关键代码如下:
0040AE2A 68 04ED4100 push 0041ED04 ; 游戏引擎线程启动
0040AE2F . 6A 01 push 1
0040AE31 . 68 D00F4400 push 00440FD0
0040AE36 . 8DAF 9C130000 lea ebp, [edi+139C]
0040AE3C . E8 0F3F0000 call 0040ED50
0040AE41 . 83C4 0C add esp, 0C
0040AE44 . 8BCF mov ecx, edi
0040AE46 . E8 65020000 call 0040B0B0
0040AE4B . C787 88130000>mov dword ptr [edi+1388], 1
0040AE55 . FF15 7C904100 call [<&KERNEL32.GetTickCount>] ; [GetTickCount
0040AE5B . 8987 84130000 mov [edi+1384], eax
0040AE61 . C74424 10 000>mov dword ptr [esp+10], 0
0040AE69 . BE 10EC4100 mov esi, 0041EC10
0040AE6E > 8B46 04 mov eax, [esi+4]
0040AE71 . 8B0E mov ecx, [esi]
0040AE73 . 50 push eax ; /Arg3
0040AE74 . 8D5424 18 lea edx, [esp+18] ; |
0040AE78 . 51 push ecx ; |Arg2
0040AE79 . 52 push edx ; |Arg1
0040AE7A . 8BCF mov ecx, edi ; |
0040AE7C . E8 DF2B0000 call 0040DA60 ; \R2无双.0040DA60
0040AE81 . 8B4E 08 mov ecx, [esi+8]
0040AE84 . 8B00 mov eax, [eax]
0040AE86 . 51 push ecx
0040AE87 . 50 push eax
0040AE88 . 8BCD mov ecx, ebp
0040AE8A . C78424 288000>mov dword ptr [esp+8028], 0
0040AE95 . E8 F6570000 call 00410690
0040AE9A . 83F8 01 cmp eax, 1
0040AE9D . 8D4C24 14 lea ecx, [esp+14]
0040AEA1 . 0F94C3 sete bl
0040AEA4 . C78424 208000>mov dword ptr [esp+8020], -1
0040AEAF . E8 E2B50000 call <jmp.&MFC42.#800_CString::~CStri>
0040AEB4 . 84DB test bl, bl
0040AEB6 75 1D jnz short 0040AED5
0040AEB8 . 8BCD mov ecx, ebp
0040AEBA . E8 F1570000 call 004106B0
0040AEBF . 8B5424 10 mov edx, [esp+10]
0040AEC3 . 83C6 0C add esi, 0C
0040AEC6 . 42 inc edx
0040AEC7 . 81FE 1CEC4100 cmp esi, 0041EC1C
0040AECD . 895424 10 mov [esp+10], edx
0040AED1 .^ 7C 9B jl short 0040AE6E
0040AED3 . EB 07 jmp short 0040AEDC
0040AED5 > 837C24 10 01 cmp dword ptr [esp+10], 1
0040AEDA 7C 1F jl short 0040AEFB
0040AEDC > E8 C9BC0000 call <jmp.&WSOCK32.#111> ; [WSAGetLastError
0040AEE1 . 50 push eax
0040AEE2 . 68 E4EC4100 push 0041ECE4 ; 连接验证服务器失败! 错误代码:%d
0040AEE7 . 6A 00 push 0
0040AEE9 . 68 D00F4400 push 00440FD0
0040AEEE . E8 5D3E0000 call 0040ED50
0040AEF3 . 83C4 10 add esp, 10
0040AEF6 . E9 5F010000 jmp 0040B05A
0040AEFB > 68 D0EC4100 push 0041ECD0 ; 连接中,请等待...
我测试过直接跳转到 0041ECD0中,可惜游戏启动不起来.老大门帮我分析下啊!
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课