2014年2月6日 星期四

TwMS v1.52.2_ICS_集氣無延遲

[enable]
RegisterSymbol(NoDealyFly)
Alloc(NoDealyFly,256)
Registersymbol(AttackTimes)
Alloc(AttackTimes, 4)
label(Fake1)
label(Fake2)
label(Fake3)
Label(Refresh)

NoDealyFly:
cmp [esp], 009B6DEF //50 e8 ?? ?? ?? ff 59 85 c0 74 10 51 8b c4 89 65 08
jne 0097e796
add esp,4
call 0097e796
push eax
call 004af791
pop ecx
test eax,eax
je Fake1
push ecx
mov eax,esp
mov [ebp+08],esp
push ebx
mov ecx,esi
mov [eax],ebx
call 00959655
jmp Fake1

Fake1:
mov eax,[esi+000051e0]
cmp esi,ebx
je Fake2
push ebx
lea ecx,[esi+000000dc]
call 00428285
mov eax,[ebp-10]
cmp [eax],019d8812
jne Fake3
lea ecx,[esi+0000846c]
call 004347ca
jmp Fake3

Fake3:
mov eax,[ebp-10]
push 64
push ebx
push 4b
push [eax]
call 009f0da6
jmp Fake2

Fake2:
push 10
push ebx
push edi
inc [AttackTimes]
cmp [AttackTimes],1
jle 009B6E4E //add esp,0c
call 00ab9921
cmp [AttackTimes],2
jg Refresh
jmp 009B6E4E


Refresh:
mov [AttackTimes],0
jmp 009B6E4E

00DBCD1C:
dd NoDealyFly
[disable]
00DBCD1C:
dd 0097e796
//6a 08 b8 ?? ?? ?? 00 e8 ?? ?? ?? 00 8b 0d ?? ?? ?? 00 85 c9 74 41
dealloc(NoDealyFly)
unregistersymbol(NoDealyFly)
dealloc(AttackTimes)
unregistersymbol(AttackTimes)

沒有留言:

張貼留言