PostFully Bypass Water Effect

Posts 1–5 of 5 · Page 1 of 1
Fully Bypass Water Effect
——-warning——-
1- it’s an assembly CE (Cheat Engine)
meaning u gotta use auto assembler, not a lua script

2- this script needs manual updating cuz it’s not just an inject, it creates a new function and uses a pointer chain so u gotta update some stuff
a- the signatures don’t worry about them, they’re stable for now
b- the offsets u gotta make sure they’re correct, updates can change them from time to time
c- the localplayer_ptr
some call it fixedbase whatever u call it this pointer needs to be updated after each update for the script to work
u can make it automatically update
example code:
Code:
// ========== OFFSETS & CONSTANTS ==========
// WARNING: THESE OFFSETS MUST BE VERIFIED AFTER EACH GAME UPDATE
// ALWAYS re-check these offsets whenever the game is updated or patched.
// If any update changes structure/layout, these values will need to be updated.

define(LOCAL_PLAYER, "Trove.exe"+11FF548)    // <-- Verify this pointer after each update
define(GRAVITY_VALUE, C1E80000)               // -29.0 as 32-bit float bit pattern

// Gravity offsets sequence
// IMPORTANT: verify these offsets (G_OFFSET_1..G_OFFSET_5) after every update
define(G_OFFSET_1, 8)     // <-- may change after updates — re-validate
define(G_OFFSET_2, 28)    // <-- may change after updates — re-validate
define(G_OFFSET_3, C4)    // <-- may change after updates — re-validate
define(G_OFFSET_4, 4)     // <-- may change after updates — re-validate
define(G_OFFSET_5, D8)    // <-- may change after updates — re-validate

// Water effect offsets sequence
// IMPORTANT: verify these offsets (W_OFFSET_1..W_OFFSET_5) after every update
define(W_OFFSET_1, 8)     // <-- may change after updates — re-validate
define(W_OFFSET_2, 28)    // <-- may change after updates — re-validate
define(W_OFFSET_3, C4)    // <-- may change after updates — re-validate
define(W_OFFSET_4, 64)    // <-- may change after updates — re-validate
define(W_OFFSET_5, 190)   // <-- may change after updates — re-validate
ok that’s the warning done
this script as its name suggests
when i made it i considered most situations u might face
it disables any effect water causes from start to finish, including gravity effect
even if u activate it underwater it still cancels the effect completely

of course it works in The Depths
finally enjoy it

 
Fully Bypass Water Effect
Code:
[ENABLE]
// Anti-water: Simplified Professional Version

// ===== AOB SCAN SIGNATURES =====
// Note: These are the patterns used to find injection points in the module.
// Keep the anti_norm order: anti_norm1, anti_norm2, anti_norm3 (this order is required)

aobscanmodule(anti_norm1, Trove.exe, 3B B7 90 01 00 00 74 08)
aobscanmodule(anti_norm2, Trove.exe, F3 0F 11 4A 18 52 8B 01 FF 50 04 8B 4E 58 XX BE)
aobscanmodule(anti_norm3, Trove.exe, F3 0F 11 4A 18 52 8B 01 FF 50 04 E9)

// Allocate codecave (only used for anti_norm3) and a one-byte flag storage
alloc(codecave, 0x200)
alloc(alloc_addr, 1)

registersymbol(alloc_addr)

// ========== OFFSETS & CONSTANTS ==========
// WARNING: THESE OFFSETS MUST BE VERIFIED AFTER EACH GAME UPDATE
// ALWAYS re-check these offsets whenever the game is updated or patched.
// If any update changes structure/layout, these values will need to be updated.

define(LOCAL_PLAYER, "Trove.exe"+11FF548)    // <-- Verify this pointer after each update
define(GRAVITY_VALUE, C1E80000)               // -29.0 as 32-bit float bit pattern

// Gravity offsets sequence
// IMPORTANT: verify these offsets (G_OFFSET_1..G_OFFSET_5) after every update
define(G_OFFSET_1, 8)     // <-- may change after updates — re-validate
define(G_OFFSET_2, 28)    // <-- may change after updates — re-validate
define(G_OFFSET_3, C4)    // <-- may change after updates — re-validate
define(G_OFFSET_4, 4)     // <-- may change after updates — re-validate
define(G_OFFSET_5, D8)    // <-- may change after updates — re-validate

// Water effect offsets sequence
// IMPORTANT: verify these offsets (W_OFFSET_1..W_OFFSET_5) after every update
define(W_OFFSET_1, 8)     // <-- may change after updates — re-validate
define(W_OFFSET_2, 28)    // <-- may change after updates — re-validate
define(W_OFFSET_3, C4)    // <-- may change after updates — re-validate
define(W_OFFSET_4, 64)    // <-- may change after updates — re-validate
define(W_OFFSET_5, 190)   // <-- may change after updates — re-validate

// ========== LABELS ==========
label(write_zero)
label(skip_write)
label(water_effect)
label(restore_registers)
label(return_addr)
label(original_code)

alloc_addr:
db 00    // one-byte flag used to record whether gravity write was done

// ========== CODECAVE (used only by anti_norm3) ==========
// codecave performs:
// 1) follow the gravity pointer chain from LOCAL_PLAYER and, if valid, write GRAVITY_VALUE (-29.0) once
// 2) follow the water-effect pointer chain from LOCAL_PLAYER and write 0 to remove water effect
// 3) maintain a one-byte flag at alloc_addr to avoid repeated writes
// 4) preserve registers and jump back to original code (return_addr)
// NOTES:
// - codecave is intentionally only hooked to anti_norm3
// - anti_norm1 and anti_norm2 are simple byte edits (see injection points below)
// - Always validate the pointer chain offsets after updates to the game

codecave:
    // Save registers we will clobber
    push edi
    push eax
    push edx
    push ecx
    push esi

    // Get the LOCAL_PLAYER pointer
    mov esi, LOCAL_PLAYER
    test esi, esi
    je write_zero          // nothing valid: fallback

    mov esi, [esi]
    test esi, esi
    je write_zero

    // Follow gravity pointer chain (sequence of offsets)
    add esi, G_OFFSET_1
    test esi, esi
    je write_zero
    mov esi, [esi]
    test esi, esi
    je write_zero

    add esi, G_OFFSET_2
    test esi, esi
    je write_zero
    mov esi, [esi]
    test esi, esi
    je write_zero

    add esi, G_OFFSET_3
    test esi, esi
    je write_zero
    mov esi, [esi]
    test esi, esi
    je write_zero

    add esi, G_OFFSET_4
    test esi, esi
    je write_zero
    mov esi, [esi]
    test esi, esi
    je write_zero

    add esi, G_OFFSET_5
    // At this point ESI should point to the gravity float location

    // Verify the target isn't the same as the current write target from the original instruction
    mov edx, [esp+8]       // edx was pushed earlier; [esp+8] corresponds to saved edx in original context
    lea eax, [edx+18]      // compute the address that original code targets (movss [edx+18], xmm1)
    cmp eax, esi
    je skip_write          // if same address, skip writing gravity

    // Check the one-byte flag in alloc_addr to avoid repeated writing
    mov al, [alloc_addr]
    test al, al
    jne water_effect       // if flag != 0 then we've already written gravity before -> skip to water effect

    // Write the gravity float (-29.0) to the gravity location
    mov [esi], GRAVITY_VALUE
    mov byte [alloc_addr], 1    // set the flag to record that we wrote gravity

water_effect:
    // Remove water effect by following the water pointer chain and writing 0
    mov edi, LOCAL_PLAYER
    test edi, edi
    je restore_registers
    mov edi, [edi]
    test edi, edi
    je restore_registers

    // Follow water effect pointer chain
    add edi, W_OFFSET_1
    test edi, edi
    je restore_registers
    mov edi, [edi]
    test edi, edi
    je restore_registers

    add edi, W_OFFSET_2
    test edi, edi
    je restore_registers
    mov edi, [edi]
    test edi, edi
    je restore_registers

    add edi, W_OFFSET_3
    test edi, edi
    je restore_registers
    mov edi, [edi]
    test edi, edi
    je restore_registers

    add edi, W_OFFSET_4
    test edi, edi
    je restore_registers
    mov edi, [edi]
    test edi, edi
    je restore_registers

    add edi, W_OFFSET_5
    test edi, edi
    je restore_registers

    mov [edi], 0     // clear the water-effect value

restore_registers:
    // Restore registers in reverse order
    pop esi
    pop ecx
    pop edx
    pop eax
    pop edi

original_code:
    // Original instruction the game had at the injection site:
    // movss [edx+18], xmm1
    // Jump back to the original return address afterwards
    movss [edx+18], xmm1
    jmp return_addr

skip_write:
    // Skip gravity write but still restore registers and return
    pop esi
    pop ecx
    pop edx
    pop eax
    pop edi
    jmp return_addr

write_zero:
    // Reset the one-byte flag (alloc_addr) if we couldn't complete pointer chain
    // This ensures that if the pointer becomes valid later, gravity can be written again once.
    mov byte [alloc_addr], 0
    pop esi
    pop ecx
    pop edx
    pop eax
    pop edi
    jmp original_code

// ========== INJECTION POINTS ==========
 // anti_norm3 - jump into codecave (codecave is dedicated to anti_norm3 only)
anti_norm3:
    jmp codecave
return_addr:

 // anti_norm1 - normal byte edit (simple patch)
 // Here we replace the original bytes with: 90 90 90 90 90 90 74 08
 // This is a simple inline byte change (no codecave hook).
anti_norm1:
    db 90 90 90 90 90 90 74 08

 // anti_norm2 - normal byte edit (change movss write to movss read)
 // We change the original opcode from F3 0F 11 (write movss) to F3 0F 10 (read movss)
 // NOTE: this is a single-byte opcode change area. Validate correctness and size.
anti_norm2:
    db F3 0F 10    // changed from F3 0F 11 (write) to F3 0F 10 (read)

// ========== DISABLE (restore originals) ==========
[DISABLE]
// restore anti_norm3 original bytes (must match exactly bytes you overwrote in ENABLE)
anti_norm3:
    db F3 0F 11 4A 18 52 8B 01 FF 50 04 E9

// restore anti_norm1 original bytes
anti_norm1:
    db 3B B7 90 01 00 00 74 08

// restore anti_norm2 original bytes (restore movss write opcode)
anti_norm2:
    db F3 0F 11

// now free allocations
dealloc(codecave)
dealloc(alloc_addr)

// unregister any symbols you registered
unregistersymbol(alloc_addr)
unregistersymbol(anti_norm1)   // only if you called registersymbol(anti_norm1) in ENABLE
unregistersymbol(anti_norm2)   // same here
unregistersymbol(anti_norm3)   // same here
hello, how you get "C1E80000"?;
"define(GRAVITY_VALUE, C1E80000)"
i was thinking it was a encryption code from the gravity value (like you do whit the speed hack)
but its not, so you care about showing what that is?

nvm, i had not understood this: "-29.0 as 32-bit float bit pattern"
great job!
why not reference the one that found it?
copy pasted the function itself from another mpgh thread and not even mentioning their name? Crazy gaming over here
Quote Originally Posted by TheRealTrovian View Post
copy pasted the function itself from another mpgh thread and not even mentioning their name? Crazy gaming over here
why not posting it yourself?
Quote Originally Posted by TheRealTrovian View Post
copy pasted the function itself from another mpgh thread and not even mentioning their name? Crazy gaming over here
how did u find me lol
i never saw someone make smth like it
there’s a guy who made smth simple but it’s diff from mine
or u want me next time to just say i made it so u be sure
Posts 1–5 of 5 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?