hello, here is my gift for you guys.... Hows thing going around here? ive been checking this forum a little bit often now..
(1) current HP dma defeat (read hp at $004d28fe):
</span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE ( TSEARCH FORMAT)</td></tr><tr><td id='QUOTE'>
</span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (injected code cave)</td></tr><tr><td id='QUOTE'>
offset 0x4d290e
push eax
push 01
mov ecx,edi
mov [0x4d28fe],eax
jmp 0x41fd3c
offset 0x41fd37
jmp 0x4d290e
[/b][/quote]
</span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (original code)</td></tr><tr><td id='QUOTE'>
offset 0x41fd37
push eax
push 01
mov ecx,edi
[/b][/quote]
[/b][/quote]
or just the pokes values:
Poke 4D290E 50 6A 01 8B CF A3 FE 28 4D 00 E9
Poke 4D2919 1F D4 F4 FF
Poke 41FD37 E9 D2 2B 0B 00
(2) for read arrow count, read pointer at $004D4718 and offset $46. (2 bytes)
ah, sorry if this is in not in the correct layout... if any problem to understand this let me know...
(1) current HP dma defeat (read hp at $004d28fe):
</span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE ( TSEARCH FORMAT)</td></tr><tr><td id='QUOTE'>
</span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (injected code cave)</td></tr><tr><td id='QUOTE'>
offset 0x4d290e
push eax
push 01
mov ecx,edi
mov [0x4d28fe],eax
jmp 0x41fd3c
offset 0x41fd37
jmp 0x4d290e
[/b][/quote]
</span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (original code)</td></tr><tr><td id='QUOTE'>
offset 0x41fd37
push eax
push 01
mov ecx,edi
[/b][/quote]
[/b][/quote]
or just the pokes values:
Poke 4D290E 50 6A 01 8B CF A3 FE 28 4D 00 E9
Poke 4D2919 1F D4 F4 FF
Poke 41FD37 E9 D2 2B 0B 00
(2) for read arrow count, read pointer at $004D4718 and offset $46. (2 bytes)
ah, sorry if this is in not in the correct layout... if any problem to understand this let me know...