能力值:
( LV2,RANK:10 )
|
-
-
2 楼
//代码用CE提取的,很多时候是这个样子
0691F6B0 - 80 69 67 FF - sub byte ptr [ecx+67],-01
0691F6B4 - FF - db -01
0691F6B5 - FF - db -01
0691F6B6 - FF - db -01
0691F6B7 - FF 68 FF - jmp far [eax-01]
0691F6BA - 91 - xchg eax,ecx
0691F6BB - 06 - push es
0691F6BC - B0 F6 - mov al,-0A
0691F6BE - 91 - xchg eax,ecx
0691F6BF - 06 - push es
0691F6C0 - 90 - nop
0691F6C1 - F6 91 06D8F691 - not byte ptr [ecx-6E0927FA]
0691F6C7 - 06 - push es
0691F6C8 - DCFF - fdiv st(7),st(0)
0691F6CA - 91 - xchg eax,ecx
0691F6CB - 06 - push es
0691F6CC - C0 9A 837C6024 80 - rcr byte ptr [edx+24607C83],-80[COLOR="SeaGreen"]//这里[/COLOR]
0691F6D3 - 7C 00 - jnge 0691F6D5
0691F6D5 - 00 00 - add [eax],al
0691F6D7 - 00 E8 - add al,ch
0691F6D9 - F6 91 06E609AE - not byte ptr [ecx-51F619FA]
0691F6DF - 05 E8030000 - add eax,000003E8
0691F6E4 - 00 00 - add [eax],al
0691F6E6 - 00 00 - add [eax],al
0691F6E8 - B4 FF - mov ah,-01
0691F6EA - 91 - xchg eax,ecx
0691F6EB - 06 - push es
0691F6EC - FF 54 DE 04 - call dword ptr [esi+ebx*8+04]
0691F6F0 - E8 030000F8 - call FE91F6F8
0691F6F5 - B1 56 - mov cl,56
0691F6F7 - 05 00000000 - add eax,00000000
0691F6FC - 04 00 - add al,00
0691F6FE - 00 00 - add [eax],al
0691F700 - 00 DC - add ah,bl
0691F702 - F8 - clc
0691F703 - 7F 00 - jg 0691F705
0691F705 - 00 08 - add [eax],cl
0691F707 - 02 28 - add ch,[eax]
0691F709 - F9 - stc
0691F70A - 91 - xchg eax,ecx
0691F70B - 06 - push es
0691F70C - 00 00 - add [eax],al
0691F70E - 08 02 - or [edx],al
0691F710 - 20 F7 - and bh,dh
0691F712 - 91 - xchg eax,ecx
0691F713 - 06 - push es
0691F714 - 00 00 - add [eax],al
0691F716 - 00 00 - add [eax],al
0691F718 - 00 00 - add [eax],al
0691F71A - 00 00 - add [eax],al
0691F71C - 00 00 - add [eax],al
0691F71E - 80 7C 00 00 00 - cmp byte ptr [eax+eax+00],00
0691F723 - 00 18 - add [eax],bl
0691F725 - 00 1A - add [edx],bl
0691F727 - 00 00 - add [eax],al
0691F729 - DCF8 - fdiv st(0),st(0)
0691F72B - 7F 00 - jg 0691F72D
0691F72D - 00 08 - add [eax],cl
0691F72F - 02 50 F9 - add dl,[eax-07]
0691F732 - 91 - xchg eax,ecx
0691F733 - 06 - push es
0691F734 - 00 00 - add [eax],al
0691F736 - 08 02 - or [edx],al
0691F738 - 48 - dec eax
0691F739 - F7 91 06000000 - not [ecx+00000006]
0691F73F - 00 00 - add [eax],al
0691F741 - 00 00 - add [eax],al
0691F743 - 00 00 - add [eax],al
0691F745 - 00 80 7C000000 - add [eax+0000007C],al
0691F74B - 00 00 - add [eax],al
0691F74D - 00 00 - add [eax],al
|
能力值:
( LV2,RANK:10 )
|
-
-
3 楼
是否在保护模式下??
|
能力值:
( LV2,RANK:10 )
|
-
-
4 楼
写回去了
|
能力值:
( LV2,RANK:10 )
|
-
-
5 楼
应该不在吧,我用Kernel Detective和CE都试了,都不行啊~
|
能力值:
(RANK:50 )
|
-
-
6 楼
下个内存断点看看谁写入的就好啦
|
能力值:
( LV2,RANK:10 )
|
-
-
7 楼
写回去的速度怎么那么快?我前改,后面马上就改回了,没它快啊~
|
能力值:
( LV2,RANK:10 )
|
-
-
8 楼
呵呵,这是一个游戏的内存,还没过调试呢,下不了断点,这个地方是我注入HOOK了一些API找到的地,前面改,后面1秒就改回来,这是什么监视?
|
能力值:
( LV2,RANK:10 )
|
-
-
9 楼
虽然不知道楼主说的是什么,但是貌似很厉害的样子
|
能力值:
(RANK:50 )
|
-
-
10 楼
要么是用某种方式校验,要么就是直接定时覆盖
|
能力值:
( LV3,RANK:30 )
|
-
-
11 楼
写回去了.下一个写入断点吧
|
能力值:
( LV2,RANK:10 )
|
-
-
12 楼
你这个不是代码吧。 是内存。
内存返回的验证什么的呗。硬件断点试试
|
能力值:
( LV2,RANK:10 )
|
-
-
13 楼
下一个写入断点试试。
|