|
|
修改这个64位,折腾了好长时间,昨晚折腾了3小时,今天又折腾了一上午,总算修改成功了,靠!!!
下述是64位的KenPlayer修改代码(逻辑与32位KenPlayer相同),插入洞穴代码后,实现按ESC键退出KenPlayer程序运行
洞穴代码:
00000001400A678A | 8179 08 00010000 | cmp dword ptr ds:[rcx+8],100 |
00000001400A6791 | 75 0E | jne 0x1400A67A1 |
00000001400A6793 | 8379 10 1B | cmp dword ptr ds:[rcx+10],1B |
00000001400A6797 | 75 08 | jne 0x1400A67A1 |
00000001400A6799 | 31C9 | xor ecx,ecx |
00000001400A679B | FF15 17090000 | call qword ptr ds:[0x00000001400A70B8] | <ExitProcess>
00000001400A67A1 | FF15 590C0000 | call qword ptr ds:[0x00000001400A7400] | <TranslateMessage>
00000001400A67A7 | E9 FAECF6FF | jmp kenplayer.1400154A6 | |
|