- Joined
- Aug 30, 2009
- Messages
- 52
- Reaction score
- 67
This addresses can only be found in CabalMain ver.46 (US)
//Remove ENC Check
(0x53CD7D): je 0053CDC7 -> jmp 0053CDC7
(0x53CD85): je 0053CE4B -->nop
//Skip MCL check
(0x53D05C): je 0053D0B5 -> jmp 0053D0B5
(0x53D061): je 0053D1A3 -->nop
(0x53D0B8): je 0053D10E -->nop
//Skip MOB check
(0x53DA14): push dword ptr ss:[ebp+ebx*4-0x14C] -> jmp 0053DA46
(0x53DA26): jmp 0053DA31 -> jmp 0053DA46
(0x53DA46): lea eax,dword ptr ss:[ebp-0x168] -> jmp 0053DAAB
(0x53DA5a): je 0053DAAB -> jmp 0053DAAB
(0x53DA61): je 0053DAA7 -> nop
(0x53DAAF): je 0053DAF6 -> nop
//To load up man/woman(12.ech)
(0x457269): CMP EAX,07 -> CMP EAX,0C
(0x457408): CMP EAX,07 -> CMP EAX,0C
//Alz Trade, Sell to 9999b
(0x5d7845): mov dword ptr ds:[edi+0x118],0x540BE3FF -> mov dword ptr ds:[edi+0x118],0xD4A50FFF
(0x5d784f): mov dword ptr ds:[edi+0x11C],0x2 -> mov dword ptr ds:[edi+0x11C],0xE8
(0x5d80c7): mov dword ptr ds:[eax+0x118],0x540BE3FF -> mov dword ptr ds:[eax+0x118],0xD4A50FFF
(0x5d80d1): mov dword ptr ds:[eax+0x11C],0x2 -> mov dword ptr ds:[eax+0x11C],0xE8
(0x62fdb0): cmp edi,0x2 -> cmp edi,0xE8
(0x62fdb7): cmp ebx,0x540BE3FF -> cmp ebx,0xD4A50FFF
//For Epaulet (Buggy)
(0x49DC35): JE 49DCC9 -> JMP 49DCC9
//For custom encryption.
(0x474208) XOR EAX,57 -> XOR EAX,?? // 4th XORKey
(0x47421A) XOR EAX,67 -> XOR EAX,?? // 3rd XORKey
(0x47422C) XOR EAX,65 -> XOR EAX,?? // 2nd XORKey
(0x47423D) XOR EAX,92 -> XOR EAX,?? // 1st XORKey
//Support map11
change ui.dat
Download:
ep2(CabalmainV25):
ep3(CabalmainV46): http://www.mediafire.com/?9pwygebk4iex26x
ep6(CabalmainV1390): http://www.mediafire.com/?ct21zbvzkttm543
MD5:497e5258ec39ac18c96cf10a6c39d3e2
//ep6: Change other language
1:0044D120 mov byte ptr ds:[ecx],0x2 -->mov byte ptr ds:[ecx],0x"Y"
2:0044d120 mov dowrd ptr ds:[ecx+0x75],0x2-->mov dowrd ptr ds:[ecx+0x75],0x?
3:0044d13a mov dowrd ptr ds:[ecx+0x75],0x2-->mov dowrd ptr ds:[ecx+0x75],0x?
4:0044d130 mov eax,dword ptr ds:[0x9B1C48]; 0x9B1C48 : ?
5:00778AD4ush 0x9AF8F8; 0x9AF8F8: [ENG]-->[Nation code]
?=(1...E)
?=1 to Korean;
?=2 to English
?=3 to Thai;
?=4 to Japanese
?=5 to German
?=6 to Portuguese
?=7 to Indonesian
?=8 to Russian
?=9 to Vietnamese
?=a to Chinese(CHN)
?=b to Chinsee(TWN)
?=c to French
?=d to Italian
?=e to Spanish
Y=9:KOR,Y=2:EN...
//Remove ENC Check
(0x53CD7D): je 0053CDC7 -> jmp 0053CDC7
(0x53CD85): je 0053CE4B -->nop
//Skip MCL check
(0x53D05C): je 0053D0B5 -> jmp 0053D0B5
(0x53D061): je 0053D1A3 -->nop
(0x53D0B8): je 0053D10E -->nop
//Skip MOB check
(0x53DA14): push dword ptr ss:[ebp+ebx*4-0x14C] -> jmp 0053DA46
(0x53DA26): jmp 0053DA31 -> jmp 0053DA46
(0x53DA46): lea eax,dword ptr ss:[ebp-0x168] -> jmp 0053DAAB
(0x53DA5a): je 0053DAAB -> jmp 0053DAAB
(0x53DA61): je 0053DAA7 -> nop
(0x53DAAF): je 0053DAF6 -> nop
//To load up man/woman(12.ech)
(0x457269): CMP EAX,07 -> CMP EAX,0C
(0x457408): CMP EAX,07 -> CMP EAX,0C
//Alz Trade, Sell to 9999b
(0x5d7845): mov dword ptr ds:[edi+0x118],0x540BE3FF -> mov dword ptr ds:[edi+0x118],0xD4A50FFF
(0x5d784f): mov dword ptr ds:[edi+0x11C],0x2 -> mov dword ptr ds:[edi+0x11C],0xE8
(0x5d80c7): mov dword ptr ds:[eax+0x118],0x540BE3FF -> mov dword ptr ds:[eax+0x118],0xD4A50FFF
(0x5d80d1): mov dword ptr ds:[eax+0x11C],0x2 -> mov dword ptr ds:[eax+0x11C],0xE8
(0x62fdb0): cmp edi,0x2 -> cmp edi,0xE8
(0x62fdb7): cmp ebx,0x540BE3FF -> cmp ebx,0xD4A50FFF
//For Epaulet (Buggy)
(0x49DC35): JE 49DCC9 -> JMP 49DCC9
//For custom encryption.
(0x474208) XOR EAX,57 -> XOR EAX,?? // 4th XORKey
(0x47421A) XOR EAX,67 -> XOR EAX,?? // 3rd XORKey
(0x47422C) XOR EAX,65 -> XOR EAX,?? // 2nd XORKey
(0x47423D) XOR EAX,92 -> XOR EAX,?? // 1st XORKey
//Support map11
change ui.dat
Download:
ep2(CabalmainV25):
ep3(CabalmainV46): http://www.mediafire.com/?9pwygebk4iex26x
ep6(CabalmainV1390): http://www.mediafire.com/?ct21zbvzkttm543
MD5:497e5258ec39ac18c96cf10a6c39d3e2
//ep6: Change other language
1:0044D120 mov byte ptr ds:[ecx],0x2 -->mov byte ptr ds:[ecx],0x"Y"
2:0044d120 mov dowrd ptr ds:[ecx+0x75],0x2-->mov dowrd ptr ds:[ecx+0x75],0x?
3:0044d13a mov dowrd ptr ds:[ecx+0x75],0x2-->mov dowrd ptr ds:[ecx+0x75],0x?
4:0044d130 mov eax,dword ptr ds:[0x9B1C48]; 0x9B1C48 : ?
5:00778AD4ush 0x9AF8F8; 0x9AF8F8: [ENG]-->[Nation code]
?=(1...E)
?=1 to Korean;
?=2 to English
?=3 to Thai;
?=4 to Japanese
?=5 to German
?=6 to Portuguese
?=7 to Indonesian
?=8 to Russian
?=9 to Vietnamese
?=a to Chinese(CHN)
?=b to Chinsee(TWN)
?=c to French
?=d to Italian
?=e to Spanish
Y=9:KOR,Y=2:EN...
Last edited: