1.添加一个按钮,并修改Caption
2.修改按钮ID为IDC_BUTTON_tree
3.双击按钮,添加按钮处理函数
DWORD byWrite;
HANDLE hp = GetGameProcessHanlde();
PVOID FarCall = VirtualAllocEx(hp,NULL,0x8FFF,MEM_COMMIT,PAGE_EXECUTE_READWRITE);
WriteProcessMemory(hp,FarCall,plant1,0x8fff,&byWrite);
//执行代码
//TRACE
<span style="white-space:pre"> </span>HANDLE th=CreateRemoteThread(hp, NULL, NULL, (LPTHREAD_START_ROUTINE)FarCall, NULL, NULL, NULL);
<span style="white-space:pre"> </span>WaitForSingleObject(th,0xFFFFFF);
<span style="white-space:pre"> </span>VirtualFreeEx(hp, FarCall, 0x8fff, MEM_DECOMMIT);
在按钮处理函数上面添加
_declspec(naked) void plant1(void)
{_asm
{
push -1
push 2
push 8 //X列
mov eax, dword ptr ds : [0x6a9ec0] //mov eax,0x6a9ec0
mov eax, dword ptr ds : [eax + 0x768]
push eax
mov eax, 2 //Y行
mov edx, 0x0040D120
call edx
ret
}
==========================下面是有参数
1.plant1函数处理成
_declspec(naked) void plant1(DWORD *pxy)
{_asm
{
mov ebx, [esp + 4] //xy
mov ecx, [ebx] //x
mov edx, [ebx + 4] //y
push - 1
push 2
push ecx //X列
//mov ebx,[esp+4+0xc] //xy
//mov ecx,[ebx] //y
//mov edx,[ebx+4] //y
mov eax, dword ptr ds : [0x6a9ec0] //mov eax,0x6a9ec0
mov eax, dword ptr ds : [eax + 0x768]
push eax
mov eax, edx//Y行
mov edx, 0x0040D120
call edx
ret
}
}
2.按钮按下处理函数
for (int x = 0; x <= 8; x++)
{
for (int y = 0; y <= 4; y++)
{
plantOne(x,y);
}
}
3.在按钮按下处理函数上添加plantOne函数
void plantOne(DWORD x, DWORD y)
{
DWORD xy[2];
xy[0] = x;//0..7
xy[1] = y;// 0..4
DWORD byWrite;
//游戏进程句柄
HANDLE hp = GetGameProcessHanlde();
//在目标进程分配内存空间 以方便写入要执行的代码
PVOID FarCall = VirtualAllocEx(hp, NULL, 0x8FFF, MEM_COMMIT, PAGE_EXECUTE_READWRITE);
PVOID CallArg = VirtualAllocEx(hp, NULL, sizeof(int)* 2, MEM_COMMIT, PAGE_READWRITE);
//向目标进程的 目标地址写入我们要执行的代码
WriteProcessMemory(hp, FarCall, plant1, 0x8FFF, &byWrite);
//向目标进程 写入参数
WriteProcessMemory(hp, CallArg, xy, sizeof(DWORD)* 2, &byWrite);
//在目标进程 指定地址 执行代码
TRACE("\n addr=%x \n", FarCall);
HANDLE th = CreateRemoteThread(hp, NULL, NULL, (LPTHREAD_START_ROUTINE)FarCall, CallArg, NULL, NULL);
WaitForSingleObject(th, 0xFFFFFFF);//等待 ...
VirtualFreeEx(hp, FarCall, 0x8FFF, MEM_DECOMMIT);
CloseHandle(th);
CloseHandle(hp);
}