D3D hack + memory addresses

08/04/2010 22:53 Jamboo#1
I wanted to keep these addresses as my own personal secret, but I haven't played BOI for months so I guess it doesn't matter if I release them or not.
Finding useful hacks takes dozens of hours of working, cuz most of what I've tried haven't worked.
Also it took me the same time to find these memory addresses.
Every address should work fine with the latest version of the client.

Here's the current addresses, pointers and offsets i've found so far:
Code:
int Off_Player_HP = 0x13F4;
int Off_Player_MaxHP = 0x13F8;
int Off_Player_MP = 0x13FC;
int Off_Player_MaxMP = 0x1400;
int Off_Player_XP = 0x1404;
int Off_Player_MaxXP = 0x1408;
int Off_Player_Name = 0x288;
int Off_Player_Mounted = 0x17C;
int Off_Player_X = 0xA8;
int Off_Player_Y = 0xAC;
int Off_Player_Speed = 0x574C;
int Off_Player_Moving = 0x924;

int Addr_Player_Coins = 0x00E60968;
int Addr_Player_Credit = 0x00E60978;
int Addr_Player_Salary = 0x00E60970;
int Addr_Player_Level = 0x00E607F8;
int Addr_Player_Attacking = 0x00B34EA4;
int Addr_Player_EXP = 0x00E60800;
int Addr_Player_MaxEXP = 0x00E609F8;
int Addr_Player_MapID = 0x00B34FB0;
int Addr_Player_Mounted2 = 0x010A05EC;
int Addr_Player_X2 = 0x00B34E30;
int Addr_Player_Y2 = 0x00B34E34;

int Off_Target_HP = 0x13F4;
int Off_Target_Mounted = 0x17C;
int Off_Target_X = 0xA8;
int Off_Target_Y = 0xAC;
int Off_Target_Speed = 0x574C;
int Off_Target_Moving = 0x924;
int Off_Target_DestX = 0x8B0;
int Off_Target_DestY = 0x8B4;

int Addr_Target_X2 = 0x0173E598;
int Addr_Target_Y2 = 0x0173E59C;
int Addr_Target_HP2 = 0x01090E0C;
int Addr_Target_IsMob = 0x0108FF34;

int Addr_Misc_ShopOpen = 0x01222DDC;
int Addr_Misc_WpnDur = 0x013CA098;

int Addr_Route_NextTurnX = 0x0173E854;
int Addr_Route_NextTurnY = 0x0173E858;
int Addr_Route_TurnsMade = 0x00E5662C;
int Addr_Route_DestX = 0x00E56668;
int Addr_Route_DestY = 0x00E5666C;
int Addr_Route_DestMapID = 0x00E56664;

int Addr_Settings_ChatInputAmnt = 0x015573F0;

int Addr_Loadmap_ID = 0x011FBF20;
int Addr_Loadmap_X = 0x011FBF44;
int Addr_Loadmap_X2 = 0x011FBF34;
int Addr_Loadmap_Y = 0x011FBF48;
int Addr_Loadmap_Y2 = 0x011FBF38;

int Addr_Camera_Zoom = 0x024DD720;
int Addr_Camera_MaxZoom = 0x024DD768;
int Addr_Camera_MinZoom = 0x024DD770;
int Addr_Camera_ZoomSmthns = 0x024DD760;
int Addr_Camera_Height = 0x024DD77C;
int Addr_Camera_Angle = 0x024DD6FC;
int Addr_Camera_Turning = 0x024DD6AC;

Let me know about the errors and stuff, thanks :)



Here's my D3D hack that has many bugs (along with PerX Injector).
Features:
Speedhack - works just fine with a +45% speed mount, if you have a slower one, don't use mounts while speedhacking
Teleport to Target - Teleports you to the target
Teleport Target - Teleports the target to you
Target Follows Me - Makes the target follow you
Target Speedhack - Makes the target faster
Teleport - Teleports to the destination (click on ground or map)(too far distances makes it teleport back)
Chat Text Width - Allows you to type 180 characters instead of 60 in the chat
First Person Mode - Play from the first person camera angle
Further Camera - Allows you to zoom the camera way further

(I'm not able to use virustotal at the moment, but you can check it if you don't trust me)

A combination of Target Speedhack, Target Follows Me and Speedhack makes farming/botting much faster. :)
Teleport Target makes it even faster, but sometimes you are not able to attack the target after teleporting it.

[Only registered and activated users can see links. Click Here To Register...]

First start the client and then inject the DLL. Press insert to toggle the menu. Do not make it autoinject on the process, or the client will crash on the startup.
If you don't know how to use an injectors, hacks arent for you.
08/05/2010 08:55 h1dan#2
how to start it first client than D3D or?
08/05/2010 09:36 jonkimchi#3
No directions ? :X
sorry, i know you have to inject but is there an option menu or wha?
08/05/2010 09:53 zlost1#4
the exe file doesnt extract from the archive. only the dll does
08/05/2010 10:40 zlost1#5
McAfee anti virus reports the exe as a back door trojan
08/05/2010 10:44 zlost1#6
Antivirus Version Last Update Result
AhnLab-V3 2010.08.05.03 2010.08.05 Backdoor/Win32.Poison
AntiVir 8.2.4.32 2010.08.04 SPR/Tool.inj.268800
Antiy-AVL 2.0.3.7 2010.08.03 Backdoor/Win32.Poison.gen
Authentium 5.2.0.5 2010.08.05 W32/MalwareS.BACP
Avast 4.8.1351.0 2010.08.04 -
Avast5 5.0.332.0 2010.08.04 -
AVG 9.0.0.851 2010.08.04 BackDoor.Generic12.BAKF
BitDefender 7.2 2010.08.05 -
CAT-QuickHeal 11.00 2010.08.05 Trojan.Agent.ATV
ClamAV 0.96.0.3-git 2010.08.05 Trojan.Poison-595
Comodo 5652 2010.08.05 ApplicUnwnt.Win32.ToolInj.2688000
DrWeb 5.0.2.03300 2010.08.05 BackDoor.Poison.2753
Emsisoft 5.0.0.36 2010.08.05 Backdoor.Win32.Poison!IK
eSafe 7.0.17.0 2010.08.04 -
eTrust-Vet 36.1.7767 2010.08.05 Win32/Poison.DZ
F-Prot 4.6.1.107 2010.08.05 W32/MalwareS.BACP
F-Secure 9.0.15370.0 2010.08.05 -
Fortinet 4.1.143.0 2010.08.05 HackerTool/X1nject
GData 21 2010.08.05 -
Ikarus T3.1.1.84.0 2010.08.05 337312 'Backdoor.Win32.Poison
Jiangmin 13.0.900 2010.08.03 Backdoor/Poison.err
Kaspersky 7.0.0.125 2010.08.05 Backdoor.Win32.Poison.aylh
McAfee 5.400.0.1158 2010.08.05 Generic BackDoor!bgb
McAfee-GW-Edition 2010.1 2010.08.05 Generic BackDoor!bgb
Microsoft 1.6004 2010.08.05 Backdoor:Win32/Poison.AR
NOD32 5341 2010.08.04 probably a variant of Win32/Agent
Norman 6.05.11 2010.08.04 W32/Suspicious_Gen2.CCX
nProtect 2010-08-04.01 2010.08.04 -
Panda 10.0.2.7 2010.08.04 Bck/Poison.F
PCTools 7.0.3.5 2010.08.04 Backdoor.Trojan
Prevx 3.0 2010.08.05 High Risk Worm
Rising 22.59.03.04 2010.08.05 -
Sophos 4.56.0 2010.08.05 Mal/Generic-A
Sunbelt 6687 2010.08.05 Trojan.Win32.Generic!BT
SUPERAntiSpyware 4.40.0.1006 2010.08.05 -
Symantec 20101.1.1.7 2010.08.05 Backdoor.Trojan
TheHacker 6.5.2.1.332 2010.08.05 Backdoor/Poison.aylh
TrendMicro 9.120.0.1004 2010.08.05 -
TrendMicro-HouseCall 9.120.0.1004 2010.08.05 -
VBA32 3.12.12.8 2010.08.04 Backdoor.Win32.Poison.axpt
ViRobot 2010.8.4.3971 2010.08.05 Backdoor.Win32.Poison.268800
VirusBuster 5.0.27.0 2010.08.04 Backdoor.Poison.WKF
Additional information
File size: 222002 bytes
MD5...: 5e60d5e1c19f8b01d6dd9d12435b8265
SHA1..: e726f3911dd968cb27b47da43a24b8922a45cbe7
SHA256: 666a2623b7b37c5fd78f2aed86beb1433aaf529a97f7934744 ace26b17e273ca
ssdeep: 3072:iGm2g/fLZK+oxMBRMjvmYEaW0xw1+JFFUHwaAnSbVmBP82FK2xD3XkEb LYe
c6aVk:iGxg/fxoXmD0xwMPBn2282xDkikeeSB
PEiD..: -
PEInfo: -
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: ZIP compressed archive (100.0%)
Symantec Reputation Network: Suspicious.Insight [Only registered and activated users can see links. Click Here To Register...]
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
<a href='http://info.prevx.com/aboutprogramtext.asp?PX5=695DCB4C002D05B71A32046EA B01D800B507D705' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=695DCB4C002D05B71A32046EA B01D800B507D705</a>

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
08/05/2010 11:48 blackmorpheus#7
Very nice hack, teleport however is very buggy.
The hacks aren't very useful.
Made this myself:
[Only registered and activated users can see links. Click Here To Register...]
08/05/2010 11:54 zlost1#8
Quote:
Originally Posted by blackmorpheus View Post
Very nice hack, teleport however is very buggy.
The hacks aren't very useful.
Made this myself:
i dont see anything in your screenshot and no links
08/05/2010 12:19 h1dan#9
wtf is this another virus?... zomg zomg zomg tell me that its not a kl or something
08/05/2010 13:52 zlost1#10
Quote:
Originally Posted by h1dan View Post
wtf is this another virus?... zomg zomg zomg tell me that its not a kl or something
yep, the reason you couldnt run it was because your anti virus detected and deleted the exe file before you could run it
08/05/2010 14:01 h1dan#11
thanks god... i extracted and found only inject and dll thingey... but no .exe

thats good ryt?
p.s. i started the injection thingey :(
08/05/2010 14:36 Jamboo#12
I see that PerX gives a lot of false positives. I'll give a zip with more injectors to choose from.

But if you want to use PerX, turn off your anti virus and it should work just fine. There's no viruses in it
08/05/2010 14:38 Jamboo#13
Quote:
Originally Posted by blackmorpheus View Post
Very nice hack, teleport however is very buggy.
The hacks aren't very useful.
Made this myself:
[Only registered and activated users can see links. Click Here To Register...]
Umm.. how is that useful then? Makes everything purple? Chams hack is pretty useless in BOI i guess..

But of course the teleport is buggy, but it's not my fault.
On long teleport distances the server detects it and it throws your character back to the original position.
08/05/2010 18:45 My420Time#14
Quote:
Originally Posted by Jamboo View Post
Umm.. how is that useful then? Makes everything purple? Chams hack is pretty useless in BOI i guess..

But of course the teleport is buggy, but it's not my fault.
On long teleport distances the server detects it and it throws your character back to the original position.
When they put in server side checks for distance warps in EverQuest we just chained them together. Have it do a math calc for maxx distance and break up the points. Then it can warp one or two times.
08/05/2010 19:42 Jamboo#15
Quote:
Originally Posted by My420Time View Post
When they put in server side checks for distance warps in EverQuest we just chained them together. Have it do a math calc for maxx distance and break up the points. Then it can warp one or two times.
I was going to do this, but it's boring to find the longest possible distance