Go Back   FileForums > Games > Game Trainers
Register FAQ Community Calendar Today's Posts Search

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 26-06-2011, 16:26
Traziz Traziz is offline
Banned
 
Join Date: Jun 2011
Location: UK
Posts: 17
Thanks: 0
Thanked 0 Times in 0 Posts
Traziz is on a distinguished road
I was talking about the link you provided, a few posts back.

If you could ask h4x0r what the llsass.exe and vcltest3.dll (sorry I said vcl3test.dll before) are for. I think it will ease peoples minds if they also knew what they were for. And why does the trainers access the registry, I have noticed on a couple I have looked at they use registry API's to do so. And also what are the other files created when the trainer runs.

Last edited by Traziz; 26-06-2011 at 16:38.
Sponsored Links
  #2  
Old 26-06-2011, 16:37
cocodrilo cocodrilo is offline
Registered User
 
Join Date: Jun 2011
Location: spain
Posts: 43
Thanks: 0
Thanked 1 Time in 1 Post
cocodrilo is on a distinguished road
Traziz this dissasemble is not from xpsupport.dll, men check form image base.... like a simple exe..... read a darkbyte text in yor image . please provide a xpsupport.dll real from sicheats.

xpsupport.dll is the original dbghelp.dll from windows . please make a link to this dll.

maybe ida and ollydbg is wrong.... please download link for debugging please.

it clearly has some interest in lying. Please update your disassembler WOW.

Last edited by cocodrilo; 26-06-2011 at 16:43.
  #3  
Old 26-06-2011, 16:42
Traziz Traziz is offline
Banned
 
Join Date: Jun 2011
Location: UK
Posts: 17
Thanks: 0
Thanked 0 Times in 0 Posts
Traziz is on a distinguished road
I used the xpsupport.dll from the Alice trainer from your site, also the xpsupport.dll from the fear 3 trainer from the link you provided which you said was clean.

Also used the fable 3 trainer from GCW which uses the same xpsupport.dll
  #4  
Old 26-06-2011, 16:46
cocodrilo cocodrilo is offline
Registered User
 
Join Date: Jun 2011
Location: spain
Posts: 43
Thanks: 0
Thanked 1 Time in 1 Post
cocodrilo is on a distinguished road
ok downloading alice trainer from sicheats. wait a moment.

please look :

Quote:

A505-E0FC/archivos$ ls | grep "xp"
xpsupport.dll-alice
xpsupport.dll-fear3
Quote:
A505-E0FC/archivos$ md5sum xpsupport.dll-*
4003e34416ebd25e4c115d49dc15e1a7 xpsupport.dll-alice
4003e34416ebd25e4c115d49dc15e1a7 xpsupport.dll-fear3
is the same file, yor image shows darkbyte string in autoassembler engine.... strange very strange . please only REAL data and binaries from debugging .

please provide a link to binary file with strange code, strings refs or any data to damage you. please a real copy from sicheats servers.

you are lying for some reason.

Last edited by cocodrilo; 26-06-2011 at 17:00.
  #5  
Old 26-06-2011, 17:03
Traziz Traziz is offline
Banned
 
Join Date: Jun 2011
Location: UK
Posts: 17
Thanks: 0
Thanked 0 Times in 0 Posts
Traziz is on a distinguished road
Goto GCW and get the fable 3 trainer and use that file.

Why you wish to call me a liar when I have tested with 3 independent files from "trusted" distributions points, and they all clearly show the same string references etc.

Is this the normal for people on sicheats to call people liars when it doesn't suit you?

I am sure Joe_Forster will check also, and I am sure he will find the same string reference and coding in all xpsupport.dll files from legitimate safe sites.


Oh wait... are you comparing the coding from the 2nd picture with the xpsupport.dll? The 2nd picture is from the actual Alice trainer and not the library (dll).

Last edited by Traziz; 26-06-2011 at 17:07.
  #6  
Old 26-06-2011, 17:07
cocodrilo cocodrilo is offline
Registered User
 
Join Date: Jun 2011
Location: spain
Posts: 43
Thanks: 0
Thanked 1 Time in 1 Post
cocodrilo is on a distinguished road
GCW has a public upload . ok, downloading fable 3 from sicheats, please wait a moment.

Quote:

Oh wait... are you comparing the coding from the 2nd picture with the xpsupport.dll? The 2nd picture is from the actual Alice trainer and not the library (dll).
not im comparing all your images, you are talking from this file. please give a public link o wait downloading trainer.

Last edited by cocodrilo; 26-06-2011 at 17:12.
  #7  
Old 27-06-2011, 04:52
Joe Forster/STA's Avatar
Joe Forster/STA Joe Forster/STA is offline
Senior forum member
 
Join Date: Nov 2000
Location: Hungary
Posts: 9,836
Thanks: 20
Thanked 342 Times in 224 Posts
Joe Forster/STA is on a distinguished road
I downloaded h4x0r's Alice: Madness Returns, Fable 3 and F.E.A.R. 3 trainers, both from Sicheats and GCW. The files in the packages for the same game are identical, except an extra promo video in one of them. Conclusion: There is no difference whether you download h4x0r's trainers from Sicheats or GCW. (Apparently, Empire's manual upload filtering works fine.)

I've checked xpsupport.dll, too, which is the same in all packages. It is, actually, identical to dbghelp.dll version 6.12, which can be downloaded along with the latest Windows SDK 7.1. Note that it contains digital signatures so it cannot be faked or tampered without anyone noticing. Conclusion: The xpsupport.dll's analyzed above are fakes.

Final conclusion: Traziz, you get one, I repeat, one more chance to prove that you're not a Cheathappens agent. A few questions for you to answer:
1. Where are the trainer packages that you (allegedly) downloaded from Sicheats and GCW? Give us the original download URL's (probably, a file sharing site that Sicheats supposedly links to) and attach them to your post.
2. How is it possible that we not only cannot find in xpsupport.dll any of the suspicious strings you reported but it turned out be (a copy of a given version of) a Windows system DLL?
3. Which trainer is supposed to create the "vcl3test.dll" file and where? The Alice: Madness Returns trainer doesn't create one.
4. Which trainers access what registry entries and how (read/write)?
5. Which trainers create what files and what do those files contain? Attach them.
(If you can use a disassembler, I'm sure you can also use Sysinternals' ProcMon to create a trace.)

As I already mentioned to Empire and TippeX, I think we're experiencing the latest - and more elaborate than ever before - attack against Sicheats on/via our forum.
__________________
Joe Forster/STA
For more information, see the FileForums forum rules and the PC Games forum FAQ!
Don't contact me via E-mail or PM to ask for help with anything other than patches (or software in general) done by me, otherwise your request may be deleted without any reply!
Homepage: http://sta.c64.org, E-mail: [email protected]; for attachments, send compressed (ZIP or RAR) files only, otherwise your E-mail will bounce back!

Last edited by Joe Forster/STA; 27-06-2011 at 05:07.
  #8  
Old 26-06-2011, 17:13
Traziz Traziz is offline
Banned
 
Join Date: Jun 2011
Location: UK
Posts: 17
Thanks: 0
Thanked 0 Times in 0 Posts
Traziz is on a distinguished road
The 1st image is from xpsupport.dll

The 2nd image is from the alice trainer binary.

the llsass references is from the xpsupport.dll and the uploading.com is from the trainer. I did point this out.
  #9  
Old 26-06-2011, 17:18
cocodrilo cocodrilo is offline
Registered User
 
Join Date: Jun 2011
Location: spain
Posts: 43
Thanks: 0
Thanked 1 Time in 1 Post
cocodrilo is on a distinguished road
Quote:

A505-E0FC/archivos$ md5sum xpsupport.dll-*
4003e34416ebd25e4c115d49dc15e1a7 xpsupport.dll-alice
4003e34416ebd25e4c115d49dc15e1a7 xpsupport.dll-fable3
4003e34416ebd25e4c115d49dc15e1a7 xpsupport.dll-fear3
Quote:
The 1st image is from xpsupport.dll
lying continuous.


wait till I go to debug the trainer and whether there are such strings will explain what the code. dll in the continuous and sustained by lies without giving me a link to the binary

1: in trainer no string llsass . wait for open string (parameter of shellexecute to open a default browser, open a haxor paypal link if you like make a voluntari donation.... lies and lies). wait a moment, please.

Last edited by cocodrilo; 26-06-2011 at 17:24.
  #10  
Old 26-06-2011, 17:30
Traziz Traziz is offline
Banned
 
Join Date: Jun 2011
Location: UK
Posts: 17
Thanks: 0
Thanked 0 Times in 0 Posts
Traziz is on a distinguished road
Quote:
Originally Posted by cocodrilo View Post
lying continuous.


wait till I go to debug the trainer and whether there are such strings will explain what the code. dll in the continuous and sustained by lies without giving me a link to the binary

1: in trainer no string llsass . wait for open string (parameter of shellexecute to open a default browser, open a haxor paypal link if you like make a voluntari donation.... lies and lies). wait a moment, please.
You call me a liar because your understanding of English is poor?

I never said the llsass was in the trainer I said it was contained in the xpsupport.dll.

I never said it forces the paypal link on anyone, NOT ONCE. I said it forces the uploading.com url on the sly. And that url is contained in the trainer.

Get your facts correct first before accusing people of things.
  #11  
Old 26-06-2011, 17:24
Traziz Traziz is offline
Banned
 
Join Date: Jun 2011
Location: UK
Posts: 17
Thanks: 0
Thanked 0 Times in 0 Posts
Traziz is on a distinguished road
Full file listing of trainer contents



Here is W32Dasm with the correct path to the file and the string reference window open to llsass reference.

  #12  
Old 26-06-2011, 17:31
cocodrilo cocodrilo is offline
Registered User
 
Join Date: Jun 2011
Location: spain
Posts: 43
Thanks: 0
Thanked 1 Time in 1 Post
cocodrilo is on a distinguished road
no images, please binaries. wait for my explanation from paypal string .

now expected to explain the disassembly you afraid you and takes away the worry in 2 seconds.

Quote:
I never said the llsass was in the trainer I said it was contained in the xpsupport.dll.
the xpsupport.dll is te same in the 3 trainers.


Quote:
I never said it forces the paypal link on anyone, NOT ONCE. I said it forces the uploading.com url on the sly. And that url is contained in the trainer.
forced? please wait a moment jejeje ¿forced? hope you understand assembler to technical debate . no more words, only evidences (files to analyze, etc etc or technical analisis)

Last edited by cocodrilo; 26-06-2011 at 17:34.
  #13  
Old 26-06-2011, 17:37
Traziz Traziz is offline
Banned
 
Join Date: Jun 2011
Location: UK
Posts: 17
Thanks: 0
Thanked 0 Times in 0 Posts
Traziz is on a distinguished road
Quote:
Originally Posted by cocodrilo View Post
forced? please wait a moment jejeje ¿forced? hope you understand assembler to technical debate . no more words, only evidences (files to analyze, etc etc or technical analisis)
Oh I understand ASM, oh yes I understand it indeed.

Anyway this conversation is over... I would rather talk to someone with a modicum of understanding in English and isn't in the habit of calling people liars because they can't understand English.

As said I am sure Joe_Forster has the know how, or maybe TippeX to check the xpsupport.dll and find the same llsass references I did. Then there will be explaining to do why it is there.
  #14  
Old 26-06-2011, 17:41
cocodrilo cocodrilo is offline
Registered User
 
Join Date: Jun 2011
Location: spain
Posts: 43
Thanks: 0
Thanked 1 Time in 1 Post
cocodrilo is on a distinguished road
Quote:

I shall wait for Joe_Forster or some other moderator or administrator here to check files from sicheats and on GCW.
files from sicheats servers, no public upload.

I fully understand what you're saying, which I do not understand is you. please tell me the address of the event table associated with that component and continue talking. now I upload some pictures.

Quote:
As said I am sure Joe_Forster has the know how, or maybe TippeX to check the xpsupport.dll and find the same llsass references I did. Then there will be explaining to do why it is there.
Please upload this file or give the md5.


Ok, the event table look donation_click and lookd address.


event_click- disasm look for address:



¿is on click event to "forces you"? juaz. a picture is worth a thousand words do you need me to explain some part of the code?. if you do not understand that, you can search around for the dede.

REPEAT, NO MORE WORDS ONLY BINARIES but same md5 from sicheats trainers. NO MORE LIES.


you is not much to speak, many posts but have not given any evidence and for today I have said enough. Joe discuss things in private and quiet will the results.

Last edited by cocodrilo; 26-06-2011 at 17:59.
  #15  
Old 26-06-2011, 17:34
Traziz Traziz is offline
Banned
 
Join Date: Jun 2011
Location: UK
Posts: 17
Thanks: 0
Thanked 0 Times in 0 Posts
Traziz is on a distinguished road
I won't bother trying to talk to you as it is evident your lack of English and misreading what is said is causing you to call me a liar, when it is you who can't understand what is being said.

I shall wait for Joe_Forster or some other moderator or administrator here to check files from sicheats and on GCW.
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Announcement and final word on the CheatHappens vs. h4x0r trainer war Joe Forster/STA Game Trainers 7 12-07-2010 08:31
(Not a bash thread) h4x0r trainers dropping dll's DABhand Game Trainers 30 20-02-2010 12:42



All times are GMT -7. The time now is 16:33.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
FileForums @ https://fileforums.com