冰楓論壇

標題: TwMS v168.3_ICS_定點生怪 [打印本頁]

作者: qkckcqkckcq    時間: 2014-3-14 17:08
標題: TwMS v168.3_ICS_定點生怪
  1. //TwMS v168.3_ICS_定點生怪
  2. //Update:QK
  3. [ENABLE]
  4. RegisterSymbol(ReLifeVac)
  5. Alloc(ReLifeVac, 256)
  6. RegisterSymbol(RelifeXY)
  7. Alloc(RelifeXY,8)
  8. RegisterSymbol(RelifeSwitch)
  9. Alloc(RelifeSwitch, 4)
  10. Label(ReLifeVacXY)
  11. Label(DoRelife)
  12. Label(Return)
  13. RelifeSwitch:
  14. DD 1
  15. ReLifeVac:
  16. Cmp [RelifeSwitch],1
  17. Je  ReLifeVacXY
  18. Cmp [RelifeSwitch],2
  19. Je  DoRelife
  20. Jmp Return
  21. ReLifeVacXY:
  22. Push Eax
  23. Mov  Eax,[014a5dcc]
  24. Push [Eax+00001288]
  25. Pop  [RelifeXY]
  26. Push [Eax+0000128c]
  27. Pop  [RelifeXY+4]
  28. Pop  Eax
  29. Mov  [RelifeSwitch],2
  30. Jmp  Return
  31. DoRelife:
  32. Cmp [Esp], 00781378   
  33. Jne Return
  34. Cmp dword ptr [Esp+18],02
  35. Jne Return
  36. Push Ecx
  37. Mov  Eax,[RelifeXY]
  38. Mov  [Esp+0c], eax
  39. Mov  Eax,[RelifeXY+4]
  40. Mov  [Esp+10], eax
  41. Push Eax
  42. Mov  Ecx,[0149e2e4]
  43. call 0048c409
  44. Mov  Ecx, eax
  45. Mov  [Esp+20], ecx
  46. Pop  Ecx
  47. Jmp  Return
  48. Return:
  49. push ebp
  50. mov ebp,esp
  51. push ebx
  52. push esi
  53. Jmp 00D3FA21+5
  54. 01228ED0:
  55. dd ReLifeVac
  56. [DISABLE]
  57. 01228ED0:
  58. dd 00D3FA21
  59. UnRegisterSymbol(ReLifeVac)
  60. DeAlloc(ReLifeVac)
  61. UnRegisterSymbol(RelifeXY)
  62. DeAlloc(RelifeXY)
  63. UnRegisterSymbol(RelifeSwitch)
  64. DeAlloc(RelifeSwitch)
複製代碼





歡迎光臨 冰楓論壇 (https://bingfong.com/) Powered by 冰楓