CoolAPB HWID bypass

Posts 1–11 of 11 · Page 1 of 1
APB HWID bypass
y0oo!

So since someone experienced hwid bans, I looked into it and yes, they actually implemented it! But yeah, lame as fuck though...well it's G1, can't expect too much

---------------------------------------------------------------------

Backup and edit the registry key (regedit.exe):

"HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptograph y"
-> MachineGuid (replace some numbers/letters with other ones...)

Then go in the "APB Reloaded\Binaries\" folder and backup and delete:
-> preferences.bin
-> Last_Session.bin

By backup I mean save the Guid somewhere (txt file,...) and the files in some
random folder (copy/paste).

Also, try to:
- change computer name
- change username
- change MAC address
- change Volume Serial Number (C: )
- delete the folders in "APB Reloaded\APBGame\Config\Account"

---------------------------------------------------------------------

And that's it!! Now you can play APB again and again and again and again...happy cheating


Here is the "Happy meal" for da reversers:
Code asm
10D75BE7 |. /EB 07 JMP SHORT 10D75BF0
10D75BE9 | |8DA424 0000 LEA ESP,[ESP]
10D75BF0 |> \B1 7F /MOV CL,7F
10D75BF2 |. 2AC8 |SUB CL,AL
10D75BF4 |. 3088 3CD111 |XOR BYTE PTR DS:[EAX+1211D13C],CL
10D75BFA |. 40 |INC EAX
10D75BFB |. 83F8 1F |CMP EAX,1F
10D75BFE |.^ 72 F0 \JB SHORT 10D75BF0
10D75C00 |. C605 5CD111 MOV BYTE PTR DS:[1211D15C],0
10D75C07 |> 8D5424 08 LEA EDX,[LOCAL.98]
10D75C0B |. 52 PUSH EDX ; /pResult => OFFSET LOCAL.98
10D75C0C |. 68 01010000 PUSH 101 ; |DesiredAccess = KEY_QUERY_VALUE|100
10D75C11 |. 6A 00 PUSH 0 ; |Reserved = 0
10D75C13 |. 68 3CD11112 PUSH OFFSET 1211D13C ; |SubKey = "Software\Microsoft\Cryptography"
10D75C18 |. 68 02000080 PUSH 80000002 ; |hKey = HKEY_LOCAL_MACHINE
10D75C1D |. FF15 20E0AD CALL DWORD PTR DS:[<&ADVAPI32.RegOpenKeyExA>] ; \ADVAPI32.RegOpenKeyExA
10D75C23 |. 85C0 TEST EAX,EAX
10D75C25 |. 75 78 JNE SHORT 10D75C9F
10D75C27 |. 56 PUSH ESI
...
...
10D75D2E |.^\72 F0 \JB SHORT 10D75D20
10D75D30 |. C605 80D111 MOV BYTE PTR DS:[1211D180],0
10D75D37 |> 68 E41FC311 PUSH OFFSET 11C31FE4 ; ASCII "w+b"
10D75D3C |. 8D4424 04 LEA EAX,[LOCAL.0]
10D75D40 |. 68 70D11112 PUSH OFFSET 1211D170 ; ASCII "preferences.bin"
10D75D45 |. 50 PUSH EAX
10D75D46 |. FF15 FCE7AD CALL DWORD PTR DS:[<&MSVCR90.fopen_s>]
10D75D4C |. 83C4 0C ADD ESP,0C
10D75D4F |. 85C0 TEST EAX,EAX
10D75D51 |. 74 04 JE SHORT 10D75D57
10D75D53 |. 32C0 XOR AL,AL



Strings were crypted with that lame xoring.

EDIT:

- GetAdaptersInfo()
- GetCurrentHwProfileW() -> "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contr ol\IDConfigDB\Hardware Profiles\0001\HwProfileGuid"


Part 2 of another post from lowHertz

hhh, seen this hwid ban is 2 stronkk for some people so I figured I might release teh bypass.

From the how_to_use_the_bypass.txt in the folder:
Quote:

----------------------------------------------------------------------------------------
-- Instructions ------------------------------------------------------------------------
----------------------------------------------------------------------------------------
1) Go in the APB install directory, then in \Binaries (where APB.exe is located)
2) Delete "Last_Sessions.bin" and "preferences.bin"
3) Create a new account for APB
4) Start APB.exe and on loading screen or at login, inject the "bypass.dll"
5) Once injected you should see a console window and as last line "Ready..."
6) You can now login with the _NEW_ account and wait until you see the message
"hwid successfully bypassed"
7) Close APB.exe (Exit game, _DO NOT_ enter any district yet)
8) Restart the game _WITHOUT_ injecting the dll, login, and join any distric you want.
Play and profit.

----------------------------------------------------------------------------------------
-- Notes -------------------------------------------------------------------------------
----------------------------------------------------------------------------------------

- You must follow the instruction's procedure EACH TIME you get hwid banned.
- The dll injection is only needed ONCE (by following the instructions). This means
that once you bypassed the ban, you won't need to inject it/reset the hwid until
you get banned again.

_IF IT DOES NOT WORK_

- You might need to replace your "fastprox.dll" located in Windows\SysWOW64\wbem with
the one provided in this folder (this is from windows 7 professional).

- This bypass has only been tested on Windows 7 Pro x64
- Follow the instructions.
- Play & Profit.






All credit to lowHertz.
All credit to lowHertz.
This is not mine.

There is the program's virus scan.

Program:
https://www.virustotal.com/file/9ab1...is/1359233360/
bypass.dll - Jotti's malware scan

The ZIP:
hwid_bypass [MPGH.net].zip - Jotti's malware scan
https://www.virustotal.com/file/2f76...is/1359233645/


I HAVE NEVER USED THIS BECAUSE I'VE NEVER BEEN BANNED, USE AT YOUR OWN RISK!!
how_to_use_the_bypass.txt2 KB · 119 downloads Scanning…
i hope it gets approved.
I don't hack from APB it's to easy to begin with but this will help alot of our members so for their sake thank you.
I thought this was patched, unless its updated.
This is still working ? Cause i'v tried it long time ago, is it updated or something ?
Quote Originally Posted by Epidex View Post
This is still working ? Cause i'v tried it long time ago, is it updated or something ?
I'm not 100% sure because i don't have a HWID banned account so i cant test it, but this is an outdated post by lowhertz on another forum, looks like people are posting outdated hacks on this forum as releases getting people banned intentionally or unintentionally.
Anyways if someone can test and confirm it works than thank the poster for an awesome post
oh crap nice man now i won't get banned muahahaha
Not to be a dumbass....but where is the dll file.....i got banned for no reason and i kinda want to send my old stuff to my new stuff
what is hwid banned?
today i got banned plz help me
THIS DOESN'T WORK ANYMORE.
@Markus

Quote Originally Posted by nigeria23 View Post
i got banned for no reason and i kinda want to send my old stuff to my new stuff

And you want to send what old stuff? The stuff from your banned account? This doesn't "unban" accounts. That's impossible. What this used to do is send false information to G1s global ban database so you can use alternate accounts without them being banned as well because they were associated with your machine ID and therefore you.
Posts 1–11 of 11 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?