1609还有一处暗桩没有拔,在局域网中会弹出东西来:
MaximunUserReached处函数的直接调用,在以前的补丁中已处理掉了。
.text:1ED84118 loc_1ED84118: ; CODE XREF: sub_1ED84040+C9j
.text:1ED84118 mov eax, [edi+44h]
.text:1ED8411B mov dword ptr [eax+50h], offset MaximunUserReached
.text:1ED84122 mov [eax+58h], edi
.text:1ED84125 cmp dword_1EFFF224, 0
.text:1ED8412C jz short loc_1ED8413B
.text:1ED8412E push offset aOz3 ; "OZ3"
.text:1ED84133 call sub_1ED8A160
.text:1ED84138 add esp, 4
.text:1EE528C9 sub_1EE528C9 proc near ; CODE XREF: sub_1EE5337F+AFp
.text:1EE528C9 push 4
.text:1EE528CB mov eax, offset __ehhandler$?CallUnexpected@@YAXPBU_s_ESTypeList@@@Z_13
.text:1EE528D0 call __EH_prolog3_catch
.text:1EE528D5 mov eax, [ecx+50h]
.text:1EE528D8 test eax, eax
.text:1EE528DA jz short loc_1EE528EA;修改为jmp即可
.text:1EE528DC push dword ptr [ecx+44h]
.text:1EE528DF and dword ptr [ebp-4], 0
.text:1EE528E3 push dword ptr [ecx+58h]
.text:1EE528E6 call eax
.text:1EE528E8 pop ecx
.text:1EE528E9 pop ecx
.text:1EE528EA
.text:1EE528EA loc_1EE528EA: ; CODE XREF: sub_1EE528C9+11j
.text:1EE528EA ; DATA XREF: sub_1EE528F0o
.text:1EE528EA call __EH_epilog3
.text:1EE528EF retn
.text:1EE528EF sub_1EE528C9 endp ; sp = -4