How to prepare your system for a screen-share (Important)

Messages
89
Social Credit
0
Do this first, and then follow my tutorial. As long as you don't have a chrome history of you going on vape's website and you don't have anything showing up in winrar/userassistview/lastactivityview, you'll be fine.
Aight the only thing that is struggling for me is the swap with another program name thing (exe version) I just don't know how to do it properly. Any guide on here? I can o lyrics trust you and vape
 

Czar

Member
Messages
126
Social Credit
0
While this is beneficial, and the shell bags thing tends to speed up PC performance anyways, 99% of the time they won't look that far. At least for lite.
I don't even run CCleaner, just self destruct and shit delete.
I got SSed a bit ago today, with a random .exe on my desktop. I didn't even have to rename it, just shift deleted.
 

Vape

Active Member
Messages
702
Social Credit
2
While this is beneficial, and the shell bags thing tends to speed up PC performance anyways, 99% of the time they won't look that far. At least for lite.
I don't even run CCleaner, just self destruct and shit delete.
I got SSed a bit ago today, with a random .exe on my desktop. I didn't even have to rename it, just shift deleted.
Wouldn't reccomend getting too cocky with that and never run lite from your desktop especially when you're not renaming it, it even says on the download page it's reccomended to rename any files. This message is there for a reason.
 

Czar

Member
Messages
126
Social Credit
0
And that shows up in prefetch so congrats you got screenshared by a retard

Go get screenshared on some random dogshit server like faithful and tell me how that turns out for you


Since you think you're soooo good
You've actually got a problem.
Faithful use Code 66 which only uses csrss or explorer for Vape lite, and this guide can't stop them from doing that.
It's useful, but it's not totally needed.
 

Czar

Member
Messages
126
Social Credit
0
Wouldn't reccomend getting too cocky with that and never run lite from your desktop especially when you're not renaming it, it even says on the download page it's reccomended to rename any files. This message is there for a reason.
Sure, you can run it from the actual file destination if you want.
Or just from a USB and eject it, I have found something (not sure what) on this guide (or perhaps it was something I've done by myself) stops Windows from logging USB input and output. I'll try to see what it was.
Also,
I'm not saying this is dumb to do. It's very good, but what I am trying to say is that 99% of staff won't SS you in a way where these things matter.
 

Vape

Active Member
Messages
702
Social Credit
2
You've actually got a problem.
Faithful use Code 66 which only uses csrss or explorer for Vape lite, and this guide can't stop them from doing that.
It's useful, but it's not totally needed.
Faithful uses code66? Never used it on me lol.
 

Czar

Member
Messages
126
Social Credit
0
With that logic, there are traces of the client being ran anywhere.
Code 66 IS used by Faithful.
Ran programs are stored in prefetch.
"There are traces of the client being run in the minecraft process"
That's Javaw, csrss and explorer strings (basically what this thread is for) are what I'm talking about.
So using a USB and making Windows stop logging ejection of the USB is actually not a bad idea.
 

Michael1111

New Member
Messages
6
Social Credit
0
I have a problem, I did all the steps, but now whenever I use google, for some reason none of my passwords save, and I need to log into YouTube and shit every time, when before this it auto logged in when I opened it, is there a solution to this, or would this tutorial have no effected my google cookies at all.
 

KhwPp

Well-Known Member
Messages
1,860
Social Credit
0
I have a problem, I did all the steps, but now whenever I use google, for some reason none of my passwords save, and I need to log into YouTube and shit every time, when before this it auto logged in when I opened it, is there a solution to this, or would this tutorial have no effected my google cookies at all.
Are you sure theyre not saving because you're in incognito..?
 

Vape

Active Member
Messages
702
Social Credit
2
Naw i'm not that dumb, might it have something to do with me running r-wipe?
Yes it was R-Wipe. This program removes all browser activity traces by default including saved passwords and auto fill forms unless configured not too.
 

Michael1111

New Member
Messages
6
Social Credit
0
Yes it was R-Wipe. This program removes all browser activity traces by default including saved passwords and auto fill forms unless configured not too.
Not even after putting "remember me" and shit it's still not working and it's pissing me off. How do I make a auto login to websites again.
 

Vape

Active Member
Messages
702
Social Credit
2
UPDATE: After the windows update all or some of these changes may have been set back to default so you will have to do this tutorial again.
 

return

Member
Messages
345
Social Credit
0
This tutorial focuses on disabling windows features that can lead to you getting caught in a screen-share. This is not a 'How to bypass a screen-share' thread you can refer to Ryan's post for that.

Ryan's post: http://bit.ly/2zsvfLc

Stop windows storing data in the Compatibility Assistant\Store registry key.

1.) Press the windows key and R at the exact same time.
2.) Type services.msc
3.) Find the 'Program compatibility assistant service'.
4.) Right click on this service and under 'startup type' select disabled.
5.) Reboot your system.

You can find out if you did this correctly by going to the following registry key and checking if there are any new logs I suggest deleting all the current ones residing within this registry key.

Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store

Stop windows storing data in the user assist view registry key.

1.) Press the windows key and R at the exact same time.
2.) Type regedit.
3.) Navigate to the following registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
4.) right click on the UserAssist registry key then select 'New' then 'key' and rename the key you created to settings.
5.) Under this registry key create a new DWORD value rename this to NoLog.
6.) Double click the DWORD key and give it a value of '1'.

Stop windows storing data in prefetch.

1.) Press the windows key and R at the exact same time.
2.) Type regedit.
3.) Navigate to this registry key 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SessionManager\Memory Management\PrefetchParameters'.
4.) Right-click on both EnablePrefetcher and EnableSuperfetch and choose modify on both of these and change the current value to 0.

Disabling memory compression.

1.) press your windows key and type in powershell right click on this and run it as administrator.
2.) Wait for the powershell to load and type the following command Disable-MMAgent -mc

Disabling MRU list's

1.) Press the windows key and R at the exact same time.
2.) type regedit
3.) Navigate to this registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
4.) Under this registry key create a new DWORD value rename this to
NoRecentDocsHistory.
5.) Right-click on the DWORD you just created 'NoRecentDocsHistory' and choose modify and change the current value to 1.

Disabling shell bags

1.) Press the windows key and R at the exact same time.
2.) type regedit.
3.) Navigate to this registry key.
HKEY_CURRENT_USER\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell
5.) Under the Shell key you will find two subkeys 'Bags' and 'BagsMRU'. delete both of these.
6.) recreate the Bags subkey. Right click the Shell key and select 'New - Key'.
7.) Under the Bags sub-key you just created, create a new sub-key. Right click the Bags key and select "New - Key". Rename the new key to 'AllFolders'.
8.) Under the AllFolders key, create a new sub-key named Shell.
9.) Under the 'Shell' sub-key you created, create a new string value named FolderType and set it to NotSpecified.

Once you have done all this restart your system for the changes to take place.

Your system is now patched.
To be fair you can just shift delete lite they can't find any proof of you using it, but obviously we go further just to not get caught lol.
 

Czar

Member
Messages
126
Social Credit
0
To be fair you can just shift delete lite they can't find any proof of you using it, but obviously we go further just to not get caught lol.
All that you need to do is rename the cheat, close the window, and shift delete the .exe. That's literally it.
 

Czar

Member
Messages
126
Social Credit
0
There's a lot of evidence on your computer - Follow @Ryan's tutorial to get rid of it.
That's bullshit. Absolute bullshit.
When you're using Vape Lite it removes traces from literally everywhere you could think of so there is no need.
I don't care about V3 since I normally don't use it, but running a .bat file is useless af.
 

return

Member
Messages
345
Social Credit
0
That's bullshit. Absolute bullshit.
When you're using Vape Lite it removes traces from literally everywhere you could think of so there is no need.
I don't care about V3 since I normally don't use it, but running a .bat file is useless af.
He removes it from pcaclient, clears every file they can trace back to Lite, so no it's not.
 
Top