新开一个线程,不停的搜索我方除主角之外的队员,然后把队员6维改为255,并且把属性上限也修改为255.所有队员装备+60的妖刀村正和+60的防具。剩下3个道具位没有修改,大家可以尝试自己去加!
特别奇怪的就是:从大航海4HD里找到的,构造的sleep函数,居然不需要push 需要睡眠的毫秒数!太奇怪了!
大家自己复制取用,代码如下:
define(DK4,DK4HD_sc.exe)
[ENABLE]
alloc(newmem, 1024)
label(tmp)
label(start)
label(out)
label(out1)
label(out_end)
label(tmp_req_end)
CreateThread(tmp)
registersymbol(tmp_req_end)
DK4HD_sc.exe+1DBC3D:
db ff
DK4HD_sc.exe+1DBC61:
db ff
DK4HD_sc.exe+1DBC75:
db ff
DK4HD_sc.exe+1DBC9B:
db ff
newmem:
tmp_req_end:
dd 0
tmp:
mov rax,DK4HD_sc.exe+42B3E0C
mov al,[rax]
mov rbx,DK4HD_sc.exe+42B134C
mov rcx,0
mov rdx,0
start:
cmp al,[rbx]
jne out1:
mov dl,ff
mov byte ptr [rbx+3],dl
mov byte ptr [rbx+4],dl
mov byte ptr [rbx+5],dl
mov byte ptr [rbx+6],dl
mov byte ptr [rbx+7],dl
mov byte ptr [rbx+8],dl
mov dl,30
mov byte ptr [rbx+17],dl
mov dl,48
mov byte ptr [rbx+18],dl
out1:
inc rcx
add rbx,30
mov rdx,DK4HD_sc.exe+42B191C
cmp rbx,rdx
ja out
cmp rcx,27
je out
jmp start
out:
//DK4HD_sc.exe+43073B0
mov rdx,DK4HD_sc.exe+43073B0
//push BB8
call qword ptr [rdx]
cmp [tmp_req_end],1
je out_end
jmp tmp
out_end:
mov rax,0
ret
dealloc(newmem)
[DISABLE]
tmp_req_end:
dd 1
unregistersymbol(tmp_req_end)
DK4HD_sc.exe+1DBC3D:
db 64
DK4HD_sc.exe+1DBC61:
db 64
DK4HD_sc.exe+1DBC75:
db 64
DK4HD_sc.exe+1DBC9B:
db 64
特别奇怪的就是:从大航海4HD里找到的,构造的sleep函数,居然不需要push 需要睡眠的毫秒数!太奇怪了!
大家自己复制取用,代码如下:
define(DK4,DK4HD_sc.exe)
[ENABLE]
alloc(newmem, 1024)
label(tmp)
label(start)
label(out)
label(out1)
label(out_end)
label(tmp_req_end)
CreateThread(tmp)
registersymbol(tmp_req_end)
DK4HD_sc.exe+1DBC3D:
db ff
DK4HD_sc.exe+1DBC61:
db ff
DK4HD_sc.exe+1DBC75:
db ff
DK4HD_sc.exe+1DBC9B:
db ff
newmem:
tmp_req_end:
dd 0
tmp:
mov rax,DK4HD_sc.exe+42B3E0C
mov al,[rax]
mov rbx,DK4HD_sc.exe+42B134C
mov rcx,0
mov rdx,0
start:
cmp al,[rbx]
jne out1:
mov dl,ff
mov byte ptr [rbx+3],dl
mov byte ptr [rbx+4],dl
mov byte ptr [rbx+5],dl
mov byte ptr [rbx+6],dl
mov byte ptr [rbx+7],dl
mov byte ptr [rbx+8],dl
mov dl,30
mov byte ptr [rbx+17],dl
mov dl,48
mov byte ptr [rbx+18],dl
out1:
inc rcx
add rbx,30
mov rdx,DK4HD_sc.exe+42B191C
cmp rbx,rdx
ja out
cmp rcx,27
je out
jmp start
out:
//DK4HD_sc.exe+43073B0
mov rdx,DK4HD_sc.exe+43073B0
//push BB8
call qword ptr [rdx]
cmp [tmp_req_end],1
je out_end
jmp tmp
out_end:
mov rax,0
ret
dealloc(newmem)
[DISABLE]
tmp_req_end:
dd 1
unregistersymbol(tmp_req_end)
DK4HD_sc.exe+1DBC3D:
db 64
DK4HD_sc.exe+1DBC61:
db 64
DK4HD_sc.exe+1DBC75:
db 64
DK4HD_sc.exe+1DBC9B:
db 64