Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [ENABLE]
- aobscanmodule(AiCantDetectYou,CrysisRemastered.exe,74 07 32 C0 E9 0E 01 00 00)
- alloc(newmem,$1000,AiCantDetectYou)//"CrysisRemastered.exe"+61A842)
- alloc(ActivateEnemiesCantSeeYou,4)
- registersymbol(AiCantDetectYou ActivateEnemiesCantSeeYou)
- label(code)
- label(return)
- newmem:
- cmp byte ptr [ActivateEnemiesCantSeeYou],1
- jne code
- AiCantSeeYouOn:
- jne AiCantDetectYou+9
- //jna CrysisRemastered.exe+61A84B
- jmp return
- code:
- je AiCantDetectYou+9
- jmp return
- AiCantDetectYou:
- jmp newmem
- nop 4
- return:
- ActivateEnemiesCantSeeYou:
- dq 0
- [DISABLE]
- AiCantDetectYou:
- db 74 07 32 C0 E9 0E 01 00 00
- unregistersymbol(AiCantDetectYou ActivateEnemiesCantSeeYou)
- dealloc(newmem)
- dealloc(ActivateEnemiesCantSeeYou)
- {
- // ORIGINAL CODE - INJECTION POINT: "CrysisRemastered.exe"+61A842
- "CrysisRemastered.exe"+61A820: 4A 8B 0C 00 - mov rcx,[rax+r8]
- "CrysisRemastered.exe"+61A824: EB 03 - jmp CrysisRemastered.exe+61A829
- "CrysisRemastered.exe"+61A826: 48 8B CD - mov rcx,rbp
- "CrysisRemastered.exe"+61A829: 48 85 C9 - test rcx,rcx
- "CrysisRemastered.exe"+61A82C: 48 0F 45 F9 - cmovne rdi,rcx
- "CrysisRemastered.exe"+61A830: 45 84 FF - test r15l,r15l
- "CrysisRemastered.exe"+61A833: 74 16 - je CrysisRemastered.exe+61A84B
- "CrysisRemastered.exe"+61A835: 66 83 7F 12 64 - cmp word ptr [rdi+12],64
- "CrysisRemastered.exe"+61A83A: 75 0F - jne CrysisRemastered.exe+61A84B
- "CrysisRemastered.exe"+61A83C: 39 2D AE A7 5C 01 - cmp [CrysisRemastered.exe+1BE4FF0],ebp
- // ---------- INJECTING HERE ----------
- "CrysisRemastered.exe"+61A842: 74 07 - je CrysisRemastered.exe+61A84B
- "CrysisRemastered.exe"+61A844: 32 C0 - xor al,al
- "CrysisRemastered.exe"+61A846: E9 0E 01 00 00 - jmp CrysisRemastered.exe+61A959
- // ---------- DONE INJECTING ----------
- "CrysisRemastered.exe"+61A84B: 49 8B 06 - mov rax,[r14]
- "CrysisRemastered.exe"+61A84E: 49 8B CE - mov rcx,r14
- "CrysisRemastered.exe"+61A851: FF 90 48 01 00 00 - call qword ptr [rax+00000148]
- "CrysisRemastered.exe"+61A857: 48 8B 17 - mov rdx,[rdi]
- "CrysisRemastered.exe"+61A85A: 48 8B CF - mov rcx,rdi
- "CrysisRemastered.exe"+61A85D: 0F B6 D8 - movzx ebx,al
- "CrysisRemastered.exe"+61A860: FF 92 48 01 00 00 - call qword ptr [rdx+00000148]
- "CrysisRemastered.exe"+61A866: 48 8B 0D AB AE 5C 01 - mov rcx,[CrysisRemastered.exe+1BE5718]
- "CrysisRemastered.exe"+61A86D: 0F B6 D3 - movzx edx,bl
- "CrysisRemastered.exe"+61A870: 44 0F B6 C0 - movzx r8d,al
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement