Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


[question-for-darkbyte]

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Cheat Engine Source
View previous topic :: View next topic  
Author Message
redeyes1
Newbie cheater
Reputation: 0

Joined: 28 Jun 2007
Posts: 13

PostPosted: Sun Jul 29, 2007 11:30 pm    Post subject: [question-for-darkbyte] Reply with quote

umm, can you tell me how to comment out these DBKFunc.c rootkit.c processlist.c memscan.c threads.c jumper.c in sources.ce, without errors, ive read your log many times on how to do it, but im not quite sure on the sys file, thats the last thing i need to do, then im releasing engine.
thx
Venom Engine1.0 is name
Back to top
View user's profile Send private message
Dark Byte
Site Admin
Reputation: 470

Joined: 09 May 2003
Posts: 25788
Location: The netherlands

PostPosted: Mon Jul 30, 2007 6:03 am    Post subject: Reply with quote

follow from the path from dbkdrvr.c
If you uncomment a function call, you have to add a new sourcefile.
So add the sourcefile and uncomment the function that was supposed to call and perhaps some others as well if you like

then check for detection
uncomment a bit and check again, etc...
till you get to the point that you need a new source file to be added and repeat the steps

_________________
Do not ask me about online cheats. I don't know any and wont help finding them.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
redeyes1
Newbie cheater
Reputation: 0

Joined: 28 Jun 2007
Posts: 13

PostPosted: Thu Aug 09, 2007 11:39 pm    Post subject: Reply with quote

hello again, ive attempted at the sys file, i finally understand how to comment it out and stuff, but i cannot find detected strings, cause i dont think it loads the sys file, but when i comment out stuf i think it dosent load, because it aint detected anywhere inbetween tests, and i uncommented the last one and it had no errors and loaded and detected. In the engine is there only like one setting i enable or sompthing to test for detected strings in sys file.
thanks again for your help, credits goes to everyone who helps
btw, its the last darn file lol, now i think im gunna gave to pospone release date cause of sys file:(
Back to top
View user's profile Send private message
Dark Byte
Site Admin
Reputation: 470

Joined: 09 May 2003
Posts: 25788
Location: The netherlands

PostPosted: Fri Aug 10, 2007 7:01 am    Post subject: Reply with quote

To test is the sys is loaded load up dbgview and add a DbgPrint("I am loaded"); line at driverentry
that will then show up in dbgview if it's running at the same time it's loaded.

Then start uncommenting simple stuff that don't require you to add new files, then when you can't get further uncomment something that does and add that file and continue.

till detected and then check the last uncommented piece of code. (not I say code as it is NOT a string)
And then recode that section sligtly different.
E.g perhaops I use a static value 0xc0000000 which may be detected and perhaps if you replace it with a variable that hold that value it isn't detected

_________________
Do not ask me about online cheats. I don't know any and wont help finding them.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
redeyes1
Newbie cheater
Reputation: 0

Joined: 28 Jun 2007
Posts: 13

PostPosted: Fri Aug 10, 2007 12:30 pm    Post subject: Reply with quote

[quote="Dark Byte"]To test is the sys is loaded load up dbgview and add a DbgPrint("I am loaded"); line at driverentry
that will then show up in dbgview if it's running at the same time it's loaded.

what is dbgview
thanks
Back to top
View user's profile Send private message
appalsap
Moderator
Reputation: 0

Joined: 27 Apr 2006
Posts: 6753
Location: Pakistan

PostPosted: Fri Aug 10, 2007 12:46 pm    Post subject: Reply with quote

http://www.microsoft.com/technet/sysinternals/utilities/debugview.mspx

It is a program that lets you view debugprints without having to debug the process.
Back to top
View user's profile Send private message
redeyes1
Newbie cheater
Reputation: 0

Joined: 28 Jun 2007
Posts: 13

PostPosted: Fri Aug 10, 2007 12:49 pm    Post subject: Reply with quote

thank u so much, i coulnt do this without yall. Smile

00000000 0.00000000 KeServiceDescriptorTableShadow[0]=80559650
00000001 0.00000950 KeServiceDescriptorTableShadow[1]=80559660
00000002 0.00001397 KeServiceDescriptorTableShadow[2]=80559670
00000003 0.00001816 KeServiceDescriptorTableShadow[3]=80559680
00000004 0.00004414 Calling ObOpenObjectByPointer
00000005 0.00005699 ntStatus=0
00000006 0.02175304 [3664] Protectme called
00000007 0.02914728 KeServiceDescriptorTableShadow[0]=80559650
00000008 0.02915678 KeServiceDescriptorTableShadow[1]=80559660
00000009 0.02916125 KeServiceDescriptorTableShadow[2]=80559670
00000010 0.02916544 KeServiceDescriptorTableShadow[3]=80559680
00000011 0.02920008 Calling ObOpenObjectByPointer
00000012 0.02921461 ntStatus=0

im guessing this means its loaded right?
once again, im sorry, im a noob at the sys file, so im learning slowly


Last edited by redeyes1 on Fri Aug 10, 2007 12:59 pm; edited 1 time in total
Back to top
View user's profile Send private message
appalsap
Moderator
Reputation: 0

Joined: 27 Apr 2006
Posts: 6753
Location: Pakistan

PostPosted: Fri Aug 10, 2007 12:59 pm    Post subject: Reply with quote

Yes
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Cheat Engine Source All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites