Unlimited Attack - Pointer: 00794C20 Offset: 1348
No Breath - Pointer: 00794C20 Offset: 2C8
Speed Attack - Pointer: 00794C20 Offset: 2D8
Char X - Pointer: 00794CB8 Offset: 57C
Char Y - Pointer: 00794CB8 Offset: 580
Item X - Pointer: 00794C20 Offset: 57C
Item Y - Pointer: 00794C20 Offset: 580
Left Wall - Pointer: 007940B0 Offset: C
Right Wall - Pointer: 007940B0 Offset: 14
Top Wall - Pointer: 007940B0 Offset: 10
Bottom Wall - Pointer: 007940B0 Offset: 18
People Scanner - Pointer: 007940b8 Offset: 18
Flash Jump - •Still Not Avilable•
Scripts:
CRC Bypass:
Quote:
[ENABLE]
ALLOC(crc,128)
ALLOC(dump,3670018)
LABEL(oldmem)
LABEL(ret)
LOADBINARY(dump,eMS.CEM)
crc:
CMP ECX,00400000
JB oldmem
CMP ECX,00780000
JA oldmem
MOV EAX,dump
ADD ECX, dump-400000
oldmem:
MOV EAX,[EBP+10]
DB 56 57
JMP ret
00458A2B:
JMP crc
ret:
[DISABLE]
00458A2B:
MOV EAX,[EBP+10]
DB 56 57
DEALLOC(crc)
DEALLOC(dump)
Full GodMode:
Quote:
[ENABLE]
//Full GodMode
0065CC2F:
db 0f 84
[DISABLE]
//Full GodMode
0065CC2F:
db 0f 85
SuperTubi
Quote:
[ENABLE]
//SuperTubi
00488724:
db 90 90
[DISABLE]
//SuperTubi
00488724:
db 75 36
Swear Filter
Quote:
[ENABLE]
//Swear Filter
0044C495:
db 90 90
[DISABLE]
//Swear Filter
0044C495:
db 74 1c
Shadow Partner
Quote:
[ENABLE]
//Shadow Partner
00645A48:
db 0f 85
[DISABLE]
//Shadow Partner
00645A48:
db 0f 84
Item Filter
Quote:
[enable]
Alloc(filter,124)
label(ifreject)
label(end)
label(skip)
Alloc(iftable,512)
label(ifexit)
filter:
push ebx
push esi
xor ebx, ebx
mov esi,iftable
ifreject:
cmp eax,[esi]
je skip
cmp [esi],ebx
je end
add esi,4
jmp ifreject
skip:
mov eax,00
end:
pop esi
pop ebx
mov [edi+34], eax
mov edi, [ebp-14]
jmp ifexit
iftable:
dd 3D7E3C //Monster Card
dd 3D8285 // White Chocolate
dd 3D8286 // Dark Chocolate
dd 00
004908DB:
jmp filter
nop
ifexit:
[disable]
004908DB:
mov [edi+34], eax
mov edi, [ebp-14]
No Breath
Quote:
[ENABLE]
//No Breath
004A7F98: //DROP ITEM
db eb 23
0048A887: //CHANGE CHANNEL
db eb 10
006B6454: //CASH SHOP
db eb 13
[DISABLE]
//No Breath
004A7F98:
db 7e 23
0048A887:
db 7e 10
006B6454:
db 7e 13
Unlimited attack
Quote:
[ENABLE]
alloc(UnlimitedAttack,64)
alloc(SecksyCheck,44)
UnlimitedAttack:
mov eax,[00794C20]
mov ebx,[eax+57c]
sub ebx,00000001
mov [eax+57c],ebx
popad
cmp eax,edi
mov [ebp-20],eax
je 0051c4fe
SecksyCheck:
pushad
mov eax,[00794C20]
mov eax,[eax+1348]
cmp eax,00000062
jnl UnlimitedAttack
popad
cmp eax,edi
mov [ebp-20],eax
je 0051c4fe
0051C498:
jmp SecksyCheck
nop
nop
[disable]
0051C498:
cmp eax,edi
mov [ebp-20],eax
je 0051C4fe
dealloc(UnlimitedAttack)
dealloc(SecksyCheck)
Pin Unrandomize
Quote:
[ENABLE]
//Pin Unrandomize
alloc(pinunrandom,128)
label(returnhere)
0060356E:
jmp pinunrandom
returnhere:
pinunrandom:
add eax,edx
push edx
shr edx,1
mov [eax],edx
pop edx
cmp byte ptr [eax],0a
jmp returnhere
[DISABLE]
//Pin Unrandomize
0060356E:
add eax,edx
cmp byte ptr [eax],0a
dealloc(pinunrandom)
Pin KeyBoard Write
Quote:
[enable]
00472C4C:
db 0f 83
[disable]
00472C4C:
db 0f 86
Full Map Item Vac
Quote:
[ENABLE]
ALLOC(ItemVAC, 124)
LABEL(ret)
ItemVAC:
DB 60
MOV ECX, [EBP+8]
MOV EBX, [EBP-24]
MOV [ECX], EBX
MOV [ECX+4], EAX
MOV ECX, EAX
MOV EAX, EBX
LEA EDX, [EAX-19]
MOV [EBP-34], EDX
LEA EDX, [ECX-32]
add EAX, 19
add ECX, A
MOV [EBP-30], EDX
MOV [EBP-2C], EAX
MOV [EBP-28], ECX
DB 61 50
push [EBP-24]
LEA EAX, [EBP-34]
JMP ret
0048F6F5:
JMP ItemVAC
DB 90 90
ret:
[DISABLE]
DEALLOC(ItemVAC)
0048F6F5:
DB 50
push [EBP-24]
lea EAX, [EBP-34]
dEM Vac || Fixed
Quote:
[enable]
alloc(dv,100)
alloc(dvtype,4)
label(normalx)
label(normaly)
label(endx)
label(endy)
label(backdv)
label(dvzero)
label(dvone)
registersymbol(dvtype)
dv:
mov eax, [00794C20]
push eax
mov eax, [eax+57C]
mov [ebx+3FC], eax
cmp [dvtype], 0
je dvzero
cmp [dvtype], 1
je dvone
sub eax, 100
jmp dvzero
dvone:
add eax, 100
dvzero:
mov [ebx+3F4], eax
pop eax
mov eax, [eax+580]
mov [ebx+3F4], eax
mov [ebx+400], eax
jmp backdv
push ecx
mov ecx, [00794C20]
add ecx,57C
cmp ebx, ecx
je normalx
mov ecx, [ecx]
cmp [dvtype], 0
cmp [dvtype], 1
sub ecx, 100
add ecx, 100
cmp [ebx],ecx
je endx
normalx:
mov [ebx],eax
endx:
pop ecx
mov edi, [ebp+10]
push ecx
mov ecx, [00794C20]
add ecx,580
cmp edi, ecx
je normaly
mov ecx, [ecx]
cmp [edi],ecx
je endy
normaly:
mov [edi],eax
endy:
pop ecx
mov ebx, [ebp+14]
0051C5E6:
jmp dv
nop
backdv:
[disable]
0051C5E6:
mov [ebx+400], eax
dealloc(dv)
dealloc(uvx)
dealloc(uvy)
dealloc(dvtype)
unregistersymbol(dvtype)
Controlled Att Tele
after adding the script go to add adress manualy
address: couler
descripiton: attack per teleport
Quote:
[ENABLE]
alloc(tele,128)
alloc(toucher,4)
alloc(couler,4)
registersymbol(couler)
label(retour)
label(desactiver)
toucher:
db 00 00 00 00
couler:
db 05 00 00 00
00658F57:
jmp tele
retour:
tele:
push eax
push ebx
inc [toucher]
mov eax,[toucher]
mov ebx,[couler]
cmp eax,ebx
pop ebx
pop eax
jl desactiver
mov [toucher],0
cmp [ebp-10],esi
jne 00658f61
jmp retour
desactiver:
cmp [ebp-10],esi
je 00658f61
jmp retour
[DISABLE]
00658F57:
cmp [ebp-10],esi
je 00658f61
Attack Teleport Dem
Quote:
[enable]
alloc(dv,100)
alloc(dvtype,4)
label(normalx)
label(normaly)
label(endx)
label(endy)
label(backdv)
label(dvzero)
label(dvone)
registersymbol(dvtype)
dv:
mov eax, [00794C20]
push eax
mov eax, [eax+57C]
mov [ebx+3FC], eax
cmp [dvtype], 0
je dvzero
cmp [dvtype], 1
je dvone
sub eax, 100
jmp dvzero
dvone:
add eax, 100
dvzero:
mov [ebx+3F4], eax
pop eax
mov eax, [eax+580]
mov [ebx+3F4], eax
mov [ebx+400], eax
jmp backdv
push ecx
mov ecx, [00794C20]
add ecx,57C
cmp ebx, ecx
je normalx
mov ecx, [ecx]
cmp [dvtype], 0
cmp [dvtype], 1
sub ecx, 100
add ecx, 100
cmp [ebx],ecx
je endx
normalx:
mov [ebx],eax
endx:
pop ecx
mov edi, [ebp+10]
push ecx
mov ecx, [00794C20]
add ecx,580
cmp edi, ecx
je normaly
mov ecx, [ecx]
cmp [edi],ecx
je endy
normaly:
mov [edi],eax
endy:
pop ecx
mov ebx, [ebp+14]
0051C5E6:
jmp dv
nop
backdv:
00658F5A:
jne 00658f61
[disable]
00658F5A:
je 00658f61
0051C5E6:
mov [ebx+400], eax
dealloc(dv)
dealloc(uvx)
dealloc(uvy)
dealloc(dvtype)
unregistersymbol(dvtype)
Selective WallVac Bypass
After adding the script add address manualy
address: bool
Descripiption Bool (When 0 = Rdy)
Quote:
[ENABLE]
alloc(begin,2048)
alloc(olddata,32)
alloc(pointer,4)
alloc(bool,4)
registersymbol(bool)
registersymbol(olddata)
label(set)
label(ret)
label(end)
begin:
cmp [bool],1
je set
ret:
mov esi,olddata
movsd
movsd
movsd
movsd
pop edi
jmp end
set:
mov esi,[007940B0]
mov esi,[esi+0C]
mov [pointer], esi
mov esi,[pointer]
mov [olddata],esi
mov esi,[007940B0]
mov esi,[esi+10]
mov [pointer], esi
mov esi,[pointer]
mov [olddata+04],esi
mov esi,[007940B0]
mov esi,[esi+14]
mov [pointer], esi
mov esi,[pointer]
mov [olddata+08],esi
mov esi,[007940B0]
mov esi,[esi+18]
mov [pointer], esi
mov esi,[pointer]
mov [olddata+0C],esi
mov [bool],0
jmp ret
0068E099:
jmp begin
end:
olddata:
DB 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
pointer:
DB 00 00 00 00
bool:
DB 01 00 00 00
[DISABLE]
dealloc(begin)
dealloc(olddata)
dealloc(pointer)
dealloc(bool)
0068E099:
movsd
movsd
movsd
movsd
pop edi
dICE Vac
Quote:
[enable]
//dICE Vac
alloc(dICE,64)
alloc(right,4)
alloc(left,4)
registersymbol(right)
registersymbol(left)
label(return)
dICE:
pushad
mov edx, [00794CB8] //Char Pointer
mov ebx, [edx+57C] //Char X
mov ecx,[edx+580] //Char Y
add ebx, [right] //Move to Right
sub ebx, [left] //Move to Left
mov eax,[007940B0] //Wall Pointer
mov [eax+C],ebx //Left
mov [eax+14],ebx //Right
mov [eax+10],ecx //Top
mov [eax+18],ecx //Bottom
popad
mov [ebx], eax
mov edi,[ebp+10]
jmp return
right: //Set right to 0.
db 00 00
left: //Set left to 0.
db 00 00
0069222D:
jmp dICE
return:
00694B33:
db 0f 84
0068E772:
db 75
0068EA0E:
db 0f 85
[disable]
//dICE Vac
0069222D:
mov [ebx], eax
mov edi,[ebp+10]
00694B33:
db 0f 85
0068E772:
db 74
0068EA0E:
db 0f 84
dealloc(dICE)
dealloc(left)
dealloc(right)
unregistersymbol(left)
unregistersymbol(right)
unrandomizer script
Quote:
[Enable]
006E3CBD:
mov eax,0 // Change "0" to unrandomize u want from 0-3
[Disable]
006E3CBD:
and eax,00007fff
Spaciall Release! Mouse Vac!
Quote:
[ENABLE]
alloc(MouserX,512)
alloc(MouserY,512)
label(back)
label(return)
0069222D:
jmp MouserX
back:
00692292:
jmp MouserY
return:
MouserX:
mov eax,[0079526c]
mov eax,[eax+10]
mov eax,[eax+80]
mov [ebx],eax
mov edi,[ebp+10]
jmp back
MouserY:
mov eax,[0079526c]
mov eax,[eax+10]
mov eax,[eax+84]
mov [edi],eax
mov ebx,[ebp+14]
jmp return
[DISABLE]
0069222D:
mov [ebx],eax
mov edi,[ebp+10]
00692292:
mov [edi],eax
mov ebx,[ebp+14]
dealloc(MouserX)
dealloc(MouserY)
Fall Through Floor
Quote:
[enable]
00690193:
db 0f 83
[disable]
00690193:
db 0f 86
Instant Drop
Quote:
[ENABLE]
00730AC0:
add [eax], al
add [eax], al
add [eax], al
add [eax], al
[DISABLE]
00730AC0:add [eax], al
add [eax], al
add [eax-71], al
inc eax
Lag Hack
Quote:
[ENABLE]
//Lag Hack
0068E4B9:
db 75
[DISABLE]
//Lag Hack
0068E4B9:
db 74
Freeze to Crash
Quote:
[Enable]
006E3CBD:
jmp 0
[Disable]
006E3CBD:
and eax,00007fff
Suck/Tele UP
Quote:
[ENABLE]
//Suck/Tele UP
00690F01:
db 76
[DISABLE]
//Suck/Tele UP
00690F01:
db 73
Suck/tele Right
Quote:
[enable]
00690E70:
db 77
[disable]
00690E70:
db 76
Suck/tele Left
Quote:
[enable]
00690E01:
db 72
[disable]
00690E01:
db 73
Levitate + Swim •Speciall release BOT OF MAP with all jobs!!
short tut: first tick suck\tele up then tick levitate + swim and after those both
ticked, untick the suck\tele up and u stay in air with out d\c =] now use dice and bot.
Quote:
[Enable]
// Levitate for sin archer and mages
0068F87C:
db 0f 85
005571B3:
db 74 04
[Disable]
// Levitate for sin
0068F87C:
db 0f 84
005571B3:
db 73 04
suck left swim addy
Quote:
[enable]
//suck left swim addy v1
alloc(Vacem,256)
label(return)
0072F808:
jmp Vacem
return:
Vacem:
inc [00687718]
nop
nop
jmp return
[disable]
//suck left swim addy v1
0072F808:
add [eax], al
add [eax], al
add [eax], al
dealloc(Vacem)
Suck Right
Quote:
[Enable]
00694B04:
db 77
[Disable]
00694B04:
db 76
Suck Left
Quote:
[enable]
0072F807:
dd 1
[disable]
0072F807:
dd 0
PerVac
Quote:
[ENABLE]
00691050:
nop
nop
nop
nop
nop
nop
[DISABLE]
00691050:
mov ecx,[edi+00000134]
lamer Vac
Quote:
[ENABLE]
0068E566:
db 0f 85 2e 01 00 00
[DISABLE]
0068E566:
db e9 2f 01 00 00
New Release - Meso Drop!
After adding the script add address manualy
address: Amount
Descripiption Amount
Quote:
[Enable]
registersymbol(Amount)
alloc(Amount,4)
alloc(Meso,32)
Meso:
mov eax, [Amount]
mov [esi+000000bc], eax
jmp 0068b202
Amount:
db 00 00
0068B1B4:
jmp Meso
db 90
[Disable]
0068B1B4:
mov [esi+000000bc], eax
dealloc(Meso,32)
dealloc(Amount,4)
unregistersymbol(Amount)
Uber CRC\Range Uber CRC ( D\C )
Quote:
[ENABLE]
registersymbol(UberX)
registersymbol(UberY)
alloc(UberY,64)
alloc(CharY,16)
alloc(UberX,64)
alloc(CharX,16)
UberX:
call 006e3bb8
push eax
mov eax, [00794CB8]
lea eax, [eax+57C]
cmp ebx, eax
je CharX
mov eax, [eax]
// sub eax, -100 // Here
mov [ebx], eax
pop eax
jmp 0069222F
CharX:
pop eax
mov [ebx], eax
jmp 0069222F
UberY:
call 006e3bb8
push eax
mov eax, [00794CB8]
lea eax, [eax+580]
cmp edi, eax
je CharY
mov eax, [eax]
mov [edi], eax
pop eax
jmp 00692294
CharY:
pop eax
mov [edi], eax
jmp 00692294
00692228:
jmp UberX
0069228D:
jmp UberY
[DISABLE]
00692228:
call 006e3bb8
0069228D:
call 006e3bb8
unregistersymbol(UberX)
unregistersymbol(UberY)
dealloc(UberY)
dealloc(CharY)
dealloc(UberX)
dealloc(CharX)
Mouse Item Looter
Quote:
[ENABLE]
alloc(MouseItemLoot, 1024)
MouseItemLoot:
pushad
mov ecx, [ebp+8]
mov ebx, [ebp-24]
mov [ecx], ebx
mov [ecx+4], eax
mov ecx, eax
mov eax, ebx
mov ebx,[0072f16c]
mov ebx,[ebx+10]
mov eax,[ebx+80] // mouse x
mov ecx,[ebx+84] // mouse y
mov [ebp-2C], eax
mov [ebp-28], ecx
popad
push eax
push [ebp-24]
lea eax, [ebp-34]
jmp 0048F6FC
0048F6F5:
jmp MouseItemLoot
nop
nop
[DISABLE]
0048F6F5:
push EAX
push [ebp-24]
lea eax, [ebp-34]
Slow DupeX
After adding the script TICK IT and go to add address manualy
make it pointer
description: Pointer Freeze
address: Pointer
Ofset: 110
Quote:
[ENABLE]
alloc(CodeCave,32)
alloc(Pointer,32)
registersymbol(CodeCave)
registersymbol(Pointer)
label(ReturnHere)
CodeCave:
push ecx
mov ecx,Pointer
mov [ecx],esi
pop ecx
mov [esi+00000114],edi
jmp ReturnHere
00691125:
jmp CodeCave
nop
ReturnHere:
[DISABLE]
00691125:
mov [esi+00000114],edi
dealloc(CodeCave)
dealloc(Pointer)
unregistersymbol(CodeCave)
unregistersymbol(Pointer)
Timed-Dupex
Quote:
[ENABLE]
registersymbol(DX)
registersymbol(DXListOffset)
registersymbol(DXType)
alloc(DX, 1024)
alloc(DXListOffset, 4)
alloc(DXType,4)
alloc(DXFindChar, 1024)
alloc(ESIList, 1024)
alloc(EDIValue, 4)
alloc(DXMap,4)
label(CompareOffset)
label(StoreESI)
label(DoNormal)
label(LeaveMe)
label(DXMonster)
label(NoDupe)
label(DoVac)
alloc(DXCounter,4)
registersymbol(VacTime)
registersymbol(TotalTime)
alloc(VacTime,4)
alloc(TotalTime,4)
alloc(DXCounter,4)
label(DXPause)
label(DXResetCounter)
label(DXReset)
label(back)
DXCounter:
add [eax],al
add [eax],al
VacTime:
js 0ff90c16
add [eax],al
TotalTime:
or [edi],al
add [eax],al
DXCounter:
sub al,01
add [eax],al
//Original Code
DXListOffset:
add [eax],al
add [eax],al
DXType:
add [eax],al
add [eax],al
DX:
push eax
push ebx
push ecx
push edx
mov ebx,[DXType]
cmp ebx, 00 // 0 = Do Nothing
je NoDupe
cmp ebx, 01
je DXFindChar
cmp ebx, 02
je DoVac
cmp ebx, 03
je DoVac
//Modified Code
cmp ebx, 04
je DXReset
jmp DoNormal
DXFindChar:
mov [esi+114],edi
mov eax,0
mov ebx,DXListOffset
mov ecx,ESIList
mov edx,EDIValue
CompareOffset:
cmp eax,[ebx]
je StoreESI
cmp esi,[ecx+eax*4]
je LeaveMe
inc eax
jmp CompareOffset
StoreESI:
mov [ecx+eax*4],esi
inc eax
mov [ebx],eax
mov [edx],edi
DoVac:
mov eax,[DXCounter]
cmp eax,[VacTime]
inc eax
mov [DXCounter],eax
jae DXPause
//Original
mov ebx,[DXListOffset]
dec ebx
mov ecx,ESIList
mov eax,[ecx+ebx*4]
cmp esi,eax
je DoNormal
mov ebx,[DXType]
cmp ebx, 02
jne DXMonster
mov edi,[eax+114]
jmp DoNormal
DXMonster:
cmp ebx, 03
jne NoDupe
mov edi,[EDIValue]
jmp DoNormal
NoDupe:
mov ebx, 0
mov [DXListOffset],ebx
mov [DXCounter],0
DoNormal:
mov [esi+114],edi
LeaveMe:
pop edx
pop ecx
pop ebx
pop eax
jmp back
DXPause:
cmp eax,[TotalTime]
jae DXResetCounter
jmp DoNormal
DXResetCounter:
mov [DXCounter],0
jmp DoNormal
DXReset:
mov ebx, 0
mov [DXListOffset],ebx
mov [DXCounter],0
mov [DXType],1
jmp DoNormal
00691125:
jmp DX
nop
back:
[DISABLE]
00691125:
mov [esi+114],edi
dealloc(DXFindChar)
dealloc(DXListOffset)
dealloc(ESIList)
dealloc(DX)
dealloc(EDIValue)
dealloc(DXCounter)
unregistersymbol(DX)
unregistersymbol(DXListOffset)
unregistersymbol(DXType)
מנהל אח שלי עים לא יצע טוב תערוך בבקשה תודה אחי















