PostCRC CShell Bypass

Posts 1–8 of 8 · Page 1 of 1
CRC CShell Bypass
CRC CShell check will happen when you enter in game and when you die, This is a way that is used since CA implemented this check.

 
The code
#ifdef CAEU
DWORD dwCRCCheckCShell_HookStart = 0x379C1F85;
DWORD dwCRCCheckCShell_JMPBack = 0x379C1F8E;
#else
DWORD dwCRCCheckCShell_HookStart = 0x379CE928;
DWORD dwCRCCheckCShell_JMPBack = 0x379CE93D;
#endif

//example : nametags
BYTE NAMETAGS1BYTES[2], NAMETAGS2BYTES[2];

some where Im doing this, for save in those array of bytes original bytes.
memcpy((void *)NAMETAGS1BYTES, (void *)dwNameTags1, 2);
memcpy((void *)NAMETAGS2BYTES, (void *)dwNameTags2, 2);

.. then :

BYTE CRCBYTE_CSHELL;
DWORD addressToPass_CShell;

__declspec(naked) void __cdecl hkCRCCheck()
{
__asm mov ebx, 0; //same for ca eu / na
__asm add ebx, edx; //same for ca eu / na -> ebx now contain the address which is getting scanned
__asm pushad; //savin stack
__asm pushfd; //savin also falgs since we are in a strange part of code, we are in the middle of themida / winlicense code mutation.

__asm mov addressToPass_CShell, ebx; //moving ebx into my dword.

if(addressToPass_CShell == dwNameTags1) //our nametags1 address is getting scanned
{
CRCBYTE_CSHELL = NAMETAGS1BYTES[0]; //im setting my own byte which ca should read to original byte.
goto JMPPoint;
}

if(addressToPass_CShell == (dwNameTags1 + 0x1)) //doing same for 2nd byte
{
CRCBYTE_CSHELL = NAMETAGS1BYTES[1];
goto JmpPoint;
}

if(addressToPass_CShell == dwNameTags2) //doing same for 2nd address of nametag etc etc
{
CRCBYTE_CSHELL = NAMETAGS2BYTES[0];
goto JmpPoint;
}
if(addressToPass_CShell == (dwNameTags2 + 0x1))
{
CRCBYTE_CSHELL = NAMETAGS2BYTES[1];
goto JmpPoint;
}

__asm popfd; //restorin stack
__asm popad; //restorin flags
__asm add al, byte ptr ds:[ebx]; //allright, no one address which we are modifyng is getting scanned so we can execute function normally.
__asm jmp dwCRCCheckCShell_JMPBack; //jmping back.

JmpPoint:
//one of our address is getting scanned so lets trick the crc
__asm popfd;
__asm popad;
__asm add al, CRCBYTE_CSHELL; //let's put in AL our original byte.
__asm jmp dwCRCCheckCShell_JMPBack; //Jmping back
}
...

DetourCreate((BYTE *)dwCRCCheckCShell_HookStart, (BYTE *)hkCRCCheck, 5);

I saw that nobody had working bypasses ( cuz there are no new releases), so i leeched one from another forum.
I DONT TAKE ANY CREDIT FOR THIS!
I LEECHED IT FROM A GUY CALLED donoob FROM ANOTHER FORUM!
Leechers gonna leech
Better than not having any releases tbh :P
Quote Originally Posted by dadowns View Post
its not the same....
and sorry if its there i couldnt find it earlier when i posted this...
Didyou even click all 3 of the links....
Quote Originally Posted by arun823 View Post
Didyou even click all 3 of the links....
yes...
anywho, sorry for the post if its "useless" in your opinion :|
Posts 1–8 of 8 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?