002825B5 8B87 B0500000 MOV EAX,DWORD PTR DS:[EDI+50B0]
002825BB 8B08 MOV ECX,DWORD PTR DS:[EAX] ; 访问内存数据2
002825BD 8B97 AC500000 MOV EDX,DWORD PTR DS:[EDI+50AC] ; 减去这个数据
002825C3 6A 0A PUSH 0A
002825C5 51 PUSH ECX
002825C6 8BCF MOV ECX,EDI
002825C8 FFD2 CALL EDX ..假数据修改.SUB指令
//
00275AD8 8B4424 04 MOV EAX,DWORD PTR SS:[ESP+4]
00275ADC 8B11 MOV EDX,DWORD PTR DS:[ECX]
00275ADE 6A 00 PUSH 0
00275AE0 50 PUSH EAX
00275AE1 8B81 9C500000 MOV EAX,DWORD PTR DS:[ECX+509C]
00275AE7 68 E9030000 PUSH 3E9
00275AEC 52 PUSH EDX
00275AED FFD0 CALL EAX USER32.SetDlgItemInt设置游戏数据
00275AEF C2 0400 RETN 4
特征代码
004825B5 8B87 B0500000 MOV EAX,DWORD PTR DS:[EDI+50B0]
004825BB 8B08 MOV ECX,DWORD PTR DS:[EAX]
004825BD 8B97 AC500000 MOV EDX,DWORD PTR DS:[EDI+50AC]
004825C3 6A 0A PUSH 0A
004825C5 51 PUSH ECX
004825C6 8BCF MOV ECX,EDI
004825C8 FFD2 CALL EDX
004825CA 894424 14 MOV DWORD PTR SS:[ESP+14],EAX
004825CE 85C0 TEST EAX,EAX
004825D0 C74424 1C 0000000>MOV DWORD PTR SS:[ESP+1C],0
004825D8 8D4424 14 LEA EAX,DWORD PTR SS:[ESP+14]
004825DC 7F 04 JG SHORT 004825E2
004825DE 8D4424 1C LEA EAX,DWORD PTR SS:[ESP+1C]
004825E2 8B10 MOV EDX,DWORD PTR DS:[EAX]
004825E4 8BB7 B0500000 MOV ESI,DWORD PTR DS:[EDI+50B0]
004825EA 8B87 60500000 MOV EAX,DWORD PTR DS:[EDI+5060]
004825F0 895424 14 MOV DWORD PTR SS:[ESP+14],EDX
004825F4 8B97 5C500000 MOV EDX,DWORD PTR DS:[EDI+505C]
004825FA 85D2 TEST EDX,EDX
004825FC 7E 18 JLE SHORT 00482616
004825FE 8D8F 1C500000 LEA ECX,DWORD PTR DS:[EDI+501C]
00482604 8B19 MOV EBX,DWORD PTR DS:[ECX]
00482606 8B9C9F 1C400000 MOV EBX,DWORD PTR DS:[EDI+EBX*4+401C]
0048260D 8B0418 MOV EAX,DWORD PTR DS:[EAX+EBX]
00482610 83C1 04 ADD ECX,4
00482613 4A DEC EDX
00482614 ^ 75 EE JNZ SHORT 00482604
00482616 8B18 MOV EBX,DWORD PTR DS:[EAX]
00482618 6A 00 PUSH 0
0048261A 6A 04 PUSH 4
0048261C 8D4424 1C LEA EAX,DWORD PTR SS:[ESP+1C]
00482620 50 PUSH EAX
00482621 56 PUSH ESI
00482622 FF97 18400000 CALL DWORD PTR DS:[EDI+4018]
00482628 50 PUSH EAX
00482629 FFD3 CALL EBX
0048262B 8B97 90500000 MOV EDX,DWORD PTR DS:[EDI+5090]
00482631 8DB7 70500000 LEA ESI,DWORD PTR DS:[EDI+5070]
00482637 6A 00 PUSH 0
00482639 8BCE MOV ECX,ESI
0048263B 897424 18 MOV DWORD PTR SS:[ESP+18],ESI
0048263F FFD2 CALL EDX
//
这里是USER32.SetDlgItemInt