#include "stdafx.h" DWORD WINAPI Thread( LPVOID lParam ) { HMODULE hModule = GetModuleHandle( L"game.dll" ); MODULEINFO mdlinfo; GetModuleInformation( GetCurrentProcess(), hModule, &mdlinfo, sizeof( mdlinfo ) ); unsigned char GameSavLoad1[] = { 0x81, 0xEC, 0x28, 0x02 }; unsigned char GameSavLoad2[] = { 0x00, 0x00, 0x53, 0x55 }; unsigned char GameSavLoad3[] = { 0x56, 0x57, 0x68, 0x54 }; unsigned int head_offs = 0x676134; unsigned int def_offs = 0x4F80C0; unsigned int offset = 0; int c= (int)hModule; int max = (int)hModule + mdlinfo.SizeOfImage - sizeof( unsigned char[4] ) * 3; while( c != max ) { if( memcmp( (void*)(c), GameSavLoad1, sizeof( GameSavLoad1 ) ) == 0 && memcmp( (void*)(c + sizeof( unsigned char[4] ) ), GameSavLoad2, sizeof( GameSavLoad2 ) ) == 0 && memcmp( (void*)(c + sizeof( unsigned char[4] ) * 2 ), GameSavLoad3, sizeof( GameSavLoad3 ) ) == 0) { break; } offset++; c++; } //TCHAR str[128]; //TCHAR str1[128]; //wsprintf( str, L"Offset found %x!\nHead:%x+%x=%x\nAny:%x+%x=%x", offset, c, head_offs , c + head_offs , c, def_offs, def_offs + c ); //wsprintf( str1, L"Size: %x", mdlinfo.SizeOfImage - sizeof( unsigned char[4] ) * 3 ); //MessageBox( 0, str, 0, MB_OK ); //MessageBox( 0, str1, 0, MB_OK ); if( c != max ) { unsigned char ammo_sig[] = { 0x66, 0x29, 0x5C, 0x7E }; unsigned char ammo_patch[] = { 0x83, 0x6C, 0x7E, 0x3C, 0x00}; while( c != max ) { if( memcmp( (void*)(c), ammo_sig, sizeof( ammo_sig ) ) == 0 ) { DWORD dwOldState; VirtualProtect( (void*)c, sizeof( ammo_patch ), PAGE_READWRITE, &dwOldState ); if( true ) { *(unsigned char*)( c ) = ammo_patch[0]; *(unsigned char*)( c + 1 ) = ammo_patch[1]; *(unsigned char*)( c + 2 ) = ammo_patch[2]; *(unsigned char*)( c + 3 ) = ammo_patch[3]; *(unsigned char*)( c + 4 ) = ammo_patch[4]; TCHAR szMsg[128]; wsprintf( szMsg, L"Memory patched: %x %x %x %x %x", *(unsigned char*)( c ), *(unsigned char*)( c + 1 ), *(unsigned char*)( c + 2 ), *(unsigned char*)( c + 3 ), *(unsigned char*)( c + 4 ) ); MessageBox( 0, szMsg, 0, MB_OK ); } else { } break; } c++; } } else { MessageBox( 0, L"Something went wrong.", 0, MB_OK ); } return 0; } BOOL APIENTRY DllMain( HMODULE hModule, DWORD ul_reason_for_call, LPVOID lpReserved ) { switch (ul_reason_for_call) { case DLL_PROCESS_ATTACH: CreateThread( 0, 0, Thread, 0, 0, 0 ); break; case DLL_THREAD_ATTACH: case DLL_THREAD_DETACH: case DLL_PROCESS_DETACH: break; } return TRUE; }