Well, I'll just tell you what I know. I know their are certain .dll files that xtrap spoofs your computer with. Also I know that xtrap sends out packets with this data invoked in it. My idea of a bypass would be along the lines of a snatch and grab. Find the file xtrap writes to and manipulate it, in the respects of ambiguity. Then proceed to re-route that file back to the correlating port, to be sent out. Thus lye making the sever believe we are not exploiting it.
Now what .dll's they are I have no idea, I'm not fluent in that respect. As for narrowing down the port and the protocol, that's child play.