hi
sorry i didn't respond - im in college and they decided to block lfe on the network which means i have to use tor to browse this place which is a real pain in the a**
i also don't tend to log in unless i need to post - so it will take time for pms to reach me
anyway u posted in the 1.9 section - i strongly recommend u move up to 2.0 - 2.0 has the dll framework which has the ground work needed to start writing new states/itrs/otherstuff
if u stay with 1.9 you will be reinventing the wheel on most of this stuff - and some of this stuff might be hard if it has changed from 2.0 and u cant base it on what silva did
if u want to learn from silvas tutorials u have to find the right ones - dont bother with the ones in the 2.0 section at first - look at the ones in this section especially this one :
http://www.lf-empire.de/forum/showthread.php?tid=489
it explains most of the basic commands u need to know like: jmp,cmp,mov,jnz,je - the dll framework is based around that idea - except insted of jmping to a place at the bottom of the exe u jmp to a location in the dll
the only thing that tutorial is lacking is how to find the code you r looking for- i dont think any tutorials cover that - maybe these:
http://www.lf-empire.de/forum/showthread.php?tid=3616 but that link is down and i dont know what it contains
i recommend looking at the dll framework only after u understand the basics of detouring code bassed on jmping - the tutorials for setting up the dll compiler is super easy to follow - dont be scared by its length it pretty much tells you to press next all the time
after you setup the compiler just look around the 2.0 section for an exe which can load the dll - 1477 likes making one for every version of 2.0 ( 2.0 , 2.0 no num, 2.0a)
also i recommend not pming random ppl and asking them to do hex stuff for u - if u make a thread about it then you will have potentially more ppl working on it and once a solution is made - it will be public and benifet a lot more ppl that way.