Monst3rClip by Zaxer & Quj - A very simple, yet effective noclip tool menu

User Tag List

Results 1 to 8 of 8
  1. #1
    Zaxer's Avatar Contributor
    Reputation
    92
    Join Date
    Sep 2008
    Posts
    159
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Monst3rClip by Zaxer & Quj - A very simple, yet effective noclip tool

    Got hacked, this thread was spam and the download link was a keylogger.
    Last edited by Zaxer; 05-01-2015 at 01:38 PM.

    Monst3rClip by Zaxer & Quj - A very simple, yet effective noclip tool
  2. #2
    biolizade's Avatar Banned
    Reputation
    1
    Join Date
    Nov 2012
    Posts
    3
    Thanks G/R
    0/0
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thank you for this. Its actually suprisingly good (considering you said it will be sloppy, dont be so hard on yourself :P).
    However, the GUI could be a little bit smoother and hotkeys would help ALOT, this is still GREAT for a freeware.
    Thanks again!

  3. #3
    Filint's Avatar Contributor Authenticator enabled
    Reputation
    167
    Join Date
    Mar 2014
    Posts
    97
    Thanks G/R
    23/56
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    DEFINITELY DO NOT DOWNLOAD THIS. NASTY VIRUS, WHICH I'M NOW FIGHTING TO REMOVE FROM MY SYSTEM.

    https://www.virustotal.com/en/file/6...is/1430425139/
    Last edited by Filint; 05-01-2015 at 04:06 AM.

  4. #4
    Jadd's Avatar 🐸 Premium Seller
    Reputation
    1511
    Join Date
    May 2008
    Posts
    2,432
    Thanks G/R
    81/333
    Trade Feedback
    1 (100%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    Ran it under a VM, it is indeed a virus coded in .NET (obfuscated with SmartAssembly.)

    I'm leaving this thread here temporarily to provide a little information about it.

    By the look of it, it's only a keylogger, so I think you do not need to worry about it collection current passwords, cookies, etc.

    In case you did run it, you can remove it like so:
    1. Disable/unplug your internet connection.
    2. Disable all startup applications via. regedit (or within Task Manager in Windows 8.1)
    3. Make sure you found the startup entry for "sysmon.exe", and deleted it. Should be located somewhere like "C:/ProgramData/<some numbers>/sysmon.exe", you should note this path down.
    4. Restart your PC, now you should notice there's only one sysmon.exe in task manager (the REAL Windows one.)
    5. Read how to take ownership of a system file: How to Delete a System File in Windows 7 or Vista
    6. Take ownership of the executable at the path you noted before.
    7. Delete the file via. Windows Explorer, you will probably have to show hidden files to see it.
    8. Enable internet, enable the other startup applications, restart your PC.

  5. #5
    Filint's Avatar Contributor Authenticator enabled
    Reputation
    167
    Join Date
    Mar 2014
    Posts
    97
    Thanks G/R
    23/56
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thanks, Jadd. I think I've got it fixed now!

  6. #6
    Jadd's Avatar 🐸 Premium Seller
    Reputation
    1511
    Join Date
    May 2008
    Posts
    2,432
    Thanks G/R
    81/333
    Trade Feedback
    1 (100%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Filint View Post
    Thanks, Jadd. I think I've got it fixed now!
    How did you manage finding the file and deleting it?

  7. #7
    Filint's Avatar Contributor Authenticator enabled
    Reputation
    167
    Join Date
    Mar 2014
    Posts
    97
    Thanks G/R
    23/56
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Jadd View Post
    How did you manage finding the file and deleting it?
    I wasn't actually able to take ownership and delete it. What I ended up doing was booting up ubuntu from a usb and replacing the two(!) sysmon.exe with 0 byte sysmon.exe files. Stopped the file from running obviously, and I was then able to take ownership and delete.

    Sorry to hear about the account hack Zaxer.

  8. #8
    Zaxer's Avatar Contributor
    Reputation
    92
    Join Date
    Sep 2008
    Posts
    159
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Filint View Post
    I wasn't actually able to take ownership and delete it. What I ended up doing was booting up ubuntu from a usb and replacing the two(!) sysmon.exe with 0 byte sysmon.exe files. Stopped the file from running obviously, and I was then able to take ownership and delete.

    Sorry to hear about the account hack Zaxer.
    It's ok

    That's a really creative way of solving the problem haha!

Similar Threads

  1. Replies: 0
    Last Post: 02-15-2011, 11:58 AM
  2. [Very Simple] Most effective ban method I've ever used
    By LiquidShizzles in forum WoW Scam Prevention
    Replies: 7
    Last Post: 12-05-2008, 11:20 AM
  3. [Guide] Badge of Justice (Simple, yet Effective)
    By ipnetz006 in forum World of Warcraft Guides
    Replies: 26
    Last Post: 06-04-2008, 01:33 AM
  4. Very .. simple request...
    By dirtywowgurrl in forum WoW ME Questions and Requests
    Replies: 2
    Last Post: 12-24-2006, 09:35 AM
  5. Very Simple Question.
    By tyman2006 in forum Community Chat
    Replies: 2
    Last Post: 12-03-2006, 11:55 PM
All times are GMT -5. The time now is 02:07 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search