QuestionHow to freeze value VB.NET

Posts 1–15 of 21 · Page 1 of 2
How to freeze value VB.NET
How to freeze value using write WriteProcessMemory (i have static address)

Code:
    Private Sub Button1_Click(sender As System.Object, e As System.EventArgs) Handles Button1.Click
        If GetProcessId("proc") = False Then
            Exit Sub
        ElseIf GetProcessId("proc") = True Then
            WriteProcessMemory(pHandle, &H5C41E8, 3145896, 1, 0)
        End If
    End Sub
End Class
I'm not trying to be rude, but are you new to programming? The way you structured your IF is just a little weird. No point in calling GetProcID() twice. That's the whole point if if/else Mistakes happen ofc, but if you don't know basic language functions, programming anything is going to be hard.

Basically to "freeze" a value, you just keep writing a new value into it every second. so technically you're not freezing it, but you write to it often enough, that it looks like the value never changes.

Something along the lines of
Code:
While (true)
WriteProcessMemory(***)
Loop
But you can't just call WriteProcessMemory(), you have to call OpenProcess() first and get a new handle to the process. I wrote a tutorial (more about reading, than writing, but same thing, just easier) just a few threads down. Long read tho :/
Code:
    Private Sub Button1_Click(sender As System.Object, e As System.EventArgs) Handles Button1.Click
        If GetProcessId("proc") = True Then
           'Found the process.
           Dim procHandle As IntPtr = OpenProcess(***)
           If procHandle <> 0 Then
           'it worked
           WriteProcessMemory(procHandle, &H5C41E8, 3145896, 1, 0)
           Else
           MsgBox("Unable to call OpenProcess(). Are you admin?")
           End If
        End If
    End Sub
^^ofc that isn't in a loop, so it'd only write the value 1 time. Just showing you the basic logic structure. Also, the way you call RPM(), the declaration looks wrong, it should maybe expect an array of bytes? Maybe read a tutorial on "How to ReadProcessMemory."

http://www.mpgh.net/forum/33-visual-...ory-part1.html There is also a part 2, I included the write functions: if you actually read the tutorial, you should be able to make the functions yourself.
abuckau907 basically explained what you need todo but depending on the game, OpenProcess usually isnt needed.

You can obtain the process handle from system diagnostic. OpenProcess is only needed in those rare cases.
Remember, if you use openprocess, close the handle when you're finish.
If you use system diagnostic, it takes care of all that.

Another option to freeze the value, set CE's debugger on it to see which instructions access it.
A simple nop would stop the value from changing. That way you wont need to use a timer or loop and just set it once.
@Pingo - when is OpenProcess not needed?
- How would you do it using System.Diagnostics ?
- Apparently Process.Handle has some nuances as far as how long it lives? if that's what you mean??
http://www.*********.com/forums/gene...time-time.html
Someone (and I) asked a very similar question at another forum. Ignore my rambling, but look at Cromon's posts.

edit: the logic behind his IF statement is so weird, I think he doesn't know programming. Wasting our time? OP plz respond
Personally i'v only had to use openprocess 1/50 times when coding something.
Depending on the memory protection.
My trainer maker uses openprocess when building, just incase.

Code:
Dim pHandle As IntPtr = System.Diagnostics.Process.GetProcessesByName("SomeProccess")(0).Handle
Obviously i wouldn't write it without checking if the process was active first but this is all thats needed.


You're right about his if/else and he definitely doesnt want GetProcessId on a loop of timer unless his memory class stores it and doesn't
keep obtaining it.
yeah, all depends on your needs I guess. Just be careful, if you use Process.Handle, do NOT store it because it's not guaranteed to 'be alive' forever. So if you only have 1 WriteProcessMemory to do, using Process.Handle is fine, but if you're going to be doing a lot of rpm/wpm then you should maybe (maybe) call OpenProcess and store the handle somewhere. The handle returned from Process.Handle WILL NOT, guaranteed, to be valid for very long (??). I think, as explained by Cromon in previous link (and CloseHandle() when you're all done ofc)


@Ac1d777 ctrl+c , ctrl+v
Code:
    Private Sub Button1_Click(sender As System.Object, e As System.EventArgs) Handles Button1.Click
        Dim procID as Int32 =  GetProcessId("proc") 
        If procID <> 0 Then
        'Found process. Now we have it's ID, but we need a 'handle' to it for wpm. Let's get one.
        Dim targetProcess as Process = Process.GetProcessById(procID) '<--Process class has a .Handle property for us :)
        WriteProcessMemory(targetProcess.Handle, &H5C41E8, 3145896, 4, 0)
        Else
        MsgBox("Process not found")   
        End If
    End Sub
End Class
^^ but you're WriteProcessMemory API declaration shouldn't expect an Integer so you won't be able to expand this code very easily : you'll need to write a proper memory class eventually.
-> I also changed (on WriteProcessMemory(***) line) the 1 into a 4, I believe that is the "data length" parameter, which is the size in bytes of your data --> it looks like you're writing in "3145896" which (looks like) and INTEGER so you need to change it to "4" bytes.
Either use a timer that ticks every X miliseconds and keeps writing to the memory or use a multithread.

Timer Class (System.Windows.Forms)


Code:
// Set to false again to stop writing to memory
private freezingV as boolean = false

private sub button1[...]
freezingV = true

dim tFreeze as new threading.thread(addressof freezeValue)
tFreeze.start()
end sub

private sub freezeValue()
while(freezingV)
//WriteProcMem
end while
end sub
Heres a simple function to grab the handle
Code:
    Public Function GetHandle(ByVal ProcessName As String) As IntPtr
        Dim Proc As Process() = Process.GetProcessesByName(ProcessName)
        Return If(Proc.Length = 0, IntPtr.Zero, Proc(0).Handle)
    End Function
But since you're wanting a loop or timer, calling GetProcessesByName every x seconds wouldn't be optimal.

Store 2 variables, the process and a boolean.
Code:
    Dim Proc As Process()
    Dim pActive As Boolean
A new GetHandle function.
Code:
    Public Function GetHandle(ByVal PName As String) As IntPtr
        If (Not pActive) Then
            Proc = Process.GetProcessesByName(PName)
            pActive = Proc.Length <> 0
        End If
        Try
            pActive = Not Proc(0).HasExited
        Catch
            pActive = False
        End Try
        Return If(pActive, Proc(0).Handle, IntPtr.Zero)
    End Function
Now that will only search for the new handle if the process exits instead of calling GetProcessesByName every x seconds.
If the process exits, it'l return IntPtr.Zero, else it returns the handle.

Your timer would look like this
Code:
    Private Sub Timer1_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer1.Tick
        Dim pHan As IntPtr = GetHandle("proc")
        If pHan <> IntPtr.Zero Then
            WriteProcessMemory(pHan, &H5C41E8, 3145896, 1, 0)
        End If
    End Sub
@Pingo - Can you comment about OpenProcess vs. Process.Handle -- I've been told to not store Proc.Handle. I'm a little confused, I thought the garbage collector/os could 're-claim' that handle at any point (grr...any point is vague, but it is what it is) and make it not valid. I don't know the internals of window: Since you keep using Process.Handle, as if my previous statement is false, will you please explain?

and (not that it matters, I know* you know* better, but)
Quote Originally Posted by Pingo View Post
Heres a simple function to grab the handle...
...
Your timer would look like this
Code:
    Private Sub Timer1_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer1.Tick
        Dim pHan As IntPtr = GetHandle("proc")
        If pHan <> IntPtr.Zero Then
            WriteProcessMemory(pHan, &H5C41E8, 3145896, 1, 0)
        End If
    End Sub
^^ the 1 is 'a problem'. Unless he only wants to write 1 byte, in which case 3145896 is too large.
msdn.com
Code:
BOOL WINAPI WriteProcessMemory(
  _In_   HANDLE hProcess,
  _In_   LPVOID lpBaseAddress,
  _In_   LPCVOID lpBuffer,
  _In_   SIZE_T nSize,
  _Out_  SIZE_T *lpNumberOfBytesWritten
);
2nd to last parameter = nSize = 4 bytes for an integer
@abuckau907
You're right about the WriteProcessMemory, it should be 4bytes for the integer.
His api layout looks strange to me so i never touched his code.
I use it like this
Code:
WriteProcessMemory(ByVal hProcess As IntPtr, ByVal lpBaseAddress As Integer, ByVal buffer As Byte(), ByVal size As Integer, ByVal lpNumberOfBytesWritten As Integer)
I was taught to use openprocess aswell.
But a vet who does this professionally set me straight.
I'm not saying he was right.
But from personal experience, i'v had more issues with openprocess.
mm..but then you learned, and OpenProcess is better.(i'm assuming the problem was with how you defiend ALL_ACCESS and/or the rest of the PROCESS_ACCESS constants)
Showing ppl to use Process.Handle might work in the short-term, for 1 button click, but may (?) cause errors for later projects. Might be worth throwing in a "btw, I recommend you use OpenProcess, look it up". Just checking if what I heard about process.handle was correct. thanks.
I do use openprocess when i need it. But i don't need it in most cases.
I don't really make trainers these days so im not too bothered about it.

I think my last hack was a managed dll which i used
Code:
Dim pHandle As IntPtr = Process.GetCurrentProcess.Handle
And Marshal.Copy for reading and writing since the read/writeprocessmemory
api's were blocked by xtrap
Thanks all for help, you allright, im newbie in vb.net and i'm never using WriteProcessMemory, im using always Mem.Inject_Jmp (For single player games)
Write_Jmp implies you're detouring, which is so much more complex than doing a simple "freeze"...that doesn't even make sense.

Mem.Inject_Jmp probably writes [jmp] + [4 byte address]

which shouldn't work for writing an Int32 value in :s you'll mangle some other data because you meant to write 4 bytes, but Inject_Jmp probably writes 5 bytes. Plain doesn't make sense.

(I guess if Inject_Jmp was writing a relative jump, and it had a small offset, it could fit into 4 bytes -- would explaining that even help)
@Ac1d777
Mem.Inject_Jmp?
Where did you get this?
If it's the class i think it might be, that was a sample injection class, not a proper memory class.
Don't use Inject_Jmp, use Patch... I'll use solitaire as an example

Accesses time played, increases the time by one every second.
Code:
006F10B0 - ff 40 08 - inc [eax+08]
Code:
Mem.Patch(&H6F10B0, "909090", "ff4008")
Nopping the 3 bytes will stop the timer.
Posts 1–15 of 21 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?