Exemple #1
0
        private IntPtr GetPointer(Process program, string asmName)
        {
            if (lastPID != program.Id)
            {
                lastPID = program.Id;
                BasePtr = IntPtr.Zero;
            }

            if (BasePtr != IntPtr.Zero)
            {
                DateTime now = DateTime.Now;
                if (now > LastVerified)
                {
                    bool isValid = Searcher.VerifySignature(program, BasePtr, Signature);
                    LastVerified = now.AddSeconds(5);
                    if (!isValid)
                    {
                        BasePtr = IntPtr.Zero;
                    }
                }

                if (BasePtr != IntPtr.Zero)
                {
                    int offset = CalculateRelative(program);
                    return(BasePtr + offset);
                }
            }

            if (string.IsNullOrEmpty(asmName))
            {
                Searcher.MemoryFilter = delegate(MemInfo info) {
                    return((info.State & 0x1000) != 0 && (info.Protect & 0x40) != 0 && (info.Protect & 0x100) == 0);
                };
            }
            else
            {
                Tuple <IntPtr, IntPtr> range = ProgramPointer.GetAddressRange(program, asmName);
                Searcher.MemoryFilter = delegate(MemInfo info) {
                    return((ulong)info.BaseAddress >= (ulong)range.Item1 && (ulong)info.BaseAddress <= (ulong)range.Item2 && (info.State & 0x1000) != 0 && (info.Protect & 0x20) != 0 && (info.Protect & 0x100) == 0);
                };
            }

            IntPtr ptr = Searcher.FindSignature(program, Signature);

            if (ptr != IntPtr.Zero)
            {
                BasePtr      = ptr;
                LastVerified = DateTime.Now.AddSeconds(5);
                int offset = CalculateRelative(program);
                return(BasePtr + offset);
            }
            return(IntPtr.Zero);
        }
        private IntPtr GetPointer(Process program, string asmName)
        {
            if (lastPID != program.Id)
            {
                lastPID = program.Id;
                BasePtr = IntPtr.Zero;

                if (string.IsNullOrEmpty(asmName))
                {
                    Searcher.MemoryFilter = delegate(MemInfo info) {
                        return((info.State & 0x1000) != 0 && (info.Protect & 0x20) != 0 && (info.Protect & 0x100) == 0);
                    };
                }
                else
                {
                    Tuple <IntPtr, IntPtr> range = ProgramPointer.GetAddressRange(program, asmName);
                    Searcher.MemoryFilter = delegate(MemInfo info) {
                        return((ulong)info.BaseAddress >= (ulong)range.Item1 && (ulong)info.BaseAddress <= (ulong)range.Item2 && (info.State & 0x1000) != 0 && (info.Protect & 0x20) != 0 && (info.Protect & 0x100) == 0);
                    };
                }
            }

            if (BasePtr != IntPtr.Zero)
            {
                int offset = 0;
                if (AutoDeref != AutoDeref.None)
                {
                    offset = program.Read <int>(BasePtr + Offset) + 4;
                }
                return(BasePtr + Offset + offset);
            }
            else
            {
                IntPtr ptr = Searcher.FindSignature(program, Signature);
                if (ptr != IntPtr.Zero)
                {
                    BasePtr = ptr;
                    int offset = 0;
                    if (AutoDeref != AutoDeref.None)
                    {
                        offset = program.Read <int>(BasePtr + Offset) + 4;
                    }
                    return(BasePtr + Offset + offset);
                }
            }
            return(IntPtr.Zero);
        }