I've watched a few videos about Pointer, but that doesn't seem to help in my case.
It's about the game World of Final Fantasy Maxima. In the Champions Medal slot in the menu, you can equip champions in three slots. And I have found a way to cheat this. Sora can also be cheated into the slot. But as soon as you unequip it, it's gone again. Unfortunately I don't know where the stock of champions is. But now I would like a pointer for the slots
I have an address that is always changing.
The address is also always within a range: 07xx9A50
With each new search, these were the latest addresses. There is only ever one hit address for the slots
RealAddress="079A9A50"/>
RealAddress="079A9A50"/>
RealAddress="079B9A50"/>
RealAddress="079E9A50"/>
RealAddress="07A09A50"/>
RealAddress="07A09A50"/>
RealAddress="07A29A50"/>
RealAddress="079D9A50"/>
RealAddress="07999A50"/>
RealAddress="079A9A50"/>
When I go to ‘find out what writes to this address’, I get two results
1406E9200 - C7 84 81 50A20300 FFFFFFFF - mov [rcx+rax*4+0003A250],FFFFFFFF -> This is triggered when I unequip the slot and it is empty
Spoiler
WOFF.exe+6E9200:
1406E91F3 - 48 8B 0D C60CD502 - mov rcx,[WOFF.exe+3439EC0]
1406E91FA - 8B 83 90070000 - mov eax,[rbx+00000790]
1406E9200 - C7 84 81 50A20300 FFFFFFFF - mov [rcx+rax*4+0003A250],FFFFFFFF <<
1406E920B - 48 8B CB - mov rcx,rbx
1406E920E - E8 8D100000 - call WOFF.exe+6EA2A0
RAX=0000000000000000
RBX=0000000017A4C400
RCX=000000000796F800
RDX=000000006765FC30
RSI=0000000008ABA970
RDI=0000000000000000
RBP=000000006765FCE0
RSP=000000006765FC70
R8=0000000017A978A0
R9=0000000000000004
R10=00000000070AEA40
R11=000000006765FB90
R12=0000000000000000
R13=0000000000000000
R14=0000000000000000
R15=0000000000000000
RIP=00000001406E920B
1406E91F3 - 48 8B 0D C60CD502 - mov rcx,[WOFF.exe+3439EC0]
1406E91FA - 8B 83 90070000 - mov eax,[rbx+00000790]
1406E9200 - C7 84 81 50A20300 FFFFFFFF - mov [rcx+rax*4+0003A250],FFFFFFFF <<
1406E920B - 48 8B CB - mov rcx,rbx
1406E920E - E8 8D100000 - call WOFF.exe+6EA2A0
RAX=0000000000000000
RBX=0000000017A4C400
RCX=000000000796F800
RDX=000000006765FC30
RSI=0000000008ABA970
RDI=0000000000000000
RBP=000000006765FCE0
RSP=000000006765FC70
R8=0000000017A978A0
R9=0000000000000004
R10=00000000070AEA40
R11=000000006765FB90
R12=0000000000000000
R13=0000000000000000
R14=0000000000000000
R15=0000000000000000
RIP=00000001406E920B
Spoiler
WOFF.exe+6EA98C:
1406EA986 - 89 74 9D 08 - mov [rbp+rbx*4+08],esi
1406EA98A - EB 05 - jmp WOFF.exe+6EA991
1406EA98C - 46 89 74 BD 08 - mov [rbp+r15*4+08],r14d <<
1406EA991 - 48 8B 5C 24 40 - mov rbx,[rsp+40]
1406EA996 - 48 8B 6C 24 48 - mov rbp,[rsp+48]
RAX=00000000FFFFFFFF
RBX=0000000000000003
RCX=000000000798F888
RDX=0000000000000007
RSI=00000000079C9A5C
RDI=00000000FFFFFFFF
RBP=00000000079C9A48
RSP=000000006767FBF0
R8=000000000000007D
R9=000000006767FC90
R10=000000000000001C
R11=0000000140000000
R12=0000000000000000
R13=0000000000000000
R14=000000000000000E
R15=0000000000000000
RIP=00000001406EA991
1406EA986 - 89 74 9D 08 - mov [rbp+rbx*4+08],esi
1406EA98A - EB 05 - jmp WOFF.exe+6EA991
1406EA98C - 46 89 74 BD 08 - mov [rbp+r15*4+08],r14d <<
1406EA991 - 48 8B 5C 24 40 - mov rbx,[rsp+40]
1406EA996 - 48 8B 6C 24 48 - mov rbp,[rsp+48]
RAX=00000000FFFFFFFF
RBX=0000000000000003
RCX=000000000798F888
RDX=0000000000000007
RSI=00000000079C9A5C
RDI=00000000FFFFFFFF
RBP=00000000079C9A48
RSP=000000006767FBF0
R8=000000000000007D
R9=000000006767FC90
R10=000000000000001C
R11=0000000140000000
R12=0000000000000000
R13=0000000000000000
R14=000000000000000E
R15=0000000000000000
RIP=00000001406EA991
Would anyone have any tips or help