Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


change game ressource

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Gamehacking
View previous topic :: View next topic  
Author Message
sasha
How do I cheat?
Reputation: 0

Joined: 11 Aug 2012
Posts: 7

PostPosted: Sat Aug 11, 2012 3:34 pm    Post subject: change game ressource Reply with quote

hello, first, I was trying to change my game resource
1) the coordinated to my push button, these are referenced from window starting position x0 y0.
2) The Push button, does not have frames, but only areas or may have to click with the mouse.

So, for example, I have coordinates x268 until x547
y399 and until y459 so the size of my options push button box = 279 to width
and 60 pixel for height.

i try, to change this coordinate, to can add new push button on other locate area.

With Cheat engine tool, yes with this tool i have found Ascii String "Options", but by these Ascii word block, here in these area, this don't content any value from coordinate or from box size.

we is possible to find this coordinate?

thank's
Back to top
View user's profile Send private message
sasha
How do I cheat?
Reputation: 0

Joined: 11 Aug 2012
Posts: 7

PostPosted: Tue Aug 14, 2012 6:02 pm    Post subject: Reply with quote

So, i think here in the game, this is impossible, after i have follow my research. My new information who i have found, is don't really push button (2D picture as background + Mouse clic coordinate to push function, without closed frame to push button box).

So as example, i change the resolution of this window.
800x600->1024x768.
here, the zone clic, hold old value to clic, but Background picture is extended.

So as Replacement, i think i will test to inject new Assembly code, to replace the old Push Button with a new Menu function, this menu should have listed all Resolution to select by user.

So is begin to 800x600 pixel
and hold to 2048x1536 pixel.

In theory, this can run, but in Practice, here i should test all if game would like this changing.

Have any people knowledge about insert to C++ programmings code, the function to made into grey, the listened Resolution without compatible with a Monitor?

Because, i have found into game code, the function we make possible to check if Monitor support the selected Resolution or not.
So i would insert this Monitor check, to use into my new Menu Function.
In this case, before the user would use new Resolution for Game, the function make direct in grey, to no accessible to select by user, the other Resolution.

Thank's for any help.
Back to top
View user's profile Send private message
n0 m3rcY
Cheater
Reputation: 0

Joined: 18 Jun 2012
Posts: 42

PostPosted: Tue Aug 14, 2012 9:38 pm    Post subject: Reply with quote

Use ollydbg to open the program, then search > for all intermodular calls. Look for CreateWindow/CreateWindowEx and find the one that makes your button (param2 will be the type, ie button).
Back to top
View user's profile Send private message
sasha
How do I cheat?
Reputation: 0

Joined: 11 Aug 2012
Posts: 7

PostPosted: Wed Aug 15, 2012 9:58 am    Post subject: Reply with quote

hi!

This is the only api CreateWindowexa call throughout my game!
(sorry, to now, i just waiting to have possibility to add screenshoot link into forum)

So here you can see it, that by this call, it create only the Main Window.
So by creating this window, it use 800x600 resolution.
And to start, it use the window style 800 00000 = Popup style
And 40 000 = Extended Style

And here to this new screenshoot.
(sorry to now, i don't have permission to add link into thread from forum)

here i done you more information about button clic.

So lParam = Static number, so this number change if i select any other button with make a clic, and if go back after to same button to select.

And hwnd number from Button = Window hwnd.
And this number change if i restart each time the Game.
So each time after game is loading, the number of hwnd to main window have new value.
Back to top
View user's profile Send private message
n0 m3rcY
Cheater
Reputation: 0

Joined: 18 Jun 2012
Posts: 42

PostPosted: Wed Aug 15, 2012 3:57 pm    Post subject: Reply with quote

sasha wrote:
hi!

This is the only api CreateWindowexa call throughout my game!
(sorry, to now, i just waiting to have possibility to add screenshoot link into forum)

So here you can see it, that by this call, it create only the Main Window.
So by creating this window, it use 800x600 resolution.
And to start, it use the window style 800 00000 = Popup style
And 40 000 = Extended Style

And here to this new screenshoot.
(sorry to now, i don't have permission to add link into thread from forum)

here i done you more information about button clic.

So lParam = Static number, so this number change if i select any other button with make a clic, and if go back after to same button to select.

And hwnd number from Button = Window hwnd.
And this number change if i restart each time the Game.
So each time after game is loading, the number of hwnd to main window have new value.

If there's only one call, check the push instructions above the call because it might just be reusing the same function to make windows that is called multiple times. You can just codecave ie:
Code:

// the other params and stuff
000a push edx     ; windowname
000b push eax     ; classname
000c jmp 0025
000f push 0001    ; exstyle
0010 call CreateWindowExA
0011 mov dword ptr ds:[001f], eax      store hwnd
...
0024 cmp [eax], 66      ; check if eax (window name) starts with 'B' for button, you can do a string compare just change the cmp and add the string next opcode or [eax+x] and loop
0025 jne 000f
0027 push 21
0028 pop [eax]       ; store 21h '!' in eax (actually i'm not sure if you can pop as a pointer, been a while :P) you can just use a pointer to a null terminated string and mov to eax
0030 jmp 000f       ; return

Or something like that to change the window name, or you could find out where it's called and codecave and add another call to the function with different params.

Ofc you could always just use a dll and subclass, but idk how to do that (I don't do dll shit much)...
Back to top
View user's profile Send private message
sasha
How do I cheat?
Reputation: 0

Joined: 11 Aug 2012
Posts: 7

PostPosted: Thu Aug 16, 2012 9:40 am    Post subject: Reply with quote

yep wait

Code:
Found intermodular calls
Address    Disassembly                                                           Destination
004010BE   CALL ESI                                                              USER32.GetSystemMetrics
00401116   CALL DWORD PTR DS:[<&user32.CreateWindowExA>]                         USER32.CreateWindowExA (this is the call)
0040112C   CALL DWORD PTR DS:[<&user32.GetWindowRect>]                           USER32.GetWindowRect
00401139   PUSH EAX                                                              (Initial CPU selection)
0040118A   CALL DWORD PTR DS:[411BF4]                                            DS:[00411BF4]=78EDFC19
004011E6   CALL DWORD PTR DS:[411B6C]                                            DS:[00411B6C]=FC0B97D7
004012E4   CALL DWORD PTR DS:[<&user32.DefWindowProcA>]                          USER32.DefWindowProcA
0040131B   CALL DWORD PTR DS:[<&user32.LoadStringA>]                             USER32.LoadStringA
00401329   CALL DWORD PTR DS:[<&user32.FindWindowA>]                             USER32.FindWindowA
00401336   CALL DWORD PTR DS:[<&user32.IsIconic>]                                USER32.IsIconic
00401343   CALL DWORD PTR DS:[<&user32.ShowWindow>]                              USER32.ShowWindow
0040134A   CALL DWORD PTR DS:[<&user32.SetForegroundWindow>]                     USER32.SetForegroundWindow
0040137A   CALL DWORD PTR DS:[<&advapi32.RegCreateKeyExA>]                       advapi32.RegCreateKeyExA
00401382   CALL DWORD PTR DS:[<&ole32.CoInitializeEx>]                           ole32.CoInitializeEx
004013C0   CALL DWORD PTR DS:[<&user32.LoadIconA>]                               USER32.LoadIconA
004013CD   CALL DWORD PTR DS:[<&user32.LoadCursorA>]                             USER32.LoadCursorA
004013D9   CALL DWORD PTR DS:[<&gdi32.GetStockObject>]                           GDI32.GetStockObject
004013F8   CALL DWORD PTR DS:[<&user32.RegisterClassExA>]                        USER32.RegisterClassExA
00401446   CALL DWORD PTR DS:[<&user32.SetForegroundWindow>]                     USER32.SetForegroundWindow
00401454   CALL DWORD PTR DS:[<&user32.ShowWindow>]                              USER32.ShowWindow
00401461   CALL DWORD PTR DS:[<&user32.SetFocus>]                                USER32.SetFocus
0040146D   CALL <JMP.&annodisplay.CreateDisplayInstance>                         annodisp.CreateDisplayInstance
0040150B   CALL EBX                                                              kernel32.LoadLibraryA
00401520   CALL DWORD PTR DS:[<&kernel32.GetProcAddress>]                        kernel32.GetProcAddress
004015B7   CALL DWORD PTR DS:[<&kernel32.GetCurrentDirectoryA>]                  kernel32.GetCurrentDirectoryA
0040162B   CALL DWORD PTR DS:[<&kernel32.GetProcAddress>]                        kernel32.GetProcAddress
00401772   CALL DWORD PTR DS:[<&kernel32.CreateMutexA>]                          kernel32.CreateMutexA
004017A0   CALL DWORD PTR DS:[<&kernel32.IsBadWritePtr>]                         kernel32.IsBadWritePtr
004019F3   CALL DWORD PTR DS:[<&advapi32.RegCloseKey>]                           advapi32.RegCloseKey
00401A1A   CALL DWORD PTR DS:[<&kernel32.CloseHandle>]                           kernel32.CloseHandle
00401B37   CALL DWORD PTR DS:[<&user32.GetDlgItem>]                              USER32.GetDlgItem
00401B4F   CALL EBX                                                              USER32.SendMessageA
00401B75   CALL EBX                                                              USER32.SendMessageA
00401BEE   CALL DWORD PTR DS:[<&advapi32.RegCreateKeyExA>]                       advapi32.RegCreateKeyExA
00401C1B   CALL DWORD PTR DS:[<&advapi32.RegSetValueExA>]                        advapi32.RegSetValueExA
00401C26   CALL DWORD PTR DS:[<&advapi32.RegCloseKey>]                           advapi32.RegCloseKey
00401C35   CALL DWORD PTR DS:[<&user32.EndDialog>]                               USER32.EndDialog
00401C5A   CALL DWORD PTR DS:[<&user32.GetWindowRect>]                           USER32.GetWindowRect
00401C68   CALL EBX                                                              USER32.GetSystemMetrics
00401C84   CALL EBX                                                              USER32.GetSystemMetrics
00401CA9   CALL DWORD PTR DS:[<&user32.SetWindowPos>]                            USER32.SetWindowPos
00401CB5   CALL DWORD PTR DS:[<&user32.GetDlgItem>]                              USER32.GetDlgItem
00401CD2   CALL DWORD PTR DS:[<&kernel32.GetCurrentDirectoryA>]                  kernel32.GetCurrentDirectoryA
00401D02   CALL DWORD PTR DS:[<&kernel32.FindFirstFileA>]                        kernel32.FindFirstFileA
00401D81   CALL DWORD PTR DS:[<&kernel32.FindNextFileA>]                         kernel32.FindNextFileA
00401D8C   CALL DWORD PTR DS:[<&kernel32.FindClose>]                             kernel32.FindClose
00401DC3   CALL DWORD PTR DS:[<&advapi32.RegCreateKeyExA>]                       advapi32.RegCreateKeyExA
00401DFB   CALL DWORD PTR DS:[<&advapi32.RegQueryValueExA>]                      advapi32.RegQueryValueExA
00401E28   CALL DWORD PTR DS:[<&advapi32.RegCloseKey>]                           advapi32.RegCloseKey
00401F33   CALL DWORD PTR DS:[<&user32.DialogBoxParamA>]                         USER32.DialogBoxParamA
004020D3   CALL DWORD PTR DS:[<&advapi32.RegSetValueExA>]                        advapi32.RegSetValueExA
00402A05   CALL DWORD PTR DS:[<&kernel32.GetVersion>]                            kernel32.GetVersion
00402A53   CALL DWORD PTR DS:[<&kernel32.GetCommandLineA>]                       kernel32.GetCommandLineA
00402A7E   CALL DWORD PTR DS:[<&kernel32.GetStartupInfoA>]                       kernel32.GetStartupInfoA
00402AA1   CALL DWORD PTR DS:[<&kernel32.GetModuleHandleA>]                      kernel32.GetModuleHandleA
00402B17   CALL DWORD PTR DS:[<&kernel32.ExitProcess>]                           kernel32.ExitProcess
00403492   CALL DWORD PTR DS:[<&kernel32.GetModuleHandleA>]                      kernel32.GetModuleHandleA
004034A2   CALL DWORD PTR DS:[<&kernel32.GetProcAddress>]                        kernel32.GetProcAddress
004039EC   CALL DWORD PTR DS:[<&kernel32.GetCPInfo>]                             kernel32.GetCPInfo
00403BF7   CALL DWORD PTR DS:[<&kernel32.GetCPInfo>]                             kernel32.GetCPInfo
00403E1A   CALL DWORD PTR DS:[<&kernel32.LCMapStringW>]                          kernel32.LCMapStringW
00403E36   CALL DWORD PTR DS:[<&kernel32.LCMapStringA>]                          kernel32.LCMapStringA
00403E7F   CALL DWORD PTR DS:[<&kernel32.LCMapStringA>]                          kernel32.LCMapStringA
00403EB7   CALL DWORD PTR DS:[<&kernel32.MultiByteToWideChar>]                   kernel32.MultiByteToWideChar
00403F0F   CALL DWORD PTR DS:[<&kernel32.MultiByteToWideChar>]                   kernel32.MultiByteToWideChar
00403F25   CALL DWORD PTR DS:[<&kernel32.LCMapStringW>]                          kernel32.LCMapStringW
00403F58   CALL DWORD PTR DS:[<&kernel32.LCMapStringW>]                          kernel32.LCMapStringW
00403FC0   CALL DWORD PTR DS:[<&kernel32.LCMapStringW>]                          kernel32.LCMapStringW
00403FE5   CALL DWORD PTR DS:[<&kernel32.WideCharToMultiByte>]                   kernel32.WideCharToMultiByte
0040420A   CALL DWORD PTR DS:[<&kernel32.HeapAlloc>]                             ntdll.RtlAllocateHeap
00404254   CALL DWORD PTR DS:[<&kernel32.HeapReAlloc>]                           ntdll.RtlReAllocateHeap
00404332   CALL DWORD PTR DS:[<&kernel32.HeapAlloc>]                             ntdll.RtlAllocateHeap
00404371   CALL DWORD PTR DS:[<&kernel32.HeapReAlloc>]                           ntdll.RtlReAllocateHeap
004043BF   CALL DWORD PTR DS:[<&kernel32.HeapReAlloc>]                           ntdll.RtlReAllocateHeap
00404461   CALL DWORD PTR DS:[<&kernel32.GetCurrentProcess>]                     kernel32.GetCurrentProcess
00404468   CALL DWORD PTR DS:[<&kernel32.TerminateProcess>]                      kernel32.TerminateProcess
004044E2   CALL DWORD PTR DS:[<&kernel32.ExitProcess>]                           kernel32.ExitProcess
0040455C   CALL DWORD PTR DS:[<&kernel32.HeapSize>]                              ntdll.RtlSizeHeap
0040460F   CALL DWORD PTR DS:[<&kernel32.HeapAlloc>]                             ntdll.RtlAllocateHeap
0040474F   CALL DWORD PTR DS:[<&kernel32.UnhandledExceptionFilter>]              kernel32.UnhandledExceptionFilter
004048CF   CALL DWORD PTR DS:[<&kernel32.GetModuleFileNameA>]                    kernel32.GetModuleFileNameA
00404B14   CALL EBP                                                              kernel32.GetEnvironmentStringsW
00404B28   CALL DWORD PTR DS:[<&kernel32.GetEnvironmentStrings>]                 kernel32.GetEnvironmentStringsA
00404B8C   CALL EDI                                                              kernel32.WideCharToMultiByte
00404BC7   CALL DWORD PTR DS:[<&kernel32.FreeEnvironmentStringsW>]               kernel32.FreeEnvironmentStringsW
00404BDA   CALL DWORD PTR DS:[<&kernel32.GetEnvironmentStrings>]                 kernel32.GetEnvironmentStringsA
00404C18   CALL DWORD PTR DS:[<&kernel32.FreeEnvironmentStringsA>]               kernel32.FreeEnvironmentStringsA
00404C84   CALL DWORD PTR DS:[<&kernel32.GetStartupInfoA>]                       kernel32.GetStartupInfoA
00404D2A   CALL DWORD PTR DS:[<&kernel32.GetFileType>]                           kernel32.GetFileType
00404D83   CALL DWORD PTR DS:[<&kernel32.GetStdHandle>]                          kernel32.GetStdHandle
00404D91   CALL DWORD PTR DS:[<&kernel32.GetFileType>]                           kernel32.GetFileType
00404DC8   CALL DWORD PTR DS:[<&kernel32.SetHandleCount>]                        kernel32.SetHandleCount
00404E03   CALL DWORD PTR DS:[<&kernel32.GetModuleHandleA>]                      kernel32.GetModuleHandleA
00404E45   CALL DWORD PTR DS:[<&kernel32.GetVersionExA>]                         kernel32.GetVersionExA
00404E7A   CALL DWORD PTR DS:[<&kernel32.GetEnvironmentVariableA>]               kernel32.GetEnvironmentVariableA
00404EDA   CALL DWORD PTR DS:[<&kernel32.GetModuleFileNameA>]                    kernel32.GetModuleFileNameA
00404F7F   CALL DWORD PTR DS:[<&kernel32.HeapCreate>]                            kernel32.HeapCreate
00404FBE   CALL DWORD PTR DS:[<&kernel32.HeapDestroy>]                           kernel32.HeapDestroy
00405058   CALL DWORD PTR DS:[<&kernel32.VirtualFree>]                           kernel32.VirtualFree
0040506A   CALL DWORD PTR DS:[<&kernel32.HeapDestroy>]                           kernel32.HeapDestroy
00405087   CALL <JMP.&kernel32.RtlUnwind>                                        ntdll.RtlUnwind
004052EA   CALL DWORD PTR DS:[<&kernel32.GetModuleFileNameA>]                    kernel32.GetModuleFileNameA
004053C0   CALL DWORD PTR DS:[<&kernel32.GetStdHandle>]                          kernel32.GetStdHandle
004053C7   CALL DWORD PTR DS:[<&kernel32.WriteFile>]                             kernel32.WriteFile
00405450   CALL DWORD PTR DS:[<&kernel32.SetFilePointer>]                        kernel32.SetFilePointer
0040545D   CALL DWORD PTR DS:[<&kernel32.GetLastError>]                          ntdll.RtlGetLastWin32Error
00405573   CALL DWORD PTR DS:[<&kernel32.WriteFile>]                             kernel32.WriteFile
004055C0   CALL DWORD PTR DS:[<&kernel32.GetLastError>]                          ntdll.RtlGetLastWin32Error
004055D8   CALL DWORD PTR DS:[<&kernel32.WriteFile>]                             kernel32.WriteFile
004055ED   CALL DWORD PTR DS:[<&kernel32.GetLastError>]                          ntdll.RtlGetLastWin32Error
00405834   CALL DWORD PTR DS:[<&kernel32.WideCharToMultiByte>]                   kernel32.WideCharToMultiByte
0040670D   CALL DWORD PTR DS:[<&kernel32.GetStringTypeW>]                        kernel32.GetStringTypeW
00406727   CALL DWORD PTR DS:[<&kernel32.GetStringTypeA>]                        kernel32.GetStringTypeA
0040675B   CALL DWORD PTR DS:[<&kernel32.GetStringTypeA>]                        kernel32.GetStringTypeA
00406793   CALL DWORD PTR DS:[<&kernel32.MultiByteToWideChar>]                   kernel32.MultiByteToWideChar
004067E9   CALL DWORD PTR DS:[<&kernel32.MultiByteToWideChar>]                   kernel32.MultiByteToWideChar
004067FB   CALL DWORD PTR DS:[<&kernel32.GetStringTypeW>]                        kernel32.GetStringTypeW
0040692E   CALL DWORD PTR DS:[<&kernel32.HeapAlloc>]                             ntdll.RtlAllocateHeap
00406BEC   CALL ESI                                                              kernel32.VirtualFree
00406C59   CALL DWORD PTR DS:[<&kernel32.HeapFree>]                              ntdll.RtlFreeHeap
00406FEE   CALL DWORD PTR DS:[<&kernel32.HeapReAlloc>]                           ntdll.RtlReAllocateHeap
00407022   CALL DWORD PTR DS:[<&kernel32.HeapAlloc>]                             ntdll.RtlAllocateHeap
0040703C   CALL DWORD PTR DS:[<&kernel32.VirtualAlloc>]                          kernel32.VirtualAlloc
00407053   CALL DWORD PTR DS:[<&kernel32.HeapFree>]                              ntdll.RtlFreeHeap
004070C8   CALL DWORD PTR DS:[<&kernel32.VirtualAlloc>]                          kernel32.VirtualAlloc
0040748C   CALL DWORD PTR DS:[<&kernel32.VirtualFree>]                           kernel32.VirtualFree
004074F9   CALL DWORD PTR DS:[<&kernel32.HeapFree>]                              ntdll.RtlFreeHeap
00407557   CALL DWORD PTR DS:[<&kernel32.IsBadWritePtr>]                         kernel32.IsBadWritePtr
00407590   CALL DWORD PTR DS:[<&kernel32.IsBadWritePtr>]                         kernel32.IsBadWritePtr
004075F0   CALL DWORD PTR DS:[<&kernel32.IsBadWritePtr>]                         kernel32.IsBadWritePtr
004078AB   CALL DWORD PTR DS:[<&kernel32.HeapAlloc>]                             ntdll.RtlAllocateHeap
004078CF   CALL EBP                                                              kernel32.VirtualAlloc
004078E9   CALL EBP                                                              kernel32.VirtualAlloc
004079AA   CALL DWORD PTR DS:[<&kernel32.VirtualFree>]                           kernel32.VirtualFree
004079C1   CALL DWORD PTR DS:[<&kernel32.HeapFree>]                              ntdll.RtlFreeHeap
004079DD   CALL DWORD PTR DS:[<&kernel32.VirtualFree>]                           kernel32.VirtualFree
00407A13   CALL DWORD PTR DS:[<&kernel32.HeapFree>]                              ntdll.RtlFreeHeap
00407A62   CALL DWORD PTR DS:[<&kernel32.VirtualFree>]                           kernel32.VirtualFree
00407CBD   CALL DWORD PTR DS:[<&kernel32.VirtualAlloc>]                          kernel32.VirtualAlloc
00408485   CALL DWORD PTR DS:[<&kernel32.HeapFree>]                              ntdll.RtlFreeHeap
00408872   CALL DWORD PTR DS:[<&kernel32.LoadLibraryA>]                          kernel32.LoadLibraryA
0040888A   CALL ESI                                                              kernel32.GetProcAddress
0040889B   CALL ESI                                                              kernel32.GetProcAddress
004088A8   CALL ESI                                                              kernel32.GetProcAddress
00408A35   CALL DWORD PTR DS:[<&kernel32.SetStdHandle>]                          kernel32.SetStdHandle
00408AAF   CALL DWORD PTR DS:[<&kernel32.SetStdHandle>]                          kernel32.SetStdHandle
00408B38   CALL DWORD PTR DS:[<&kernel32.GetFileType>]                           kernel32.GetFileType
00408B42   CALL DWORD PTR DS:[<&kernel32.GetLastError>]                          ntdll.RtlGetLastWin32Error
00408C24   CALL DWORD PTR DS:[<&kernel32.HeapAlloc>]                             ntdll.RtlAllocateHeap
0040985D   CALL DWORD PTR DS:[<&kernel32.FlushFileBuffers>]                      kernel32.FlushFileBuffers
00409867   CALL DWORD PTR DS:[<&kernel32.GetLastError>]                          ntdll.RtlGetLastWin32Error
00409B89   CALL DWORD PTR DS:[<&kernel32.CloseHandle>]                           kernel32.CloseHandle
00409B93   CALL DWORD PTR DS:[<&kernel32.GetLastError>]                          ntdll.RtlGetLastWin32Error


so here section from my windowcreatexa.

Code:
004010B3   . EB 4D          JMP SHORT 1503Star.00401102
004010B5   > 56             PUSH ESI
004010B6   . 8B35 C0744100  MOV ESI,DWORD PTR DS:[<&user32.GetSystem>;  USER32.GetSystemMetrics
004010BC   . 6A 00          PUSH 0                                   ; /Index = SM_CXSCREEN
004010BE   . FFD6           CALL ESI                                 ; \GetSystemMetrics
004010C0   . 3905 58544100  CMP DWORD PTR DS:[415458],EAX
004010C6   . 7E 05          JLE SHORT 1503Star.004010CD
004010C8   . A3 58544100    MOV DWORD PTR DS:[415458],EAX
004010CD   > 6A 01          PUSH 1
004010CF   . FFD6           CALL ESI
004010D1   . 8B0D 5C544100  MOV ECX,DWORD PTR DS:[41545C]
004010D7   . 5E             POP ESI
004010D8   . 3BC8           CMP ECX,EAX
004010DA   . 7E 08          JLE SHORT 1503Star.004010E4
004010DC   . 8BC8           MOV ECX,EAX
004010DE   . 890D 5C544100  MOV DWORD PTR DS:[41545C],ECX
004010E4   > 8B15 2C544100  MOV EDX,DWORD PTR DS:[41542C]
004010EA   . A1 58544100    MOV EAX,DWORD PTR DS:[415458]
004010EF   . 6A 00          PUSH 0
004010F1   . 52             PUSH EDX
004010F2   . 6A 00          PUSH 0
004010F4   . 6A 00          PUSH 0
004010F6   . 51             PUSH ECX
004010F7   . 50             PUSH EAX
004010F8   . 68 00000080    PUSH 80000000                      ;? (if i change this two first value, the programm Crash, third is only ok.)
004010FD   . 68 00000080    PUSH 80000000                      ;?
00401102   > 68 00000080    PUSH 80000000                      ; Window Ws_Popup Style
00401107   . 68 A41C4100    PUSH 1503Star.00411CA4                   ;  ASCII "Anno1503"
0040110C   . 68 38544100    PUSH 1503Star.00415438                   ;  ASCII "Anno 1503"
00401111   . 68 00000400    PUSH 40000                               ; |ExtStyle = WS_EX_APPWINDOW
00401116   . FF15 B4744100  CALL DWORD PTR DS:[<&user32.CreateWindow>; \CreateWindowExA
0040111C   . 85C0           TEST EAX,EAX
0040111E   . A3 28544100    MOV DWORD PTR DS:[415428],EAX
00401123   . 75 01          JNZ SHORT 1503Star.00401126
00401125   . C3             RETN
00401126   > 68 18544100    PUSH 1503Star.00415418                   ; /pRect = 1503Star.00415418
0040112B   . 50             PUSH EAX                                 ; |hWnd
0040112C   . FF15 B8744100  CALL DWORD PTR DS:[<&user32.GetWindowRec>; \GetWindowRect


And this last, coming from Stack Window.

Code:
0012F998   00040000  |ExtStyle = WS_EX_APPWINDOW
0012F99C   00415438  |Class = "Anno 1503"
0012F9A0   00411CA4  |WindowName = "Anno1503"
0012F9A4   80000000  |Style = WS_POPUP
0012F9A8   00000000  |X = 0
0012F9AC   00000000  |Y = 0
0012F9B0   00000320  |Width = 320 (800.)
0012F9B4   00000258  |Height = 258 (600.)
0012F9B8   00000000  |hParent = NULL
0012F9BC   00000000  |hMenu = NULL
0012F9C0   00000000  |hInst = NULL
0012F9C4   00000000  \lParam = NULL


and later down, i find this!

Code:
00401C4D   > 8BBC24 7403000>MOV EDI,DWORD PTR SS:[ESP+374]
00401C54   . 8D5424 20      LEA EDX,DWORD PTR SS:[ESP+20]
00401C58   . 52             PUSH EDX                                 ; /pRect
00401C59   . 57             PUSH EDI                                 ; |hWnd
00401C5A   . FF15 B8744100  CALL DWORD PTR DS:[<&user32.GetWindowRec>; \GetWindowRect
00401C60   . 8B1D C0744100  MOV EBX,DWORD PTR DS:[<&user32.GetSystem>;  USER32.GetSystemMetrics
00401C66   . 6A 00          PUSH 0                                   ; /Index = SM_CXSCREEN
00401C68   . FFD3           CALL EBX                                 ; \GetSystemMetrics
00401C6A   . 99             CDQ
00401C6B   . 8B4C24 20      MOV ECX,DWORD PTR SS:[ESP+20]
00401C6F   . 2BC2           SUB EAX,EDX
00401C71   . 8BF0           MOV ESI,EAX
00401C73   . 8B4424 28      MOV EAX,DWORD PTR SS:[ESP+28]
00401C77   . 2BC1           SUB EAX,ECX
00401C79   . 6A 01          PUSH 1                                   ; /Index = SM_CYSCREEN
00401C7B   . 99             CDQ                                      ; |
00401C7C   . 2BC2           SUB EAX,EDX                              ; |
00401C7E   . D1FE           SAR ESI,1                                ; |
00401C80   . D1F8           SAR EAX,1                                ; |
00401C82   . 2BF0           SUB ESI,EAX                              ; |
00401C84   . FFD3           CALL EBX                                 ; \GetSystemMetrics
00401C86   . 8B6C24 24      MOV EBP,DWORD PTR SS:[ESP+24]
00401C8A   . 6A 01          PUSH 1                                   ; /Flags = SWP_NOSIZE
00401C8C   . 99             CDQ                                      ; |
00401C8D   . 2BC2           SUB EAX,EDX                              ; |
00401C8F   . 6A 00          PUSH 0                                   ; |Height = 0
00401C91   . 8BC8           MOV ECX,EAX                              ; |
00401C93   . 8B4424 34      MOV EAX,DWORD PTR SS:[ESP+34]            ; |
00401C97   . 2BC5           SUB EAX,EBP                              ; |
00401C99   . 6A 00          PUSH 0                                   ; |Width = 0
00401C9B   . 99             CDQ                                      ; |
00401C9C   . 2BC2           SUB EAX,EDX                              ; |
00401C9E   . D1F9           SAR ECX,1                                ; |
00401CA0   . D1F8           SAR EAX,1                                ; |
00401CA2   . 2BC8           SUB ECX,EAX                              ; |
00401CA4   . 51             PUSH ECX                                 ; |Y
00401CA5   . 56             PUSH ESI                                 ; |X
00401CA6   . 6A FF          PUSH -1                                  ; |InsertAfter = HWND_TOPMOST
00401CA8   . 57             PUSH EDI                                 ; |hWnd
00401CA9   . FF15 D4744100  CALL DWORD PTR DS:[<&user32.SetWindowPos>; \SetWindowPos
00401CAF   . 68 F3030000    PUSH 3F3                                 ; /ControlID = 3F3 (1011.)
00401CB4   . 57             PUSH EDI                                 ; |hWnd
00401CB5   . FF15 C8744100  CALL DWORD PTR DS:[<&user32.GetDlgItem>] ; \GetDlgItem
00401CBB   . 8BE8           MOV EBP,EAX
00401CBD   . 8D4424 30      LEA EAX,DWORD PTR SS:[ESP+30]
00401CC1   . 50             PUSH EAX                                 ; /Buffer
00401CC2   . 68 00010000    PUSH 100                                 ; |BufSize = 100 (256.)
00401CC7   . C78424 3801000>MOV DWORD PTR SS:[ESP+138],10            ; |
00401CD2   . FF15 94734100  CALL DWORD PTR DS:[<&kernel32.GetCurrent>; \GetCurrentDirectoryA
00401CD8   . 8D4C24 30      LEA ECX,DWORD PTR SS:[ESP+30]
00401CDC   . 8D9424 7002000>LEA EDX,DWORD PTR SS:[ESP+270]
00401CE3   . 51             PUSH ECX
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Gamehacking All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites