#include "stdafx.h"
DWORD WINAPI Thread( LPVOID lParam )
{
HMODULE hModule = GetModuleHandle( L"game.dll" );
MODULEINFO mdlinfo;
GetModuleInformation( GetCurrentProcess(), hModule, &mdlinfo, sizeof( mdlinfo ) );
unsigned char GameSavLoad1[] = { 0x81, 0xEC, 0x28, 0x02 };
unsigned char GameSavLoad2[] = { 0x00, 0x00, 0x53, 0x55 };
unsigned char GameSavLoad3[] = { 0x56, 0x57, 0x68, 0x54 };
unsigned int head_offs = 0x676134;
unsigned int def_offs = 0x4F80C0;
unsigned int offset = 0;
int c= (int)hModule;
int max = (int)hModule + mdlinfo.SizeOfImage - sizeof( unsigned char[4] ) * 3;
while( c != max )
{
if( memcmp( (void*)(c), GameSavLoad1, sizeof( GameSavLoad1 ) ) == 0 &&
memcmp( (void*)(c + sizeof( unsigned char[4] ) ), GameSavLoad2, sizeof( GameSavLoad2 ) ) == 0 &&
memcmp( (void*)(c + sizeof( unsigned char[4] ) * 2 ), GameSavLoad3, sizeof( GameSavLoad3 ) ) == 0)
{
break;
}
offset++; c++;
}
//TCHAR str[128];
//TCHAR str1[128];
//wsprintf( str, L"Offset found %x!\nHead:%x+%x=%x\nAny:%x+%x=%x", offset, c, head_offs , c + head_offs , c, def_offs, def_offs + c );
//wsprintf( str1, L"Size: %x", mdlinfo.SizeOfImage - sizeof( unsigned char[4] ) * 3 );
//MessageBox( 0, str, 0, MB_OK );
//MessageBox( 0, str1, 0, MB_OK );
if( c != max )
{
unsigned char ammo_sig[] = { 0x66, 0x29, 0x5C, 0x7E };
unsigned char ammo_patch[] = { 0x83, 0x6C, 0x7E, 0x3C, 0x00};
while( c != max )
{
if( memcmp( (void*)(c), ammo_sig, sizeof( ammo_sig ) ) == 0 )
{
DWORD dwOldState;
VirtualProtect( (void*)c, sizeof( ammo_patch ), PAGE_READWRITE, &dwOldState );
if( true )
{
*(unsigned char*)( c ) = ammo_patch[0];
*(unsigned char*)( c + 1 ) = ammo_patch[1];
*(unsigned char*)( c + 2 ) = ammo_patch[2];
*(unsigned char*)( c + 3 ) = ammo_patch[3];
*(unsigned char*)( c + 4 ) = ammo_patch[4];
TCHAR szMsg[128];
wsprintf( szMsg, L"Memory patched: %x %x %x %x %x", *(unsigned char*)( c ), *(unsigned char*)( c + 1 ), *(unsigned char*)( c + 2 ), *(unsigned char*)( c + 3 ), *(unsigned char*)( c + 4 ) );
MessageBox( 0, szMsg, 0, MB_OK );
}
else
{
}
break;
}
c++;
}
}
else
{
MessageBox( 0, L"Something went wrong.", 0, MB_OK );
}
return 0;
}
BOOL APIENTRY DllMain( HMODULE hModule,
DWORD ul_reason_for_call,
LPVOID lpReserved
)
{
switch (ul_reason_for_call)
{
case DLL_PROCESS_ATTACH:
CreateThread( 0, 0, Thread, 0, 0, 0 );
break;
case DLL_THREAD_ATTACH:
case DLL_THREAD_DETACH:
case DLL_PROCESS_DETACH:
break;
}
return TRUE;
}
Comments