麗麗 發表於 2020-9-27 12:25:35

TwMS v228.1 ICS 自動洗内潛

本帖最後由 麗麗 於 2020-9-27 12:30 編輯


Alloc(AutoResetAbilityICS,512)
Alloc(AutoResetAbilityDelay,4)
Alloc(AutoResetAbilityTimer,4)
Alloc(PotentialGrade,4)
Label(AutoResetAbility)
Label(AutoResetAbilityExit)
Alloc(AutoResetAbilityICS2,512)
Label(AutoResetAbility2)
Alloc(AutoResetAbilityICS3,512)

PotentialGrade:
DD 3

AutoResetAbilityDelay:
DD 3E8

AutoResetAbilityTimer:
DD 0

AutoResetAbilityICS:
cmp ,00B69B7A
jne GetFocus
mov ,AutoResetAbility
jmp GetFocus

AutoResetAbilityICS2:
cmp ,02E58183
jne GetLastError
mov ,AutoResetAbility2
jmp GetLastError

AutoResetAbilityICS3:
cmp ,02B8759F
jne RtlAllocateHeap
mov ,02B87768
jmp RtlAllocateHeap

AutoResetAbility:
cmp ,0
je 00B69B7A
pushad
mov ecx,
call 02DCC590
cmp eax,
jge AutoResetAbilityExit
call 02B5FD00
mov edx,eax
sub edx,
cmp edx,
jl AutoResetAbilityExit
mov ,eax
mov ecx,
push 00
push 00
push 00
push 00
call 02E57FC0
jmp AutoResetAbilityExit

AutoResetAbilityExit:
popad
jmp 00B69B7A

AutoResetAbility2:
add esp,08
mov ecx,esp
push eax
mov ,00000000
call 00482E40
mov eax,6
jmp 02E58199


044FDBB8:
DD AutoResetAbilityICS

039FE1C4:
DD AutoResetAbilityICS2

044FD9FC:
DD AutoResetAbilityICS3


044FDBB8:
DD GetFocus

039FE1C4:
DD GetLastError

044FD9FC:
DD RtlAllocateHeap

DeAlloc(AutoResetAbilityICS)
DeAlloc(AutoResetAbilityDelay)
DeAlloc(AutoResetAbilityTimer)
DeAlloc(PotentialGrade)
DeAlloc(AutoResetAbilityICS2)
DeAlloc(AutoResetAbilityICS3)
頁: [1]
查看完整版本: TwMS v228.1 ICS 自動洗内潛