Retail Client Auto Shutdown when IDA PRO/x64dbg/overdumpfix is in the hdd menu

User Tag List

Results 1 to 7 of 7
  1. #1
    SailorMars's Avatar Member
    Reputation
    8
    Join Date
    Oct 2015
    Posts
    49
    Thanks G/R
    0/7
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Retail Client Auto Shutdown when IDA PRO/x64dbg/overdumpfix is in the hdd

    Wonder if anyone experienced this. I don't have any cheat yet. Didn't inject anything to the retail client, didn't run any program remotely related to automation (autohotkey,etc). But prior to running the retail client, i just copied to my hdd the IDA Pro (installer only), a full copy of X64dbg and the zip file Overwatch-dump-fix -master.zip. Then i ran the retail client and login to my characters. The game ran fine for a while. Then I opened the pdf of ScyllaHida's documentation. I've never run the IDA/x64dbg. But the retail client suddenly shutdown automatically indicating it detected something.

    Does that mean the retail client is scanning my hdd for any of the above programs? Or is it simply opening a pdf file related to ScyllaHide causes a detection? I DON'T HAVE ANY CHEATS in my hdd, so it is impossible for it to be related to real cheat being detected.

    Anyone have similar experience?
    Last edited by SailorMars; 04-26-2020 at 07:15 AM.

    Retail Client Auto Shutdown when IDA PRO/x64dbg/overdumpfix is in the hdd
  2. #2
    krustx's Avatar Member
    Reputation
    11
    Join Date
    Nov 2018
    Posts
    6
    Thanks G/R
    2/4
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Sounds like they are scanning window titles in a primitive way? Rename the PDF file so it doesn't show Scylla substrings in it's title and give it a try.

  3. #3
    CodeBytes's Avatar Member
    Reputation
    14
    Join Date
    Feb 2020
    Posts
    39
    Thanks G/R
    7/7
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    They definitely scan window titles (and run other checks too). Open CE/ReClass/whatever in a hex editor like HxD and rename all strings that match the window title of your program to something else. Of course, back up your exes first in case you mess something up. You will still periodically crash with a renamed program as well, but the crashes are much less frequent. I have not yet had to rename the strings in IDA. There are a ton of legit reasons to have IDA open, and Blizzard can't penalize you for that (unless, of course, you try to attach the debugger. Then you can most certainly expect a crash).

    If you don't feel like renaming your pdf file, you can just open it in a sandbox. You could also browse websites in a sandbox so the tab title doesn't trigger a crash. If not for the crash, then for good measure. Using a sandbox to browse the web can be safer than not.

  4. #4
    SailorMars's Avatar Member
    Reputation
    8
    Join Date
    Oct 2015
    Posts
    49
    Thanks G/R
    0/7
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    its seems that even having Chrome opening the Scyllahide Github page could cause a shutdown (it shutdown when i clicked the github page's release tab). My previous case could be caused by viewing a youtube video related to Scyllahide. The Chrome's window title is set to the title of the active tab/youtube video title. That's sad.

    Running x64dbg, even for debugging something else not related to wow also causes a shutdown.
    Last edited by SailorMars; 04-27-2020 at 08:09 AM.

  5. #5
    Seifer's Avatar Site Donator
    Reputation
    129
    Join Date
    Apr 2007
    Posts
    270
    Thanks G/R
    1/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by SailorMars View Post
    Does that mean the retail client is scanning my hdd for any of the above programs? Or is it simply opening a pdf file related to ScyllaHide causes a detection? I DON'T HAVE ANY CHEATS in my hdd, so it is impossible for it to be related to real cheat being detected.

    Anyone have similar experience?
    It's not scanning your filesystem; it's only scanning your memory. And IIRC they only crash the process when they found something fishy running.

  6. #6
    SailorMars's Avatar Member
    Reputation
    8
    Join Date
    Oct 2015
    Posts
    49
    Thanks G/R
    0/7
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    today, i just carelessly opened the ScyllaHide-master.zip by winrar and it crashed my wow client. I'm quite sure that they're doing a primitive window title scan for the keyword "ScyllaHide".

  7. #7
    aeo's Avatar Contributor
    Reputation
    127
    Join Date
    Apr 2007
    Posts
    270
    Thanks G/R
    84/62
    Trade Feedback
    7 (100%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    As stated above just having the scyllahide github page open will crash you. Its windows titles.

Similar Threads

  1. [Mac] Ida Pro - Auto analysis never completes - solution?
    By Tanaris4 in forum WoW Memory Editing
    Replies: 18
    Last Post: 04-14-2011, 11:47 AM
  2. Shutdown when bot is done
    By bartman66 in forum World of Warcraft General
    Replies: 10
    Last Post: 11-08-2009, 11:29 AM
  3. auto shutdown and wierd items [help]
    By backlash52 in forum World of Warcraft Emulator Servers
    Replies: 9
    Last Post: 07-01-2008, 11:26 AM
  4. Client memory update when no focus?
    By skypa in forum WoW Memory Editing
    Replies: 0
    Last Post: 03-29-2008, 08:00 PM
  5. Where can I find a cracked IDA Pro
    By vivec45 in forum World of Warcraft General
    Replies: 2
    Last Post: 08-16-2007, 01:57 AM
All times are GMT -5. The time now is 05:20 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search