高级玩家

- 贡献度
- 1
- 金元
- 3487
- 积分
- 353
- 精华
- 0
- 注册时间
- 2012-12-14
|
本帖最后由 ze277050246 于 2021-1-28 19:01 编辑
你版本号对么?我只玩了18721版本. 所以数据都是按照18721找的.. 如果你的是其他版本..你可以CE改.
符文=2字节
经验和金钱=4字节
技能点=1字节
钥匙=2字节
血蓝=2字节
下边是特征码.可以改汇编代码实现功能.
------------------------------------------------------------------------------
血特征码:8B 46 0C 89 44 24 30 8B 46 10 89 44 24 34 8B 44 24 14 +BB
008CB7E5 - 2B C6 - sub eax,esi <<< 减血
008CB7E7 - 8B 4C 24 20 - mov ecx,[esp+20]
008CB7EB - 66 89 87 62010000 - mov [edi+00000162],ax
008CB7F2 - 85 C9 - test ecx,ecx
008CB7F4 - 74 13 - je 008CB809
008CB7F6 - 8B 01 - mov eax,[ecx]
008CB7F8 - 68 B091D900 - push 00D991B0 : [00C6AB88]
008CB7FD - 8B 00 - mov eax,[eax]
008CB7FF - FF D0 - call eax
008CB801 - 8B 4C 24 20 - mov ecx,[esp+20]
008CB805 - 8B D0 - mov edx,eax
008CB807 - EB 02 - jmp 008CB80B
008CB809 - 33 D2 - xor edx,edx
008CB80B - A1 A8D2D900 - mov eax,[00D9D2A8] : [2A3203D0]
008CB810 - C6 44 24 0C 00 - mov byte ptr [esp+0C],00
008CB815 - 83 B8 3C030000 00 - cmp dword ptr [eax+0000033C],00
008CB81C - 0F85 B1000000 - jne 008CB8D3
008CB822 - 8B 80 74010000 - mov eax,[eax+00000174]
008CB828 - 8B 80 DC000000 - mov eax,[eax+000000DC]
008CB82E - 85 C0 - test eax,eax
008CB830 - 74 05 - je 008CB837
008CB832 - 8B 40 04 - mov eax,[eax+04]
008CB835 - EB 02 - jmp 008CB839
008CB837 - 33 C0 - xor eax,eax
008CB839 - 8A 40 50 - mov al,[eax+50]
008CB83C - 24 0F - and al,0F
008CB83E - 3C 02 - cmp al,02
008CB840 - 0F85 8D000000 - jne 008CB8D3
008CB846 - 85 D2 - test edx,edx
008CB848 - 74 21 - je 008CB86B
008CB84A - 8B 92 BC000000 - mov edx,[edx+000000BC]
008CB850 - 85 D2 - test edx,edx
008CB852 - 74 17 - je 008CB86B
008CB854 - 8B 44 24 0C - mov eax,[esp+0C]
008CB858 - 80 7A 10 01 - cmp byte ptr [edx+10],01
008CB85C - BA 01000000 - mov edx,00000001
008CB861 - 0FB6 C0 - movzx eax,al
008CB864 - 0F44 C2 - cmove eax,edx
008CB867 - 89 44 24 0C - mov [esp+0C],eax
008CB86B - 85 C9 - test ecx,ecx
008CB86D - 74 52 - je 008CB8C1
008CB86F - 8B 01 - mov eax,[ecx]
008CB871 - 8B 40 04 - mov eax,[eax+04]
------------------------------------------------------------------------------
蓝特征码:8B 43 58 2B 43 54 C1 F8 02 83 F8 01 +4c
01551886 - 68 E019BF01 - push 01BF19E0 : [01ACAB88]
0155188B - FF 10 - call dword ptr [eax]
0155188D - 85 C0 - test eax,eax
0155188F - 74 0C - je 0155189D
01551891 - 8B C8 - mov ecx,eax
01551893 - E8 F893F6FF - call 014BAC90
01551898 - 83 F8 01 - cmp eax,01
0155189B - 74 5C - je 015518F9
0155189D - 8B 07 - mov eax,[edi]
0155189F - 8B CF - mov ecx,edi
015518A1 - FF 77 40 - push [edi+40]
015518A4 - 0FB7 B3 5E010000 - movzx esi,word ptr [ebx+0000015E]
015518AB - 8B 80 04010000 - mov eax,[eax+00000104]
015518B1 - FF D0 - call eax
015518B3 - 0FB6 C0 - movzx eax,al
015518B6 - 8B CF - mov ecx,edi
015518B8 - 66 2B F0 - sub si,ax <<<减蓝
015518BB - 66 89 B3 5E010000 - mov [ebx+0000015E],si
015518C2 - 8B 07 - mov eax,[edi]
015518C4 - FF 77 40 - push [edi+40]
015518C7 - 8B 80 08010000 - mov eax,[eax+00000108]
015518CD - FF D0 - call eax
015518CF - 0FB6 D0 - movzx edx,al
015518D2 - 8B 47 40 - mov eax,[edi+40]
015518D5 - 89 55 FC - mov [ebp-04],edx
015518D8 - 8B 70 3C - mov esi,[eax+3C]
015518DB - 3B 70 40 - cmp esi,[eax+40]
015518DE - 74 19 - je 015518F9
015518E0 - 8B F8 - mov edi,eax
015518E2 - 8B 0E - mov ecx,[esi]
------------------------------------------------------------------------------
无冷却特征码:55 8B EC 68 84 00 00 00 E8 08 +80
006E9C80 - 55 - push ebp
006E9C81 - 8B EC - mov ebp,esp
006E9C83 - 56 - push esi
006E9C84 - 8B F1 - mov esi,ecx
006E9C86 - C7 06 386BC900 - mov [esi],00C96B38 : [006F0410]
006E9C8C - E8 7F0F0000 - call 006EAC10
006E9C91 - F6 45 08 01 - test byte ptr [ebp+08],01
006E9C95 - 74 0E - je 006E9CA5
006E9C97 - 68 84000000 - push 00000084
006E9C9C - 56 - push esi
006E9C9D - E8 DB293700 - call 00A5C67D
006E9CA2 - 83 C4 08 - add esp,08
006E9CA5 - 8B C6 - mov eax,esi
006E9CA7 - 5E - pop esi
006E9CA8 - 5D - pop ebp
006E9CA9 - C2 0400 - ret 0004
006E9CAC - CC - int 3
006E9CAD - CC - int 3
006E9CAE - CC - int 3
006E9CAF - CC - int 3
006E9CB0 - C7 41 6C 0000803F - mov [ecx+6C],3F800000 : [00000000] 无冷却
------------------------------------------------------------------------------
箭矢特征码:83 FB 03 77 4C +1A
00E162ED - 83 FB 03 - cmp ebx,03
00E162F0 - 77 4C - ja 00E1633E
00E162F2 - 80 7C 24 5C 00 - cmp byte ptr [esp+5C],00
00E162F7 - 74 03 - je 00E162FC
00E162F9 - 88 5F 76 - mov [edi+76],bl
00E162FC - A1 A8D22D01 - mov eax,[012DD2A8] : [2B221710]
00E16301 - 8B 88 74010000 - mov ecx,[eax+00000174]
00E16307 - 80 AC 19 C0010000 01 - sub byte ptr [ecx+ebx+000001C0],01 箭矢
------------------------------------------------------------------------------
攻速特征码:F3 0F 10 4E 70 D9 5D FC +8
0104F2E6 - 6A 00 - push 00
0104F2E8 - 8B 80 B8000000 - mov eax,[eax+000000B8]
0104F2EE - FF D0 - call eax
0104F2F0 - D8 7D 08 - fdivr dword ptr [ebp+08]
0104F2F3 - 0F57 C0 - xorps xmm0,xmm0
0104F2F6 - 8B 06 - mov eax,[esi]
0104F2F8 - F3 0F10 4E 70 - movss xmm1,[esi+70]
0104F2FD - D9 5D FC - fstp dword ptr [ebp-04]
0104F300 - F3 0F5C 4D FC - subss xmm1,[ebp-04] 攻速
0104F305 - 0F2F C1 - comiss xmm0,xmm1
0104F308 - F3 0F11 4E 70 - movss [esi+70],xmm1
0104F30D - 0F83 AF000000 - jae 0104F3C2
0104F313 - F3 0F10 05 B0B46201 - movss xmm0,[0162B4B0] : [(float)1.0000]
0104F31B - F3 0F5C C1 - subss xmm0,xmm1
0104F31F - 51 - push ecx
0104F320 - 8B CE - mov ecx,esi
0104F322 - F3 0F11 46 6C - movss [esi+6C],xmm0
0104F327 - F3 0F10 45 08 - movss xmm0,[ebp+08]
0104F32C - F3 0F11 04 24 - movss [esp],xmm0
0104F331 - FF 90 FC000000 - call dword ptr [eax+000000FC]
0104F337 - E9 8E000000 - jmp 0104F3CA
0104F33C - F3 0F10 4E 6C - movss xmm1,[esi+6C]
0104F341 - 0F2F C8 - comiss xmm1,xmm0
0104F344 - 76 3D - jna 0104F383
0104F346 - 8B 06 - mov eax,[esi]
0104F348 - FF 76 40 - push [esi+40]
0104F34B - 8B 80 B0000000 - mov eax,[eax+000000B0]
0104F351 - FF D0 - call eax
0104F353 - D8 7D 08 - fdivr dword ptr [ebp+08]
0104F356 - 0F57 C9 - xorps xmm1,xmm1
0104F359 - F3 0F10 46 6C - movss xmm0,[esi+6C]
0104F35E - D9 5D 08 - fstp dword ptr [ebp+08]
0104F361 - F3 0F5C 45 08 - subss xmm0,[ebp+08]
0104F366 - 0F2F C8 - comiss xmm1,xmm0
0104F369 - F3 0F11 46 6C - movss [esi+6C],xmm0
0104F36E - 72 5D - jb 0104F3CD
0104F370 - 8B 06 - mov eax,[esi]
0104F372 - 8B CE - mov ecx,esi
0104F374 - C7 46 6C 00000000 - mov [esi+6C],00000000
0104F37B - FF 90 F8000000 - call dword ptr [eax+000000F8]
0104F381 - EB 47 - jmp 0104F3CA
0104F383 - 0F2F C1 - comiss xmm0,xmm1
0104F386 - 76 05 - jna 0104F38D
0104F388 - 0F2F C2 - comiss xmm0,xmm2
0104F38B - 77 33 - ja 0104F3C0
0104F38D - 8D 45 08 - lea eax,[ebp+08]
0104F390 - F3 0F11 4D 08 - movss [ebp+08],xmm1
0104F395 - 50 - push eax
|
|