How to Find WeaponMGR

Posts 1–15 of 16 · Page 1 of 2
How to Find WeaponMGR
101F8119 68 98834510 PUSH CShell.10458398 ; ASCII "ReloadAnimRatio"
101F811E D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]
101F8124 55 PUSH EBP
101F8125 E8 86C21D00 CALL CShell.103D43B0
101F812A 83C4 08 ADD ESP,8
101F812D 85C0 TEST EAX,EAX
101F812F 74 46 JE SHORT CShell.101F8177
101F8131 8B48 04 MOV ECX,DWORD PTR DS:[EAX+4]
101F8134 8B51 04 MOV EDX,DWORD PTR DS:[ECX+4]
101F8137 8B0D 9C02EA10 MOV ECX,DWORD PTR DS:[10EA029C]
101F813D 85C9 TEST ECX,ECX
101F813F 8B5A 04 MOV EBX,DWORD PTR DS:[EDX+4]
101F8142 74 0E JE SHORT CShell.101F8152
101F8144 A1 A002EA10 MOV EAX,DWORD PTR DS:[10EA02A0]
101F8149 2BC1 SUB EAX,ECX
101F814B C1F8 02 SAR EAX,2
101F814E 3BF0 CMP ESI,EAX
101F8150 72 08 JB SHORT CShell.101F815A
101F8152 FFD7 CALL EDI
101F8154 8B0D 9C02EA10 MOV ECX,DWORD PTR DS:[10EA029C]
101F815A 53 PUSH EBX
101F815B 8D3CB1 LEA EDI,DWORD PTR DS:[ECX+ESI*4]
101F815E FF15 94C34110 CALL DWORD PTR DS:[1041C394] ; MSVCR80.atof
101F8164 D95C24 14 FSTP DWORD PTR SS:[ESP+14]
101F8168 D94424 14 FLD DWORD PTR SS:[ESP+14]
101F816C 8B07 MOV EAX,DWORD PTR DS:[EDI]
101F816E D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]
101F8174 83C4 04 ADD ESP,4
101F8177 68 7C834510 PUSH CShell.1045837C ; ASCII "CrossHairRatioPerRealSize"
101F817C 55 PUSH EBP
101F817D E8 2EC21D00 CALL CShell.103D43B0
101F8182 83C4 08 ADD ESP,8
Quote Originally Posted by Astr3Lune View Post
101F8119 68 98834510 PUSH CShell.10458398 ; ASCII "ReloadAnimRatio"
101F811E D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]
101F8124 55 PUSH EBP
101F8125 E8 86C21D00 CALL CShell.103D43B0
101F812A 83C4 08 ADD ESP,8
101F812D 85C0 TEST EAX,EAX
101F812F 74 46 JE SHORT CShell.101F8177
101F8131 8B48 04 MOV ECX,DWORD PTR DS:[EAX+4]
101F8134 8B51 04 MOV EDX,DWORD PTR DS:[ECX+4]
101F8137 8B0D 9C02EA10 MOV ECX,DWORD PTR DS:[10EA029C]
101F813D 85C9 TEST ECX,ECX
101F813F 8B5A 04 MOV EBX,DWORD PTR DS:[EDX+4]
101F8142 74 0E JE SHORT CShell.101F8152
101F8144 A1 A002EA10 MOV EAX,DWORD PTR DS:[10EA02A0]
101F8149 2BC1 SUB EAX,ECX
101F814B C1F8 02 SAR EAX,2
101F814E 3BF0 CMP ESI,EAX
101F8150 72 08 JB SHORT CShell.101F815A
101F8152 FFD7 CALL EDI
101F8154 8B0D 9C02EA10 MOV ECX,DWORD PTR DS:[10EA029C]
101F815A 53 PUSH EBX
101F815B 8D3CB1 LEA EDI,DWORD PTR DS:[ECX+ESI*4]
101F815E FF15 94C34110 CALL DWORD PTR DS:[1041C394] ; MSVCR80.atof
101F8164 D95C24 14 FSTP DWORD PTR SS:[ESP+14]
101F8168 D94424 14 FLD DWORD PTR SS:[ESP+14]
101F816C 8B07 MOV EAX,DWORD PTR DS:[EDI]
101F816E D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]
101F8174 83C4 04 ADD ESP,4
101F8177 68 7C834510 PUSH CShell.1045837C ; ASCII "CrossHairRatioPerRealSize"
101F817C 55 PUSH EBP
101F817D E8 2EC21D00 CALL CShell.103D43B0
101F8182 83C4 08 ADD ESP,8
101F8154 8B0D 9C02EA10 MOV ECX,DWORD PTR DS:[10EA029C]
101F815B 8D3CB1 LEA EDI,DWORD PTR DS:[ECX+ESI*4]
101F816C 8B07 MOV EAX,DWORD PTR DS:[EDI]
101F816E D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]

Check th colors, or
Easier form:
ECX := 10EA029C; (pWeaponMgr = *(DWORD*)(CShell + 0xEA029C) )
EDI := ECX+ESI*4; (CurrentWeapon = pWeaponMgr + (4 * i) )
EAX := EDI ( CurrentWeapon = *(DWORD*)(CurrentWeapon) )
[EAX+C3C] = ReloadAnimRatio
Quote Originally Posted by rabir007 View Post


101F8154 8B0D 9C02EA10 MOV ECX,DWORD PTR DS:[10EA029C]
101F815B 8D3CB1 LEA EDI,DWORD PTR DS:[ECX+ESI*4]
101F816C 8B07 MOV EAX,DWORD PTR DS:[EDI]
101F816E D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]

Check th colors, or
Easier form:
ECX := 10EA029C; (pWeaponMgr = *(DWORD*)(CShell + 0xEA029C) )
EDI := ECX+ESI*4; (CurrentWeapon = pWeaponMgr + (4 * i) )
EAX := EDI ( CurrentWeapon = *(DWORD*)(CurrentWeapon) )
[EAX+C3C] = ReloadAnimRatio






so wich this weaponMgr ===> 0xEA029C ?
Quote Originally Posted by Astr3Lune View Post
so wich this weaponMgr ===> 0xEA029C ?
-_- yes, that is the WeaponMgr...
Quote Originally Posted by rabir007 View Post


-_- yes, that is the WeaponMgr...
ok thanks.

can you help me other my question?
Quote Originally Posted by Astr3Lune View Post
ok thanks.

can you help me other my question?
Excatly ?
/msg2short
Quote Originally Posted by rabir007 View Post


Excatly ?
/msg2short


can you give me simple source wallhack undetect only?
please i need simple source wallhack undetect auto on.

i'm use this memory memcpy((VOID*)0x6D29F4 , "\x00\x00\x00\x00\x00\x00", 6);
But it's Detect.

and I'm use other memroy memcpy((VOID*)0x6D29F4 , "\x90\x90\x90\x90\x90\x90", 6);
undetect but wallhack not Work.

Why?
can you Help me about this memory?
sory Bad English
Quote Originally Posted by Biesi View Post


what do you mean?

CPU architecture
Intel x86 CPU family



Mnemonic
NOP


Bytes
1; 1–9 for i686



Opcode
0x90; 0x0f 0x1f[2]

Notes












i'm not understand
help me
Quote Originally Posted by Astr3Lune View Post
i'm not understand
help me
You should read the text ..
In computer science, a NOP or NOOP (short for No Operation) is an assembly language instruction, sequence of computer programming language statements, or computer protocol command that effectively does nothing at all.
Quote Originally Posted by ARGB View Post
You should read the text ..
In computer science, a NOP or NOOP (short for No Operation) is an assembly language instruction, sequence of computer programming language statements, or computer protocol command that effectively does nothing at all.


i'm not understand

Can you give me tutorial memory wallhack in ollyDbg?
Quote Originally Posted by Astr3Lune View Post
Can you give me tutorial memory wallhack
you wont understand it - only c&p
Quote Originally Posted by Biesi View Post


you wont understand it - only c&p





0045B6D4 75 11 JNZ SHORT crossfir.0045B6E7
0045B6D6 830D 18CD6D00 01 OR DWORD PTR DS:[6DCD18],1
0045B6DD B8 70CB6D00 MOV EAX,crossfir.006DCB70
0045B6E2 E8 19A60600 CALL crossfir.004C5D00
0045B6E7 8B06 MOV EAX,DWORD PTR DS:[ESI]
0045B6E9 8B50 18 MOV EDX,DWORD PTR DS:[EAX+18]
0045B6EC 8D4C24 58 LEA ECX,DWORD PTR SS:[ESP+58]

How to find NOP wallhack in OllyDbg?
Posts 1–15 of 16 · Page 1 of 2
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?