Trainers on the original Xbox are patch files with a .ETM extension. They alter memory or game logic at runtime, enabling features like infinite health, ammo, or debug displays. These are typically activated through in-game button combos or toggled in launchers such as XBMC.
Overview
An .ETM file is a binary structure written in C and encoded in little-endian format. It includes a compact header followed by pointers to various functional sections, such as toggle states, text labels, and actual patch instructions. The primary role of the trainer is to inject code or alter memory values at runtime in a way that the game accepts.
Trainers do not modify the game executable (.XBE) directly—instead, they hook or patch memory at specific offsets while the game is running. They are often created through disassembly and trial/error, and many follow similar internal structures.
.ETM File Structure
The trainer format begins with a small header that describes the internal layout. Below is a breakdown:
Header Section
| Offset | Size | Name | Description | Notes |
|---|---|---|---|---|
| 0x0000 | 0x0004 | FileSize of Patch | Total size of the .ETM file | |
| 0x0004 | 0x0002 | Version | Trainer format version | Typically 0x0001 |
| 0x0006 | 0x0004 | HeaderSize | Marks where the header ends and body begins | Typically 0x0023 |
| 0x000A | 0x0004 | Offset Pointer - OptionListToggle | Offset location of trainer options to toggle on/off | Bitflags for each trainer option |
| 0x000E | 0x0004 | Offset Pointer - OptionTextPointers | Offset location of the "OptionTextPointers" | This section contains offset locations for "Patch Title", "Description" and "Option Name(s)" |
| 0x0012 | 0x0004 | Offset Pointer - TitleID(s) | Offset location of a list of supported Title IDs | Allows multiple Title IDs |
| 0x0016 | 0x0004 | Offset Pointer - EntryPoint | Offset location that contains the patch instructions | Usually assembled opcodes that replace bytes |
| 0x001A | 0x0004 | Reserved | Unused | |
| 0x001E | 0x0004 | Reserved | Unused | |
| 0x0022 | 0x0001 | MasterEnable | Global enable switch (True/False) | Typically 0x00 unless pre-enabled |
Option List Toggle
Located via the pointer at offset 0x000A, the OptionListToggle section defines which trainer features are enabled at runtime. Each option typically occupies a byte or bitfield indicating its toggle state. The Default state is "00", and trainer managers manipulate this at run-time in their UI.
Option Text Pointers
Located via the pointer at offset 0x000E, this section maps to human-readable strings used in a trainer manager's UI to describe each cheat option. The pointers here are used to render trainer option names dynamically.
Title ID(s)
Located via the pointer at offset 0x0012, this section lists the unique Xbox game identifiers (Title IDs) the trainer supports. One .ETM can be used across multiple regional versions or game editions if the memory layout is compatible.
Entry Point (Patches)
Located via the pointer at offset 0x0016, this section is where the core functionality lives. It usually consists of compiled Xbox assembly instructions and/or memory writes. These are executed by the trainer engine at runtime. The structure is flexible enough to support various modifications like:
- Overwriting memory to NOP instructions (e.g., disabling health subtraction)
- Injecting jump instructions to new behavior
- Writing fixed values like ammo counts or flags
Activating Trainers
Trainers are usually toggled through:
- Toggled to enabled and launched via apps like XBMC, EvolutionX or Xored Trainer Launcher that support .ETM loading
- Pressing button combination macros (hardcoded in the trainer) during gameplay
Creating Your Own Trainers
Crafting .ETM files usually involves:
- Reverse engineering games using tools like Ghidra or IDA Pro
- Finding code caves or unused memory regions
- Identifying the game logic you want to manipulate
- Assembling code or generating memory write instructions
- Populating an .ETM header and sections accordingly
For more advanced patching workflows, you may want to study .XBE disassembly in detail and correlate memory addresses with .ETM injection logic.
Summary
.ETM trainer files act as structured memory patches for original Xbox games, enabling real-time game modifications without modifying the core executable. They use clearly defined offsets and internal sections for toggles, UI text, game compatibility, and patch injection.
Understanding the structure and layout is crucial for building stable, effective trainers that enhance games without crashing them.