<ID>3</ID>
</Hotkey>
<Hotkey>
<Action>Decrease Value</Action>
<Keys>
<Key>40</Key>
</Keys>
<Value>0.5</Value>
<ID>4</ID>
</Hotkey>
<Hotkey>
<Action>Set Value</Action>
<Keys>
<Key>99</Key>
</Keys>
<Value>0.25</Value>
<ID>5</ID>
</Hotkey>
<Hotkey>
<Action>Set Value</Action>
<Keys>
<Key>100</Key>
</Keys>
<Value>0</Value>
<ID>6</ID>
</Hotkey>
</Hotkeys>
</CheatEntry>
<CheatEntry>
<ID>6</ID>
<Description>"rapid fire "</Description>
<Color>80000008</Color>
<VariableType>Float</VariableType>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>9D8</Offset>
<Offset>230</Offset>
</Offsets>
</CheatEntry>
<CheatEntry>
<ID>16</ID>
<Description>"uav"</Description>
<Color>80000008</Color>
<VariableType>Binary</VariableType>
<BitStart>7</BitStart>
<BitLength>1</BitLength>
<ShowAsBinary>0</ShowAsBinary>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>59C</Offset>
<Offset>0</Offset>
<Offset>24CC</Offset>
<Offset>3AC</Offset>
</Offsets>
</CheatEntry>
<CheatEntry>
<ID>10</ID>
<Description>"uav"</Description>
<Color>80000008</Color>
<VariableType>Binary</VariableType>
<BitStart>7</BitStart>
<BitLength>1</BitLength>
<ShowAsBinary>0</ShowAsBinary>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>59C</Offset>
<Offset>8</Offset>
<Offset>24CC</Offset>
<Offset>3AC</Offset>
</Offsets>
</CheatEntry>
<CheatEntry>
<ID>15</ID>
<Description>"uav"</Description>
<Color>80000008</Color>
<VariableType>Binary</VariableType>
<BitStart>7</BitStart>
<BitLength>1</BitLength>
<ShowAsBinary>0</ShowAsBinary>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>59C</Offset>
<Offset>10</Offset>
<Offset>24CC</Offset>
<Offset>3AC</Offset>
</Offsets>
</CheatEntry>
<CheatEntry>
<ID>17</ID>
<Description>"uav"</Description>
<Color>80000008</Color>
<VariableType>Binary</VariableType>
<BitStart>7</BitStart>
<BitLength>1</BitLength>
<ShowAsBinary>0</ShowAsBinary>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>59C</Offset>
<Offset>18</Offset>
<Offset>24CC</Offset>
<Offset>3AC</Offset>
</Offsets>
</CheatEntry>
<CheatEntry>
<ID>18</ID>
<Description>"uav"</Description>
<Color>80000008</Color>
<VariableType>Binary</VariableType>
<BitStart>7</BitStart>
<BitLength>1</BitLength>
<ShowAsBinary>0</ShowAsBinary>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>59C</Offset>
<Offset>28</Offset>
<Offset>24CC</Offset>
<Offset>3AC</Offset>
</Offsets>
</CheatEntry>
<CheatEntry>
<ID>19</ID>
<Description>"uav"</Description>
<Color>80000008</Color>
<VariableType>Binary</VariableType>
<BitStart>7</BitStart>
<BitLength>1</BitLength>
<ShowAsBinary>0</ShowAsBinary>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>59C</Offset>
<Offset>50</Offset>
<Offset>24CC</Offset>
<Offset>3AC</Offset>
</Offsets>
</CheatEntry>
<CheatEntry>
<ID>20</ID>
<Description>"uav"</Description>
<Color>80000008</Color>
<VariableType>Binary</VariableType>
<BitStart>7</BitStart>
<BitLength>1</BitLength>
<ShowAsBinary>0</ShowAsBinary>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>59C</Offset>
<Offset>58</Offset>
<Offset>24CC</Offset>
<Offset>3AC</Offset>
</Offsets>
</CheatEntry>
<CheatEntry>
<ID>21</ID>
<Description>"uav"</Description>
<Color>80000008</Color>
<VariableType>Byte</VariableType>
<Address>"ava.exe"+01C5AA10</Address>
<Offsets>
<Offset>59C</Offset>
<Offset>90</Offset>
<Offset>24CC</Offset>
<Offset>3AC</Offset>
</Offsets>
</CheatEntry>
</CheatEntries>
<CheatCodes>
<CodeEntry>
<Description>Change of movss xmm0,[ebp-04]</Description>
<Address>016A98FB</Address>
<ModuleName>ava.exe</ModuleName>
<ModuleNameOffset>7798FB</ModuleNameOffset>
<Before>
<Byte>02</Byte>
<Byte>8B</Byte>
<Byte>E5</Byte>
<Byte>5D</Byte>
<Byte>C3</Byte>
</Before>
<Actual>
<Byte>F3</Byte>
<Byte>0F</Byte>
<Byte>10</Byte>
<Byte>45</Byte>
<Byte>FC</Byte>
</Actual>
<After>
<Byte>A1</Byte>
<Byte>40</Byte>
<Byte>1E</Byte>
<Byte>01</Byte>
<Byte>02</Byte>
</After>
</CodeEntry>
<CodeEntry>
<Description>Change of mov [ava.exe+1C5AA10],eax</Description>
<Address>016A996F</Address>
<ModuleName>ava.exe</ModuleName>
<ModuleNameOffset>77996F</ModuleNameOffset>
<Before>
<Byte>FF</Byte>
<Byte>83</Byte>
<Byte>C4</Byte>
<Byte>04</Byte>
<Byte>5F</Byte>
</Before>
<Actual>
<Byte>A3</Byte>
<Byte>10</Byte>
<Byte>AA</Byte>
<Byte>B8</Byte>
<Byte>02</Byte>
</Actual>
<After>
<Byte>5E</Byte>
<Byte>8B</Byte>
<Byte>E5</Byte>
<Byte>5D</Byte>
<Byte>C3</Byte>
</After>
</CodeEntry>
<CodeEntry>
<Description>Change of add [eax],al</Description>
<Address>5379DB38</Address>
<ModuleName/>
<ModuleNameOffset>0</ModuleNameOffset>
<Before>
<Byte>20</Byte>
<Byte>00</Byte>
<Byte>00</Byte>
<Byte>C8</Byte>
<Byte>42</Byte>
</Before>
<Actual>
<Byte>00</Byte>
<Byte>00</Byte>
</Actual>
<After>
<Byte>C8</Byte>
<Byte>42</Byte>
<Byte>00</Byte>
<Byte>00</Byte>
<Byte>00</Byte>
</After>
</CodeEntry>
<CodeEntry>
<Description>Change of inc edx</Description>
<Address>5379DB37</Address>
<ModuleName/>
<ModuleNameOffset>0</ModuleNameOffset>
<Before>
<Byte>34</Byte>
<Byte>20</Byte>
<Byte>00</Byte>
<Byte>00</Byte>
<Byte>C8</Byte>
</Before>
<Actual>
<Byte>42</Byte>
</Actual>
<After>
<Byte>90</Byte>
<Byte>90</Byte>
<Byte>C8</Byte>
<Byte>42</Byte>
<Byte>00</Byte>
</After>
</CodeEntry>
<CodeEntry>
<Description>Change of dec esp</Description>
<Address>5379DB2D</Address>
<ModuleName/>
<ModuleNameOffset>0</ModuleNameOffset>
<Before>
<Byte>00</Byte>
<Byte>00</Byte>
<Byte>00</Byte>
<Byte>00</Byte>
<Byte>CD</Byte>
</Before>
<Actual>
<Byte>4C</Byte>
</Actual>
<After>
<Byte>80</Byte>
<Byte>42</Byte>
<Byte>00</Byte>
<Byte>5D</Byte>
<Byte>34</Byte>
</After>
</CodeEntry>
</CheatCodes>

</Structure>
</Structures>
<Comments>Info about this table:
</Comments>
</CheatTable>




 
Bypass source (working)
#include <Windows.h>
#include <iostream>
#include <tlhelp32.h>
#include <stdio.h>

using namespace std;

DWORD GetProcessId(const TCHAR* lpProcessName)
{
DWORD dwProcessId = 0;

PROCESSENTRY32 entry;
entry.dwSize = sizeof(PROCESSENTRY32);

HANDLE snapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, NULL);

if (snapshot != INVALID_HANDLE_VALUE)
{
if (Process32First(snapshot, &entry))
{
do
{
if (_wcsicmp(entry.szExeFile, lpProcessName) == 0)
{
dwProcessId = entry.th32ProcessID;
break;
}
} while (Process32Next(snapshot, &entry));
}

CloseHandle(snapshot);
}

return dwProcessId;
}

void suspend(DWORD processId)
{
HANDLE hThreadSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPTHREAD, 0);

THREADENTRY32 threadEntry;
threadEntry.dwSize = sizeof(THREADENTRY32);

if (hThreadSnapshot != INVALID_HANDLE_VALUE)
{
if (Thread32First(hThreadSnapshot, &threadEntry))
{
do
{
if (threadEntry.th32OwnerProcessID == processId)
{
HANDLE hThread = OpenThread(THREAD_ALL_ACCESS, FALSE, threadEntry.th32ThreadID);

if (hThread)
{
SuspendThread(hThread);
CloseHandle(hThread);
}

}
} while (Thread32Next(hThreadSnapshot, &threadEntry));
}

CloseHandle(hThreadSnapshot);
}
}

int main(int argc, TCHAR* argv[])
{
HANDLE h = GetStdHandle(STD_OUTPUT_HANDLE);
SetConsoleTextAttribute(h, FOREGROUND_RED | FOREGROUND_INTENSITY);

SetConsoleTitle(TEXT(" ByPass.exe "));



cout << "ByPass" << endl;

DWORD dwProcessId;

while (!(dwProcessId = GetProcessId(TEXT("AVA.exe"))))
Sleep(1);


cout << "Searching for Xingcode!" << endl;

SetConsoleTextAttribute(h, FOREGROUND_GREEN | FOREGROUND_INTENSITY);

HANDLE hProcess = OpenProcess(PROCESS_VM_READ | PROCESS_VM_WRITE | PROCESS_VM_OPERATION, FALSE, dwProcessId);

if (hProcess)
{
cout << "XingCode Located..." << endl;

SetConsoleTextAttribute(h, FOREGROUND_RED | FOREGROUND_INTENSITY);


const DWORD dwLocationOfFunction = 0x0026CE40; //Update this value

INT Offsets;
BYTE FirstByte;



DWORD dwOldProtection;

while (!ReadProcessMemory(hProcess, (LPVOID)dwLocationOfFunction, &FirstByte, sizeof(FirstByte), NULL) || FirstByte != 0x55)
{
if (GetLastError() == ERROR_ACCESS_DENIED)
cout << "ERROR_ACCESS_DENIED" << endl;

Sleep(1);
}



//cout << "Bypassing Xingcode" << endl;


SetConsoleTextAttribute(h, FOREGROUND_GREEN | FOREGROUND_INTENSITY);

const BYTE ByteToWrite = 0xc3;



BOOL bSuccess = VirtualProtectEx(hProcess, (LPVOID)dwLocationOfFunction, sizeof(FirstByte), PAGE_EXECUTE_READWRITE, &dwOldProtection);

if (bSuccess)
bSuccess = WriteProcessMemory(hProcess, (LPVOID)dwLocationOfFunction, &ByteToWrite, sizeof(ByteToWrite), NULL);

CloseHandle(hProcess);


if (bSuccess)



cout << "Xingcode Bypassed " << endl;




}



cin.get();
return 0;
}
Quote Originally Posted by SneakyM0F0 View Post
0026CE40 55 PUSH EBP // Current addy for Xingcode initialization

- - - Updated - - -

UAV Starts at "ava.exe"+01C5AA10 / 3ac / 24cc / 0 / 59c type Binary length 1 / Start bit (7) You're welcome ....
Increment the zero offset by a factor of two to get the others . ( 3ac / 24cc /8 / 59c ) ( 3ac / 24cc /10 / 59c )

- - - Updated - - -



If you know how to use cheat engine ...
yea dude im working on it thanks men
I included some reference code . Copy paste will not work just use the info it is all correct . The bypass is working if you know how to use it in a C++ console app.
Hmm interesting to see that my source code is still on the web. And as a side note, SneakyM0F0; AVA.exe module has a dynamic base address this time so it might not always work... You need to find the base address of the module, then add the offset.
Quote Originally Posted by Jabberwock View Post
Hmm interesting to see that my source code is still on the web. And as a side note, SneakyM0F0; AVA.exe module has a dynamic base address this time so it might not always work... You need to find the base address of the module, then add the offset.
Thanks for the tip and yeah it is your source FULL CREDITS on the method. There is more than one way of doing this though
Quote Originally Posted by Jabberwock View Post
Hmm interesting to see that my source code is still on the web. And as a side note, SneakyM0F0; AVA.exe module has a dynamic base address this time so it might not always work... You need to find the base address of the module, then add the offset.
Could you tell me if xigncode blocks openprocess ?
Quote Originally Posted by SneakyM0F0 View Post
Thanks for the tip and yeah it is your source FULL CREDITS on the method. There is more than one way of doing this though
nahh... Didn't mention it for the credits though.

Quote Originally Posted by antep2727 View Post
Could you tell me if xigncode blocks openprocess ?
Yep. They do block it. That's why you need to do your stuff before they load their driver.

With a lua script you can go about it like this:

Code:
function loop()
    local hud = readInteger('["ava.exe"+01c5aa10]+3ac')
    if hud ~= nil and hud ~= 0 then
       local count = readInteger('[["ava.exe"+01c5aa10]+3ac]+24d0')
       if count ~= nil and count > 1 then
          local array = readInteger('[["ava.exe"+01c5aa10]+3ac]+24cc')
          for i=0, count-2 do
              local pawn = readInteger(array + i*8)
              if pawn ~= nil and pawn ~= 0 then
                 local uav = pawn + 0x59c
                 local value = bOr(readBytes(uav, 1), 0x80)
                 writeBytes(uav, value)
              end
          end
       end
    end
end

function bypass(timer)
  if getOpenedProcessID() == 0 then
    openProcess("ava.exe")
  end
  if getOpenedProcessID() ~= 0 then
    if readBytes('"ava.exe"+1d310', 1) == 0x55 then
      writeBytes('"ava.exe"+1d310', 0xc3)
      timer_setInterval(timer, 500)
      timer_onTimer(timer, loop)
    end
  end
end

t = createTimer(nil);
timer_setInterval(t, 10)
timer_onTimer(t, bypass)
Posts 1–15 of 17 · Page 1 of 2
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?