Jump to content

About a hacker


koed12
 Share

Recommended Posts

Hi,

 

Today 2 people got hacked by a guy..

First of all DO NOT DOWNLOAD everything you find online even if your friend or a stranger is sending to you...

2 people got hacked because someone told them to download a server and he sent a link with the server files (virus)...it is a RAT (I am not going to explain what this is)...But they can do and see everything on your pc..download or upload files...EVERYTHING...so do a favor to yourselves and do not open every link they send to you..use your common sense...

 

If someone got infected ask for my help or someone else help to remove it...

 

Edit : I think the name of the program is Corechat

 

Edit 2 : CoreChat can be found in core's fiesta installation folder.

 

Edited by koed12
Link to comment
Share on other sites

Lesson to be learned? Download from our official links instead of accepting other's. Furthermore even if there would have been a CoreChat, I have no idea how would that even auto-run without a modified installer. The Launcher only looks for and launches the Client.exe, and in case it doesn't find it, it initiates a integrity check, which is also normal, no "CoreChat" involved.

 

By default if you install our client, it will ask you if you want to auto-run it, in which even it launches the "Launcher.exe" and nothing else.

 

My guess is you have been infected by a virus that makes up random file names and duplicates itself wherever it can. Please do a full virus scan on your PC, but be aware that our Client.exe will most probably be deleted too.

 

I repeated this several thousand times, if your antivirus reports our Client.exe as a virus, which isn't a virus by the way, it is because it's highly encrypted and it doesn't have a valid "header" (not that you would know what that is), thus the antivirus can't scan it in-depth, therefore it automatically classifies it as a virus.

 

If this happens you can always download the Client.exe again- by visiting our lovely F.A.Q. thread.

Link to comment
Share on other sites

If you've been infected by a RAT, which I suspect may be the case, I highly suggest you consider reinstalling windows. You can read what a RAT is here: http://searchsecurity.techtarget.com/definition/RAT-remote-access-Trojan
 
You can look for RAT removal programs, but if you've been infected by a RAT the best solution is for a windows reinstall. You can check if you've been infected by a RAT by checking the connections to your computer which are currently active, you can find out more about that here: https://www.youtube.com/watch?v=LT-wVgq3c8c
 
Rats do not need to be directly installed on your computer, by simply visiting a website and click Allow or accepting a message will make your computer vulnerable. Most anti-security software can't detect RAT's so you could be infected for months and not know about it.
 
Make sure to change all of your passwords once you are 200% sure you've gotten rid of it.
 
On the other hand you could consider yourself lucky as it might only be a key logger, in which case you'd only need to remove the key logger. I'm sure there is a tutorial for it somewhere.
 
Don't download, unknown programs from friends or people. Even friends you've known online or in real life might betray you to get something they want. Stay safe.

Link to comment
Share on other sites

Is CoreChat the infected "file" or whatever that people should get rid of? Or is it the file that will be infected if you download the the "download" that you are talking about.

Yea thats the name of the virus..

 

Also if i was that skid i would made a backup of my virus in another file in case someone find the original one and delete it...this way i will still have the RAT installed on pc...so either scan your pc with a antivirus but dont rely on AVs cause it is very easy to make a virus FUD...open up your Task Manger and look for programs that running and they are unknown to you..but DO NOT STOP any process cause you may make your pc unstable.. Use rkill and if you are lucky maybe it is gonna find this virus...

 

Now if you are unsure about your pcs safety re-install windows as Fardob suggested...

And next time use your common sense..

 

Also check the websites and programs they sent to you through skype..Cause maybe this guy got skype accounts and using them to spread the virus...

 

If someone has this virus file please sent it to me.I would like to see if it is virus or keylogger and play with it :D

Edited by koed12
Link to comment
Share on other sites

You do not have to re-install windows if you know how to get rid of it..Keep a backup of your windows and re-install them without losing something in case you get infected and you do not know how to remove it..And since core's launcher is clear and the virus need a modified client to run and since the client is clear of viruses it will attach itself probably on your explorer.exe..Since this is the default option of the virus..And I am pretty sure this guy have not changed it..

 

BUT IN ANY CASE DO NOT DELETE YOUR EXPLORER.EXE TASK OR FILE....

Edited by koed12
Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
 Share

×
×
  • Create New...