EasyMap for Diablo II v1.1 - Release

Status
Not open for further replies.

zackdizzle

Member!
Joined
Jul 26, 2005
Messages
59
Reaction score
0
Location
Canada
so wait does this mh work and is it clean, whats the final answer on this. should I use? yes or no.
 

Wing Zero

lol just as planned
Joined
Oct 27, 2002
Messages
12,206
Reaction score
16
omg stop making me have 2 sodes :(
1 person say ok blah blah
otehr says clean blah blah
XD
 

t.A.T.u97

BattleForums Senior Member
Joined
May 26, 2003
Messages
2,491
Reaction score
0
Location
t.A.T.u Land!
Website
www.tatu.us
Wow how many times do I have to say.

It is backdoored, just as all the other netterhaufen things. He will always backdoor his stuff, do not use anything netter is producing.

It opens port 1010, which ANY maphack that is legit and is safe to use will not open any port. It leads to a nice place of information that belongs to Jan.

Case closed. Mousepad will release theirs in no time.
 

Forged

Premium Member
Joined
Nov 28, 2002
Messages
5,433
Reaction score
0
Location
Texas
Website
www.securegamers.com
I opened it with win32dasm, I didn't see anything out of the ordinary, he isn't using any kind of winsocks api or anything that would email him your cdkeys. So I think it is clean but I am not 100% sure.

I don't know why he is using the sendmessage api(as I have never made a d2 hack), that could possiblly be used to send him your cd-key but you would notice it if you whispered your account information.
 

PauseBreak

BattleForums Senior Member
Joined
Aug 27, 2003
Messages
4,616
Reaction score
12
But he is sending something out? That's no good.
 

Johnny

IMMERSION RUINED
Joined
Mar 24, 2005
Messages
2,375
Reaction score
1
Location
Garden Grove, CA
i'm taking tatu's words and just not going to use it.

i downloaded it and ran it for a few mins, then closed deleted/removed it from my comp. I am not still at risk am I? I'll wait for mousepads and/or c3po's maphack to be released.
 

Wing Zero

lol just as planned
Joined
Oct 27, 2002
Messages
12,206
Reaction score
16
god this is confusing
 

Hitsua

+
Joined
May 26, 2003
Messages
4,305
Reaction score
5
OMFG WHEN I OPENDED IT, IT SAID THERE WUZ A vIRUS AND THEN QUZIMOTO CAME OUT AND HACKED MY CMOPOUTER AND THEN I PLAYED DIABLO.

BAN BAN BAN.
 

Forged

Premium Member
Joined
Nov 28, 2002
Messages
5,433
Reaction score
0
Location
Texas
Website
www.securegamers.com
t.A.T.u97 said:
It works, yes, but it is Jan. Although I am a europe user (last netterhaufen things he would not release europe accounts) I'm still gonna wait another day or 2 for maphack. Friend talked to the guy and sure enough its backdoored. Heres what he said to moi:

Artwork © says:
it opend connection on port 1010
Artwork © says:
no mh does that unless it's scripted to send out packets
Artwork © says:
i read his source
Artwork © says:
and i found a nice backdoor in it

(Thanks ert you sexy hoe)

Really, impatience will pwn any of you. Its maphack for christ sakes....

Why don't you tell artwork to post the source code...
 

deepfutu

Member!
Joined
Jul 20, 2005
Messages
16
Reaction score
0
I have fixed the link in the first post *yet again*, as I've installed a new forum now.

You may post suggestions for version 1.1 in this thread, if you like :).

-Jan

Edit: About the rumors that it's not safe: The file has been verified to be safe from many independent sources. You may want to take a look at diabloworld.com - they have stickied my post and mirror a definite safe version of my file (if you don't trust my server).
 

MacMan

BattleForums Senior Member
Joined
May 17, 2003
Messages
1,943
Reaction score
1
It's not a matter of the file's security, it's a matter of your source code.

Oh and I'm not insinuating anything (or am I?), but I found this interesting:

***********
Port number:
1010

Common name(s):
doly surf

Service description(s):
Doly Trojan Horse surf

Actions:
Remote Access / Keylogger / IRC trojan

Registers:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKEY_USER\.Default\Software\Marabilis\ICQ\Agent\Apps\
***********
 

Johnny

IMMERSION RUINED
Joined
Mar 24, 2005
Messages
2,375
Reaction score
1
Location
Garden Grove, CA
macman, what are the names of the registries, instead of the location. i want them delete :-/
 

MacMan

BattleForums Senior Member
Joined
May 17, 2003
Messages
1,943
Reaction score
1
Normally, the Doly "client" software is run whenever the victim's computer is turned on. In case his backdoor retains this characteristic, delete any registries whose data load "tesk.exe." Otherwise, I assume EasyMap is just the client software in disguise, so don't run it. (And I'm sure if he's using a modified trojan, and he's smart enough to map hack D2, then he's probably smart enough to change any registry entries that might incriminate him, as well as the name of "tesk.exe.")
 
Status
Not open for further replies.
Top