How to unpack CShell.dll and find addies
Hello everyone!Today i will explain in a perfect way (just to know! only in words no pics) how to unpack CShell.dll and find the addies.
Good here we start.
1.First u need OllyDbg better use the one on attachment its 0.93 the one that lauwy used.Ty lauwy
2.Open it and go to options->appearance and then got to the tab named Directories u have the UDD file and u must chose the directorie of OllyDbg
like example-> UDD: C:\Documents and Settings\Alex\Desktop\OllyDbG\UDD for UDD
Plugin -> C:\Documents and Settings\Alex\Desktop\OllyDbg
Then we can start!!
3a.Close OllyDbg then u must put loadlib.exe in ur crossfire folder.
The one that will be in attachment.
3b.loadlib.exe will open a cmd promt which will say the library has been loaded
Press any .........
do not press anything just minimize it.Coz ur gonna need it.
4.Finally open OllyDbg the one with red icon.
do not scary when u will see that its named Olllllly
its just the v0.93 bug
5a.I the left up part of olly u will see some tabs especially the plugin one
5b.Press the tab named File then attach and search for loadlib.exe which we opened 4 min ago search for it then press it once then press the attach button
5c.after u pressed it an entry point alert will appear (read it if u want) and press ok
6a.Right click on the CPU (the window that appeared) and Serach for -> All refered text strings
6b.Then another window will appear named text strings referenced .....
Good we are close to the addies
7a.Now Up there are some letters L E M and so on u must press the M button
7b.Another window will appear named Memory Map
8.Click on loadlib.exe .text code or
CShell.dll .text code
it must be in this format no other
9.Click the tab Plugins -> OllyDbg PE Dumper ->Make dump of process
10a.Then u choose CShell.dll (1000000) and click Dump
10b.Then u must save it as on file name write _CShell
and save as type dinamik link library or .dll
10c.pedumper will appear and say that its saved and press ok
11.now press again the tab File -> Open then choose _CShell.dll from Crossfire folder . file name _CShell.dll and open it
12.Now open the window text strings referenced maximize it and then right click ->Search for text -> u must ONLY tick entire scope ONLY ->ReloadAnimRatio
13.Excelent u found the features but the addies?
14a.Right Click any feature ->follow in desassembler for example NoReload
14b.The code is the one which says [EAX+2420] for ReloadAnimRatio=NoReload
And the code starts with 0x and the numbers or letters that are after [EAX+2420] for NoReload
After u did all of these things you found the features and after the addies
but you won't need to do all of these, step by step all the time.
When u want to look for addies next time just press in Olly File ->Open in CF folder and open _CShell.dll and just search for the addies.
Virus Scans:
http://www.virustotal.com/file-scan/...93f-1309011306
http://www.virustotal.com/file-scan/...125-1307461644
!!HAVE FUN!!
Credits:al3xman for writing all this
@Coke
aprove it if u want..
Download:OllyDbg for olly
Good here we start.
1.First u need OllyDbg better use the one on attachment its 0.93 the one that lauwy used.Ty lauwy
2.Open it and go to options->appearance and then got to the tab named Directories u have the UDD file and u must chose the directorie of OllyDbg
like example-> UDD: C:\Documents and Settings\Alex\Desktop\OllyDbG\UDD for UDD
Plugin -> C:\Documents and Settings\Alex\Desktop\OllyDbg
Then we can start!!
3a.Close OllyDbg then u must put loadlib.exe in ur crossfire folder.
The one that will be in attachment.
3b.loadlib.exe will open a cmd promt which will say the library has been loaded
Press any .........
do not press anything just minimize it.Coz ur gonna need it.
4.Finally open OllyDbg the one with red icon.
do not scary when u will see that its named Olllllly
its just the v0.93 bug
5a.I the left up part of olly u will see some tabs especially the plugin one
5b.Press the tab named File then attach and search for loadlib.exe which we opened 4 min ago search for it then press it once then press the attach button
5c.after u pressed it an entry point alert will appear (read it if u want) and press ok
6a.Right click on the CPU (the window that appeared) and Serach for -> All refered text strings
6b.Then another window will appear named text strings referenced .....
Good we are close to the addies
7a.Now Up there are some letters L E M and so on u must press the M button
7b.Another window will appear named Memory Map
8.Click on loadlib.exe .text code or
CShell.dll .text code
it must be in this format no other
9.Click the tab Plugins -> OllyDbg PE Dumper ->Make dump of process
10a.Then u choose CShell.dll (1000000) and click Dump
10b.Then u must save it as on file name write _CShell
and save as type dinamik link library or .dll
10c.pedumper will appear and say that its saved and press ok
11.now press again the tab File -> Open then choose _CShell.dll from Crossfire folder . file name _CShell.dll and open it
12.Now open the window text strings referenced maximize it and then right click ->Search for text -> u must ONLY tick entire scope ONLY ->ReloadAnimRatio
13.Excelent u found the features but the addies?
14a.Right Click any feature ->follow in desassembler for example NoReload
14b.The code is the one which says [EAX+2420] for ReloadAnimRatio=NoReload
And the code starts with 0x and the numbers or letters that are after [EAX+2420] for NoReload
After u did all of these things you found the features and after the addies
but you won't need to do all of these, step by step all the time.
When u want to look for addies next time just press in Olly File ->Open in CF folder and open _CShell.dll and just search for the addies.

Virus Scans:
http://www.virustotal.com/file-scan/...93f-1309011306
http://www.virustotal.com/file-scan/...125-1307461644
!!HAVE FUN!!
Credits:al3xman for writing all this
@Coke
aprove it if u want..
Download:OllyDbg for olly
loadlib.rar

!