You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

C++如何通过内存地址或特征码修改游戏内实体位置的存储数值?

C++ 游戏内存数值修改实现方案

一、直接通过静态内存地址修改(仅适用于固定基址场景)

你提供的地址0x7FF6CC7DCCD为64位地址,操作前需确认该地址是实体位置的最终基址,还是实体对象(object)的基址:

  • 如果是位置属性的直接地址,可直接强转为对应类型指针修改数值,实体位置通常为3个连续的float类型(X/Y/Z轴),可根据实际存储类型调整:
constexpr uintptr_t posAddr = 0x7FF6CC7DCCD;

// 解除内存页写入保护
DWORD oldProtect;
VirtualProtect(reinterpret_cast<LPVOID>(posAddr), 0xC, PAGE_READWRITE, &oldProtect);

// 写入新坐标
float* pPos = reinterpret_cast<float*>(posAddr);
pPos[0] = 100.0f; // X轴
pPos[1] = 200.0f; // Y轴
pPos[2] = 300.0f; // Z轴

// 恢复原内存保护权限
VirtualProtect(reinterpret_cast<LPVOID>(posAddr), 0xC, oldProtect, &oldProtect);

注:如果0x7FF6CC7DCCD是实体对象的基址,需要加上位置属性的偏移量才能拿到坐标实际地址,偏移值可通过Cheat Engine调试获取,示例代码如下(假设位置偏移为0x30):

uintptr_t entityBase = *reinterpret_cast<uintptr_t*>(0x7FF6CC7DCCD);
float* pPos = reinterpret_cast<float*>(entityBase + 0x30);

二、通过特征码扫描定位地址(通用稳定方案)

静态地址会随游戏重启、版本更新变动,用特征码定位兼容性更强,你提供的特征码修正为标准十六进制格式为9F 4F F0 C4 A8 70 39 41,实现逻辑如下:

  • 先获取游戏主模块的内存范围,遍历区间匹配特征码,匹配成功后根据调试得到的偏移计算出实体位置的实际地址
#include <windows.h>
#include <vector>
#include <cstdint>
#include <cstring>

// 特征码扫描函数
uintptr_t FindSignature(uintptr_t moduleBase, size_t moduleSize, const std::vector<uint8_t>& sig, const char* mask) {
    size_t sigLen = strlen(mask);
    for (size_t i = 0; i < moduleSize - sigLen; i++) {
        bool match = true;
        for (size_t j = 0; j < sigLen; j++) {
            if (mask[j] == 'x' && *reinterpret_cast<uint8_t*>(moduleBase + i + j) != sig[j]) {
                match = false;
                break;
            }
        }
        if (match) return moduleBase + i;
    }
    return 0;
}

// 调用示例
void ModifyEntityPosition() {
    // 获取游戏主模块基址,注入场景下GetModuleHandle(NULL)即为主exe模块
    uintptr_t moduleBase = reinterpret_cast<uintptr_t>(GetModuleHandle(NULL));
    MODULEINFO moduleInfo;
    GetModuleInformation(GetCurrentProcess(), reinterpret_cast<HMODULE>(moduleBase), &moduleInfo, sizeof(moduleInfo));

    // 填入特征码和掩码,x代表精准匹配,?代表通配
    std::vector<uint8_t> sig = {0x9F, 0x4F, 0xF0, 0xC4, 0xA8, 0x70, 0x39, 0x41};
    const char* mask = "xxxxxxxx";

    uintptr_t sigAddr = FindSignature(moduleBase, moduleInfo.SizeOfImage, sig, mask);
    if (!sigAddr) return; // 特征码匹配失败直接返回

    // 此处偏移需根据你调试得到的结果调整,示例假设特征码地址+0x10为实体位置地址
    uintptr_t posAddr = sigAddr + 0x10;

    // 后续修改逻辑和静态地址修改逻辑一致
    DWORD oldProtect;
    VirtualProtect(reinterpret_cast<LPVOID>(posAddr), 0xC, PAGE_READWRITE, &oldProtect);
    float* pPos = reinterpret_cast<float*>(posAddr);
    pPos[0] = 100.0f;
    pPos[1] = 200.0f;
    pPos[2] = 300.0f;
    VirtualProtect(reinterpret_cast<LPVOID>(posAddr), 0xC, oldProtect, &oldProtect);
}

内容的提问来源于stack exchange,提问作者user11889309

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.02 19:15:01