Quote:
Originally Posted by fear-x
i have a problem too !
_KDMemory_GetModuleBaseAddress returns the correct address but the rest memory read after this gives wrong addres... ?
Quote:
;~ #AutoIt3Wrapper_UseX64=n ; 32 Bit application
#AutoIt3Wrapper_UseX64=y ; 64 Bit application
#RequireAdmin
#include "KDMemory.au3"
; Cheat Engine (x64) Tutorial Step 6: Pointers: (PW=098712)
Const $processName = "Aion.bin", $moduleName = "Game.dll"
Const $baseOffset = 0x00DB61F0
Const $offsets[3] = [0x0, 0x368, 0x13cc]
$processId = ProcessExists($processName)
If $processId == 0 Then
MsgBox(48, "Error", "'" & $processName & "' is not running!")
Else
$handles = _KDMemory_OpenProcess($processId)
If @error Then
MsgBox(48, "Error", "Can't open '" & $processName & "'!" & @CRLF & "@error: " & @error)
Else
$baseAddress = _KDMemory_GetModuleBaseAddress($handles, $moduleName) + $baseOffset
;~ MsgBox(0, "", $baseAddress);correct return
If @error Then
MsgBox(48, "Error", "Can't get ModuleBaseAddress ('" & $moduleName & "')!" & @CRLF & "@error: " & @error & ", @extended: " & @extended)
Else
$memoryData = _KDMemory_ReadProcessMemory($handles, $baseAddress, "BYTE", $offsets)
;~ $memoryData = _KDMemory_ReadProcessString($handles, $baseAddress, $offsets, "WCHAR[100]")
If @error Then
MsgBox(48, "Error", "Can't read memory!" & @CRLF & "@error: " & @error & ", @extended: " & @extended)
Else
MsgBox(64, "Info", "Address: " & $memoryData[0] & @CRLF & "Value: " & $memoryData[1])
EndIf
EndIf
_KDMemory_CloseHandles($handles)
EndIf
EndIf
|
|
The reason why the pointer address is wrong is because my UDF doesn't need the useless (and annoying) zero-offset. Instead of using two offsets you're using three offsets.
Code:
$memoryData = _KDMemory_ReadProcessMemory($handles, $baseAddress, "BYTE", $offsets)
This line would read a single byte (one non-Unicode char) instead of a complete string.
Code:
;~ $memoryData = _KDMemory_ReadProcessString($handles, $baseAddress, $offsets, "WCHAR[100]")
This line can't work. The fourth parameter ($unicode) can be either 0 or 1. It determines if the string is a Unicode string or not. It should be 1 in your case. This function will read the complete string, you don't have to make the decision how long the string could be.
It would also be correct if you replace the function with _KDMemory_ReadProcessMemory(), but I recommend to use the _KDMemory_ReadProcessString() function.