Loadlib by Nik0815 (And how to use it)

Posts 1–14 of 14 · Page 1 of 1
Loadlib by Nik0815 (And how to use it)
I wanted to release my loadlib for dumping CShell.dll

Tutorial:

- Put the Loadlib.exe in your CF folder
- Start it
- Install the plugin PE Dumper in Ollydbg (Attachment)
- Start Ollydbg
- Attach -> Loadlib.exe
- View -> Module -> CShell.dll
- Click on Plugins -> PE Dumper -> Make dump of process
- Save the dumped CShell.dll
- DONE!

Now how to use it:

- Open Ollydbg
- Open -> DumpedCShell.dll
- Search for all referenced text strings
- Search for text -> ReloadAnimRatio
- Click on it
- Now look for 101EBB2E . D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]
- In C++:
Code:
#define WeaponMgr 0x0000000
#define NoReload 0xC3C
- So C3C is the offset
- Before you can use the offset you have to find the WeaponMgr Pointer


VT:

Loadlib by Nik0815.rar : https://www.virustotal.com/de/file/e...23e1/analysis/
Loadlib by Nik0815.exe : https://www.virustotal.com/de/file/c...253e/analysis/

Ollydbg: https://www.virustotal.com/de/file/7...1f72/analysis/
PE Dumper(Plugin) : https://www.virustotal.com/de/file/8...4fbf/analysis/


Creditz:

- Me (Coding)
- [I]fLuX (Helping)

-------------------------
Hope I could help you

bye.
Ollydbg_mpgh.net.zip12.8 MB · 237 downloads Scanning…
OllyDbg PE Dumper v3.03_mpgh.net.rar88 KB · 190 downloads Scanning…
LoadLib by Nik0815_mpgh.net.rar13 KB · 295 downloads Scanning…
Quote Originally Posted by _PuRe.LucK* View Post
#define WeaponMgr 0x0000000
#define NoReload 0xC3C
WeaponMgr is definitely not 0 ..
and why dumping it? you can load the module without any errors and view it in olly - easier
Quote Originally Posted by ARGB View Post
WeaponMgr is definitely not 0 ..
and why dumping it? you can load the module without any errors and view it in olly - easier
Its an example...
You can find the address
Quote Originally Posted by ARGB View Post
WeaponMgr is definitely not 0 ..
and why dumping it? you can load the module without any errors and view it in olly - easier
probably for anti-leeching ...
Quote Originally Posted by _PuRe.LucK* View Post
Its an example...
You can find the address
are you kidding me? you dont know what youre doing, you dont need to dump it if you can load it with loadlibrary, but I guess ah nvm its just noob-coded thats why u need to dump it
Quote Originally Posted by ARGB View Post
are you kidding me? you dont know what youre doing, you dont need to dump it if you can load it with loadlibrary, but I guess ah nvm its just noob-coded thats why u need to dump it
Or maybe he / she really just wrote a random address just to show, how it supposed to seem like...
Quote Originally Posted by rabir007 View Post


Or maybe he / she really just wrote a random address just to show, how it supposed to seem like...
Yep...............
still not needed, everybody here should be able to code such a simple application ..
This has already posted, if I'm not mistaken.
less the LoadLib by Nik0815.
Thanks.
Help please
how to Find WeaponMGR ???
Please
Code:
---------------------------
E:\CrossFire\EU\LoadLib by Nik0815.exe
---------------------------
E:\CrossFire\EU\LoadLib by Nik0815.exe is not a valid Win32 application.


---------------------------
OK   
---------------------------
Really F*king, How to work....
Thank you man... awesome, i like it
Posts 1–14 of 14 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us