xXDzepniXx How do I cheat?
Reputation: 0
Joined: 30 Jul 2013 Posts: 3 Location: In your basement, playing the computer.
|
Posted: Sat May 24, 2014 10:50 pm Post subject: [HELP] Figuring out new codes |
|
|
So, I got these patched codes, and they're not in AOB (Array of Bytes) I don't know how to figure out the new ones, I am guessing it uses AA to figure it out, so that's why I'm here. Here, have this, I don't know whether I look for this, or not.
mov [edx-35]
mov [edx-31]
mov [edx-2D]
mov [edx-29]
mov [edx-25]
mov [edx-21]
mov [edx-1D]
Some of you may recognize this, yes, but lets keep anything NOT education in this topic, yes? So I'll also give you this:
mov [edx-35],69666F64, as you can see it's not in AOB, and I don't quite know what the 69666F64 is in, it certainly isn't AOB. Now, we have this:
cmp edx,00010000
jl originalcode
cmp [edx-35],'load'
jne originalcode So, what is this? I'm trying to break all these parts down, but I see this, and it tells me nothing, and I have guesses, that's it.
originalcode:
push ebp
mov ebp,esp
push ecx
push ecx
exit:
jmp returnhere
"MSVCR110.dll"+151FC:
jmp newmem
returnhere:
At the top, this is the rest, yes there will be a little missing, but I'm putting up what I need to know about, so the MSVCR110.dll tells me that I look into the dll? Which I did, and since it's patched codes, I did not find the same ones. But what is the "+151FC"? And the rest, does the:
originalcode:
push ebp
mov ebp,esp
push ecx
push ecx
Say that only THESE, push, ecx, ebp, esp, will be in the code? I have second thoughts seeing edx. But, it's all guesses. So thanks for reading, and I hope someone can help me.
|
|