99% Sure One Just Attempted to Infect me

Status
Not open for further replies.
Lihtsaber1 said:
Well he said i could have a test slave and i still aint had that yet no logs have come in yet....

I sent a test slave. I have no clue if your project neptune is setup right.
 
Pro said:
More pics:
The process it starts isn't the same as mine:
The process I used is msdcsc.exe
While the procces it started was MSBuild.exe

TmIdy.png

He crypted mine for me and i tested it on myself and i have that too. Cant remove it. GREAT!
 
Pro said:
More pics:
The process it starts isn't the same as mine:
The process I used is msdcsc.exe
While the procces it started was MSBuild.exe

TmIdy.png

No shit it corrupted. I should of been more specific in the post. I enabled startup on my crypter while you had it enabled on your RAT. There are a different set of settings to use if it is setup like that.
 
I say the staff should give Pro and One timeouts to make them think about what they have done.
 
http://puu.sh/sX42
Those are the exact settings I use for my RAT as those are the settings specified in my crypter tutorial for BlackShades.
 
Pro said:
Also:

Negative (-1): Has no knowledge of hacking, >gets free crypt, assumes user who crypted is infecting him because it has persistence enabled.

No Crypters i've heard of allow you to enable or disable persistence installation. That's something configured in server setup.

Sadly plenty of crypters do that. I think the files are just corrupted and nothing really happened.
 
ViN said:
Voodin said:
I say the staff should give Pro and One timeouts to make them think about what they have done.

It is a possibility that they both did not do anything. Just a little confusion.

That's what I am thinking. /Closed till I get home (omw)
 
One said:
Pro said:
One said:
My RAT injects into AppLaunch...
http://puu.sh/sX2F
I will show all my victims if needed.

Iba0P.png

AppLaunch


From OP.


Game?
I have no clue if my crypter injects into appalaunch or my RAT does.

If you crypted your rat with your crypter they will have the same process when ran.
 
Why don't you just ask for him to recrypt then watch over teamviewer?
 
Status
Not open for further replies.
Back
Top