, here's the function that gets triggered when you keep "C" pressed for example:
Code: Select all
FC_m64.dll+F4E1DE0 - 48 89 5C 24 08 - mov [rsp+08],rbx
FC_m64.dll+F4E1DE5 - 48 89 6C 24 10 - mov [rsp+10],rbp
FC_m64.dll+F4E1DEA - 48 89 74 24 20 - mov [rsp+20],rsi
FC_m64.dll+F4E1DEF - 57 - push rdi
FC_m64.dll+F4E1DF0 - 48 83 EC 20 - sub rsp,20 { 32 }
FC_m64.dll+F4E1DF4 - C6 81 40010000 01 - mov byte ptr [rcx+00000140],01 { 1 }
FC_m64.dll+F4E1DFB - 41 0FB6 F0 - movzx esi,r8l
FC_m64.dll+F4E1DFF - 48 89 D5 - mov rbp,rdx
FC_m64.dll+F4E1E02 - 48 89 CF - mov rdi,rcx
FC_m64.dll+F4E1E05 - 45 84 C0 - test r8l,r8l
FC_m64.dll+F4E1E08 - 75 27 - jne FC_m64.dll+F4E1E31 <-- 75 to EB (JMP this for extended duration)
FC_m64.dll+F4E1E0A - F3 0F10 49 20 - movss xmm1,[rcx+20]
FC_m64.dll+F4E1E0F - 48 8B 49 10 - mov rcx,[rcx+10]
FC_m64.dll+F4E1E13 - E8 98C5BAF1 - call FC_m64.dll+108E3B0
FC_m64.dll+F4E1E18 - 48 8B 07 - mov rax,[rdi]
FC_m64.dll+F4E1E1B - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1E1E - FF 90 88000000 - call qword ptr [rax+00000088]
FC_m64.dll+F4E1E24 - 84 C0 - test al,al
FC_m64.dll+F4E1E26 - 74 09 - je FC_m64.dll+F4E1E31
FC_m64.dll+F4E1E28 - 48 8B 4F 10 - mov rcx,[rdi+10]
FC_m64.dll+F4E1E2C - E8 9F2BBBF1 - call FC_m64.dll+10949D0
FC_m64.dll+F4E1E31 - 48 8D 8F 30010000 - lea rcx,[rdi+00000130]
FC_m64.dll+F4E1E38 - E8 132EDAF0 - call FC_m64.dll+284C50
FC_m64.dll+F4E1E3D - 84 C0 - test al,al
FC_m64.dll+F4E1E3F - 74 3D - je FC_m64.dll+F4E1E7E
FC_m64.dll+F4E1E41 - 48 8D 8F 30010000 - lea rcx,[rdi+00000130]
FC_m64.dll+F4E1E48 - E8 5398DBF0 - call FC_m64.dll+29B6A0
FC_m64.dll+F4E1E4D - 84 C0 - test al,al
FC_m64.dll+F4E1E4F - 75 2D - jne FC_m64.dll+F4E1E7E
FC_m64.dll+F4E1E51 - F3 0F10 0D BFDBC9F4 - movss xmm1,[FC_m64.dll+417FA18] { (-1.00) }
FC_m64.dll+F4E1E59 - 48 8D 8F 30010000 - lea rcx,[rdi+00000130]
FC_m64.dll+F4E1E60 - E8 4BE6DCF0 - call FC_m64.dll+2B04B0
FC_m64.dll+F4E1E65 - 48 8B 07 - mov rax,[rdi]
FC_m64.dll+F4E1E68 - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1E6B - FF 90 88000000 - call qword ptr [rax+00000088]
FC_m64.dll+F4E1E71 - 84 C0 - test al,al
FC_m64.dll+F4E1E73 - 74 09 - je FC_m64.dll+F4E1E7E
FC_m64.dll+F4E1E75 - 48 8B 4F 10 - mov rcx,[rdi+10]
FC_m64.dll+F4E1E79 - E8 8231BBF1 - call FC_m64.dll+1095000
FC_m64.dll+F4E1E7E - 0F57 C0 - xorps xmm0,xmm0
FC_m64.dll+F4E1E81 - 0F2F 47 2C - comiss xmm0,[rdi+2C]
FC_m64.dll+F4E1E85 - 73 0C - jae FC_m64.dll+F4E1E93
FC_m64.dll+F4E1E87 - 40 84 F6 - test sil,sil
FC_m64.dll+F4E1E8A - 75 07 - jne FC_m64.dll+F4E1E93
FC_m64.dll+F4E1E8C - F3 0F10 4F 28 - movss xmm1,[rdi+28]
FC_m64.dll+F4E1E91 - EB 08 - jmp FC_m64.dll+F4E1E9B
FC_m64.dll+F4E1E93 - F3 0F10 0D 7DDBC9F4 - movss xmm1,[FC_m64.dll+417FA18] { (-1.00) }
FC_m64.dll+F4E1E9B - 48 8D 8F 20010000 - lea rcx,[rdi+00000120]
FC_m64.dll+F4E1EA2 - E8 09E6DCF0 - call FC_m64.dll+2B04B0
FC_m64.dll+F4E1EA7 - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1EAA - E8 D1DA9CF2 - call FC_m64.dll+1EAF980
FC_m64.dll+F4E1EAF - 4C 8D 47 38 - lea r8,[rdi+38]
FC_m64.dll+F4E1EB3 - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1EB6 - 48 8D 57 48 - lea rdx,[rdi+48]
FC_m64.dll+F4E1EBA - 0FB6 D8 - movzx ebx,al
FC_m64.dll+F4E1EBD - E8 BECB9EF2 - call FC_m64.dll+1ECEA80
FC_m64.dll+F4E1EC2 - B8 80000000 - mov eax,00000080 { 128 }
FC_m64.dll+F4E1EC7 - 84 DB - test bl,bl
FC_m64.dll+F4E1EC9 - BA 90000000 - mov edx,00000090 { 144 }
FC_m64.dll+F4E1ECE - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1ED1 - 0F45 D0 - cmovne edx,eax
FC_m64.dll+F4E1ED4 - 48 01 FA - add rdx,rdi
FC_m64.dll+F4E1ED7 - E8 B4C69EF2 - call FC_m64.dll+1ECE590
FC_m64.dll+F4E1EDC - 44 8B 8F E8000000 - mov r9d,[rdi+000000E8]
FC_m64.dll+F4E1EE3 - 48 8D 97 EC000000 - lea rdx,[rdi+000000EC]
FC_m64.dll+F4E1EEA - 44 8B 87 E0000000 - mov r8d,[rdi+000000E0]
FC_m64.dll+F4E1EF1 - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1EF4 - E8 27CC9EF2 - call FC_m64.dll+1ECEB20
FC_m64.dll+F4E1EF9 - 48 8D 97 F0000000 - lea rdx,[rdi+000000F0]
FC_m64.dll+F4E1F00 - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1F03 - E8 28C69EF2 - call FC_m64.dll+1ECE530
FC_m64.dll+F4E1F08 - 48 8B 5F 08 - mov rbx,[rdi+08]
FC_m64.dll+F4E1F0C - 48 8D 8B F0060000 - lea rcx,[rbx+000006F0]
FC_m64.dll+F4E1F13 - E8 783DD7F0 - call FC_m64.dll+255C90
FC_m64.dll+F4E1F18 - 84 C0 - test al,al
FC_m64.dll+F4E1F1A - 74 5D - je FC_m64.dll+F4E1F79
FC_m64.dll+F4E1F1C - 48 83 BB F8060000 00 - cmp qword ptr [rbx+000006F8],00 { 0 }
FC_m64.dll+F4E1F24 - 74 53 - je FC_m64.dll+F4E1F79
FC_m64.dll+F4E1F26 - 48 8B 5F 08 - mov rbx,[rdi+08]
FC_m64.dll+F4E1F2A - 48 8D 8B F0060000 - lea rcx,[rbx+000006F0]
FC_m64.dll+F4E1F31 - E8 5A3DD7F0 - call FC_m64.dll+255C90
FC_m64.dll+F4E1F36 - 84 C0 - test al,al
FC_m64.dll+F4E1F38 - 74 3F - je FC_m64.dll+F4E1F79
FC_m64.dll+F4E1F3A - 48 8B 8B F0060000 - mov rcx,[rbx+000006F0]
FC_m64.dll+F4E1F41 - 48 8B 01 - mov rax,[rcx]
FC_m64.dll+F4E1F44 - FF 50 68 - call qword ptr [rax+68]
FC_m64.dll+F4E1F47 - 84 C0 - test al,al
FC_m64.dll+F4E1F49 - 74 2E - je FC_m64.dll+F4E1F79
FC_m64.dll+F4E1F4B - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1F4E - E8 5D44D0F0 - call FC_m64.dll+1E63B0
FC_m64.dll+F4E1F53 - 48 8B 4F 08 - mov rcx,[rdi+08]
FC_m64.dll+F4E1F57 - 4C 8D 44 24 40 - lea r8,[rsp+40]
FC_m64.dll+F4E1F5C - 45 31 C9 - xor r9d,r9d
FC_m64.dll+F4E1F5F - 8B 00 - mov eax,[rax]
FC_m64.dll+F4E1F61 - 48 8B 91 F8060000 - mov rdx,[rcx+000006F8]
FC_m64.dll+F4E1F68 - 89 44 24 40 - mov [rsp+40],eax
FC_m64.dll+F4E1F6C - 48 8B 4A 10 - mov rcx,[rdx+10]
FC_m64.dll+F4E1F70 - 8B 52 38 - mov edx,[rdx+38]
FC_m64.dll+F4E1F73 - 48 8B 01 - mov rax,[rcx]
FC_m64.dll+F4E1F76 - FF 50 08 - call qword ptr [rax+08]
FC_m64.dll+F4E1F79 - 48 8B 07 - mov rax,[rdi]
FC_m64.dll+F4E1F7C - 44 0FB6 C6 - movzx r8d,sil
FC_m64.dll+F4E1F80 - 48 89 EA - mov rdx,rbp
FC_m64.dll+F4E1F83 - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1F86 - FF 50 70 - call qword ptr [rax+70]
FC_m64.dll+F4E1F89 - 80 7F 1C 00 - cmp byte ptr [rdi+1C],00 { 0 }
FC_m64.dll+F4E1F8D - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1F90 - 74 0D - je FC_m64.dll+F4E1F9F
FC_m64.dll+F4E1F92 - 48 8B 07 - mov rax,[rdi]
FC_m64.dll+F4E1F95 - 31 D2 - xor edx,edx
FC_m64.dll+F4E1F97 - FF 50 60 - call qword ptr [rax+60]
FC_m64.dll+F4E1F9A - E9 C3000000 - jmp FC_m64.dll+F4E2062
FC_m64.dll+F4E1F9F - E8 DCD99CF2 - call FC_m64.dll+1EAF980
FC_m64.dll+F4E1FA4 - 4C 8D 47 68 - lea r8,[rdi+68]
FC_m64.dll+F4E1FA8 - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1FAB - 48 8D 57 78 - lea rdx,[rdi+78]
FC_m64.dll+F4E1FAF - 0FB6 D8 - movzx ebx,al
FC_m64.dll+F4E1FB2 - E8 C9CA9EF2 - call FC_m64.dll+1ECEA80
FC_m64.dll+F4E1FB7 - B8 C0000000 - mov eax,000000C0 { 192 }
FC_m64.dll+F4E1FBC - 84 DB - test bl,bl
FC_m64.dll+F4E1FBE - BA D0000000 - mov edx,000000D0 { 208 }
FC_m64.dll+F4E1FC3 - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1FC6 - 0F45 D0 - cmovne edx,eax
FC_m64.dll+F4E1FC9 - 48 01 FA - add rdx,rdi
FC_m64.dll+F4E1FCC - E8 BFC59EF2 - call FC_m64.dll+1ECE590
FC_m64.dll+F4E1FD1 - 44 8B 8F 14010000 - mov r9d,[rdi+00000114]
FC_m64.dll+F4E1FD8 - 48 8D 97 18010000 - lea rdx,[rdi+00000118]
FC_m64.dll+F4E1FDF - 44 8B 87 0C010000 - mov r8d,[rdi+0000010C]
FC_m64.dll+F4E1FE6 - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E1FE9 - E8 32CB9EF2 - call FC_m64.dll+1ECEB20
FC_m64.dll+F4E1FEE - 48 8B 5F 08 - mov rbx,[rdi+08]
FC_m64.dll+F4E1FF2 - 48 8D 8B F0060000 - lea rcx,[rbx+000006F0]
FC_m64.dll+F4E1FF9 - E8 923CD7F0 - call FC_m64.dll+255C90
FC_m64.dll+F4E1FFE - 84 C0 - test al,al
FC_m64.dll+F4E2000 - 74 60 - je FC_m64.dll+F4E2062
FC_m64.dll+F4E2002 - 48 83 BB F8060000 00 - cmp qword ptr [rbx+000006F8],00 { 0 }
FC_m64.dll+F4E200A - 74 56 - je FC_m64.dll+F4E2062
FC_m64.dll+F4E200C - 48 8B 5F 08 - mov rbx,[rdi+08]
FC_m64.dll+F4E2010 - 48 8D 8B F0060000 - lea rcx,[rbx+000006F0]
FC_m64.dll+F4E2017 - E8 743CD7F0 - call FC_m64.dll+255C90
FC_m64.dll+F4E201C - 84 C0 - test al,al
FC_m64.dll+F4E201E - 74 42 - je FC_m64.dll+F4E2062
FC_m64.dll+F4E2020 - 48 8B 8B F0060000 - mov rcx,[rbx+000006F0]
FC_m64.dll+F4E2027 - 48 8B 01 - mov rax,[rcx]
FC_m64.dll+F4E202A - FF 50 68 - call qword ptr [rax+68]
FC_m64.dll+F4E202D - 84 C0 - test al,al
FC_m64.dll+F4E202F - 74 31 - je FC_m64.dll+F4E2062
FC_m64.dll+F4E2031 - 48 89 F9 - mov rcx,rdi
FC_m64.dll+F4E2034 - E8 7743D0F0 - call FC_m64.dll+1E63B0
FC_m64.dll+F4E2039 - 48 8B 4F 08 - mov rcx,[rdi+08]
FC_m64.dll+F4E203D - 4C 8D 44 24 40 - lea r8,[rsp+40]
FC_m64.dll+F4E2042 - 41 B9 01000000 - mov r9d,00000001 { 1 }
FC_m64.dll+F4E2048 - 8B 00 - mov eax,[rax]
FC_m64.dll+F4E204A - 48 8B 91 F8060000 - mov rdx,[rcx+000006F8]
FC_m64.dll+F4E2051 - 89 44 24 40 - mov [rsp+40],eax
FC_m64.dll+F4E2055 - 48 8B 4A 10 - mov rcx,[rdx+10]
FC_m64.dll+F4E2059 - 8B 52 38 - mov edx,[rdx+38]
FC_m64.dll+F4E205C - 48 8B 01 - mov rax,[rcx]
FC_m64.dll+F4E205F - FF 50 08 - call qword ptr [rax+08]
FC_m64.dll+F4E2062 - 48 8B 5C 24 30 - mov rbx,[rsp+30]
FC_m64.dll+F4E2067 - 48 8B 6C 24 38 - mov rbp,[rsp+38]
FC_m64.dll+F4E206C - 48 8B 74 24 48 - mov rsi,[rsp+48]
FC_m64.dll+F4E2071 - 48 83 C4 20 - add rsp,20 { 32 }
FC_m64.dll+F4E2075 - 5F - pop rdi
FC_m64.dll+F4E2076 - C3 - ret