[Tutorial] Hide Any Program From the Anti-Cheat menu

User Tag List

Page 1 of 4 1234 LastLast
Results 1 to 15 of 57
  1. #1
    gurud's Avatar Contributor CoreCoins Purchaser
    Reputation
    129
    Join Date
    Oct 2013
    Posts
    223
    Thanks G/R
    2/31
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    [Tutorial] Hide Any Program From the Anti-Cheat

    Introduction:

    This tutorial and it's tools have the purpose to hide any program from being found by the PoE Anti-Cheat.

    It uses a few methods to hide a program from view of any program looking, because of that it is detected by most Anti Virus as a potentially risky software.

    I recommend that before trying any of these steps you read thought all the topic, so you can decide if you actually want to do this.

    Because it can hide any program i'll use Cheat Engine 6.3 as an example.

    Also the PoE Anti-Cheat, can still find out if you changed the game memory, so you will be able to use the PoeHUD, Multiscript and Bots or any other program as long as it does not change memory like a maphack would.

    All the programs have a readme text inside that should be read before using it.

    If you decide to follow these steps i'm not responsible if anything bad happens in your computer.



    Step 1 - Disabling UAC:

    1. CLICK HERE





    Step 2 - Changing the Window Name:


    1. Fist Download the file at the end of this post and extract it.
    2. Go to Window Renamer and open Window Renamer.exe.
    3. Chose the window you want to rename and change it.





    Step 3 - Hiding the Process

    For this there are 2 methods i'll be teaching one for x32 users and one for x64 users.

    Method for users using Vista and Windows 7 x32:

    This is not 100% undetected but it should be fine for the current detection of PoE.

    1. Go to HideToolz x32 paste.
    2. If you are a Vista user run the shutdown_fix_vista_only.reg and restart computer.
    3. Run the program HideToolz.exe. It should appear "Driver Loaded" if not restart your computer and try again.
    4. Once the driver is loaded find cheatengine.exe and click Hide.



    Method for users using Vista and Windows 7 x64:

    This method is 100% undetected no game would ever find as it hides the program in kernel ring0 level.

    1. Go to Signature Scanner Overrider paste.
    2. Run dseo13b.exe.
    3. Check "Enable Test Mode" and click next.
    4. Check "Exit" and click next and Restart your computer.
    5. Go to Disable PathGuard paste.
      **Important. This next step will create a new boot option "PatchGuard Disabled v3" which allows for loading of unsigned x64 bit drivers.
    6. Run mk_bcdentry.cmd and follow directions on screen.
    7. A patcher will start, you must press "Patch" then "Exit" before continuing with mk_bcdentry.cmd.
      Next steps should be done every time you want to hide a program.
    8. Restart and boot on "PatchGuard Disabled v3" option.
    9. Go to hidecon x64 paste.
    10. Start cmd as administrator (LINK)
    11. Inside cmd navigate to hidecon x64 paste (see image bellow)
    12. Confirm you are at the correct paste by typing hidecon

    13. Type "hidecon -ld" to load the driver.

    14. Type "hidecon -l" to display process list and save the ProcessId of the program you wanna hide.

    15. Type "hidecon -ph ProcessId" to hide the program.

    16. Type "hidecon -ud" to unload the driver (to leave no traces).





    Credits:
    Fyyre - For most of the tools.
    binary modifications, etc - by Fyyre




    Download:

    Hide.rar | Mediafire
    Last edited by gurud; 01-23-2015 at 12:55 PM.
    If i helped you in any way consider supporting me by donating in paypal at: [email protected]

    [Tutorial] Hide Any Program From the Anti-Cheat
  2. Thanks Parog, Capotaum, a3yet, NoodlesAreTheBest (4 members gave Thanks to gurud for this useful post)
  3. #2
    Deathnugget's Avatar Member
    Reputation
    1
    Join Date
    Dec 2009
    Posts
    7
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thanks for the guide. Will test it out this afternoon!

  4. #3
    scharush's Avatar Member
    Reputation
    1
    Join Date
    Jan 2015
    Posts
    13
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thanks for that. I have windows 8 tho, does that mean I can't use this guide?

    Also, I've heared the program "Spyshelter" should make any kind of hacks undetectable with the creation of rules. Is that true? If so, why not use it instead?
    Last edited by scharush; 01-22-2015 at 07:08 AM.

  5. #4
    tvinki's Avatar Active Member
    Reputation
    20
    Join Date
    Mar 2014
    Posts
    159
    Thanks G/R
    34/18
    Trade Feedback
    3 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    but still need way to use zoom, fulbright, suspend particles without ban )

  6. #5
    doragon's Avatar Contributor
    Reputation
    80
    Join Date
    Nov 2014
    Posts
    176
    Thanks G/R
    9/15
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    lol u found Fyyre )) it was coolest site in time when l2j c5 was developed (more then 9 years ago), nostalgia.

  7. #6
    magicneo's Avatar Member
    Reputation
    1
    Join Date
    Jan 2015
    Posts
    37
    Thanks G/R
    3/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Hey,

    Im stuck at point 6.

    I run Mk_bcdentry then i got this



    After that i boot on PatchGuard Disabled but it fail to launch window so nothing appens then i get back to boot menu

  8. #7
    ocslappy's Avatar Member
    Reputation
    4
    Join Date
    Jun 2013
    Posts
    93
    Thanks G/R
    5/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by magicneo View Post
    Hey,

    Im stuck at point 6.

    I run Mk_bcdentry then i got this



    After that i boot on PatchGuard Disabled but it fail to launch window so nothing appens then i get back to boot menu
    It's probably your anti-cheat software that deletes the files ntkrnlmp.exe & osload.exe before you even restarted and thats why PatchGuard Disabled boot wont load.

  9. #8
    SpaceGuy119's Avatar Member
    Reputation
    9
    Join Date
    Aug 2014
    Posts
    325
    Thanks G/R
    7/7
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Gurud, how do you feel about the accusations that your pot script is causing bans?

  10. #9
    datz's Avatar Active Member
    Reputation
    22
    Join Date
    Aug 2013
    Posts
    532
    Thanks G/R
    166/19
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    this seems way to complicated.

  11. #10
    snier's Avatar Member
    Reputation
    1
    Join Date
    Mar 2013
    Posts
    77
    Thanks G/R
    1/0
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    what the point of all of this if we cant use any hack? Need only zoom and bright and if i understand correct that tools not allow us to use them

  12. #11
    gurud's Avatar Contributor CoreCoins Purchaser
    Reputation
    129
    Join Date
    Oct 2013
    Posts
    223
    Thanks G/R
    2/31
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by SpaceGuy119 View Post
    Gurud, how do you feel about the accusations that your pot script is causing bans?
    I don't think they are banning people for using multiscript, i've only see people saying they got the warning when they run PoeHUD or the trainer.
    but it should be detected right now (if GGG wants to detect it), but i'm working on making it undetected right now.

    Originally Posted by snier View Post
    what the point of all of this if we cant use any hack? Need only zoom and bright and if i understand correct that tools not allow us to use them
    It can make PoeHUD (without client hacks), Multiscript and any Bot's undetected.
    Last edited by gurud; 01-23-2015 at 12:24 PM.
    If i helped you in any way consider supporting me by donating in paypal at: [email protected]

  13. #12
    HvC's Avatar Contributor
    Reputation
    138
    Join Date
    Jan 2015
    Posts
    324
    Thanks G/R
    0/50
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by gurud View Post
    I don't think they are banning people for using multiscript, i've only see people saying they got the warning when they run PoeHUD or the trainer.
    but it should be detected right now (if GGG wants to detect it), but i'm working on making it undetected right now.


    It can make PoeHUD, Multiscript and any Bot's undetected.
    It can make the exe undetected but not what they do aka if you do that to a maphack it'll still be detected because the Poe ac thread will look for the pattern and flag you if it did find something.

  14. #13
    Kapsel498's Avatar Banned
    Reputation
    3
    Join Date
    Mar 2011
    Posts
    24
    Thanks G/R
    0/2
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I just want to know that gurud, right now your multicript is writing memory for e.g. auto quit option, so this could be detected?

  15. #14
    immor's Avatar Active Member
    Reputation
    20
    Join Date
    Mar 2008
    Posts
    68
    Thanks G/R
    3/4
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Another way to hide a process from the Task-Manager is to use hyde.dll. This 'can' be easily integrated into an AutoHotkey Script. Using this dll also got the advantage that you dont need to disable UAC or use any unsigned drivers, Sadly there is also quite a huge disadvantage,,, This does only work if you are using a x64 bit OS and the 64 bit version of AutoHotkey or if you're using a x86 bit OS and the 32 bit version of AutoHotkey. This does not work if you have a x64 bit OS but use 32 bit AHK (and/or vice versa)!

    Nevertheless maybe someone may have some use for this.

    Code:
    /*
    		hyde.dll hides a process from the Task-Manager on Windows2k/Windows7 (x86/x64 bit)!
    
    		Your process can inject it into other processes however you like.  The example uses
    		SetWindowsHookEx with a CBT hook (the dll  exports a CBTProc) to inject it into all
    		running processes.
    
    		Press Esc to exit the script.
    
    		Note: if you do not compile the  script, AutoHotKey.exe gets hidden.  Otherwise the
    		the name of the .exe gets hidden.
    
    		Important: This does only work if you are using a x64 bit OS and the 64 bit version
    		of AutoHotkey or if you're using a x86 bit OS and the 32 bit version of AutoHotkey.
    		This does not work if you have a x64 bit OS but use 32 bit AHK (and/or vice versa)!
    */
    
    #NoEnv
    SetWorkingDir %A_ScriptDir%
    
    OnExit, ExitSub
    
    RunAsAdmin()
    
    if ((A_Is64bitOS=1) && (A_PtrSize!=4))
    	hMod := DllCall("LoadLibrary", Str, "hyde64.dll", Ptr)
    else if ((A_Is32bitOS=1) && (A_PtrSize=4))
    	hMod := DllCall("LoadLibrary", Str, "hyde.dll", Ptr)
    Else
    {
    	MsgBox, Mixed Versions detected!`nOS Version and AHK Version need to be the same (x86 & AHK32 or x64 & AHK64).`n`nScript will now terminate!
    	ExitApp
    }
    
    if (hMod)
    {
    	hHook := DllCall("SetWindowsHookEx", Int, 5, Ptr, DllCall("GetProcAddress", Ptr, hMod, AStr, "CBProc", ptr), Ptr, hMod, Ptr, 0, Ptr)
    	if (!hHook)
    	{
    		MsgBox, SetWindowsHookEx failed!`nScript will now terminate!
    		ExitApp
    	}
    }
    else
    {
    	MsgBox, LoadLibrary failed!`nScript will now terminate!
    	ExitApp
    }
    
    MsgBox, % "Process ('" . A_ScriptName . "') hidden!"
    Return
    
    Esc::ExitApp
    
    RunAsAdmin()
    {
    	Global 0
    	IfEqual, A_IsAdmin, 1, Return 0
    	
    	Loop, %0%
    		params .= A_Space . %A_Index%
    	
    	DllCall("shell32\ShellExecute" (A_IsUnicode ? "":"A"),uint,0,str,"RunAs",str,(A_IsCompiled ? A_ScriptFullPath : A_AhkPath),str,(A_IsCompiled ? "": """" . A_ScriptFullPath . """" . A_Space) params,str,A_WorkingDir,int,1)
    	ExitApp
    }
    
    ExitSub:
    	if (hHook)
    	{
    		DllCall("UnhookWindowsHookEx", Ptr, hHook)
    		MsgBox, % "Process unhooked!"
    	}
    	if (hMod)
    	{
    		DllCall("FreeLibrary", Ptr, hMod)
    		MsgBox, % "Library unloaded"
    	}
    ExitApp
    I have included this script aswell as both dll's into the rar file found in the attachment,
    Attached Files Attached Files

  16. #15
    scharush's Avatar Member
    Reputation
    1
    Join Date
    Jan 2015
    Posts
    13
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Can these methods only be used with windows vista or 7? Anything I can do if I've got windows 8?

Page 1 of 4 1234 LastLast

Similar Threads

  1. Does the anti cheat care about autoit send()'s?
    By cannolite in forum Path of Exile
    Replies: 3
    Last Post: 01-23-2016, 03:38 PM
  2. [Selling] Selling any GAMETIME ,blizzard games, any mount from the store. SUPER CHEAP
    By Sup3r in forum World of Warcraft Buy Sell Trade
    Replies: 4
    Last Post: 11-09-2012, 10:06 PM
  3. [Question] "Hide" some divs from the source
    By Achi3 in forum Programming
    Replies: 11
    Last Post: 11-24-2009, 02:09 PM
  4. [Guide] Unbanning Yourself From ANY Program
    By Pwntzyou in forum Community Chat
    Replies: 108
    Last Post: 12-13-2008, 03:22 PM
  5. Any program to delete accounts that haven't loged in from a certain date?
    By mafiaboy in forum World of Warcraft Emulator Servers
    Replies: 6
    Last Post: 12-10-2007, 07:18 AM
All times are GMT -5. The time now is 02:10 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search