冰楓論壇

標題: TwMS 206.2 MISS無敵 [ICS] [打印本頁]

作者: prt    時間: 2018-4-18 15:14
標題: TwMS 206.2 MISS無敵 [ICS]
  1. //TwMS 206.2 MISS無敵 [ICS]
  2. [Enable]
  3. Alloc(Hook_Main,128)
  4. Label(HookFun)

  5. Hook_Main:
  6. Cmp [Esp+18],01E7A21F
  7. Jne 0147AFF0
  8. Mov [Esp+18],HookFun
  9. Jmp 0147AFF0

  10. HookFun:
  11. mov [ebp+esi*4-48],eax
  12. inc esi
  13. cmp esi,08
  14. jnge 01E7A210
  15. mov edi,[ebp-000000C0]
  16. mov ecx,edi
  17. mov [ebp-00000118],00000000
  18. mov [ebp-00000108],00000000
  19. mov [ebp-00000134],00000000
  20. mov [ebp-0000012C],00000000
  21. mov [ebp-0000009C],00000000
  22. mov [ebp-000000D4],00000000
  23. mov [ebp-00000098],00000000
  24. call 008508E0
  25. push eax
  26. mov eax,[ebx]
  27. mov ecx,ebx
  28. call dword ptr [eax+70]
  29. push eax
  30. mov eax,[ebx]
  31. mov ecx,ebx
  32. call dword ptr [eax+6C]
  33. push eax
  34. call 007C04B0
  35. add esp,0C
  36. mov [ebp-00000130],eax
  37. xor eax,eax
  38. mov [ebp-0000011C],00000000
  39. lea ecx,[ebx+00000120]
  40. mov [ebp-00000120],00000000
  41. mov [ebp-00000144],eax
  42. mov [ebp-0000010C],eax
  43. mov [ebp-00000160],eax
  44. mov [ebp-000000EC],eax
  45. mov [ebp-00000100],eax
  46. mov [ebp-00000158],eax
  47. mov [ebp-000000DC],eax
  48. mov [ebp-000000AC],eax
  49. mov [ebp-00000174],eax
  50. mov [ebp-000000F4],eax
  51. mov [ebp-00000104],eax
  52. mov [ebp-000000C4],eax
  53. call 00B59150
  54. push eax
  55. call 004BF410
  56. add esp,04
  57. mov [ebp-70],eax
  58. lea ecx,[ebx+00000120]
  59. call 00B59160
  60. push eax
  61. call 004BF410
  62. add esp,04
  63. mov ecx,ebx
  64. mov [ebp-00000110],eax
  65. cmp dword ptr [ebp-74],00
  66. jne 01E7BFA1

  67. 033B264C:
  68. DD Hook_Main
  69. [Disable]
  70. 033B264C:
  71. DD 0147AFF0
  72. DeAlloc(Hook_Main)
複製代碼

作者: kuangshen    時間: 2018-5-6 14:36
請問大大,數據里的033B264C:這個地址是一個什麼特殊的地址嗎?在研究前面的數據時發現怎麼也找不到這個地址。




歡迎光臨 冰楓論壇 (https://bingfong.com/) Powered by 冰楓