关于star6.1添加环击
最近一个月在火神和琳神的指导下,对EXE修改有点小成就,今天就看了下毅大的环击。试试移植到6.1上,经过测试后成功。下面分享下代码给论坛的朋友。
0040CE50 > 8B4D F4 MOV ECX,DWORD PTR SS:[EBP-C]
0040CE53 . 8A41 FF MOV AL,BYTE PTR DS:[ECX-1]
0040CE56 . 8845 E8 MOV BYTE PTR SS:[EBP-18],AL
0040CE59 . 8B45 E4 MOV EAX,DWORD PTR SS:[EBP-1C]
0040CE5C . 66:8B50 06 MOV DX,WORD PTR DS:[EAX+6]
0040CE60 . 8955 EC MOV DWORD PTR SS:[EBP-14],EDX
0040CE63 . EB 03 JMP SHORT Ekd5.0040CE68
0040CE65 > FF45 F0 INC DWORD PTR SS:[EBP-10]
0040CE68 > 837D F0 08 CMP DWORD PTR SS:[EBP-10],8
0040CE6C . 73 6D JNB SHORT Ekd5.0040CEDB
0040CE6E . FF75 F0 PUSH DWORD PTR SS:[EBP-10] ; /Arg2
0040CE71 . 8D45 EC LEA EAX,DWORD PTR SS:[EBP-14] ; |
0040CE74 . 50 PUSH EAX ; |Arg1
0040CE75 . E8 7B8B0200 CALL Ekd5.004359F5 ; \Ekd5环.004359F5
0040CE7A . 83C4 08 ADD ESP,8
0040CE7D . 50 PUSH EAX ; /Arg1
0040CE7E . 8D4D FC LEA ECX,DWORD PTR SS:[EBP-4] ; |
0040CE81 . E8 1597FFFF CALL Ekd5.0040659B ; \Ekd5环.0040659B
0040CE86 . 8D4D FC LEA ECX,DWORD PTR SS:[EBP-4]
0040CE89 . 51 PUSH ECX ; /Arg1
0040CE8A . E8 F5890200 CALL Ekd5.00435884 ; \Ekd5环.00435884
0040CE8F . 83C4 04 ADD ESP,4
0040CE92 . 8845 F8 MOV BYTE PTR SS:[EBP-8],AL
0040CE95 . 3C FF CMP AL,0FF
0040CE97 .^74 CC JE SHORT Ekd5环.0040CE65
0040CE99 . 3A45 E8 CMP AL,BYTE PTR SS:[EBP-18]
0040CE9C .^74 C7 JE SHORT Ekd5环.0040CE65
0040CE9E . 8AC8 MOV CL,AL
0040CEA0 . E8 5493FFFF CALL Ekd5.004061F9
0040CEA5 . E8 6698FFFF CALL Ekd5.00406710
0040CEAA . 8BF0 MOV ESI,EAX
0040CEAC . 8B4D E4 MOV ECX,DWORD PTR SS:[EBP-1C]
0040CEAF . E8 5C98FFFF CALL Ekd5.00406710
0040CEB4 . 8A55 14 MOV DL,BYTE PTR SS:[EBP+14]
0040CEB7 . 80FA 00 CMP DL,0
0040CEBA . 75 04 JNZ SHORT Ekd5.0040CEC0
0040CEBC . 3BF0 CMP ESI,EAX
0040CEBE . 75 0E JNZ SHORT Ekd5.0040CECE
0040CEC0 > 80FA 01 CMP DL,1
0040CEC3 . 75 04 JNZ SHORT Ekd5.0040CEC9
0040CEC5 . 3BF0 CMP ESI,EAX
0040CEC7 . 74 05 JE SHORT Ekd5.0040CECE
0040CEC9 > 80FA 02 CMP DL,2
0040CECC .^75 97 JNZ SHORT Ekd5.0040CE65
0040CECE > 8B45 F4 MOV EAX,DWORD PTR SS:[EBP-C]
0040CED1 . 8A4D F8 MOV CL,BYTE PTR SS:[EBP-8]
0040CED4 . 8808 MOV BYTE PTR DS:[EAX],CL
0040CED6 . FF45 F4 INC DWORD PTR SS:[EBP-C]
0040CED9 .^EB 8A JMP SHORT Ekd5环.0040CE65
0040CEDB > 8B45 F4 MOV EAX,DWORD PTR SS:[EBP-C]
0040CEDE . C600 FF MOV BYTE PTR DS:[EAX],0FF
0040CEE1 . 8B45 10 MOV EAX,DWORD PTR SS:[EBP+10]
0040CEE4 . E9 1A900200 JMP Ekd5.00435F03
以上代码可以直接抄。然后把原有的穿透位置替换一个,435F28-435F48中选一个。建议选取435F3C(六格)改成40CE50就可以实现了。
图片附件:
[环击]
TIM图片20171127221236.jpg (2017-11-27 22:13, 32.4 K)
|