Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Flyff > Flyff Hacks, Bots, Cheats, Exploits & Macros
You last visited: Today at 05:21

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[Windows 7 x64] Gameguard Bypass for CE

Discussion on [Windows 7 x64] Gameguard Bypass for CE within the Flyff Hacks, Bots, Cheats, Exploits & Macros forum part of the Flyff category.

Reply
 
Old 10/22/2020, 16:56   #46
 
netHoxInc's Avatar
 
elite*gold: 117
Join Date: Jan 2008
Posts: 790
Received Thanks: 992
Another option would be a selfmade driver. Even tho GG is ring3, we dont rly need to go ring0 ro achieve that, it just makes it being an easy solution without much reversing of GG.
netHoxInc is offline  
Old 10/22/2020, 22:04   #47
 
cookie69's Avatar
 
elite*gold: 0
Join Date: Nov 2009
Posts: 627
Received Thanks: 688
Quote:
Originally Posted by I Feelz I View Post
the kernel driver is only for w7 x64. u can try it with titanhide but i didnt give support for it.
There is even a better and powerful free tool called Windows Kernel Driver and it works with 32/64 versions from windows Xp to win10:

But even after I hided CE, it still get's detected by gg so maybe you need to understand how CE gets detected (maybe a noob window search, a registry search...)

By the way, WKE is detected by antivir but it is false positive as it is using a fake sign certificate which gets detected by most antivir.
cookie69 is offline  
Old 10/26/2020, 02:38   #48
 
elite*gold: 0
Join Date: Jul 2020
Posts: 81
Received Thanks: 10
In the past this was the only method that has worked for me and im scared to install a windows 7 version on top of my windows 10. I feel like this is going to break my computer lolz

I have tried editing cheat engine window title, button, process name and rename some buttons to something else but it still got detected.
TheAllfather is offline  
Old 10/26/2020, 12:52   #49
 
elite*gold: 0
Join Date: Feb 2010
Posts: 127
Received Thanks: 74
Quote:
Originally Posted by TheAllfather View Post
In the past this was the only method that has worked for me and im scared to install a windows 7 version on top of my windows 10. I feel like this is going to break my computer lolz

I have tried editing cheat engine window title, button, process name and rename some buttons to something else but it still got detected.
Just use a Virutal Machine. This is easy to install and to configure.
If you have Windows 10 Pro - Use Hyper-V.
Hömer is offline  
Old 12/09/2020, 02:54   #50
 
elite*gold: 117
The Black Market: 102/0/0
Join Date: Dec 2012
Posts: 659
Received Thanks: 75
Quote:
Originally Posted by cookie69 View Post
There is even a better and powerful free tool called Windows Kernel Driver and it works with 32/64 versions from windows Xp to win10:

But even after I hided CE, it still get's detected by gg so maybe you need to understand how CE gets detected (maybe a noob window search, a registry search...)

By the way, WKE is detected by antivir but it is false positive as it is using a fake sign certificate which gets detected by most antivir.

did u disable the patchguard from w10 before?
I Feelz I is offline  
Old 12/15/2021, 13:20   #51
 
Gyakusatsu-'s Avatar
 
elite*gold: 0
Join Date: Sep 2020
Posts: 7
Received Thanks: 0
everything's fine.
1. PatchGuard disabled (even windows10 (also 17134+))
2. Hidecon -ph /* (PID) CheatEngine (v7.3) */
3. Starting play2bit-deFlyff in Virtualbox without Sound actived ( Warning MSG before GG can start, for (me) more time analysing PID+Attach Neuz.exe )
4. Detecting.

Same Method on patched x64 Windows-10 (also 17134+with UPGDSED)
4. Detected.

Next try: TitanHide (Both x64 Windows-7001 and Windows-10)
1. Until step warning ''no Sound'' so, I have enough time to explore the PID of Neuz and Attach with CE / x64dbg

2. Hiding after Attach via GUI
( 2.5 hiding PID with Hidecon )
3. Detected.

i think there is a system of instant closing after Attach with Debugger
maybe i am using wrong version of CE / 64dbg?
maybe i should attach GameMon.des to hide?

Also i would talk about the code of changing the interface of CE..just as repack.
Here's the code:
Gyakusatsu- is offline  
Old 12/03/2024, 12:53   #52
 
elite*gold: 0
Join Date: Nov 2024
Posts: 8
Received Thanks: 0
Quote:
Originally Posted by cookie69 View Post
If you do it perfectly, you must be able to bypass the gg with CE and you can even modify Game memory (I did a mistake when I said that you can't modify the memory..)
I personally had to re-patch the kernel to be able to use CE again but it is working and it is undetected with Windows 7 x64 bits

Hello, nice work here!

So, I was trying to bypass the hackshield on a certain Flyff pserver via reverse engineering its MiniA.exe via x32dbg software. The results got me stuck so below are the steps i did including the results of each.

1st. I did the sunkist method so i can launch the MiniA.exe via shortcut so it looks like i launch it on launcher.

2nd. I attached the MiniA.exe to x32dbg app to reverse the address where 'EHSvc.dll' is located. Did changes i have found on the internet. (changing the memory address of 'EHSvc.dll' to 2 bytes (00 00))

3rd. So, after the modifications, i have patched the MiniA.exe to the game folder but with different name so the original MiniA.exe would be backed up.

4th. Changed the names on the game folder so I would run the MiniA.exe(patched) via MiniA.exe - shortcut.

5th(result1). Right after launching the MiniA.exe - shortcut even in administrator, the process exits immediately. So, attached MiniA.exe(patched) again on debbuger to modify the kernel32.ExitProcess. Locates its address and assembled it to 'ret' so it wont exit.

6th(result2). After doing the first workaround and patched it, i ended up with an .exe that could not be read by the game so i guess that was not the right move, i even did the same modification on kernel32.TerminateProcess but ended up with the same result.

Now i am kinda stuck with this and been searching for workarounds tho. Any clarifications on my steps that made me wrong is highly appreciated!

Thanks guys
rftech23 is offline  
Reply


Similar Threads Similar Threads
SO.. there is no gameguard bypass? (i need old gameguard files)
07/28/2011 - Cabal Online - 16 Replies
i been reading around about how to bypass gameguard, it seems that emulating the http server is the best way, anyone have a copy of old cabal? i need gameguard.des and gameguard/ folder.
Windows 7 32x - gameguard
06/15/2009 - Shaiya - 2 Replies
how can i get around gameguard?
Please Release only CRC bypass and/or Gameguard bypass >>NO ONE KLICK HACKS!<<
10/24/2008 - Dekaron - 8 Replies
Release only a CRC bypass and Gameguard bypass ! That will not destroy the game because alle the noobs are only able to use a " ONE KLICK HACK" because they dont know how to use winhex or csv files. Somebody who is to stupid to read a simple tutorial isn´t be able to HACK ! >> If there is a working Dekaron EU CRC Bypass << post it << :handsdown:
CabalBot PH cannot bypass GameGuard on Windows Vista
07/04/2008 - Cabal Hacks, Bots, Cheats, Exploits & Macros - 4 Replies
i'm using windows vista ultimate 32 bit but it seems that cabalbot 1.03 doesn't bypass gameguard (or emulate gameguard) i've deleted the gameguard folder and gameguard.des. opened cabalbot PH 1.03 (the latest cabalbot). right click cabalbot -> start game -> search cabalmain.exe -> game starts. but i just see a message saying that there is an error in the hacking detection blah blah.... my friend and i have the same cabal installer and updates and he was using windows xp. cabalbot works...



All times are GMT +1. The time now is 05:21.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.