Jump to content

Hacking Nvidia's Drivers!

Hello, guys! While EAC works fine now, we still have problems with CS:GO FACEIT Anti-Cheat system. After installing FACEIT system completely looses Nvidia GPU... Solution is to uninstall FACEIT and reinstall custom drivers again. Any idea how to solve this particular issue?

Link to comment
Share on other sites

Link to post
Share on other sites

  • 4 weeks later...
On 1/24/2023 at 5:16 PM, dartraiden said:

Patched dlls signed with leaked NVIDIA certificate. This makes anticheats happy. Otherwise, if the dlls are signed by some other certificate (not from nvidia), anti-cheats will refuse to load them and 3D acceleration will not work in these games.

 

.cat file signed with leaked Chinese certificate. This certificate has not been revoked, but has expired. Therefore, the signature must have a timestamp. The timestamp is a kind of confirmation from a third party that the driver was signed in the past, when the certificate has not yet expired.

 

Hello, I found out about this article. 

https://guanjia.qq.com/news/n3/2509.html

 

Quote

 

2. Virus analysis

The QQ_Protect.sys series Trojan driver service name is QQ_ProtectSer . Most of the signature information is henan pushitong intelligent technology , and the PDB character information also directly shows that this series of viruses is a lock home page: xxx\LockHomePage(ApcInject)\x64\Win7Release\QQ_Protect_X64_.pdb,

 

9352a66058bb49d4f00b06c5b46ea4f1.png

Driver service for pipoc lock homepage Trojan registration

09da3887543566633d1960c3fce8382e.png

Virus drivers are digitally signed

 

 

After the Trojan horse runs and loads, it will set a process creation callback and a module loading callback , and monitor the process creation event in the process creation callback. If it is a browser process, it will hijack the homepage by tampering with the process startup parameters.

 

 
 
They are talking about similar stuff. It is the same signature that these trojans are using. Can you confirm that this driver, https://drive.google.com/file/d/17chs7zrX_Lm5yNwEO7KDRfIVgVmI2A81/view?usp=sharing 
that the other guy has shared is safe @dartraiden ?  What do you recommend for reverse engineering the binaries of this driver, and the bundled installer? 
I also heard that signed drivers are really confusing antiviruses as they bypass some kind of analysis.
 
I also noticed anydesk starting on by itself and somehow somebody connected without any confirmation message or password: 

 

It was happening before or after this driver I am not sure. But anyone else can confirm any unusual activity like this  @tarkh with this driver, I would really appreciate any responses.
" Source : Powershell.exe, Website blocked due to riskware **---- schnell-vpn.xyz  blah blah "
  On startup there was a blank powershell window opening. I am not sure if this came with this driver or not. @tarkh Can you also download MalwareBytes and run a scan? 
I don't want to fearmonger but I have some doubts.
 
I also found out about this guys profile, I think this is the original author. https://tieba.baidu.com/p/8147226114?pn=1 
What does CYX mean? It is the nickname of the guy, they are calling each other big brothers, teacher or sth. Google translate is weird.
 
Link to comment
Share on other sites

Link to post
Share on other sites

Since the leaked certificates are freely available, they can be used to sign any binary, both malicious and useful.

 

19 hours ago, AngryShark said:
that the other guy has shared is safe

Yes, it is safe. Only 10 files are differ from original driver package

 

mstsc_xtVpC0Q4VY.png

 

You can remove signature from binaries with FileUnsigner then compare them with a hex editor. You will see that there are not many changes and they are all related to the card PIDs.

Link to comment
Share on other sites

Link to post
Share on other sites

please help[ me my nvidia p104 direct compute cant  active,how to solve it????hf.gif.405e72eed5aeaba1c3bd42555c384444.gif

Link to comment
Share on other sites

Link to post
Share on other sites

  • 2 weeks later...
On 2/18/2023 at 9:09 PM, AngryShark said:

It was happening before or after this driver I am not sure. But anyone else can confirm any unusual activity like this  @tarkh with this driver, I would really appreciate any responses.

" Source : Powershell.exe, Website blocked due to riskware **---- schnell-vpn.xyz  blah blah "
  On startup there was a blank powershell window opening. I am not sure if this came with this driver or not. @tarkh Can you also download MalwareBytes and run a scan? 
I don't want to fearmonger but I have some doubts.
 

Hi! I'm not using this driver. Downloaded latest driver from Nvidia, then did the patch by @dartraiden , then created *.bat script for installing cert in to the system, then repacked everything with NVCleanstall into single installer with bat execution preinstall.

Link to comment
Share on other sites

Link to post
Share on other sites

Hey everyone i think i figured out why the p102-100 with 10gb bios is so problematic. It has a gp102 die. And its counterpart (the unreleased 1080ti 10gb) was given pci x16 as well as outfitted with ports.

 

 

Only the titanxp, and 1080ti had the "102" status(dies) as far as released consumer cards go. As well as the "mining 5gb p102" which i used a hack to make work. 

While the gtx 1080 itself used the same die as a 1070(p104). Hence why 106 and 104 work as all these cards had laptop varients at some point with the die allowing for prime or hybrid hacking. I cannot access nvidia settings with the 10gb bios flashed to my p102. But intrestingly i did see this... 

the kernel module in use is nvidia. 

 

the steps to recrates this is

- use a "regular" or p106/p104 gpu to install the nvidia drivers like normal and make sure you have "nvidia prime" and "prime-select" nvidia installed. then power off the system normally. it should show up like "sse2/p104-100 or "sse2/p106-100" after the rrestart from installing the nvidia driver. once it works, power off pc and physically swap in the p102. it will use the nvidia module but niot show a driver is in use anywhere else implying much like on windows where theres no control pannel unless you have an hdmi inside the card, this is happening here. will try saudering an hdmi port and see if this works but it appears this is why. just a guess, i bios flashed it myself so no idea. i.m vary new to saudering and i use ubuntu unity 22.04. note: iy will swap back to igpu if you have the 102 in and have igpu after (if you cant get this to work) the igpu, easiest fix is to driver swap and restart to swap back to sse2, but if antyones better at saudering and has a spare 102 lying around just a theory, hopefully i helped someone happy gaming

Screenshot from 2023-03-06 22-13-56.png

main rig:

CPU: 8086k @ 4.00ghz-4.3 boost

PSU: 750 watt psu gold (Corsair rm750)

gpu:axle p106-100 6gbz msi p104-100 @ 1887+150mhz oc gpu clock, 10,012 memory clock*2(sli?) on prime w coffee lake igpu

Mobo: Z390 taichi ultimate

Ram: 2x8gb corsair vengence lpx @3000mhz speed

case: focus G black

OS: ubuntu 16.04.6, and umix 20.04

Cooler: mugen 5 rev b,

Storage: 860 evo 1tb/ 120 gb corsair force nvme 500

 

backup

8gb ram celeron laptop/860 evo 500gb

Link to comment
Share on other sites

Link to post
Share on other sites

On 2/19/2023 at 7:25 PM, dartraiden said:

Since the leaked certificates are freely available, they can be used to sign any binary, both malicious and useful.

 

Yes, it is safe. Only 10 files are differ from original driver package

 

mstsc_xtVpC0Q4VY.png

 

You can remove signature from binaries with FileUnsigner then compare them with a hex editor. You will see that there are not many changes and they are all related to the card PIDs.

sorry, im newbie and come here specially because interested in this cheap 2nd hand GPU for gaming 🙂

so this driver can be used for any P106-100 ?

Link to comment
Share on other sites

Link to post
Share on other sites

On 12/4/2022 at 1:04 AM, jbcgames said:

so using this, will i just install driver without using patch or regedit ??

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, Ridwan99 said:

sorry, im newbie and come here specially because interested in this cheap 2nd hand GPU for gaming 🙂

so this driver can be used for any P106-100 ?

Absolutely

2 hours ago, Ridwan99 said:

so using this, will i just install driver without using patch or regedit ??

No

TimeSpy_P106-100.jpg

Link to comment
Share on other sites

Link to post
Share on other sites

On 3/5/2023 at 3:02 AM, tarkh said:

Hi! I'm not using this driver. Downloaded latest driver from Nvidia, then did the patch by @dartraiden , then created *.bat script for installing cert in to the system, then repacked everything with NVCleanstall into single installer with bat execution preinstall.

I can't pass EAC with the patch. So I returned back to 417.22

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, ogel2 said:

Absolutely

 

Thanks gans for the info 🙂 

so we still need to do patch or regedit to make it work...noted...thankfully it not seems too hard to follow for a newbie like me, 😛

i dont do online games, so i wont need to worry about it, as long as it can work for light games, like GTA5 or skyrim. 

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, Ridwan99 said:

Thanks gans for the info 🙂 

so we still need to do patch or regedit to make it work...noted...thankfully it not seems too hard to follow for a newbie like me, 😛

i dont do online games, so i wont need to worry about it, as long as it can work for light games, like GTA5 or skyrim. 

The best driver for online games 417.22

For offline games you can use any version you want post 417.22 with dartraiden patch.

 

Link to comment
Share on other sites

Link to post
Share on other sites

On 1/4/2023 at 4:18 PM, chenmoyu said:

Hello everyone, I made nVidia's 527.56 driver patch, and now it can pass EAC. You can see that the games that can pass the test include APEX, cs go, and pubg. Now I need more playtesting. Please send me screenshots of unplayable games。The driver link is here:https://drive.google.com/file/d/17chs7zrX_Lm5yNwEO7KDRfIVgVmI2A81/view?usp=sharing

 

屏幕截图 2023-01-03 135110.jpg

屏幕截图 2023-01-03 161706.jpg

屏幕截图 2023-01-03 162035.jpg

屏幕截图 2023-01-03 162312.jpg

Hello, I try to play Valorant with this driver, but the game doesn't want to use the GPU. I already try to setting in the NVIDIA control panel but it didn't work. The game always play with iGPU.

i'm using windows 10 22h2 19045.2604 ghostspectre edition

Link to comment
Share on other sites

Link to post
Share on other sites

20 minutes ago, asher_3 said:

Hello, I try to play Valorant with this driver, but the game doesn't want to use the GPU. I already try to setting in the NVIDIA control panel but it didn't work. The game always play with iGPU.

i'm using windows 10 22h2 19045.2604 ghostspectre edition

What kind of card you use? He's using 40HX. 

Link to comment
Share on other sites

Link to post
Share on other sites

18 minutes ago, ogel2 said:

What kind of card you use? He's using 40HX. 

I'm using p106-100. But i try to play genshin and minecraft it can work completely fine.

Link to comment
Share on other sites

Link to post
Share on other sites

When I at the riot client, it is using the p106, but when the game's start, it switched to iGPU

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, asher_3 said:

When I at the riot client, it is using the p106, but when the game's start, it switched to iGPU

I think 417.22/23 more suitable for online games. I played many competitive game with that version with zero problem.

Valorant, CS-GO, Dota 2, APEX, Fortnite, PUBG Steam and so on.

Can you mention what games that need a newer driver version? Maybe I will test that.

Link to comment
Share on other sites

Link to post
Share on other sites

Ok, thanks. I'll change the driver with the 417.22 version. I actually don't need the newer version, i'm just too lazy to change the driver.

9 hours ago, ogel2 said:

I think 417.22/23 more suitable for online games. I played many competitive game with that version with zero problem.

Valorant, CS-GO, Dota 2, APEX, Fortnite, PUBG Steam and so on.

Can you mention what games that need a newer driver version? Maybe I will test that.

 

Link to comment
Share on other sites

Link to post
Share on other sites

On 2/24/2023 at 10:54 AM, skydit said:

please help[ me my nvidia p104 direct compute cant  active,how to solve it????hf.gif.405e72eed5aeaba1c3bd42555c384444.gif

Have you tried using the Registry Editor? It works for me.

Watch this video to find where and what the changes are.

 

Link to comment
Share on other sites

Link to post
Share on other sites

On 1/25/2023 at 8:48 AM, dartraiden said:

Use this.

Does this work for a p102-10010gb? Or is it possible i could swap the .inf file with the p102-100 one? Found an old 384 driver that was made for a p102 supposedly. But my pc keeps restarting when i try to install it. This is a fresh windows 10 install. 

main rig:

CPU: 8086k @ 4.00ghz-4.3 boost

PSU: 750 watt psu gold (Corsair rm750)

gpu:axle p106-100 6gbz msi p104-100 @ 1887+150mhz oc gpu clock, 10,012 memory clock*2(sli?) on prime w coffee lake igpu

Mobo: Z390 taichi ultimate

Ram: 2x8gb corsair vengence lpx @3000mhz speed

case: focus G black

OS: ubuntu 16.04.6, and umix 20.04

Cooler: mugen 5 rev b,

Storage: 860 evo 1tb/ 120 gb corsair force nvme 500

 

backup

8gb ram celeron laptop/860 evo 500gb

Link to comment
Share on other sites

Link to post
Share on other sites

anyone know why igpu is yellow warning??

i disable secure boot, set using igpu using 512mb memory.

i install driver 417.22 normally, then do the registry, delete adaptertype and make mshybrid from 0 to 1

i can set using high performance, but cannot run games and just crash

any one know why?? am i doing something wrong here??

 

And also i cannot open Nvidia control panel 😞 i am using win 10 21h2 if im not mistaken

gagal2.jpg

gagal 3.jpg

Link to comment
Share on other sites

Link to post
Share on other sites

if i take off the P106-100, the igpu seem to be fine

is the P106-100 is broken?? seem good while installed, just somekinda have confict with igpu??

tried adding more ram to igpu, maxed in 1024MB, still the same problem, code 12, not enough free resources, why is that??

any help would be appreciated...

gagal 4.jpg

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Ridwan99 said:

if i take off the P106-100, the igpu seem to be fine

is the P106-100 is broken?? seem good while installed, just somekinda have confict with igpu??

tried adding more ram to igpu, maxed in 1024MB, still the same problem, code 12, not enough free resources, why is that??

any help would be appreciated...

Try to delete Nvidia device and Intel device from Device manager, reboot, then install Intel with igpu drivers from website support section of your MoBo, reboot again, then install Nvidia patched driver.

*** Also download and install Chipset drivers (INF, MEI) from website support section of your MoBo.

Link to comment
Share on other sites

Link to post
Share on other sites

I am using asus b85m-g

Yes, download driver from asus website, only 1 unknown i dont know what is that...

I tried disable lan, audio and usb in bios

 

Still same if i plug the evga p106-100 in

 

Now i tried looking the resources

Hope can know which one is conflicted

 

If anyone know why, please give some enlightenment...thanks

 

 

 

 

 

 

 

 

 

 

 

 

 

IMG_20230311_183043.jpg

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×