PDA

View Full Version : Wallhack Release - skinnyM


skinnym666
14th November 2007, 00:26
Here is a wallhack/chams for Cod4
It is a simple Direct3d Wrapper but it works, slowly on my PC but it works.

The source code is available.

-skinnyM

Holz
14th November 2007, 00:57
As he said, he provided the source code over at GD.


I just wouldn't try to create the game's process at all, at least not with that permanent path to the application.

And screenshots are always nice to see. :)

viglen
14th November 2007, 03:19
i loaded it and it crashed the game in 5 secs

BlackDove
14th November 2007, 03:43
These files appear to be legitimate. I have no access to GD anymore since they banned my account by mistake for being a "multi-account".

I advise not to use this until screenshots are posted.

Weedh3ad
14th November 2007, 05:01
What's up with all the new-comers in the CoD4 section?

I wouldnt try this until its verified with a scan and screenshot.
Especially since this guy is new here.

Holz
14th November 2007, 05:59
Again, the source code is available at GD, check and compile it yourself if you want to.

Not sure if it actually works (for everyone), though.

Macpunk
14th November 2007, 06:26
At GD, only one complaint of it not working has been given. However, there has been more work in CoD4 recently, and I'm pretty sure it's not a fake. It's open source, and available at GD, so check for yourself.

It's using CRCs, so your settings might affect whether it works or not. Also, everyone knows that not all hooking techniques work on every OS version, so that might explain the crashing.

--Macpunk

SniperColt50
14th November 2007, 19:42
If u dont trust it, recompile the source code at GD, u will see its exactly the same and so its not a troyan...

mmmmm6m
14th November 2007, 20:58
whatever it dosn't works 4 me

muiz
14th November 2007, 21:22
doesnt work for me either :(

Holz
14th November 2007, 21:23
Okay, just added the source code to the first post here at MPC as well now, I guess that's alright and avoids some of the unnecessary trouble.

Please check it out and compile it yourself instead of randomly screaming that it's a virus or whatever - I also deleted a bunch of such posts.


The cheat not working for you for whatever reason is a different story which I myself won't (be able to) go into, though.

Mazta
15th November 2007, 03:15
there a hotkey to start it up?

milkman9999
15th November 2007, 03:15
it says it cant create process on win vista home

Shazzel
15th November 2007, 07:56
Not working for me (vista 64)

Holz
15th November 2007, 08:04
it says it cant create process on win vista home

if(!CreateProcess("C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe", NULL, NULL, NULL, FALSE, NULL, NULL, "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare", &st, &Proc_Info))
{
printf("Error: Couldn't Create process");
return 0;
}

I just wouldn't try to create the game's process at all, at least not with that permanent path to the application.

: /

Shizarp
15th November 2007, 08:26
this thing loads but how is it suppose to work because i cant see anything behind thew walls ?????????

daniel1906
15th November 2007, 16:04
Any 1 tested this in antivir scan ? ! PB proff ? screenshots ? And how is it works ? !

mmmmm6m
15th November 2007, 16:10
He gave source code , Can someone who know C++ check it ?

Peanut12
15th November 2007, 23:33
just scan it on virus total or something, decompile it, be really careful. NEVER run it at all before u are sure its safe, one time is all it takes and you are screwed

Shazzel
16th November 2007, 00:14
Possibly a new variant of W32/SecRisk-ProcessPatcher-based!Maximus

W32/SecRisk-ProcessPatcher-based!Maximus

Virus.Win32.FileInfector.gen (suspicious)



Which makes me a sad panda, because it got pass my first round of tests.

Hopefully I can get rid of it without a reformat. Needless to say the link should be removed unless you like giving out virus's.

Swift2
16th November 2007, 00:22
Told you its a virus keyloggger!

Shazzel
16th November 2007, 00:46
You didnt tell me heh. They must have deleted some posts or something.

wurzil
16th November 2007, 00:53
Possibly a new variant of W32/SecRisk-ProcessPatcher-based!Maximus

W32/SecRisk-ProcessPatcher-based!Maximus

Virus.Win32.FileInfector.gen (suspicious)



Which makes me a sad panda, because it got pass my first round of tests.

Hopefully I can get rid of it without a reformat. Needless to say the link should be removed unless you like giving out virus's.

I'm pretty sure that is a false positive, and nothing to be alarmed about.

kater
16th November 2007, 01:14
detected Nov 15, 2007 6:08 PM est time

Shazzel
16th November 2007, 01:20
Antivirus Version Last Update Result

AhnLab-V3 2007.11.16.0 2007.11.15 -

AntiVir 7.6.0.34 2007.11.15 -

Authentium 4.93.8 2007.11.15 Possibly a new variant of W32/SecRisk-ProcessPatcher-based!Maximus

Avast 4.7.1074.0 2007.11.15 -

AVG 7.5.0.503 2007.11.15 -

BitDefender 7.2 2007.11.15 -

CAT-QuickHeal 9.00 2007.11.15 -

ClamAV 0.91.2 2007.11.15 -

DrWeb 4.44.0.09170 2007.11.15 -

eSafe 7.0.15.0 2007.11.14 -

eTrust-Vet 31.2.5297 2007.11.15 -

Ewido 4.0 2007.11.15 -

FileAdvisor 1 2007.11.15 -

Fortinet 3.11.0.0 2007.10.19 -

F-Prot 4.4.2.54 2007.11.14 W32/SecRisk-ProcessPatcher-based!Maximus

F-Secure 6.70.13030.0 2007.11.15 -

Ikarus T3.1.1.12 2007.11.15 -

Kaspersky 7.0.0.125 2007.11.15 -

McAfee 5164 2007.11.15 -

Microsoft 1.3007 2007.11.12 -

NOD32v2 2661 2007.11.15 -

Norman 5.80.02 2007.11.15 -

Panda 9.0.0.4 2007.11.15 -

Prevx1 V2 2007.11.15 -

Rising 20.18.31.00 2007.11.15 -

Sophos 4.23.0 2007.11.15 -

Sunbelt 2.2.907.0 2007.11.15 -

Symantec 10 2007.11.15 -

TheHacker 6.2.9.129 2007.11.15 -

VBA32 3.12.2.5 2007.11.15 -

VirusBuster 4.3.26:9 2007.11.15 -

Webwasher-Gateway 6.0.1 2007.11.15 Virus.Win32.FileInfector.gen (suspicious)





Running Trend Macro right now for whole pc, if its a false positive then it should find nothing.

wurzil
16th November 2007, 01:41
Antivirus Version Last Update Result

AhnLab-V3 2007.11.16.0 2007.11.15 -

AntiVir 7.6.0.34 2007.11.15 -

Authentium 4.93.8 2007.11.15 Possibly a new variant of W32/SecRisk-ProcessPatcher-based!Maximus

Avast 4.7.1074.0 2007.11.15 -

AVG 7.5.0.503 2007.11.15 -

BitDefender 7.2 2007.11.15 -

CAT-QuickHeal 9.00 2007.11.15 -

ClamAV 0.91.2 2007.11.15 -

DrWeb 4.44.0.09170 2007.11.15 -

eSafe 7.0.15.0 2007.11.14 -

eTrust-Vet 31.2.5297 2007.11.15 -

Ewido 4.0 2007.11.15 -

FileAdvisor 1 2007.11.15 -

Fortinet 3.11.0.0 2007.10.19 -

F-Prot 4.4.2.54 2007.11.14 W32/SecRisk-ProcessPatcher-based!Maximus

F-Secure 6.70.13030.0 2007.11.15 -

Ikarus T3.1.1.12 2007.11.15 -

Kaspersky 7.0.0.125 2007.11.15 -

McAfee 5164 2007.11.15 -

Microsoft 1.3007 2007.11.12 -

NOD32v2 2661 2007.11.15 -

Norman 5.80.02 2007.11.15 -

Panda 9.0.0.4 2007.11.15 -

Prevx1 V2 2007.11.15 -

Rising 20.18.31.00 2007.11.15 -

Sophos 4.23.0 2007.11.15 -

Sunbelt 2.2.907.0 2007.11.15 -

Symantec 10 2007.11.15 -

TheHacker 6.2.9.129 2007.11.15 -

VBA32 3.12.2.5 2007.11.15 -

VirusBuster 4.3.26:9 2007.11.15 -

Webwasher-Gateway 6.0.1 2007.11.15 Virus.Win32.FileInfector.gen (suspicious)





Running Trend Macro right now for whole pc, if its a false positive then it should find nothing.

I'm 99.99% certain that it is a false positive caused by the way the injector/loader works :)
If you want to feel extra safe, just use another loader with the .dll.

BlackDove
16th November 2007, 02:02
If it's a keylogger, than what good is it if it doesn't connect to the Internet? Your firewalls should be triggering if the process is asking for access.

No point in this thread continuing since the hack doesn't appear to work.

Closed.

Holz
16th November 2007, 05:45
Wow, seriously, all these false accusions have been pissing me off lately.

People just base their opinions and posts on shitty virus scans. In this case it even just said "file injector".. guess what, such a cheat has to be injected into the game, eh?

Here even the source code was provided, gee.


And that the cheat doesn't really seem to work and the process creation part in the loader sucks are different stories.