CA-NA [BYPASS ADDIES]

Posts 1–15 of 24 · Page 1 of 2
CA-NA [BYPASS ADDIES]
Credits to BigBoy for finding these addies
0xD1E44
0xD4328
0xD4334
0xD5A88
0xD5AD4
0xD5B04
0xCA2EC
0xC92F8
0xD0AC8
0xCA2EC
0xD5B04
0xD5B0C
0xC92FC
0xC92F4
0xD4340
0xD0680
0xD3E28
0xD3E48
0xD691C
0xCA2EC
0xD5ACC
0xD43C4
0xD4334
if this has been posted before
although i doubt it has
close
this has not been posted before, but most people dont know how to use them
I know you guys don't like it but this is what the source section is for so moved
Nice, lets see if i can do anything with them
Quote Originally Posted by zmansquared View Post
Nice, lets see if i can do anything with them
Good Luck..
zman, if u get anythin. make sure to pack it. -.-
Dont worry. the only problem is that choobs think its a virus if i pack it with themida
Quote Originally Posted by zmansquared View Post
Dont worry. the only problem is that choobs think its a virus if i pack it with themida
You shouldn't worry about them [us]. If they [we] can't interpret the virus scans, then they [we] shouldn't download them in the first place. :P

Good luck on your endeavors.
Quote Originally Posted by zmansquared View Post
Dont worry. the only problem is that choobs think its a virus if i pack it with themida
Fuck the choobs, lol If they think it's a virus, it's less likely to be leeched and detected.
ok thanks, i was just saying
also another good point.

/lock thread (trying to keep spam down) but dont delete
Anyway we could get more info? It'd be helpful to know what each address is to.
if u packed with UPX or somethin. it wouldnt show up as much on the virus scans
What we do with the addies? i try OLLYDBG i didnt find anything what we need to do? to make this work?
This could help some people. I remembered that I had this floating around in a folder. I changed the addresses around to the one's ihelper released. This may not be right...i been working on it and i get this one error with the header.


it's an example of how a bypass works.
I don't know much about code so don't flame if you cant get it to work.
because i can't neither.!
All i say is, just mess with it.
Code:
////////////////////////////////////////begin///////////

#define "x_file.h"

int EhSvc = (long)GetModuleHandleA("EhSvc.dll");
'if'(EhSvc !=0);{
DWORD OldProtect;

int EhPtr   = (0xD1E44);
int Memory1 =(EhSvc+0xD4328);//HS-Addy
int Memory2 =(EhSvc+0xD4334);//Hs-Addy-Jump
int Memory3 =(EhSvc+0xD5A88);//Hs-Addy-Jump
int Memory4 =(EhSvc+0xD5AD4);//Hs-Addy-Jump
int Memory5 =(EhSvc+0xD5B04);//Hs-Addy-Jump
int Memory6 =(EhSvc+0xCA2EC);//Hs-Addy-Jump
int Memory7 =(EhSvc+0xC92F8);//Hs-Addy-Jump
int Memory8 =(EhSvc+0xD0AC8);//Hs-Addy-Jump
int Memory9 = (EhSvc+0xCA2EC);//Hs-Addy-Jump
int Memory10 =(EhSvc+0xD5B04);//Hs-Addy-Jump
int Memory11 =(EhSvc+0xD5B0C);//Hs-Addy-Jump
int Memory12 =(EhSvc+0xC92FC);//Hs-Addy-Jump
int Memory13 =(EhSvc+0xC92F4);//Hs-Addy-Jump
int Memory14 =(EhSvc+0xD4340);//Hs-Addy-Jump
int Memory15 =(EhSvc+0xD0680);//Hs-Addy-Jump
int Memory16 =(EhSvc+0xD3E28);//Hs-Addy-Jump
int Memory17 =(EhSvc+0xD3E48);//Hs-Addy-Jump
int Memory18 =(EhSvc+0xD691C);//Hs-Addy-Jump
int Memory19 =(EhSvc+0xCA2EC);//Hs-Addy-Jump
int Memory20 =(EhSvc+0xD5ACC);//Hs-Addy-Jump
int Memory21 =(EhSvc+0xD43C4);//Hs-Addy-Jump
int Memory22 =(EhSvc+0xD4334);//Hs-Addy-Jump

VirtualProtect((void*)(Memory1),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory1) = 4;
VirtualProtect((void*)(Memory2),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory2) = 4;
VirtualProtect((void*)(Memory3),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory3) = 4;
VirtualProtect((void*)(Memory4),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory4) = 4;
VirtualProtect((void*)(Memory5),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory5) = 4;
VirtualProtect((void*)(Memory6),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory6) = 4;
VirtualProtect((void*)(Memory7),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory7) = 4;
VirtualProtect((void*)(Memory8),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory8) = 4;
VirtualProtect((void*)(Memory9),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory9) = 4;
VirtualProtect((void*)(Memory10),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory10) = 4;
VirtualProtect((void*)(Memory11),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory11) = 4;
VirtualProtect((void*)(Memory12),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory12) = 4;
VirtualProtect((void*)(Memory13),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory13) = 4;
VirtualProtect((void*)(Memory14),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory14) = 4;
VirtualProtect((void*)(Memory15),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory15) = 4;
VirtualProtect((void*)(Memory16),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory16) = 4;
VirtualProtect((void*)(Memory17),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory17) = 4;
VirtualProtect((void*)(Memory18),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory18) = 4;
VirtualProtect((void*)(Memory19),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory19) = 4;
VirtualProtect((void*)(Memory20),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory20) = 4;
VirtualProtect((void*)(Memory21),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory21) = 4;
VirtualProtect((void*)(Memory22),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);
*(DWORD*)(Memory22) = 4;
VirtualProtect((void*)(Memory23),0x6,PAGE_EXECUTE_READWRITE,&OldProtect);



Sleep(5);
}
////////////////////////////////////end/////////////////////////
Posts 1–15 of 24 · Page 1 of 2
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?