|
Cheat Engine The Official Site of Cheat Engine
|
View previous topic :: View next topic |
Author |
Message |
gir489 Grandmaster Cheater Reputation: 14
Joined: 03 Jan 2012 Posts: 835 Location: Maryland, United States
|
Posted: Fri Jan 19, 2018 1:22 pm Post subject: Need help calling an imported function from within the DLL. |
|
|
So, I'm trying to call GetKeyState inside the DLL, since it's part of the import address table at FC3_d3d11.dll+1AA43DD.
I assembled a CALL ds:11AA43DD instruction with IDA's assembler, and it looks fine, but when I load it up with Cheat Engine, it gets a random offset each time.
I noticed that other locations that call it, usually have FF 15 00000000, with the 4 0s populated by the location of the IAT function during instantiation. FF 15 is a call exact.
So how can I get my injected code cave to update the address when the DLL is loaded? I'm basically doing this so I don't have to load Cheat Engine every time I play FC3, because I just want my code to be there already when I start the game.
|
|
Back to top |
|
|
OldCheatEngineUser Whateven rank Reputation: 20
Joined: 01 Feb 2016 Posts: 1587
|
Posted: Fri Jan 19, 2018 2:40 pm Post subject: |
|
|
the offset you patched using ida was the raw offset (probably), not the virtual offset. (there is different types of offsets)
about injecting you code cave to be there forever .. im not sure if CE is the best tool to do it.
but you can open the executable as a file using CE, and allocate memory there.
note:
im not sure whats wrong with CE when opening a file, seems it cant search for the given pattern of bytes.
_________________
About Me;
I Use CE Since Version 1.X, And Still Learning How To Use It Well!
Jul 26, 2020
STN wrote: | i am a sweetheart. |
|
|
Back to top |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
|