emiedumalasa (02-23-2021),mamo007 (02-21-2021),SpiderEater420 (02-23-2021),TheGe2k (02-22-2021)
Hello MPGH, today I'll share how to disable CodeHunter (Internal AntiCheat).
This address is for CFPH.
Good Luck
Don't ask to me how to use it.
Code:MemCpy((void*)(dwCodeHunterBase + 0x19070), (void*)"\xC3", 1); //Pattern Scan MemCpy((void*)(dwCodeHunterBase + 0x9D70), (void*)"\xC3", 1); // Detect VTable MemCpy((void*)(dwCodeHunterBase + 0x8C10), (void*)"\xC3", 1); //Detect Resource MemCpy((void*)(dwCodeHunterBase + 0x1480), (void*)"\xC3", 1); //Detect module MemCpy((void*)(dwCodeHunterBase + 0x42E0), (void*)"\xC3", 1); //Detect Byte
Last edited by dreek1; 02-21-2021 at 02:23 PM.
Public Hack:Jun 2012 / Dec 2017
emiedumalasa (02-23-2021),mamo007 (02-21-2021),SpiderEater420 (02-23-2021),TheGe2k (02-22-2021)
surprised no one asks how to use it even after 24h lol
Then, I will be the first who’s asking on how to use it?
DWORD dwCodeHunterBase = (DWORD)GetModuleHandleA(CShell);
I’m just kidding, @dreek1 how about the codehunter function inside crossfire.exe I just remembered, maybe 4 years ago when I’m exploring the crossfire.exe I notice the said function but I just ignore it. Anyway, with all due respect, would you mind providing pattern on the posted addresses, thank you.
Last edited by emiedumalasa; 02-23-2021 at 09:21 PM.
is this thing can bypass heartbeat check?
nice
Last edited by Anger5K; 03-11-2021 at 09:28 PM.
My Own Hack!!!
How about updating those offset ? I manage to get the dwCodeHunterBase but i got confused how I would be able to update those offsets .
Hopefully you can give some tips. Thank you
Dumped CodeHunter module : (Please Approve )
https://www.virustotal.com/gui/file/...363d/detection
Last edited by oMega_Pie; 04-13-2021 at 06:16 AM. Reason: Added Dump File for reference.
Anger5K (09-03-2021),qq963485005 (06-04-2021),sevengo (04-21-2021),VRXX (04-13-2021)