Hello community.

12/24/2013 00:52 cheyester10#1
I have a sincere question about disabling HGWC. I have the file detection, the keep alive, the ban and thread functions. I'm coding a method to do the work for me. However I can't get it to work in ollydbg because I can't find a way to stop it from crashing. Any suggestions when I should disable those things to stop it from doing that?
12/24/2013 09:17 onahoe#2
You've to suspend the threadr to avoid a dc..
12/24/2013 17:27 cheyester10#3
I did, it still dc.
12/24/2013 19:34 onahoe#4
Send me your code with a pn / skype. i'll take a look..
12/24/2013 20:54 cheyester10#5
As I said, I can't code it if I can't get it to work in olly.
12/25/2013 18:06 Forbidi#6
Are you getting crash after attaching the debugger ?
Try to use veh debugger or another ...
12/25/2013 18:08 cheyester10#7
I'm getting crashed after I suspend and stuff then detaching.
12/25/2013 18:51 Omdi#8
Did you already think about that the crash is caused by OllyDbg and not your patches?
12/25/2013 19:02 cheyester10#9
It's not the patches. It's when I detach hgwc then unsuspend it crashes. I think it's because of the wrong jmps. Let me make sure. :)
12/26/2013 19:46 cheyester10#10
Late reply, yea it's still crashing for some reason.
12/26/2013 20:58 Forbidi#11
Quote:
Originally Posted by cheyester10 View Post
I have a sincere question about disabling HGWC. I have the file detection, the keep alive, the ban and thread functions. I'm coding a method to do the work for me. However I can't get it to work in ollydbg because I can't find a way to stop it from crashing. Any suggestions when I should disable those things to stop it from doing that?
I understand from you first post that you don't really need a debugger like ollydbg cuz i thing that attaching a debugger to HGWC is detected. What you need is only to nope the function that you mention before, so like i said before just attach CE, search the function, and change opcodes nothing more, if you still have crash that's mean that HGWC don't get the return that he must get so it give a dc all what you have to do is backtrace the func and bypass it ;o
12/27/2013 02:14 cheyester10#12
i backtraced the function and it still crashes for some reason. I think something is wrong with hgwc.exe hehe.
12/28/2013 23:38 cheyester10#13
It's working now. I didn't run olly as admin. e.e