@Cucurucho :
@ztthik :
@steve00 :
@Enki :
Let them run thru in that CALL and set trace /debug and step in that sub routine.Quote:
I Reach perfect to:
10002860 SUB ESP, 000000C8 <- here is starting of countrymakeinus.dll
1.mm just a question. I have to BYPASS those CALL like OR LET THEM RUN?:
.
-1000288B CALL 1001E804
.
-10002AC0 CALL dword ptr[100303a0]
.
You just press F8 when hit that instruction. I post it to reference only just for your information.Quote:
2. And what about this one?(It happens be4 those ones and if i let it run it makes a big jump and seems to take me out of countrymakeinUS.dll)
.
-10002875 CALL DWORD PTR[100301fc]<--- JUMPS TO 00973928 -PUSH GETSYSTEMTIME
Like this CALL there are some others betwen 10002860 SUB ESP and 10003110 RET that take me out from countrymakeinUS.dll i mean If only change those JNE betwen 10002860 SUB ESP and 10003110 RET and let the CALL's run It makes jumps that don't let me reach to 10003110 RET
@ztthik :
Cool, Nice job great man.Quote:
I followed the traces and made it work finally.
I have no problems to release all the data. However, anantasia suggested to do it yourself. I'm not going to release them at the moment.
@steve00 :
Good for explain that. If possible i would like to ad more information in RED text and I think you copy wrong guide please look in Post #1.Quote:
/** set trace
00403685 call 403cf6 <- call SV routine (PF11 to activate and disable button as picture below)
. I think this is saying to press the F11 key but then later in the forum ananstia said this:
This is just information that this command will call Scripte routine you must enter to trace/debug it
.
00403CF6 JMP DWORD PTR[00429508] <- this command jump to long address. Almost use pointer to point long address to go. So PTR[00429508] = 10002860
. ok, the trick here was explained by anantasia on a later page in the forum, what you have to do is replace the 00429508 in the brackets with 10002860, WHEN YOU DO THIS you will end up with a very weird string that looks something like this jmp dword ptr [l0lzo1z2lv0lo120l2zlvol0lzo1z2lv0]..(again if i am correct)
This is information again to known that after above CALL will send u here and it's will starting execute command in countrymakeinUS.dll
It's use with CE(Cheat Engine). To monitor/freeze memory address.Quote:
how do u use the co.ct file?
@Enki :
Try not ruin code by change it to NOP. Just only change EIP.Quote:
Any idea? when i hit start my client close.