Fully Bypass Water Effect
——-warning——-
1- it’s an assembly CE (Cheat Engine)
meaning u gotta use auto assembler, not a lua script
2- this script needs manual updating cuz it’s not just an inject, it creates a new function and uses a pointer chain so u gotta update some stuff
a- the signatures don’t worry about them, they’re stable for now
b- the offsets u gotta make sure they’re correct, updates can change them from time to time
c- the localplayer_ptr
some call it fixedbase whatever u call it this pointer needs to be updated after each update for the script to work
u can make it automatically update
example code:
ok that’s the warning done
this script as its name suggests
when i made it i considered most situations u might face
it disables any effect water causes from start to finish, including gravity effect
even if u activate it underwater it still cancels the effect completely
of course it works in The Depths
finally enjoy it
1- it’s an assembly CE (Cheat Engine)
meaning u gotta use auto assembler, not a lua script
2- this script needs manual updating cuz it’s not just an inject, it creates a new function and uses a pointer chain so u gotta update some stuff
a- the signatures don’t worry about them, they’re stable for now
b- the offsets u gotta make sure they’re correct, updates can change them from time to time
c- the localplayer_ptr
some call it fixedbase whatever u call it this pointer needs to be updated after each update for the script to work
u can make it automatically update
example code:
Code:
// ========== OFFSETS & CONSTANTS ========== // WARNING: THESE OFFSETS MUST BE VERIFIED AFTER EACH GAME UPDATE // ALWAYS re-check these offsets whenever the game is updated or patched. // If any update changes structure/layout, these values will need to be updated. define(LOCAL_PLAYER, "Trove.exe"+11FF548) // <-- Verify this pointer after each update define(GRAVITY_VALUE, C1E80000) // -29.0 as 32-bit float bit pattern // Gravity offsets sequence // IMPORTANT: verify these offsets (G_OFFSET_1..G_OFFSET_5) after every update define(G_OFFSET_1, 8) // <-- may change after updates — re-validate define(G_OFFSET_2, 28) // <-- may change after updates — re-validate define(G_OFFSET_3, C4) // <-- may change after updates — re-validate define(G_OFFSET_4, 4) // <-- may change after updates — re-validate define(G_OFFSET_5, D8) // <-- may change after updates — re-validate // Water effect offsets sequence // IMPORTANT: verify these offsets (W_OFFSET_1..W_OFFSET_5) after every update define(W_OFFSET_1, 8) // <-- may change after updates — re-validate define(W_OFFSET_2, 28) // <-- may change after updates — re-validate define(W_OFFSET_3, C4) // <-- may change after updates — re-validate define(W_OFFSET_4, 64) // <-- may change after updates — re-validate define(W_OFFSET_5, 190) // <-- may change after updates — re-validate
this script as its name suggests
when i made it i considered most situations u might face
it disables any effect water causes from start to finish, including gravity effect
even if u activate it underwater it still cancels the effect completely
of course it works in The Depths
finally enjoy it
Fully Bypass Water Effect
Code:
[ENABLE]
// Anti-water: Simplified Professional Version
// ===== AOB SCAN SIGNATURES =====
// Note: These are the patterns used to find injection points in the module.
// Keep the anti_norm order: anti_norm1, anti_norm2, anti_norm3 (this order is required)
aobscanmodule(anti_norm1, Trove.exe, 3B B7 90 01 00 00 74 08)
aobscanmodule(anti_norm2, Trove.exe, F3 0F 11 4A 18 52 8B 01 FF 50 04 8B 4E 58 XX BE)
aobscanmodule(anti_norm3, Trove.exe, F3 0F 11 4A 18 52 8B 01 FF 50 04 E9)
// Allocate codecave (only used for anti_norm3) and a one-byte flag storage
alloc(codecave, 0x200)
alloc(alloc_addr, 1)
registersymbol(alloc_addr)
// ========== OFFSETS & CONSTANTS ==========
// WARNING: THESE OFFSETS MUST BE VERIFIED AFTER EACH GAME UPDATE
// ALWAYS re-check these offsets whenever the game is updated or patched.
// If any update changes structure/layout, these values will need to be updated.
define(LOCAL_PLAYER, "Trove.exe"+11FF548) // <-- Verify this pointer after each update
define(GRAVITY_VALUE, C1E80000) // -29.0 as 32-bit float bit pattern
// Gravity offsets sequence
// IMPORTANT: verify these offsets (G_OFFSET_1..G_OFFSET_5) after every update
define(G_OFFSET_1, 8) // <-- may change after updates — re-validate
define(G_OFFSET_2, 28) // <-- may change after updates — re-validate
define(G_OFFSET_3, C4) // <-- may change after updates — re-validate
define(G_OFFSET_4, 4) // <-- may change after updates — re-validate
define(G_OFFSET_5, D8) // <-- may change after updates — re-validate
// Water effect offsets sequence
// IMPORTANT: verify these offsets (W_OFFSET_1..W_OFFSET_5) after every update
define(W_OFFSET_1, 8) // <-- may change after updates — re-validate
define(W_OFFSET_2, 28) // <-- may change after updates — re-validate
define(W_OFFSET_3, C4) // <-- may change after updates — re-validate
define(W_OFFSET_4, 64) // <-- may change after updates — re-validate
define(W_OFFSET_5, 190) // <-- may change after updates — re-validate
// ========== LABELS ==========
label(write_zero)
label(skip_write)
label(water_effect)
label(restore_registers)
label(return_addr)
label(original_code)
alloc_addr:
db 00 // one-byte flag used to record whether gravity write was done
// ========== CODECAVE (used only by anti_norm3) ==========
// codecave performs:
// 1) follow the gravity pointer chain from LOCAL_PLAYER and, if valid, write GRAVITY_VALUE (-29.0) once
// 2) follow the water-effect pointer chain from LOCAL_PLAYER and write 0 to remove water effect
// 3) maintain a one-byte flag at alloc_addr to avoid repeated writes
// 4) preserve registers and jump back to original code (return_addr)
// NOTES:
// - codecave is intentionally only hooked to anti_norm3
// - anti_norm1 and anti_norm2 are simple byte edits (see injection points below)
// - Always validate the pointer chain offsets after updates to the game
codecave:
// Save registers we will clobber
push edi
push eax
push edx
push ecx
push esi
// Get the LOCAL_PLAYER pointer
mov esi, LOCAL_PLAYER
test esi, esi
je write_zero // nothing valid: fallback
mov esi, [esi]
test esi, esi
je write_zero
// Follow gravity pointer chain (sequence of offsets)
add esi, G_OFFSET_1
test esi, esi
je write_zero
mov esi, [esi]
test esi, esi
je write_zero
add esi, G_OFFSET_2
test esi, esi
je write_zero
mov esi, [esi]
test esi, esi
je write_zero
add esi, G_OFFSET_3
test esi, esi
je write_zero
mov esi, [esi]
test esi, esi
je write_zero
add esi, G_OFFSET_4
test esi, esi
je write_zero
mov esi, [esi]
test esi, esi
je write_zero
add esi, G_OFFSET_5
// At this point ESI should point to the gravity float location
// Verify the target isn't the same as the current write target from the original instruction
mov edx, [esp+8] // edx was pushed earlier; [esp+8] corresponds to saved edx in original context
lea eax, [edx+18] // compute the address that original code targets (movss [edx+18], xmm1)
cmp eax, esi
je skip_write // if same address, skip writing gravity
// Check the one-byte flag in alloc_addr to avoid repeated writing
mov al, [alloc_addr]
test al, al
jne water_effect // if flag != 0 then we've already written gravity before -> skip to water effect
// Write the gravity float (-29.0) to the gravity location
mov [esi], GRAVITY_VALUE
mov byte [alloc_addr], 1 // set the flag to record that we wrote gravity
water_effect:
// Remove water effect by following the water pointer chain and writing 0
mov edi, LOCAL_PLAYER
test edi, edi
je restore_registers
mov edi, [edi]
test edi, edi
je restore_registers
// Follow water effect pointer chain
add edi, W_OFFSET_1
test edi, edi
je restore_registers
mov edi, [edi]
test edi, edi
je restore_registers
add edi, W_OFFSET_2
test edi, edi
je restore_registers
mov edi, [edi]
test edi, edi
je restore_registers
add edi, W_OFFSET_3
test edi, edi
je restore_registers
mov edi, [edi]
test edi, edi
je restore_registers
add edi, W_OFFSET_4
test edi, edi
je restore_registers
mov edi, [edi]
test edi, edi
je restore_registers
add edi, W_OFFSET_5
test edi, edi
je restore_registers
mov [edi], 0 // clear the water-effect value
restore_registers:
// Restore registers in reverse order
pop esi
pop ecx
pop edx
pop eax
pop edi
original_code:
// Original instruction the game had at the injection site:
// movss [edx+18], xmm1
// Jump back to the original return address afterwards
movss [edx+18], xmm1
jmp return_addr
skip_write:
// Skip gravity write but still restore registers and return
pop esi
pop ecx
pop edx
pop eax
pop edi
jmp return_addr
write_zero:
// Reset the one-byte flag (alloc_addr) if we couldn't complete pointer chain
// This ensures that if the pointer becomes valid later, gravity can be written again once.
mov byte [alloc_addr], 0
pop esi
pop ecx
pop edx
pop eax
pop edi
jmp original_code
// ========== INJECTION POINTS ==========
// anti_norm3 - jump into codecave (codecave is dedicated to anti_norm3 only)
anti_norm3:
jmp codecave
return_addr:
// anti_norm1 - normal byte edit (simple patch)
// Here we replace the original bytes with: 90 90 90 90 90 90 74 08
// This is a simple inline byte change (no codecave hook).
anti_norm1:
db 90 90 90 90 90 90 74 08
// anti_norm2 - normal byte edit (change movss write to movss read)
// We change the original opcode from F3 0F 11 (write movss) to F3 0F 10 (read movss)
// NOTE: this is a single-byte opcode change area. Validate correctness and size.
anti_norm2:
db F3 0F 10 // changed from F3 0F 11 (write) to F3 0F 10 (read)
// ========== DISABLE (restore originals) ==========
[DISABLE]
// restore anti_norm3 original bytes (must match exactly bytes you overwrote in ENABLE)
anti_norm3:
db F3 0F 11 4A 18 52 8B 01 FF 50 04 E9
// restore anti_norm1 original bytes
anti_norm1:
db 3B B7 90 01 00 00 74 08
// restore anti_norm2 original bytes (restore movss write opcode)
anti_norm2:
db F3 0F 11
// now free allocations
dealloc(codecave)
dealloc(alloc_addr)
// unregister any symbols you registered
unregistersymbol(alloc_addr)
unregistersymbol(anti_norm1) // only if you called registersymbol(anti_norm1) in ENABLE
unregistersymbol(anti_norm2) // same here
unregistersymbol(anti_norm3) // same here
