PostEasiest Way For Beginners Who Want To UnPack CShell And Find Addys

Posts 1–15 of 17 · Page 1 of 2
Easiest Way For Beginners Who Want To UnPack CShell And Find Offsets
Hey Guys,
Since some people are having hard time in CShell unpacking am gonna do An Easy tutorial for beginners with Screen Shots and maybe A Video...

Code:
1- Download loadib (in attachments) and extract it in CrossFire Folder

2-download Olly..also in attachments... and extract it on desktop... Run as Admin if Win 7

3-Open loadib.. and then Go To Olly and Select file>attach>C:/ program files/Crossfire/loadib.exe

4-U will find a Medium Sized window on the left with a small icon "C"

5- Any Where in that window "C" press Right Click>View>Module "Cshell"

6- Then in "C" press right click>search For>All Refrenced Text Strings

7- Another Small window will open Called "R"

8- Right Click Any where at "R" then Search For Text (And Be sure to Tick Entire Scope and Un Tick Case Sensetive)

9-Search for any text strings...I will give alot of examples Below...Like "BulletPosOffset" = NoRecoil

10-The Right Click on It and Make Follow in Disambeller..and then find ur addys and UR DONE!!
Screen Shots:




















the part with the black Box is the WeaponMgr just remove the 10 and replace it with 0x so we change it from "10A68F90"
to "0xA68F90"






Virus Scans:

1-loadib: (100% clean)

loadlib.rar MD5:c00affd0d11ea934f4992b47eddc73e3 - VirSCAN.org Scanners did not find malware!

loadlib.rar - Jotti's malware scan

2-Olly:

OllyDbg.rar - Jotti's malware scan



Some Errors:

1-You may get a wierd Error when u open loadib.exe

2- U may Get Error When u open Olly...


Solutions:

Simple...If u read what i said

1-Just Delete msvcr100.dll from Crossfire folder and open loadib again

2- open olly and go to options>appearence>Directorires and Choose ur place in which u have put olly

Credits:
1- Me


Hope It gets Sticky

Some Text Strings Examples:

DamageZone


MoveSpeedPenalty = NoWepWeight
WallShotDamageRatio = shoot through walls
ChangeWeaponAnimRatio = NoChange Delay
CrossHairRatioPerRealSize =NoSpread
SingleFire/RepeatFire/ShrapnelFire/DelayFire/AlternateFire = fire types
ShotsPerAmmo = Shotgun spread
AmmoDamage = OHK
UnlimitedAmmo = No Reload
,4 3RepeatFireMode = fire types
,8 2RepeatFireMode = fire types
,10 1RepeatFireMode = fire types
KnifeNormalRange = knife long range
BulletPosOffset = NoRecoil
LowerAnimRate = LessRecoil
OllyDbg.rar7.3 MB · 1,722 downloads Scanning…
loadlib.rar4 KB · 859 downloads Scanning…
/req Stick
this will help biggeners
Quote Originally Posted by DaRk View Post
/req Stick
this will help biggeners
O Thx errol finally on my side
Where`s the attachment?
#request sticky .
bytheway can these also work on other games too?
What the fuck do you call an addy?
Addy = addresse (For example: 0x7F8 != addresse)
0x7F8 = Offset
Not a sticky worth, but good job though
Quote Originally Posted by A$IAN View Post
What the fuck do you call an addy?
Addy = addresse (For example: 0x7F8 != addresse)
0x7F8 = Offset
Not a sticky worth, but good job though
dont get what u are saying :l
Quote Originally Posted by moathebest View Post
dont get what u are saying :l
With addy, you mean offset.
I don´t know who started with "addy".
An add yis an addresse and for example, DamageZone is an addresse
Quote Originally Posted by A$IAN View Post

With addy, you mean offset.
I don´t know who started with "addy".
An add yis an addresse and for example, DamageZone is an addresse
Oh... kay then i will change the title
What he is sayying is:

That this is not an addy this is an offset.. 0x7F8 ,
This Tutorial will help beginners a lot
Good job
I am a little lost here... i can get through to the part where you get the addys but once you go to disassembler, I cant do anything past that. already tried and got detected. D:
I also dont know what values to put in the place of the addys, so if anyone could please tell me what to do, id be so grateful.
Quote Originally Posted by danielkillsya2 View Post
I am a little lost here... i can get through to the part where you get the addys but once you go to disassembler, I cant do anything past that. already tried and got detected. D:
I also dont know what values to put in the place of the addys, so if anyone could please tell me what to do, id be so grateful.
Well that depends on ur knowledge of asembeller but for beginnersu will find the addy like [EAX+1930] or [EDX+1930]

so in C++ its
#define 0x1930
Quote Originally Posted by moathebest View Post
Well that depends on ur knowledge of asembeller but for beginners you will find the addy like [EAX+1930] or [EDX+1930]

so in C++ its
#define 0x1930
So, i just add 0x to the start of the code/value? or do i NEED the #define 0x_______
Alrighty then.

Also, I can BARELY code anything. But i do have some experience with ASM, if using Cheat Engine to find and alter values counts XD (i mean actually getting into the system, filled with ESI, EDX and EBX, etc. and changing them.)

One last thing, if you ever get time, please post a video of this. If I cant do it myself, I could probably get the whole thing using video. Im kinda one of those people who learn by watching XD
Quote Originally Posted by danielkillsya2 View Post
So, i just add 0x to the start of the code/value? or do i NEED the #define 0x_______
Alrighty then.

Also, I can BARELY code anything. But i do have some experience with ASM, if using Cheat Engine to find and alter values counts XD (i mean actually getting into the system, filled with ESI, EDX and EBX, etc. and changing them.)

One last thing, if you ever get time, please post a video of this. If I cant do it myself, I could probably get the whole thing using video. Im kinda one of those people who learn by watching XD
Well ya u put 0x before the addy... the addy= 1930...= 0x1930 and i would put a video if i know how to record one and i know video is easier than steps so if u told me how to record one i would put it
Posts 1–15 of 17 · Page 1 of 2
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?