Zelaron Gaming Forum  
Stats Arcade Portal Forum FAQ Community Calendar Today's Posts Search
Go Back   Zelaron Gaming Forum > Zelaron Gaming > Diablo III > Diablo I & II

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next

 
Reply
Posted 2003-07-12, 08:36 AM in reply to tacoX's post "!!Warning!!"
www.d2hacking.com is pointed at http://www.pixelmethods.com/d2h/index2.htm and resolves to 209.120.206.164.

pixelmethods.com is pointed at the Nameservers own by muderopolis.com

http://www.pixelmethods.com/d2h/dls/aim.zip
http://www.pixelmethods.com/d2h/dls/d2hackit.zip
http://www.pixelmethods.com/d2h/dls/herzonggol.zip
http://www.pixelmethods.com/d2h/dls/isspamsetup.zip
http://www.pixelmethods.com/d2h/dls/pinda.zip
http://www.pixelmethods.com/d2h/dls/wirt.zip
http://www.pixelmethods.com/d2h/dls/yayD2H.zip

Every single one of these files contains the same file, setup.exe which is a trojan. The payload is
c:\mswinsck.ocx
c:\kernel32.exe
c:\conversions.ini

conversions.ini allows the typing of characters that you cannot see, and this trojan allows the access to steal the account name // pw and cdkeys of the game Diablo 2

Blizzard.com has released on official warning at http://www.battle.net/forums/thread...nt=0#post322018

Please remove these files and I certainly hope that this user is removed from your services

fyi: This person is in the Diablo 2 community as TacoX, a recent administrator at www.zelaron.com
Old
Profile PM WWW Search
Kronix is neither ape nor machine; has so far settled for the in-betweenKronix is neither ape nor machine; has so far settled for the in-between
 
Kronix
 



 

Bookmarks

« Previous Thread | Next Thread »

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules [Forum Rules]
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -6. The time now is 10:43 PM.
'Synthesis 2' vBulletin 3.x styles and 'x79' derivative
by WetWired the Unbound and Chruser
Copyright ©2002-2008 zelaron.com
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
This site is best seen with your eyes open.