- UID
- 8784
- 帖子
- 4732
- 主題
- 343
- 精華
- 0
- 積分
- 3298
- 楓幣
- 2832
- 威望
- 3240
- 存款
- 0
- 贊助金額
- 0
- 推廣
- 0
- GP
- 9
- 閱讀權限
- 90
- 性別
- 保密
- 在線時間
- 1162 小時
- 註冊時間
- 2012-6-9
- 最後登入
- 2024-12-15
|
不隱藏因為你們用了一定斷線XD
不斷線方法我不公布ˊ_>ˋ- //TwMs v157.1 定點吸怪
- //更新: QK
- [Enable]
- registersymbol(MobVac)
- Alloc(MobVac,1024)
- registersymbol(Choose)
- Alloc(Choose,4)
- registersymbol(VacXY)
- Alloc(VacXY,8)
- label(FakeJmp)
- label(FakeJmp2)
- label(WriteXY)
- label(MobVacX)
- Label(EndVac)
- Choose:
- DD 1
- MobVac:
- Cmp [Esp], 006833E7 //eb ? 8b ? e8 ? ? ? ? 83 ? ? 53 83 ? ? 50 -- AOB-2
- Jne 00A8E3F7 //8b 81 c3 8b 89 c2 8b c1
- Add Esp, 4
- Call 00A8E3F7
- cmp [Choose],0
- je 006833E7 // =ADD
- cmp [Choose],1
- je WriteXY
- cmp [Choose],2
- je MobVacX
- jmp 006833E7 // =ADD
- //-------------------------------------------------------------------
- WriteXY:
- pushad
- mov eax,[0106ea8c] //8b ? ? ? ? ? 50 57 8d ? ? 50 53 e8 ? ? ? ? 8b
- mov eax,[eax+10a0] //8b ? ? ? ? ? 3b ? ? 7c ? 33 ? 40 5f -8B 86 ?? ?? 00 00 D1 FA 2B C2
- mov [VacXY],eax
- mov eax,[0106ea8c]
- mov eax,[eax+10a4] //8B 86 ?? ?? 00 00 D1 FA 2B C2 _AOB+4
- mov [VacXY+4],eax
- mov [Choose],2
- popad
- jmp 006833E7 // =ADD
- //-------------------------------------------------------------------
- MobVacX:
- push eax //50 8b ? e8 ? ? ? ? 23 ? ? 83 ? ? 75 ? 8b -- AOB-2
- mov ecx,esi
- call 0067aa4e
- and edi,[ebp-28]
- cmp edi,ffffffff
- jne FakeJmp2
- mov ecx,esi
- call 0065664c
- cmp eax,edi
- jle 00683417
- cmp [ebp-20],ebx
- je FakeJmp2
- cmp [esi+000005c0],ebx
- jne FakeJmp2
- mov ecx,esi
- call 00656676
- test eax,eax
- jne FakeJmp2
- cmp [esi+000000d4],bl
- jne FakeJmp2
- cmp [esi+000000d5],bl
- jne FakeJmp2
- mov ecx,esi
- call 00656622
- cmp eax,03
- je FakeJmp
- mov ecx,esi
- call 00656622
- cmp eax,04
- jne FakeJmp2
- jmp FakeJmp
- //-------------------------------------------------------------------
- FakeJmp:
- cmp [esi+000004c4],ebx
- jne FakeJmp2
- push 64
- push ebx
- push ebx
- push ebx
- push ebx
- push ebx
- push ebx
- push ebx
- push ebx
- push ffffffff
- mov ecx,esi
- call 0067f607
- jmp FakeJmp2
- //-------------------------------------------------------------------
- FakeJmp2:
- mov ecx,esi
- pushad
- mov ebx,esi
- mov eax,[ebx+00000194] //8b ? ? ? ? ? 3b ? 74 ? 83 ? ? eb ? 33 ? 8b ? ? ? ? ? 89
- add eax,FFFFFFF4 //更新
- mov ebx,eax
- add eax,10
- Cmp [Ebx+04], 1
- Je EndVac
- Mov [Ebx+04], 1
- Push Esi
- Mov Esi, Eax
- Mov Eax, [VacXY]
- Mov [Ebx+000006b4], Eax //f6 c4 01 75 12 39 8b -AOB_1
- Mov word ptr [Ebx+00000250], Ax //8b 86 8d 48 8b 01 8b cf
- Mov Eax, [VacXY+04]
- Mov [Ebx+000006b8], Eax // -AOB_+4
- Mov word ptr [Ebx+00000252], Ax //Mov word ptr [Ebx+00000XXX] +2
- Mov Eax, Esi
- Pop Esi
- mov [ebx+2b8],6 //8b cf ff 8b 45 28
- mov edi,[eax]
- mov ecx,eax
- add edi,00000088 //更新
- push 0
- push 0
- push 0
- push 0
- push [VacXY+4]
- push [VacXY]
- push 1
- call dword ptr [edi]
- jmp EndVac
- //-------------------------------------------------------------------
- EndVac:
- popad
- mov ecx,esi
- jmp 0068346F //jmp FakeJmp2 下一個!
- 00E99698:
- DD MobVac
- [Disable]
- 00E99698: //6
- DD 00A8E3F7
- Choose:
- DD 1
- DeAlloc(MobVac)
- DeAlloc(VacXY)
複製代碼 |
|