HideDLL

Posts 16–30 of 52 · Page 2 of 4
How to use it i want to make my Hook undedected !
Quote Originally Posted by vinke2013 View Post
How to use it i want to make my Hook undedected !
you failed
Quote Originally Posted by vinke2013 View Post
How to use it i want to make my Hook undedected !
Your hook
If you knew C++ you would know how to use it
Btw it doesn't make your hook undetected!
Quote Originally Posted by [H]aaBX View Post
Your hook
If you knew C++ you would know how to use it
Btw it doesn't make your hook undetected!

So I got my hook that was detected, and with this it wasn't detected anymore.
It basicly hide's your dll injection, not the functions inside it.
Don't call me a leecher, don't say:"dude thats totally not helpful" or something...
If you don't like it, go away.
Code:
void HideDLL(HINSTANCE hModule)
{
    DWORD dwPEB_LDR_DATA = 0;
    _asm
    {
        pushad;
        pushfd;
        mov eax, fs:[30h]             
        mov eax, [eax+0Ch]               
        mov dwPEB_LDR_DATA, eax    

        InLoadOrderModuleList:
            mov esi, [eax+0Ch]         
            mov edx, [eax+10h]         

        LoopInLoadOrderModuleList: 
            lodsd                 
            mov esi, eax    
            mov ecx, [eax+18h]  
            cmp ecx, hModule    
            jne SkipA         
            mov ebx, [eax]      
            mov ecx, [eax+4]  
            mov [ecx], ebx    
            mov [ebx+4], ecx      
            jmp InMemoryOrderModuleList 

        SkipA:
            cmp edx, esi     
            jne LoopInLoadOrderModuleList

        InMemoryOrderModuleList:
            mov eax, dwPEB_LDR_DATA
            mov esi, [eax+14h]
            mov edx, [eax+18h]

        LoopInMemoryOrderModuleList: 
            lodsd
            mov esi, eax
            mov ecx, [eax+10h]
            cmp ecx, hModule
            jne SkipB
            mov ebx, [eax] 
            mov ecx, [eax+4]
            mov [ecx], ebx
            mov [ebx+4], ecx
            jmp InInitializationOrderModuleList

        SkipB:
            cmp edx, esi
            jne LoopInMemoryOrderModuleList

        InInitializationOrderModuleList:
            mov eax, dwPEB_LDR_DATA
            mov esi, [eax+1Ch]      
            mov edx, [eax+20h]      

        LoopInInitializationOrderModuleList: 
            lodsd
            mov esi, eax        
            mov ecx, [eax+08h]
            cmp ecx, hModule        
            jne SkipC
            mov ebx, [eax] 
            mov ecx, [eax+4]
            mov [ecx], ebx
            mov [ebx+4], ecx
            jmp Finished

        SkipC:
            cmp edx, esi
            jne LoopInInitializationOrderModuleList

        Finished:
            popfd;
            popad;
    }
}

Credits:Gellin.
Quote Originally Posted by vinke2013 View Post
It basicly hide's your dll injection, not the functions inside it.
@vinke2013
^The gay is talking shit. As he said its not hiding your functions. If it would hide the functions you could use GetModuleHandle - but you CANT !
What hook? That while(1) ?
Quote Originally Posted by Biesi View Post
What hook? That while(1) ?
Guys I am talking by D3D hook @[H]aaBX


---------- Post added at 04:56 PM ---------- Previous post was at 04:55 PM ----------

Quote Originally Posted by [H]aaBX View Post
Your hook
If you knew C++ you would know how to use it
Btw it doesn't make your hook undetected!
Iam talking about d3d hook..
Quote Originally Posted by RobinC View Post
Iam talking about d3d hook..
Did I say Memory Hook ?!
And If it really would make your hook undetected then would kareem and the other pros release their hacks again..
Quote Originally Posted by [H]aaBX View Post
Did I say Memory Hook ?!
And If it really would make your hook undetected then would kareem and the other pros release their hacks again..
kareem and pro?
Quote Originally Posted by Dragon(H)ell View Post
@RobinC take it advice from me,never share any codes here (your codes nor codes you found and want to share) all here are leechers and NQQBS
Agree
@[H]aaBX Well I dont use getmodulehandle in my current d3d hack.. And if you dont like it or something, then no comment please.
Quote Originally Posted by RobinC View Post
@[H]aaBX Well I dont use getmodulehandle in my current d3d hack.. And if you dont like it or something, then no comment please.
Yes. X-Trap only detects those strings: "cshell.dll", "CSHELL.DLL", "CSHELL.DLL", ..
Quote Originally Posted by [H]aaBX View Post
Yes. X-Trap only detects those strings: "cshell.dll", "CSHELL.DLL", "CSHELL.DLL", ..
Just use:

while( TRUE )
{
DWORD pfpfp = ( DWORD )LoadLibrary(XorStr<0xB3,11,0x01ABF04F>("\xF0\xE7\ xDD\xD3\xDB\xD4\x97\xDE\xD7\xD0"+0x01ABF04F).s);
if( !pfpfp )
{


Or something?
Quote Originally Posted by RobinC View Post
Just use:

while( TRUE )
{
DWORD pfpfp = ( DWORD )LoadLibrary(XorStr<0xB3,11,0x01ABF04F>("\xF0\xE7\ xDD\xD3\xDB\xD4\x97\xDE\xD7\xD0"+0x01ABF04F).s);
if( !pfpfp )
{


Or something?
XOR (En)cryption works ofc. But only GetModuleHandle( "CShell.dll" ) won't make your hack (doesn't matter whether mem or d3d) undetected
Quote Originally Posted by [H]aaBX View Post
XOR (En)cryption works ofc. But only GetModuleHandle( "CShell.dll" ) won't make your hack (doesn't matter whether mem or d3d) undetected
I know But I use this for other games, and it pretty works fine, so for this to I bet.
Posts 16–30 of 52 · Page 2 of 4

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us