Loading CShell.dll and editing memory without injection

Posts 16–22 of 22 · Page 2 of 2
Quote Originally Posted by Code[VB] View Post
nice but easy ... with vb you can make the same and can still use resice window with gdi methods
well, i dont know VB but i think it doesnt support pointers
so how can you call WriteProcessMemory?

---------- Post added at 02:53 PM ---------- Previous post was at 02:46 PM ----------

Quote Originally Posted by _corn_ View Post
lol tried that but it says

GetProcessImageFileNameA was not declared in this scope.
idk
try these
#pragma comment(lib, "psapi.lib")
#pragma comment(lib, "kernel32.lib")

~EDIT~
there is another 2 mistakes
Crossfire = dwPID[i]
i forgot the ;

and
ProcessClose
change to CloseHandle
@_corn_

~EDIT2~
change the line with GetImage bla bla to
GetModuleBaseNameA(hProc, NULL, FileName, 100);
idk
try these
#pragma comment(lib, "psapi.lib")
#pragma comment(lib, "kernel32.lib")

~EDIT~
there is another 2 mistakes
Crossfire = dwPID[i]
i forgot the ;

and
ProcessClose
change to CloseHandle
@_corn_
i picked up the ; mistake :P

still doesnt work, that is the only error now, was not declared in this scope. Maybe the arguments are wrong?
@giniyat101

---------- Post added at 10:03 AM ---------- Previous post was at 10:00 AM ----------

also

CShell + address

says no match for operator +

i need to use variable, as it reads the address from text file.

~EDIT~
i am using Code::Block and when i build it says ingoring #pragma comment

~EDIT 2~
for(int i=0,i<loop,i++)

expected initializer before < token
Ok I have fixed all errors apart from these ones which have randomly popped up:

Code:
undefined reference to `EnumProcesses@12'|
undefined reference to `GetModuleBaseNameA@16'|
undefined reference to `EnumProcessModules@16'|
undefined reference to `GetModuleBaseNameA@16'|
Quote Originally Posted by giniyat101 View Post
well, i dont know VB but i think it doesnt support pointers
so how can you call WriteProcessMemory?

---------- Post added at 02:53 PM ---------- Previous post was at 02:46 PM ----------


idk
try these
#pragma comment(lib, "psapi.lib")
#pragma comment(lib, "kernel32.lib")

~EDIT~
there is another 2 mistakes
Crossfire = dwPID[i]
i forgot the ;

and
ProcessClose
change to CloseHandle
@_corn_

~EDIT2~
change the line with GetImage bla bla to
GetModuleBaseNameA(hProc, NULL, FileName, 100);
like this
Code:
 Private Declare Function WriteProcessMemory Lib "kernel32" Alias "WriteProcessMemory" (ByVal hProcess As Integer, ByVal lpBaseAddress As Integer, ByRef lpBuffer As Integer, ByVal nSize As Integer, ByRef lpNumberOfBytesWritten As Integer) As Integer
my vb hack function look something like this
Code:
  string1 = readdll("CShell.dll")
  string2 = "&H" & Hex(string1 + address)
  WriteMemory(string2, value, bytes)
Quote Originally Posted by Code[VB] View Post
like this
Code:
 Private Declare Function WriteProcessMemory Lib "kernel32" Alias "WriteProcessMemory" (ByVal hProcess As Integer, ByVal lpBaseAddress As Integer, ByRef lpBuffer As Integer, ByVal nSize As Integer, ByRef lpNumberOfBytesWritten As Integer) As Integer
my vb hack function look something like this
Code:
  string1 = readdll("CShell.dll")
  string2 = "&H" & Hex(string1 + address)
  WriteMemory(string2, value, bytes)
i kinda understand.. you mean that byref is like pointers in c++? i see you are using it instead of passing pointers
Quote Originally Posted by _corn_ View Post
ok lets explain.

i want to do the same as a hack, so basically, get the handle for CShell, add on the addresss and addy, and write to that memory, just like in a hack dll. except from a separate exe file.

also, what the hell is a wstring and what is it for?
I think u want to make it run automatic...not injecting...so try making a loader in VB its much easier lol...
I have a question. Anyone can make it work with normal XTrap running. I have been try this method before and when XTrap appear, process CrossFire was protected so i can get anything from it but with bypass Xtrap my program work and i can modify any i want. My CF in VietNam and i newbie c++.

I use WriteProcessMemory.

I sure we can modify crossfire execute file before XTrap coming (can't modify CShell because it come up after XTrap), I have been use this method for HGWC to disable CheckFile, for something in crossfire.dat (it is CF execute file in my country) and all still work up to now.

I have fail in this method for normal XTrap. With Bypass XTrap i can't play game because it always Disconnect From Server. Finally, I still use inject .
Can someone share me bypass XTrap work not disconnect i will share method to Full Unpack CShell (i tested with Bypass Xtrap and it work normally).

Edit: wchar (wide char) is unicode char (i think and pretty sure about that because when i scan text in CE i have to use Unicode to find them). It use for all function end with "W" ex: CreateProcessW()... And btw "A" is ascii: GetModuleBaseNameA(). Sorry if i wrong .
Posts 16–22 of 22 · Page 2 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us