Please tell me all when u go through that CALL 41C6B4 at address 40367C. What u go and where u jump and which u by pass.Quote:
Originally posted by anantasia+Jan 5 2007, 20:50--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (anantasia @ Jan 5 2007, 20:50)</td></tr><tr><td id='QUOTE'> <!--QuoteBegin--)ª(SLAYER)ª(@Jan 5 2007, 20:25
i did it from the begining and it still shows me the "Returns to Game and press Key F11 or * to start the Partner!" and it doesnt do anything when i press F11 or * :rolleyes: so can you pliz tell me wat to do to fix it?
can you tell me wat is "RET routine" thx.
Here is example trace address u must do,
00403685 CALL 00403CF6 <- this command to call routine at address 00403CF6 and when hit command RET. It's will return to next address 40368A
0040368A mov eax,[esi+1c]
.
.
00403CF6 JMP DWORD PTR[00429508] <- this command jump to long address. Almost use pointer to point long address to go. So PTR[00429508] = 10002860
.
.
10002860 SUB ESP, 000000C8 <- here is starting of countrymakeinus.dll
.
.
1000288B CALL 1001E804 <- this call check that it's right user/pass or not?
.
10002895 JNE 101zo1z21v01o12012z1vo101zo1z21v0+5d <- If wrong it's will jump to exit.. So this point we should by pass and go next command
10002897 CMP [esp+000000d4],fffd7fd0
100028A2 JNE 101zo1z21v01o12012z1vo101zo1z21v0+5d <- the another one , so just by pass to next command
100028A4 MOV eax,[esp+000000d8]
.
.
/* there amount 10-20 jump condition at here try by pass only JNE
.
.
10002AC0 CALL dword ptr[100303a0]
.
.
/* there amount 10-20 jump condition at here try by pass only JNE
.
.
10003110 RET <- finished sub routine and return to address 40368A
Hope u got it. [/b][/quote]
I Reach perfect to:
10002860 SUB ESP, 000000C8 <- here is starting of countrymakeinus.dll
1.mm just a question. I have to BYPASS those CALL like OR LET THEM RUN?:
.
-1000288B CALL 1001E804
.
-10002AC0 CALL dword ptr[100303a0]
.
2. And what about this one?(It happens be4 those ones and if i let it run it makes a big jump and seems to take me out of countrymakeinUS.dll)
.
-10002875 CALL DWORD PTR[100301fc]<--- JUMPS TO 00973928 -PUSH GETSYSTEMTIME
Like this CALL there are some others betwen 10002860 SUB ESP and 10003110 RET that take me out from countrymakeinUS.dll i mean If only change those JNE betwen 10002860 SUB ESP and 10003110 RET and let the CALL's run It makes jumps that don't let me reach to 10003110 RET
Hope u understand what i mean xDD