[TUTORIAL] MTA:SA METHOD FOR SERIAL SPOOFING 2026

horacy

Известный
Автор темы
111
98
I'm sharing a method for spoofing serial numbers in MTA:SA. It's my own method, developed based on publicly available projects. It's probably the only publicly available and free method available today, as I couldn't find a thread that would allow it. :firedevil:

The method definitely work, I checked it several times.


If you managed to change your serial number, give me reputation in return
BW93jt2.gif


Below I am including all the sources I used:
PHP:
Use temp-spoofer from my attachment because it is modified
https://www.unknowncheats.me/forum/anti-cheat-bypass/742461-windows-kernel-driver-temp-spoofer.html
https://github.com/TheCruZ/kdmapper
https://github.com/Scrut1ny/Windows-MAC-Address-Spoofer
https://github.com/boshyxd/HWIDInspector
and others

Additional software required:
Код:
Python
Visual studio 2022
WDK and SDK 26100.6584 or other

Advantages and disadvantages of the following method:
Код:
+ It does not require a disk format, although you can probably skip some steps in this method by formatting it.

+ Permanent, new SERIAL, you can freely set the random seed to generate a new one or keep the old one

+ It's free but time-consuming

- Requires creating a new user account and deleting the old account, as well as transferring AppData, which may cause problems

- There is no 100% certainty that this method removes all traces

- It requires some intermediate knowledge, for those who don't know much I think they will be able to handle the AI chat.

Dangers of this method:
Код:
- Post some user in original temp spoofer thread mentioned the possibility of system corruption, which requires formatting, but that likely relates to EFI spoofing, which is disabled by default in the spoofer solution. In any case, I didn't have this problem when spoofing a disk in a VM or locally, but take this as a warning.

- Possibility of damaging program data stored in the Appdata folder

- BSOD

Possible minor Windows errors. So far, I've encountered:

- A slow right-click context menu is caused by a program remaining in the registry that doesn't exist but was previously in appdata. This can be easily fixed with shellview.

- The Start Menu sometimes crashes, only if you loading a driver using kdmapper. You can still use the system after the crash, but without the Start Menu. It resolves after a restart.

- Windows accounts disappear upon login; you can only log in with the main account. This resolves after enabling a special administrator account and setting a password for that account in cmd.

- Trouble finding various options in the Start Menu. For example, I can't open Folder Options, but I can open them with Win+R.

- Most of these problems can probably be avoided by using a registry backup of the most important system keys.


TODO

Код:
- [B][COLOR="Red"]For some reason, sometimes the old serial number remains at the beginning until we connect to the server, this may mean that not all traces have been removed![/COLOR][/B]

- Find all the traces after using MTA, exact methods of obtaining the serial number through MTA so as not to make unnecessary steps

- Getting rid of unnecessary steps from the method?

- Fix registry and mac spoofing functions in temp-spoofer, add spoofing options like in HWIDInspector

- Introduce GPU spoofing capability for AMD and other parameters

- Creating one solution in exe format, spoofing the serial number with one click and the ability to set the serial

- Instead of using a spoofer, create code that can infect MTA and replace all serial numbers in packets and overwrite MTA functions that query the system for hardware identifiers 

- Check if this method will effectively avoid GLOBAL BAN in MTA, if not, find out why it doesn't work and fix it

- Modify the spoofer to make it undetectable


INSTRUCTION:
Код:
Administrator permissions required
[COLOR="Red"][B]Disable all Windows Defender options, disable or remove your antivirus
In cmd as administrator, add your system drive to exclusions: powershell -Command "Add-MpPreference -ExclusionPath 'c:'"

From now on, close MTA and GTA SA and do not open them[/B][/COLOR]

Download the required software from req_soft.txt. Install PYTHON only on the new user profile.

Download, extract every downloaded program into the folder containing the file with the download link for that program:
 \spoof_method_release\Windows-MAC-Address-Spoofer-main\download.txt
 \spoof_method_release\HWIDInspector-main\download.txt
 \spoof_method_release\cleaning scripts\INSTALL_SUDO_BEFORE_CLEAN.txt
 \spoof_method_release\driver\x64\Release\download_kdmapper.txt REQUIRES COMPILATION, do it!

Compile the kdmapper solution, place the exe file into \spoof_method_release\driver\x64\Release
 Compile the \spoof_method_release\driver solution

I recommend opening the solution and changing the registry keys to your own names in main.cpp! It is best to use names of existing programs!

[BEFORE RUNNING BAT SCRIPTS, MAKE SURE THEY WILL WORK ON THE SYSTEM DRIVE AND ON THE DRIVE WHERE MTA FILES ARE LOCATED]

WIN + R > type cmd > ctrl + shift + enter > cd your_path\spoof_method_release\cleaning scripts
 You run the scripts by typing their name in cmd
  Type clean_mta.bat and wait for it to finish

Type samp_reg_remove.bat and wait for it to finish

(CAUTION: The script below deletes temporary data, which may contain data from programs you use!)

Type clear_temp_data.bat and wait for it to finish
 Delete the mtasa-1.6.exe installer files or any other MTA installer files in the folder where you save downloaded files

Press the WIN + R shortcut and type ms-settings:otherusers
 Click Add > I don't have this person's sign-in information... > Add a user without a Microsoft account
  > think of a new username > click on the new account in the list > Change account type > Administrator > OK

Press the WIN + R shortcut, type cmd, click ctrl + shift + enter, and type net user Administrator /active:yes
 ctrl + alt + delete, log out, log in to the new account, log out, and log in to the Administrator account

After logging into the administrator account, press win + r and type
 control folders > View > Hidden files and folders > Show hidden files... > Apply

CAUTION: The operations on AppData below may damage/delete data used by any programs on your system
 You do this at your OWN RISK. If you have any data that might be stored in AppData, back up the entire
  folder into an archive before the operation, though it may take a while.

Open the path system_drive\Users
 Go into the folder with your old account name, select everything you need except "AppData", and click CUT

Return to the Users folder, go into the folder with the new username, and paste all data there

Then return to your old user folder and go into the appdata folder. On the DESKTOP, create folders Local, LocalLow, Roaming

Then on the desktop, open each of the above folders, return to the appdata folder
 Sequentially perform the following operations for Local, LocalLow, Roaming
  Move folders with the names of the programs you care about to the folders on the desktop
   Meaning: files from the appdata/Local folder are moved to the Local folder on the desktop

From each folder, I recommend at least moving folders named:
 [anything with Microsoft in the name], VisualStudio, chrome/mozilla/other browser you use, AMD/ATI/NVIDIA,
  [names of programs you care about]

Then open the users/new_username folder and open or create the AppData folder if it does not exist
 Into AppData, paste all folders from the desktop: local, local low, roaming, and replace

Press WIN + R, type netplwiz, and click ctrl + shift + enter

[This step will delete all user data!]

Click on your old account in the list and then delete it

Return to the AppData folder, delete the folder with your old account name, and empty the recycle bin

Open regedit under the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
 In profile list, check the sub-keys and look at the ProfileImagePath parameter to see if the old account is present

Press WIN + R, type cmd, and click ctrl + shift + enter
 Type net user Administrator /active:no, restart the computer, and then log into the new account

Install some VPN or not if you already have one, it will come in handy later

It is best to remove the old GTA SA and install it so that the path looks like this: C:\Program Files (x86)\Rockstar Games\GTA San Andreas

Open regedit with the path HKEY_LOCAL_MACHINE\SOFTWARE, right-click SOFTWARE > New > Key > type name [YOUR_NAME]
 if you didn't change the name in main.cpp, type "changeme", create inside changeme/your_name a QWORD 64 named changemeSerialSeed/or your_name
  click Decimal, type a random string of digits with a maximum length of 10, this is your seed so that your data is not constantly random

Open spoof_method_release\HWIDInspector-main

type in cmd pip install -r requirements.py
 then open HWIDInspector.py, in the GUI click Restart as Admin
  in OverView at the very top, copy your original parameters if
  you want to be able to revert to them: MachineGuid, computer name, Installation id.
   Save your parameters in a safe place. Click generate GUID and apply changes,
   run random_name.bat, copy the generated name and paste it into computer name, click
    generate installationID, click rename Computer and set installationID, and close the program.

Open cmd as administrator, type getmac, copy your original addresses and save them in a safe file.
 open \spoof_method_release\Windows-MAC-Address-Spoofer-main\WMAS.bat as administrator, repeat for
  each NIC > Randomize MAC address and close.

Open regedit as administrator HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CI\Config
 Create DWORD 32-bit > name: VulnerableDriverBlocklistEnable > Value: 0

Open HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios

If the HypervisorEnforcedCodeIntegrity sub-key exists, open it; if not, create the HypervisorEnforcedCodeIntegrity sub-key in scenarios
 Open HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity
  Create DWORD 32-bit > name: Enabled > value: 0

Turn off the computer, then check in the BIOS if you have the Secure Boot option and disable it; if you don't have it, do nothing. Restart.

[CAUTION: IF THE DRIVER WORKS INCORRECTLY, IT MAY CAUSE SYSTEM CORRUPTION DURING DISK SPOOFING!]

Go to \spoof_method_release\driver\x64\Release, press win + r, type cmd, type in cmd cd ...\spoof_method_release\driver\x64\Release
 run: kdmapper_Release.exe WindowsDriver.sys. If you didn't get a BSOD and the driver loaded, check the registry

HKEY_LOCAL_MACHINE\SOFTWARE[your_name] in this key, the driver should create values with spoof status and the load status
 of the seed from which component data IDs are generated; it is important to have a fixed seed because we will have a fixed serial.

```
IF EVERYTHING WORKS, DELETE ALL KEYS EXCEPT THE KEY WITH YOUR SEED.

```

Run cmd as administrator and type:
 bcdedit /set testsigning on
  bcdedit /set nointegritychecks on

Go to \spoof_method_release\cleaning scripts, run clear_temp_data.bat as administrator.

Go to the main GTA SA folder, copy the file spoof_method_release\cleaning scripts\randomizer_gta_installation.bat into the main folder
 run it as administrator. When the script finishes, delete it.

[CAUTION: IF THE DRIVER WORKS INCORRECTLY, IT MAY CAUSE SYSTEM CORRUPTION DURING DISK SPOOFING!]

In C:\ProgramData, create a folder with the name of an existing program, e.g., dolby. Drop the file
 spoof_method_release\driver\x64\Release\WindowsDriver.sys into the folder and rename it to your name, e.g., dolby.sys.
  COME UP WITH A NAME
  Then run cmd as administrator and type
  sc create dolby binPath= "C:\ProgramData\dolby\dolby.sys" type= kernel start= auto

Go to the start menu, from now on hold SHIFT the entire time, click restart, the advanced startup menu will open
 Troubleshoot > Advanced options > Startup Settings > Restart
  wait for the computer to restart and then select the option DISABLE DRIVER SIGNATURE ENFORCEMENT

Check in the registry if the keys were created; if the spoofing statuses have a value of 1, it succeeded, this is almost the end.

Go to \spoof_method_release\cleaning scripts, run clear_temp_data.bat as administrator.
Go to \spoof_method_release\cleaning scripts, run emul_temp_data.bat as administrator.
 If Windows settings/disk cleanup open, close them.

Download [https://yogadns.com/download/YogaDNSSetup.exe]and install it
 Open the program and import the configuration \spoof_method_release\cleaning scripts\yoga.xml
  configuration > rules > check if MTA rules exist, disable them, and click OK.

Run the VPN and use it whenever you connect to MTA or launch MTA.
 Open a private browser window or use the Mullvad browser, download the MTA installer.
  Run YogaDNS, go to rules and check everything for MTA, click OK.
   Open cmd, type ping multitheftauto.com; if it doesn't respond, it's okay.

Install MTA normally, launch MTA. MTA crashes or closing without an error after seeing the menu may occur,
 launch MTA like this 3 times, don't worry. Then close all MTA-related programs.

Go to \spoof_method_release\cleaning scripts, run clean_mta.bat as administrator.
Go to \spoof_method_release\cleaning scripts, run clear_temp_data.bat as administrator.
Go to \spoof_method_release\cleaning scripts, run emul_temp_data.bat as administrator.
Go to the main GTA SA folder, copy the file spoof_method_release\cleaning scripts\randomizer_gta_installation.bat into the main folder
 Run the script as administrator and delete it.

Open cmd as administrator and type:
sc stop your_name
sc delete your_name
 bcdedit /set testsigning off
 bcdedit /set nointegritychecks off

Then delete the C:\ProgramData\your_name folder and restart the computer. If you cannot delete it, rename the folder and delete it after a restart. Restart the computer again.

Go to \spoof_method_release\driver\x64\Release, press win + r, type cmd, type in cmd cd ...\spoof_method_release\driver\x64\Release
 run: kdmapper_Release.exe your_driver.sys. From now on, whenever you intend to launch MTA, you must do this before launching it.

Turn on YogaDNS, make sure MTA is blocked. Install MTA and create a local server.
 after joining the server, open the console and type serial, the serial should change. Exit MTA.

Go to \spoof_method_release\cleaning scripts, run clean_mta.bat as administrator.
Go to \spoof_method_release\cleaning scripts, run clear_temp_data.bat as administrator.
Go to \spoof_method_release\cleaning scripts, run emul_temp_data.bat as administrator.
Go to the main GTA SA folder, copy the file spoof_method_release\cleaning scripts\randomizer_gta_installation.bat into the main folder
 Run the script as administrator and delete it.

Run YogaDNS, configuration > rules > disable all rules for MTA and click OK.
 Install MTA again, run the VPN, and you can safely enter servers on the internet.

By: thorus.m47k0j3bc4
 

Вложения

  • spoof_method_release.zip
    685.6 KB · Просмотры: 2
  • Нравится
Реакции: TheBadZero