Page 1 of 1

MHS - Cannot find anything

PostPosted: Thu Jun 26, 2008 3:10 am
by cichociemny
Frist i want find adress for speedwalk hack on Cabal Online EU (because is easy to find) my range is 01900000 - 02000000 and my adress for speedwalk is 01BFD77C (i find that using CE + bypasser, works fine)
So i want do this same thing in MHS (because MHS don't need bypass in EU version) so i attach MHS when gameguard is download updates (because when GG starts, hide process cabalmain.exe), start search and... nothing found,
If i add adress manualy and lock it, nothing happen :(
Any idea what i do wrong ?
Sorry 4 my english :],

PostPosted: Thu Jun 26, 2008 3:57 am
by Sychotix
MHS attaches to itself for GameGuard. They do it to fool noobs.

PostPosted: Thu Jun 26, 2008 9:46 am
by L. Spiro
They don’t do it on purpose; it is just the nature of their hooks they use for detection.
You can get around their hooks with the right AAC settings.


L. Spiro

PostPosted: Thu Jun 26, 2008 4:01 pm
by cichociemny
I tested diffrent AAC settinga 3-4 hours and i only got;
- Game closes when i start search,
- Game closes when i freeze walue (lot of time)
- Gameguard DC game when i freeze value
- System crash (nothing responding, only hard reset work)
- BSOD (rare suprise :twisted: )
I think te correct AAC settings is the key, but i canot find it :/

PostPosted: Thu Jun 26, 2008 7:08 pm
by L. Spiro
cichociemny wrote:- Game closes when i freeze walue (lot of time)

I hope you noted that combination because that was the correct one.

With that combination you have bypassed the nProtect Game Guard hooks and can view the game RAM. But if you modify it you will trigger their CRC protections and the game will close. But that is a separate bypass that you have to make on your own (via scripting) or download.
The point is that the basic bypass existed in that combination and you could access the game RAM. That is enough for a lot of things.


L. Spiro

PostPosted: Thu Jun 26, 2008 8:55 pm
by Sychotix
since he tried it already, I'll give him the correct combination (that was posted by you)

You shoulda searched for "nProtect AAC" and seen if anyone had posted it =P http://memoryhacking.com/forums/viewtop ... rotect+aac

The last knob must be greater than 4 to hack nProtect Game Guard games (fixes the problem where MHS reads itself).

The 3rd knob should be greater than 2.

You must open in Restricted Mode.


L. Spiro

PostPosted: Thu Jun 26, 2008 10:52 pm
by JB Gzn
thanks sychotix, maybe i can try it on rakion

PostPosted: Sat Jun 28, 2008 3:17 pm
by cichociemny
L. Spiro wrote:I hope you noted that combination because that was the correct one.

Nope. :oops:

So even if i got correct AAC settings, i stil need crc bypas :(
Thnx for explain,