By
shoot
Re-VAC & 2003 - 2005 offset update list!
Credits go to R3dGhost and KenshinAMV for the goodies, because I'm too much of a lazy bastard to get all this stuff on my own
YOU WILL NEED:
A Hex editor (Hex Workshop, Hex Editor XVI32,etc >Just google it)
UPX (
http://upx.sourceforge.net/download/...le/upx190w.zip)
A Cheat to Revac (
http://www.mpcdownloads.com/_mpc_d0wn_h4x_/CS1.6/) (this has a good database of old cheats Pick an Opengl Cheat to start with)
++++++++++++++++++++
STEP 1: UnPacking
The first thing you do is unpack the .dll..
install upx to c:\documents & settings\username, also put the cheat .dll in this folder
go to start>programs>accessories>command prompt
use the command
"upx -d dllname.dll"
if the dll was packed, upx will unpack it, giving you access to a larger amount of strings..
upx -d (decompress)
upx -9 (efficient pack)
upx -force (force pack)
++++++++++++++++++++++
STEP 2: Strings
Go to the cheat .dll and right click>open with>Your Hex editor (If the hex editor isnt right in the list, got to select program from a list and select it)
Now u will see a bunch of wierd signs and squares.
Go up to the tool bar to search>Find a window will come up , where it says text search for one of the cheats cvars (ie. wall, aim etc)
In most cheats, all of the cvars are in the same spot in the .dll. use this to ur advantage.
My personal technique, is when you find the spot with the cvars, scroll UP in the .dll until the english words end and u just see more squares-
and more signs.
**********************
REMEMBER THAT U MUST RENAME THE CVARS WITH THE SAME AMMOUNT OF CHARACTERS OR THE CHEAT WONT FUNCTION!!!!!!!!!
*********************************************
**********************
most tutorials will tell u to search for all of the cvars individually
and change them as u find them.. I find this time consuming so i just search for them after when i think that im dont renaming them,
then i search for them and if i find any, i rename them
++++++++++++++++++++++
Step 3: OFFSETS
This is for more advanced cheats only, known as either Hybirds or client hooks.
here is an example of what u do with an offset:
An offset looks like this "0x02882255" for an example.. but in the .dll it is stored backwards
so the offset "0x02882255" becomes "02 88 22 55" (note: u remove the 0x) then reverse:
"55 22 88 02" (Note: the spaces are not to be used in your serch, they just amke it less confusing)
you will need to know wen the cheat u are revacing was detected so that u know which offsets to replace.
you can find this on game-deception.org probably
NOTE: Your are NOT finding "strings" for offsets.. make sure it is set to find and replace "hex values" and not "Text Values"
Code:
October 12, 2003
==========
pEngfuncs: 0x1EAC270
pEfxAPI: 0x1EC7600
pTriAPI: 0x1EC7CE8
pNetAPI: 0x1EC1BC0
pDemoAPI: 0x1EAD28C
pEventAPI: 0x1EB64F8
pVoiceTweak: 0x1ED2D80
pPmove: 0x2D4F320
pEngstudio: 0x1EC7A60
__________________________
January 15, 2004
==========
pEngfuncs: 0x1EAD270
pNetAPI: 0x1EC2CB8
pEfxAPI: 0x1EC86F8
pTriAPI: 0x1EC8DE0
pEventAPI: 0x1EB75F0
pVoiceTweak: 0x1ED3F68
pPmove: 0x2D50A20
pEngstudio: 0x1EC8B58
pUserCmd: 0x2EDDA1C
pParams: 0x13FA08
__________________________
March 7, 2004
==========
pEngfuncs: 0x1eb32b0
pEfxAPI: 0x1eceda0
pEventAPI: 0x1ebdb50
pTriAPI: 0x1ecf488
pNetAPI: 0x1ec92fc
pDemoAPI: 0x1eb42e4
pVoiceTweak: 0x1eda6c0
pPlayermove: 0x2d5b180
pEngstudio: 0x1ecf200
__________________________
March 24, 2004
==========
pEngfuncs: 0x01EB1270
pEngstudio: 0x01ECCE40
pPmove: 0x02D56720
Slots: 0x01EB1478
__________________________
April 03, 2004
==========
Engfuncs: 0x1EB2288
Engstudio: 0x1ECDE90
ppmove: 0x2D57C60
Slots: 0x1EB2498
LTFX Speedhack: 0x02805DE0
__________________________
April 29, 2004
==========
pEngfuncs: 0x1eb2288
pEngstudio: 0x1ece010
ppmove: 0x2d59f20
__________________________
June 2, 2004
==========
Engfuncs: 1EB32B0
Engstudio: 1ECF0D8
Pmove: 2D5B000
Slots: 1EB34C0
__________________________
June 07, 2004
==========
pEngfuncs: 0x1eb32b0
pEfxAPI: 0x1eceda8
pEventAPI: 0x1ebdb58
pTriAPI: 0x1ecf490
pNetAPI: 0x1ec9304
pDemoAPI: 0x1eb42d4
pVoiceTweak: 0x1eda6c8
pPlayermove: 0x2d5b180
pEngstudio: 0x1ecf208
__________________________
June 14, 2004
==========
pEngfuncs: 0x1eb32b0
pEfxAPI: 0x1ecec98
pEventAPI: 0x1ebdae0
pTriAPI: 0x1ecf380
pNetAPI: 0x1ec9254
pDemoAPI: 0x1eb42e4
pVoiceTweak: 0x1eda5a0
pPlayermove: 0x2d5b000
pEngstudio: 0x1ecf0f8
sound: 0x01D95CA0
__________________________
June 19, 2004
==========
pEngfuncs: 0x1eb32b0
pEfxAPI: 0x1ecec98
pEventAPI: 0x1ebdae0
pTriAPI: 0x1ecf380
pNetAPI: 0x1ec9254
pDemoAPI: 0x1eb42e4
pVoiceTweak: 0x1eda5a0
pPlayermove: 0x2d5b000
pEngstudio: 0x1ecf0f8
__________________________
June 21, 2004
==========
pEngfuncs: 0x1eb32b0
pEfxAPI: 0x1ececa8
pEventAPI: 0x1ebdad8
pTriAPI: 0x1ecf390
pNetAPI: 0x1ec9264
pDemoAPI: 0x1eb42c4
pVoiceTweak: 0x1eda5a0
pPlayermove: 0x2d5b000
pEngstudio: 0x1ecf108
sound: 0x01D95D20
__________________________
June 25, 2004
==========
pEngfuncs: 0x1eb32b0
pEfxAPI: 0x1ececa8
pEventAPI: 0x1ebdad8
pTriAPI: 0x1ecf390
pNetAPI: 0x1ec9264
pDemoAPI: 0x1eb42c4
pVoiceTweak: 0x1eda5a0
pPlayermove: 0x2d5b000
pEngstudio: 0x1ecf108
Slots: 0x1EB34C0
__________________________
July 8, 2004
==========
pEngfuncs: 0x1eb32b0
pEfxAPI: 0x1eceda0
pEventAPI: 0x1ebdb50
pTriAPI: 0x1ecf488
pNetAPI: 0x1ec92fc
pDemoAPI: 0x1eb42e4
pVoiceTweak: 0x1eda6c0
pPlayermove: 0x2d5b180
pEngstudio: 0x1ecf200
__________________________
July 8, 2004 Second Update
==========
pEngfuncs: 0x1eb32b0
pEfxAPI: 0x1eceda0
pEventAPI: 0x1ebdb50
pTriAPI: 0x1ecf488
pNetAPI: 0x1ec92fc
pDemoAPI: 0x1eb42e4
pVoiceTweak: 0x1eda6c0
pPlayermove: 0x2d5b180
pEngstudio: 0x1ecf200
RetarT Pointer: 0x01A044A0
__________________________
July 22, 2004
==========
RetarT Pointer: 0x01A179A0
__________________________
July 25, 2004
==========
RetarT Pointer: 0x01A179C0
__________________________
August 11, 2004
==========
pEngfuncs: 0x1eb32b0
pEfxAPI: 0x1eced90
pEventAPI: 0x1ebdb40
pTriAPI: 0x1ecf478
pNetAPI: 0x1ec92ec
pDemoAPI: 0x1eb42d4
pVoiceTweak: 0x1eda6b0
pPlayermove: 0x2d5b160
pEngstudio: 0x1ecf1f0
Sound ESP: 0x1d961d0
__________________________
June 7th 2005
==========
Slot Ptr: 0x01A179D0
Wrapper : 0x01EB54C8
pEngineFuncs : 0x01EB52B8
Studio Interface : 0x01ED14C4
Engine Studio : 0x01ED1400
PlayerMove : 0x02D5D9E0