BMWROCKS
4th October 2009, 16:22
HOPE THIS SHIT GETS PATCHED. ENJOY GUYS. i INTIALLY WAS GOING TO GIVE IT TO SUM1, BUT THEN, I WAS LIKE OWELL, I NEED A BIGGER E-PENOR, SO YEAH
βΩπρ
4th October 2009, 16:42
2 ppl already released the reset script, so it doesnt matter anyway.
ostespiseren
4th October 2009, 16:49
LOL! LOLOLOLOLOLOLOLOLOLOLOLOLLO, Fail.
aniq420
4th October 2009, 16:54
Phail
it prob. a virus 1st post aswell >:(
Ant3
4th October 2009, 17:10
I hope it's a virus that sezabi doesn't find, AND a script so the leecher will get infected and the hack will hopefully get patched.
kiquu
4th October 2009, 17:39
cant download need to wait for moderator pff :(:(
Šěžăbĭ
4th October 2009, 17:49
This is a CE trainer + a keylogger. It has some nice scripts though.
They are
[enable]
alloc(nodelay,128)
alloc(counter,4)
label(reset)
label(return)
nodelay:
inc [counter]
cmp [counter],4
jge 00674d55 // get from nodelay opcode
jmp 00674d35 // 56 8b cb e8 ? ? ? ? eb ? ff b3 ? ? ? ? e8
reset:
call 007d918a // get from reset opcode
mov [counter],0
jmp return
007D74C7: // e8 ? ? ? ? e9 ? ? ? ? ff 75 ? 8b ? ? ff ? ? ff
jmp reset
return:
00674CE1: // 7f ? 8b 83 ? ? ? ? 48 74 ? 48 75 ? 8b c6
jmp nodelay
db 90 90 90 90
[disable]
007D74C7:
call 007d918a
00674CE1:
jg 00674d55
mov eax,[ebx+000000b4]
dealloc(nodelay)
dealloc(counter)
[enable]
//Stupid mobs.
0081A7B3: // 75 1a 6a ? 89 10 8b 44 24 ? 57 81 c6 ? ? ? ? 56 89 01
db 74
[disable]
0081A7B3:
db 75
[enable]
alloc(MouseFlyX,512)
label(MouseFlyY)
label(ReturnX)
label(ReturnY)
label(NormalX)
label(NormalY)
MouseFlyX:
push ecx
mov ecx,[00998edc]
mov ecx,[ecx+e88]
cmp ecx,esi
pop ecx
jne NormalX
mov eax,[00999298]
mov eax,[eax+978]
mov eax,[eax+80]
NormalX:
mov [ebx],eax
mov edi,[ebp+10]
jmp ReturnX
MouseFlyY:
push ecx
mov ecx,[00998edc]
mov ecx,[ecx+e88]
cmp ecx,esi
pop ecx
jne NormalY
mov eax,[00999298]
mov eax,[eax+978]
mov eax,[eax+84]
NormalY:
mov [edi],eax
mov ebx,[ebp+14]
jmp ReturnY
008185E8:
jmp MouseFlyX
ReturnX:
0081864D:
jmp MouseFlyY
ReturnY:
[disable]
008185E8:
mov [ebx],eax
mov edi,[ebp+10]
0081864D:
mov [edi],eax
mov ebx,[ebp+14]
[enable]
// eMS uEMI (unknowN- dEMI)
// They obfuscated the dEMI address, this does the
// same effect as dEMI, with a different method.
alloc(VacX,512)
alloc(Range,04)
label(VacY)
label(NextMobX)
label(NextMobY)
label(ReturnX)
label(ReturnY)
label(NormalX)
label(NormalY)
Range:
db 30
VacX:
push ecx
push edx
mov ecx,[00998edc] // char ptr
mov ecx,[ecx+e88] // pID offset
cmp ecx,esi
jne NormalX
mov ecx,[00998eec] // mob count base
mov ecx,[ecx+28] // mob count offset + 4
cmp ecx,0
je NormalX
sub ecx,10
mov edx,ecx
NextMobX:
mov ecx,[edx+14]
mov edx,[edx+4]
add eax,[Range]
mov [ecx+4a0],eax // mob x offset
sub eax,[Range]
cmp edx,0
jne NextMobX
NormalX:
pop edx
pop ecx
mov [ebx],eax
mov edi,[ebp+10]
jmp ReturnX
// ---------------------------------------------
VacY:
push ecx
push edx
mov ecx,[00998edc]
mov ecx,[ecx+e88]
cmp ecx,esi
jne NormalY
mov ecx,[00998eec]
mov ecx,[ecx+28]
cmp ecx,0
je NormalY
sub ecx,10
mov edx,ecx
NextMobY:
mov ecx,[edx+14]
mov [ecx+4a4],eax
mov edx,[edx+4]
cmp edx,0
jne NextMobY
NormalY:
pop edx
pop ecx
mov [edi],eax
mov ebx,[ebp+14]
jmp ReturnY
// ---------------------------------------------
008185E8:
jmp VacX
ReturnX:
0081864D:
jmp VacY
ReturnY:
[disable]
008185E8:
mov [ebx],eax
mov edi,[ebp+10]
0081864D:
mov [edi],eax
mov ebx,[ebp+14]
dealloc(VacX)
dealloc(Range)
[enable]
//cseax under
alloc(VacX,512)
label(VacY)
label(ReturnX)
label(ReturnY)
label(NormalX)
label(NormalY)
VacX:
push ecx
mov ecx,[00998edc]
mov ecx,[ecx+e88]
cmp ecx,esi
pop ecx
je NormalX
mov eax,[00998edc]
mov eax,[eax+e50]
add eax,0
NormalX:
mov [ebx],eax
mov edi,[ebp+10]
jmp ReturnX
VacY:
push ecx
mov ecx,[00998edc]
mov ecx,[ecx+e88]
cmp ecx,esi
pop ecx
je NormalY
mov eax,[00998edc]
mov eax,[eax+e54]
add eax,50
NormalY:
mov [edi],eax
mov ebx,[ebp+14]
jmp ReturnY
008185E8:
jmp VacX
ReturnX:
0081864D:
jmp VacY
ReturnY:
[disable]
008185E8:
mov [ebx],eax
mov edi,[ebp+10]
0081864D:
mov [edi],eax
mov ebx,[ebp+14]
dealloc(VacX)
[enable]
// dEMI UP
// eMS uEMI (unknowN- dEMI)
// They obfuscated the dEMI address, this does the
// same effect as dEMI, with a different method.
alloc(VacX,512)
alloc(Range,04)
label(VacY)
label(NextMobX)
label(NextMobY)
label(ReturnX)
label(ReturnY)
label(NormalX)
label(NormalY)
Range:
db 70
VacX:
push ecx
push edx
mov ecx,[00998edc] // char ptr
mov ecx,[ecx+e88] // pID offset
cmp ecx,esi
jne NormalX
mov ecx,[00998eec] // mob count base
mov ecx,[ecx+28] // mob count offset + 4
cmp ecx,0
je NormalX
sub ecx,10
mov edx,ecx
NextMobX:
mov ecx,[edx+14]
mov edx,[edx+4]
mov [ecx+4a0],eax // mob x offset
cmp edx,0
jne NextMobX
NormalX:
pop edx
pop ecx
mov [ebx],eax
mov edi,[ebp+10]
jmp ReturnX
// ---------------------------------------------
VacY:
push ecx
push edx
mov ecx,[00998edc]
mov ecx,[ecx+e88]
cmp ecx,esi
jne NormalY
mov ecx,[00998eec]
mov ecx,[ecx+28]
cmp ecx,0
je NormalY
sub ecx,10
mov edx,ecx
NextMobY:
mov ecx,[edx+14]
mov edx,[edx+4]
sub eax,[Range]
mov [ecx+4a4],eax
add eax,[Range]
cmp edx,0
jne NextMobY
NormalY:
pop edx
pop ecx
mov [edi],eax
mov ebx,[ebp+14]
jmp ReturnY
// ---------------------------------------------
008185E8:
jmp VacX
ReturnX:
0081864D:
jmp VacY
ReturnY:
[disable]
008185E8:
mov [ebx],eax
mov edi,[ebp+10]
0081864D:
mov [edi],eax
mov ebx,[ebp+14]
dealloc(VacX)
dealloc(Range)
[Enable]
//Blink GodMode
007A98BF: //83 EF 1E 57 8D 8B 14 19 00 00 E8 AF 56 C7 FF 3B
add edi,1e
[Disable]
007A98BF: //83 EF 1E 57 8D 8B 14 19 00 00 E8 AF 56 C7 FF 3B
sub edi,1e
There's also a comment - Demi(UP) only works with lvl 100 summon.
Powered by vBulletin™ Version 4.0.2 Copyright © 2010 vBulletin Solutions, Inc. All rights reserved.