Addys + Dumped Cshell.dll

Posts 1–15 of 25 · Page 1 of 2
Addys + Dumped Cshell.dll
A few addys i found and i dumped the cshell.dll so for the people who cant dump it.


No Reload = 0x2424
No Spread = 0x2428
WeaponMgr = 0xA287A8
C4Defuse time = 0x2D0E7C //not sure
C4Plant time = 0x2D0E8C //not sure
C4Defuse Distance = 0x2D0E64 //not sure


virustotal: VirusTotal - Free Online Virus, Malware and URL Scanner

Jotti: Dumped.rar - Jotti's malware scan
Dumped.rarattachment deleted · 235 downloads before removal
Nice Thank You But Where Weapon Mgr ?
Mhmmmmmmmmm
its the same addys? lol
kkkk EY ALGUEM PODE ME PASAR U M HAKER Q ESTEJA FUNFANDO SOU BRAZILEIRO
MSN:CABECAO19962009@.hotMAIL.COM
Quote Originally Posted by matheus12131 View Post
kkkk EY ALGUEM PODE ME PASAR U M HAKER Q ESTEJA FUNFANDO SOU BRAZILEIRO
MSN:CABECAO19962009@.hotMAIL.COM
English please
Quote Originally Posted by joered View Post
A few addys i found and i dumped the cshell.dll so for the people who cant dump it.


No Reload = 0x2424
No Spread = 0x2428
WeaponMgr = 0xA287A8
C4Defuse time = 0x2D0E7C //not sure
C4Plant time = 0x2D0E8C //not sure
C4Defuse Distance = 0x2D0E64 //not sure


virustotal: VirusTotal - Free Online Virus, Malware and URL Scanner

Jotti: Dumped.rar - Jotti's malware scan
NoSpread is wrong or the same as

NoChangeWeapon: 0x2428


and how did u found that addy for c4plant time , c4defuse time , C4DefuseDistance?

i found:
C4Plant time: 0x7c
C4defuse time: 0x80
C4DefuseDistance: 0x84
Quote Originally Posted by proman98 View Post
NoSpread is wrong or the same as

NoChangeWeapon: 0x2428


and how did u found that addy for c4plant time , c4defuse time , C4DefuseDistance?

i found:
C4Plant time: 0x7c
C4defuse time: 0x80
C4DefuseDistance: 0x84
Oh ok thanks

Ehm i saw in olly something with DefuseDistance and stuff
Hey, how did you dump the CShell.dll?
DefuseDistance and C4 Plant Time and Defuse Time...i heard they are server sided
Quote Originally Posted by ntontos View Post
DefuseDistance and C4 Plant Time and Defuse Time...i heard they are server sided
They aren't .
Your dumped CShell is badly unpacked
It's mostly unusable
Only Weapon Part is Readable on your dumped CShell
Here's mine + unpacked_crossfire.exe
Open both in IDA to look for addies

Virus Scans :
- VirusTotal.com : https://www.virustotal.com/file-scan...a7b-1309059511
- Jotti.org : unpacked_crossfire_files.rar - Jotti's malware scan

Note : DrWeb is a good antivirus but this time it failed hard

Note2 : idb files are database files for IDA use them if you want

/req approve
@Shane
@Haze
@Coke
@Ghost
@Thunder
@Gab
unpacked_crossfire_files.rarattachment deleted · 40 downloads before removal
this is totally stupid! why would we need these when proman posted everything???????
Need Help which Value i have to freeze
for No Reload
Thanks
Posts 1–15 of 25 · Page 1 of 2

Post a Reply

Tags for this Thread

None

Talk with us