I wanted to release my loadlib for dumping CShell.dll
Tutorial:
- Put the Loadlib.exe in your CF folder
- Start it
- Install the plugin PE Dumper in Ollydbg (Attachment)
- Start Ollydbg
- Attach -> Loadlib.exe
- View -> Module -> CShell.dll
- Click on Plugins -> PE Dumper -> Make dump of process
- Save the dumped CShell.dll
- DONE!
Now how to use it:
- Open Ollydbg
- Open -> DumpedCShell.dll
- Search for all referenced text strings
- Search for text -> ReloadAnimRatio
- Click on it
- Now look for 101EBB2E . D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]
- In C++:
WeaponMgr is definitely not 0 ..
and why dumping it? you can load the module without any errors and view it in olly - easier
Originally Posted by ARGB
WeaponMgr is definitely not 0 ..
and why dumping it? you can load the module without any errors and view it in olly - easier
Its an example...
You can find the address
Originally Posted by Nik0815
Its an example...
You can find the address
are you kidding me? you dont know what youre doing, you dont need to dump it if you can load it with loadlibrary, but I guess ah nvm its just noob-coded thats why u need to dump it
Originally Posted by ARGB
are you kidding me? you dont know what youre doing, you dont need to dump it if you can load it with loadlibrary, but I guess ah nvm its just noob-coded thats why u need to dump it
Or maybe he / she really just wrote a random address just to show, how it supposed to seem like...
Originally Posted by rabir007
Or maybe he / she really just wrote a random address just to show, how it supposed to seem like...
Yep...............
still not needed, everybody here should be able to code such a simple application ..
Originally Posted by ARGB
WeaponMgr is definitely not 0 ..
and why dumping it? you can load the module without any errors and view it in olly - easier
probably for anti-leeching ...
This has already posted, if I'm not mistaken.
less the LoadLib by Nik0815.
Thanks.
---------------------------
E:\CrossFire\EU\LoadLib by Nik0815.exe
---------------------------
E:\CrossFire\EU\LoadLib by Nik0815.exe is not a valid Win32 application.
---------------------------
OK
---------------------------