TwMS v148_ICS_物品過濾


既然有人發了我也就來發囉...

//TwMS v148_ICS_物品過濾
//Update: Onion
//Up to date at 2012/08/15

[Enable]
Registersymbol(CheckESP)
Alloc(CheckESP,512)
Registersymbol(ItemList)
Alloc(ItemList,204800)
Label(HookESP)
Label(HookFun)
Label(HookOr1)
Label(HookOr2)
Label(Filter)
Label(Skip)
Label(End)

ItemList:
//請在以下加入欲過濾名單

//請在以上加入欲過濾名單
DD 00

CheckESP:
Cmp [Esp+6C], 004ED391
Je  HookESP
Jmp 00726AC5

HookESP:
Mov [Esp+6C], HookFun
Jmp 00726AC5

HookFun:
mov eax,[ebp-1C]
mov esi,[ebp-50]
mov [esi+1C],al
cmp eax,01
Je HookOr1
cmp eax,02
Je HookOr1
xor al,al
Jmp HookOr2
HookOr1:
mov al,01
HookOr2:
mov [esi+1D],al
mov [esi+20],edi
mov edi,[ebp+08]
mov ecx,edi
call 00408B02
movzx eax,al
mov ecx,edi
Xor Eax, Eax //過濾楓幣,不要請註解掉這行
mov [esi+30],eax
call 00408B5E
PUSH ESI
MOV ESI,ItemList

Filter:
CMP EAX,C350
JLE End
CMP DWORD PTR DS:[ESI],0
Je End
CMP DWORD PTR DS:[ESI],EAX
Je Skip
ADD ESI,4
JMP Filter
Skip:
XOR EAX,EAX
End:
POP ESI
MOV ECX,EDI
MOV [ESI+34],EAX
Jmp 004ED3CC

00DE5FEC:
DD CheckESP

[Disable]

00DE5FEC:
DD 00726AC5
UnRegistersymbol(CheckESP)
DeAlloc(CheckESP)
UnRegistersymbol(ItemList)
DeAlloc(ItemList)

留言

本月最夯

偷用電腦,怎知?事件檢視器全記錄!(開機時間、啟動項時間...)