[Tutorial] How to make a stealthy Virtual Machine

  Рет қаралды 867,297

Jim Browning

Jim Browning

Күн бұрын

This is a tutorial, so no scambaiting here this time. If you want to avoid scammers picking up that you're baiting them with a Virtual Machine, this is how to make it really stealthy.
You'll need the following Registry Point:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum
Search for the following 4 GUIDs:
{4d36e967-e325-11ce-bfc1-08002be10318}
{4d36e968-e325-11ce-bfc1-08002be10318}
{4d36e965-e325-11ce-bfc1-08002be10318}
{4d36e96f-e325-11ce-bfc1-08002be10318}
You can download the VMware Tools stealthy registry files from :
s000.tinyupload... (v14+)
OR
mega.nz/#F!PlM... (v8-v13)
This will work for Windows 7, 8, 8.1 and 10 with VMware tools 10.10
I'll do a VBOX/WIn7 version soon.
Happy scambaiting!

Пікірлер: 1 800
@thomasc.8274
@thomasc.8274 6 жыл бұрын
Or change your grandma's computer to look like a vm so she's immuned
@buggsy5
@buggsy5 6 жыл бұрын
Microsoft should include a VM in all their releases and install them. It should then be relatively easy to make it appear to scammers that the machine is in VM mode, even when it isn't. Then until they figure out a way to get around the common VM software versions, they would have to treat all intended victims as if VM was not in use.
@gmonkman
@gmonkman 6 жыл бұрын
ha, i like your thnking
@primeplatypus1799
@primeplatypus1799 6 жыл бұрын
BEST IDEA EVER
@Nash1a
@Nash1a 6 жыл бұрын
It is a great idea until enough people do it and the tech scammers get wise to it.
@m_jr7066
@m_jr7066 6 жыл бұрын
Nash1a but then you could use vm and they wouldn’t say anything...ITS NEVER ENDING
@tosgem
@tosgem 5 жыл бұрын
The way he says "Give yourself ownership, give yourself permission" sounds like some kind of new-age motivational speech / self improvement
@sasodoma
@sasodoma 4 жыл бұрын
I always find it amusing when Windows tells me to request permission from myself.
@nadurokorte9917
@nadurokorte9917 4 жыл бұрын
"Obama giving himself an medal"
@rayjaymor8754
@rayjaymor8754 4 жыл бұрын
@Max Raider I'm honestly looking forward to an actually decent DE coming out that will make Linux completely noob friendly. I'm only using Windows to play very specific games these days. Everything else is via Ubuntu.
@Rickety3263
@Rickety3263 4 жыл бұрын
tosgem reflecthost=“true”
@Asocial_Ace
@Asocial_Ace 4 жыл бұрын
@@rayjaymor8754Linux Mint is very user friendly for a windows user. Most desktop environments are extremely customizable as well. I find kde to be one of the easiest to customize out of the box.
@alpitu21
@alpitu21 5 жыл бұрын
2 gb of ram, 500gb samsung ssd, nvidia gtx 1080. noice.
@vendybirdsvadl7472
@vendybirdsvadl7472 5 жыл бұрын
vm computer: why you gave me 2 gb of ram?
@tactical_slime4608
@tactical_slime4608 4 жыл бұрын
my 4gb intel hd laptop: FINALLY A WORTHY OPPONENT
@alexandernicholas5309
@alexandernicholas5309 4 жыл бұрын
And single core processer at 17:10
@Technology_2020
@Technology_2020 4 жыл бұрын
and NEC
@souta95
@souta95 4 жыл бұрын
@@alexandernicholas5309 ...A single core Phenom II X4 CPU... ;-)
@speedyJ0hnny
@speedyJ0hnny 5 жыл бұрын
Me: (Never Planning to do any scambaiting) Interesting
@dsfuidsfiojausefdsfsee3331
@dsfuidsfiojausefdsfsee3331 5 жыл бұрын
Me Want but can't yet be bothered to do it with VMware and via emails
@fnacoo
@fnacoo 4 жыл бұрын
@@informalmods6044 now 206 likes
@Daniel-tg5tm
@Daniel-tg5tm 4 жыл бұрын
@@fnacoo now 207
@eeejajduanenakdnnae
@eeejajduanenakdnnae 4 жыл бұрын
@@Daniel-tg5tm now 230
@Crazyclay78YT
@Crazyclay78YT 4 жыл бұрын
i would love to, but my machine doesn't let vmware run, or rather I get a thing t the bottom of the settings page that says, "hardware virtualization is not supported by host machine" and I turn it off and the alert is still there.
@DoubleU555
@DoubleU555 7 жыл бұрын
Honestly the best way to create convincing looking VM is to make the desktop look like as if it's really used by a typical scammer's victim. You know, fill it with some documents, shortcuts, and a tacky looking wallpaper on top of it.
@cm0s
@cm0s 7 жыл бұрын
I agree with what you said except the wallpaper part, since it doesn't really matter as most remote desktop software will disable the wallpaper while the connection is active.
@santosic
@santosic 7 жыл бұрын
That would be my next step after doing the stuff in this tutorial. To take away that whole too new look, I'd just install a lot of the apps I use on my actual machine, and have their icons on the desktop. Would legitimize it even more (especially if the scammer DID in fact open the installed programs dialog, they'd see a lot of them installed)
@TR2000LT
@TR2000LT 7 жыл бұрын
Keg LOL
@ips7
@ips7 7 жыл бұрын
I just died laughing.. So wrong though. So wrong!
@MisterMander
@MisterMander 7 жыл бұрын
Double thanks for the advice pal
@retropcs88
@retropcs88 4 жыл бұрын
I would have way too much fun with this. The VM would look like this: Computer: IBM PC AT RAM: 2Mb Video Card: Plantronics Color+ HDD: Seagate ST-225 Disk drives: Mitsumi High Density Floppy drive Processor: Intel 286-16
@loominatrx
@loominatrx 4 жыл бұрын
lmao
@preinstalleduser2309
@preinstalleduser2309 4 жыл бұрын
Retro PCs CPU: intel 8086, RAM:512mb,
@CNETech
@CNETech 4 жыл бұрын
@@preinstalleduser2309 512MB RAM is shit of 2004, ya dingus
@froschgrosch5247
@froschgrosch5247 4 жыл бұрын
And running Windows 10
@choco-kun7221
@choco-kun7221 4 жыл бұрын
Lolll
@zech6846
@zech6846 5 жыл бұрын
GTX 1080 + phenom + 2Gb of RAM. At least scammers aren't smart.
@DandelionYudeul
@DandelionYudeul 5 жыл бұрын
Sir in addition to our 50$ gold package we can take your graphics card for free and change it with a better one for your cpu.
@delectantix2830
@delectantix2830 5 жыл бұрын
Or even better AMD Threadripper and a NVidia 9600m... Who had also an laptop with this card?
@JonnyInfinite
@JonnyInfinite 5 жыл бұрын
You have best configuration..
@HappyBeezerStudios
@HappyBeezerStudios 4 жыл бұрын
Actually not that bad, considering that we pretend to got infected with everything under the sun.
@tuomollo
@tuomollo 4 жыл бұрын
Single core Phenom x4 ;)
@benedict8720
@benedict8720 5 жыл бұрын
Idk why but I feel like I can trust this guy with my life
@michaelmullen3923
@michaelmullen3923 5 жыл бұрын
You're not alone
@alexrawson8492
@alexrawson8492 4 жыл бұрын
But can you trust him with $20?
@TheHiroClaw123
@TheHiroClaw123 4 жыл бұрын
@@alexrawson8492 he'll probably spend it on bestbuy only for him to tell the female worker to cancel the shipment and freeze the 20 dollar bill
@TheHiroClaw123
@TheHiroClaw123 4 жыл бұрын
and I would be ok with that
@love999cats
@love999cats 4 жыл бұрын
But you wouldn't want to be his enemy
@strawloki7133
@strawloki7133 7 жыл бұрын
*scammers taking notes*
@MidnightHabit
@MidnightHabit 7 жыл бұрын
Only the few smart ones. I'm guessing the majority aren't really that savvy.
@mdamaged
@mdamaged 7 жыл бұрын
boom!
@ionymous6733
@ionymous6733 7 жыл бұрын
just as Jim took note of them checking the hard drive name
@primemeow
@primemeow 7 жыл бұрын
Or just directly copy it from your host's Device Manager.
@therealb888
@therealb888 7 жыл бұрын
TCOM Reborn It's always safe to keep your host as anonymous as possible.
@cactoidjim1477
@cactoidjim1477 3 жыл бұрын
The fact that they're at the point where they are checking for VMs means that ScamBaiting is working.
@orkhepaj
@orkhepaj 3 жыл бұрын
i dont get why they dont write some scripts , it would look more professional too
@jnawk83
@jnawk83 3 жыл бұрын
@@orkhepaj that would require they be professional. no professional would work for them.
@phildenfer
@phildenfer 2 жыл бұрын
It's about escalation. They scam, we scambait. They check for scambaiter VMs, we use stealth VMs. They'll have to check that we are bad at acting, we'll take acting lessons to get better at faking to be potential targets :D And then.... We clone Jim Browning, that's the AI project to create fake victims with AI. Might waste their time.
@itzlqmer6084
@itzlqmer6084 2 жыл бұрын
@@orkhepaj they do, idk about 1year ago but nowadays they do
@CuttheropeTutorials
@CuttheropeTutorials 2 жыл бұрын
@@itzlqmer6084 the scammer i called today had their “bank server” be a batch file, not just notepad or cmd.
@DayTripperID
@DayTripperID 7 жыл бұрын
Did my first scambaiting call today after going through all the vm preparation, stealthing & weathering to make it look used, and the dude didn't even do any checks for VM!
@mikejameson7678
@mikejameson7678 7 жыл бұрын
jeep What an idiot the scammer was... Did you remember to refilter with Documents, and files?
@wasserruebenvergilbungsvirus
@wasserruebenvergilbungsvirus 5 жыл бұрын
Let me guess, you use Arch btw? :D
@internalscreaming9538
@internalscreaming9538 5 жыл бұрын
“And that’s why arch will always be the best” the neck beard says after scratching the dorito dust off his glob of a chin.
@TheTheninjagummybear
@TheTheninjagummybear 5 жыл бұрын
@@internalscreaming9538, The fuck?
@ignat340
@ignat340 5 жыл бұрын
@@internalscreaming9538 h-h-hey shut up
@georgemorley1029
@georgemorley1029 5 жыл бұрын
“Oh! I see that! Alright...” Like a slug retreating from salt.
@typingcat
@typingcat 4 жыл бұрын
"Thank you, come again." would be my response to his retreat.
@Sprinkleycakes
@Sprinkleycakes 7 ай бұрын
Hahahaha underrated comment.
@preinstalleduser2309
@preinstalleduser2309 4 жыл бұрын
This was one of the best videos you’ve done in my honest opinion. Teaching other people how to scam the scammers is a great way to lessen the number of scammers. Wasting their time “safely” is key.
@InfinityBS
@InfinityBS Жыл бұрын
@reapiu8316Get a VPN 🙂
@crylune
@crylune Жыл бұрын
@reapiu8316 they can't do jack shit with an IP address. cookies, maybe. but the IP threat is meh. I regularly give out my public IP to people threatening to "DDOS" me and see what they do. As expected they do nothing.
@AcessDBpro
@AcessDBpro 6 жыл бұрын
14:56 A savvy scammer will notice that your new file name does not have the same icon as the other two files of the same name, and will also probably notice the huge discrepancy in file size. I suggest using another installed executable that is not like the other files it is trying to emulate. I would also throw on a bunch of various files that don't contain personal information, or better yet, a lot of files with your fictitious alias' name/family/employment information that typical users would have after frequent usage on their computer.
@hul8376
@hul8376 3 жыл бұрын
@Cipheiz lol
@bufordmaddogtannen
@bufordmaddogtannen 3 жыл бұрын
I'd avoid all the fuss and just remove the entry from HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall Although iirc there should be a visibility flag that can be toggled to make an uninstall entry appear or disappear at will.
@marshallpieri3737
@marshallpieri3737 3 жыл бұрын
@@bufordmaddogtannen thanks man
@frgging
@frgging 7 жыл бұрын
If you have a windows 10 VM, go to task manager, click performance tab and click cpu on the left. You'll see 'Virtual Machine: Yes' at right bottom. And there's no L1,L2,L3 cache.
@bitelaserkhalif
@bitelaserkhalif 6 жыл бұрын
Louis Lu one reason why I'm using XP VM
@kjl3080
@kjl3080 6 жыл бұрын
Louis Lu this needs mdre likes
@Freeak6
@Freeak6 6 жыл бұрын
If you use VMWare, just activate "Virtualize Intel VT-x/EPT or AMD-V/RVI" in the settings of the VM, and this will be gone and you will have L1,L2,L3 cache :)
@robbinklg9
@robbinklg9 4 жыл бұрын
@@Freeak6 I am in the VM settings but I can't find the setting.. -Edit found it, it's under hardware, processor
@곽봉수-w8v
@곽봉수-w8v 4 жыл бұрын
For people using libvirt, add in cpu tag.
@xdramen538
@xdramen538 3 жыл бұрын
this guys understanding of technology is scary, i’m glad he’s on our side.
@williamm.1412
@williamm.1412 7 жыл бұрын
Hi again Jim. I was blown away by this tutorial. Excellent work! At first I thought too many of your viewers would have a hard time comprehending everything. But no....it was just me, lol I read all the comments and was impressed with everyone's feedback. Obviously this will be useful to many of your viewers.Well done!!
@NickolaySheitanov
@NickolaySheitanov 6 жыл бұрын
William M. Its not hard if you aren’t repulsed by computers and have a bit of an open mind you’ll see how easy it is. Really not complicated.
@Tailss1
@Tailss1 5 жыл бұрын
4:45 Save all that with permissions and make sure you are either logged in as local administrator or the account you are logged in with is in the administrators group. Registry objects belong to owner Administrators group by default.
@TheOwlGilga
@TheOwlGilga 7 жыл бұрын
I love how your channel is growing, keep it up Jim! Good stuff!
@TheOwlGilga
@TheOwlGilga 7 жыл бұрын
Also shows how ententertaining it is to watch someone absolutely dismantle them hahaha
@timroberts69
@timroberts69 7 жыл бұрын
It reflects just how pissed off we are at these guys ripping off elderly people and computer non-savvy people. And how sick we are of the repeat phone calls from these scumbags.
@Okurka.
@Okurka. 6 жыл бұрын
17:08 That AMD Phenom II X4 965 having 1 core is a dead giveaway.
@rorymorgan6091
@rorymorgan6091 4 жыл бұрын
Scammers aren't smart though 👁️👃👁️
@ThackshilaUdage
@ThackshilaUdage 3 жыл бұрын
Exactly my thoughts!!
@alexbrooks6141
@alexbrooks6141 7 жыл бұрын
Thanks for this, your advice helped! It's surprising to see them becoming so smart, today I called one company up and before assisting they did very vigorous checks to see if the computer was not a virtual machine! I use VirtualBox so some of the steps I had to implement.
@narektorosyan863
@narektorosyan863 5 жыл бұрын
A real Samsung SSD does not label itself as "Samsung 500GB ATA", it's something like "SAMSUNG MZNLN128HCGR-000L2".
@GibusWearingMann
@GibusWearingMann 5 жыл бұрын
Yeah, but most tech support scammers aren't that sophisticated.
@SleepyDudu
@SleepyDudu 5 жыл бұрын
@@GibusWearingMann still tho
@64bit72
@64bit72 5 жыл бұрын
Maybe a fake one will show it like that
@Daunlouded
@Daunlouded 4 жыл бұрын
My Samsung SSD's are shown almost exactly like that: "Samsung SSD 850 EVO 500GB". However Seagate's HDD is shown as "ST4000VX007-2DT166" so it shows only the model number and nothing else. This is running Windows 8.1 Pro, so I dunno if it makes a difference when running other OS.
@kenny-ph9dw
@kenny-ph9dw 4 жыл бұрын
rename
@mick7909
@mick7909 7 жыл бұрын
love that they know we are playing with them... I hope loads of them watch this vid, tell their scum friends and they all start checking... the more time we make them use up every time ... the less cslls they take.
@hernanipereira
@hernanipereira 3 жыл бұрын
Jim, i personally i have great admiration and respect for the work u do in this channel, scamming the scammers, reporting them to the autorities, etc, and this video is another example of it. One of the best of this kind (scambaiting, tech-savy stuff etc). Thank you for another informative and useful video!
@SireSquish
@SireSquish 7 жыл бұрын
Do the reverse on your tech naive family/friend's computers as a backup in case they are fooled by scammers :)
@roddydykes7053
@roddydykes7053 4 жыл бұрын
Awesome idea, as a “why not” kind of thing
@darynkatano
@darynkatano 5 жыл бұрын
A better way to change the device names, which also works with other virtual machine software is to open device manager, and for each device that gives away that it's a VM opening its properties, opening the "Details" tab, copying the "Driver key" value, searching the registry for it, and changing the "Friendly name" values, or creating them, after giving yourself permission to edit the keys
@EUHUGOROGER
@EUHUGOROGER 11 ай бұрын
WOW THANKS FOR THIS COMMENT! HELPED ME OUT A LOT!
@ShaunDobbie
@ShaunDobbie 7 жыл бұрын
Can you please do a tutorial on capturing the data in wireshark?
@ShaunDobbie
@ShaunDobbie 7 жыл бұрын
Thanks, could you also tell me what websites give these scam popups? I had one with an 0800 number and lost the number.
@rosalieivady1886
@rosalieivady1886 7 жыл бұрын
Pirate Bay??? Really? Gosh, I go there quite often, but never seen one.. True as it is I just ignore all irrelevant content there - and now that I check this post is 5 months old :D
@hasnieking
@hasnieking 7 жыл бұрын
In Wireshark go to the tab capture, then options. A window will open with your network cards. Select the one you're using and click start. That's all.
@mikejameson7678
@mikejameson7678 7 жыл бұрын
Enter Wireshark (not legacy). In the "...using this filter:" command box, write 'udp'... The box will turn green. After that, click on "VirtualBox/VMware Host-Only Network." Or "Wireless Network". Thats it.. You get many IP's. But if some are unrelated to "192." 'Series', its a secondary connection, comming from a website, or direct connection between two Computers. That aren't from the same network.. No Problem!
@VulcanOnWheels
@VulcanOnWheels 6 жыл бұрын
If you want to know more about Wireshark, then watch this playlist: kzbin.info/www/bejne/bImYhaqsfL17hpI
@renmikandhevaryndaypi
@renmikandhevaryndaypi Жыл бұрын
Even though this tutorial is designed for virtual machines, it helped me fix an issue with HID devices on my real system. Thanks, Jim.
@the_synack
@the_synack 7 жыл бұрын
+Jim Browning To make Windows 10 not report that its running under a hypervisor, you'll have to add this to your vmx file. cpuid.1.ecx="0---:----:----:----:----:----:----:----" This will mask out the bit in the CPUID that lets the OS know its running under a hypervisor, otherwise it'll say in the task manager under performance -> CPU that its a virtual machine, which could blow your cover. Not sure what the performance impact is, but I'm sure it probably isn't much if any at all. Also, msinfo32 will also report that the machine is running under a hypervisor unless you change this.
@grady.stu.8300
@grady.stu.8300 4 жыл бұрын
I'm over halfway through all your videos. Not only are you the first channel to do that but I also watch them in entirety. I really enjoy your videos man.
@NithinJune
@NithinJune 4 жыл бұрын
Jim: "I have to go out to programs, and back to programs and features to see the changes" Refresh button: "Am I a joke to you?"
@curiouscollectiblesAU
@curiouscollectiblesAU 4 жыл бұрын
Having to click refresh button to see new changes F5 hotkey:
@daddykool3290
@daddykool3290 2 жыл бұрын
Jim's instructed are quite clear. This is a virtual machine so it’s OK to poke around the registry but it’s even more important that you only change the registry if you know what you’re doing especially on a non virtual machine. Thanks Jim.
@adrasx6999
@adrasx6999 4 жыл бұрын
So in order to improve the security of my family members I just need to rename their devices to VMWare. That's a nice idea :D
@obfuscated3090
@obfuscated3090 2 жыл бұрын
If your family members have thin clients connecting to a VM server you get ease of administration further improving their security. Used thin clients are often very reasonable and powerful enough to be thick clients if you want that.
@ericmiller3284
@ericmiller3284 4 жыл бұрын
Another exceptional video, clear, concise and to the point and extremely informative to the viewer. I can't thank you enough for all your hard work and time you put into creating this exceptional video!
@Baked_Potato1996
@Baked_Potato1996 6 жыл бұрын
i love at the beginning he sees the VM ..."oh...alright" and hangs up lol gives up
@KaleshwarVhKaleshwarVh
@KaleshwarVhKaleshwarVh 4 жыл бұрын
I really felt it when you said ' please comment and subscribe because it gives me MOTIVATION to do these kinda videos '. I have subscribed long back I start with liking the video and then watch it. But that hit me. Thank you for spreading awareness.
@ahmedsalman3294
@ahmedsalman3294 3 жыл бұрын
I wish to have more tutorials from you. This is brilliant stuff. You are a hero jim.
@lgarcia67
@lgarcia67 3 жыл бұрын
This is awesome, the more people fighting back the better. Listening to those conversations I can tell that they have some very basic knowledge of computers and dos commands. They know enough to scam old people.
@pipbaxter5286
@pipbaxter5286 6 жыл бұрын
I would really like to see you getting into all the machines on their network and transferring horrendous viruses that will take ages to get rid of.
@alexanderdelguidice4660
@alexanderdelguidice4660 4 жыл бұрын
I've been working on something that takes advantage of AnyDesk's file transfer system that does what you described. It doesn't infect every computer on their network but it takes their computer down. It's on github and is simply called "Fake AnyDesk Update"
@HassanSelim0
@HassanSelim0 4 жыл бұрын
@@alexanderdelguidice4660 The instructions say "connect to the scammer's pc using AnyDesk", but doesn't the scam usually involve them connecting to me and not the other way round? How do you get the files to their PC?
@ultimatedude5686
@ultimatedude5686 4 жыл бұрын
Hassan Selim He has some way to reverse the connection idk how
@followthemoney1466
@followthemoney1466 3 жыл бұрын
Im 9 months late to this, but it seems BossMan takes care to not infect them, just call them on their BS. He also occasionally mentions the legality of what he is doing....does that concern any of you guys with infecting them? ....easy, easy, I dont need the lecture..the thieving scamming sunsabeaches should get everything they deserve every day of the week, and twice on Sunday...just asking for input from other viewers ...and yah, make their computers hotter than radioactive sludge, serves the mofos right....if you care to hehe
@c9rm3n
@c9rm3n 3 жыл бұрын
I started watching these videos a few weeks ago, and have thought about doing something similar to what you are doing, I'm sick of these 6 spam calls a day. Thanks for showing this, though I'm still not sure I'm going to try it. I frequently waste their (scammer's) time but what I've seen you do in video over the last week has been epic. Keep up the great work.
@chrisangel7383
@chrisangel7383 7 жыл бұрын
thank you for what you do, and helping us keep up with the ever changing environment!
@kabo0m
@kabo0m Жыл бұрын
I came back for this on my NEW PC! Thanks Jim as always!
@usernamenotfound4047
@usernamenotfound4047 7 жыл бұрын
Alternatively you could just make the scammer unable to even check those entries in the first place. I also suggest setting the registry entries from an Admin command line instead of changing permissions in the registry. But great tutorial. (Name your Devices "Tech Scammer detected!" and see what they do :D ) I also wonder how Tech Scammers deal with Linux machines
@grandpied
@grandpied 7 жыл бұрын
Scammers are allergic to penguins.
@therealb888
@therealb888 7 жыл бұрын
The_Matrix, linux is also much more open than windows. Don't be a linux fanboy. Once u have the root password linux is far less secure than windows. Check out that channel that has a guy's mother who tries new oses. Their videos go like "Mum tries to destroy ubuntu" or something.
@bitelaserkhalif
@bitelaserkhalif 6 жыл бұрын
b888 sudo rm -rf --preserve-root
@shadowsinsomniacs9943
@shadowsinsomniacs9943 6 жыл бұрын
Also the point of this is to waste the scammers time, if you have linux they will just hang up...
@whydohandlesexistAAA
@whydohandlesexistAAA 6 жыл бұрын
b888 "once u have root password" You would need to get it from the actual user since linux doesn't store passwords in plain text. Considering people don't randomly tell people with malicious intentions their root passwords, windows doesn't stand a chance in terms of security. You usually don't encounter ransomware which use leaked NSA backdoors on linux.
@useemehere2
@useemehere2 3 жыл бұрын
I love your channel and you are a Hero for me because you help a lots of people specially those seniors who have a little knowldage about PC and I'm so happy that you are teaming up with other KZbinr like Pierogi (ScammerPayback) and some other who are really very helpful in combating this plague of society. More power to you all. We are your fan and thank you for your service.
@kluchaklepana8371
@kluchaklepana8371 7 жыл бұрын
7 scammers hate this
@XxalightnerxX
@XxalightnerxX 6 жыл бұрын
Fuck i fell for your picture
@mbocco83
@mbocco83 6 жыл бұрын
I came here to write too, I thought I had a damn scratch on my screen.
@Blobbo
@Blobbo 6 жыл бұрын
26*
@robbievermillion5101
@robbievermillion5101 6 жыл бұрын
28
@BillAnt
@BillAnt 6 жыл бұрын
And 34 likes your comment ;)
@praevasc4299
@praevasc4299 5 жыл бұрын
Please don't forget to not leave the browser's history empty. That's among the first things they check. They ask what browser you use, they open it, see that the history is empty or almost empty, then they make an attempt at syskey then hang up. It's also recommended to just have a scammy pop-up ad visible in one browser tab, because they often start with asking you to show them the error message you got. It seems they've already encountered many scambaiters who just call them on the number they've seen in other scambaiting videos, but can't show them the "error message".
@CyberQuickYT
@CyberQuickYT 4 жыл бұрын
Windows: so you need regedit edit these fields which are found using this weird key. Linux: just fucking sudo nano /etc/whatever
@undefinednotfound
@undefinednotfound 4 жыл бұрын
@top text Nano is the best
@Tamramsy
@Tamramsy 4 жыл бұрын
Justinas nano is the best but vim is superior for editing code
@undefinednotfound
@undefinednotfound 4 жыл бұрын
@@Tamramsy vim is too confusing
@undefinednotfound
@undefinednotfound 4 жыл бұрын
@top text???
@markwilkinson3375
@markwilkinson3375 4 жыл бұрын
vim gang represent
@HippieInHeart
@HippieInHeart 3 жыл бұрын
you probably know this by now but just in case anyone else comes along who doesn't know it: f5 to refresh does not only work in the browser, it also works in normal folders and windows. so instead of always having to go out and back in to the installed programs window, you can simply hit f5 and it should refresh automatically. can't test this myself right now unfortunately, but i'm fairly certain it'll work.
@zorsenothorse
@zorsenothorse 4 жыл бұрын
Presses windows key, starts typing VMware, "sir you are on a virtual machine"
@elephystry
@elephystry 4 жыл бұрын
I think that’s only if you have Tools
@HassanSelim0
@HassanSelim0 4 жыл бұрын
it's trivial to delete vmware from your start menu list, it's just shortcuts.
@MrSaemichlaus
@MrSaemichlaus 4 жыл бұрын
Leave a tab with a Jim Browning video open on your granny's pc. Scammers will know and leave.
@danielabrahams4061
@danielabrahams4061 4 жыл бұрын
Or have a 'scam baiting' desktop background - or set a text message for the background like 'I know this is a scam' :)
@F4LDT-Alain
@F4LDT-Alain 4 жыл бұрын
I've just hit by accident a French language (my native language) equivalent of these fake "Critical Windows Alert" pages today. I've made a quick call, someone picked up so the number still is active. It's a grey and slow week-end so I'm going to have some fun with them too. But before this I shall use this helpful information to carefully disguise my VM, thanks. Now up to playing amateur Jim Browning too!
@followthemoney1466
@followthemoney1466 3 жыл бұрын
It is 9 months later, hoping you got them better than they got you
@AhnafAbdullah
@AhnafAbdullah 5 жыл бұрын
You have to give those scammers props, at least they were smart enough to figure out that it's fake Wish they used that intelligence on helping people...
@Frog-ko6uu
@Frog-ko6uu 3 жыл бұрын
Beautiful video man! I use VirtualBox from time to time, and making it look like a real computer might come in handy. This is what makes Windows so amazing IMO, you can change just about anything about it. That also means you can screw it up and have to start over, but that’s a nice thing about a VM.
@jonathanrose829
@jonathanrose829 6 жыл бұрын
Your computer needs fixation before you can go to the goat house.
@nichderjeniche
@nichderjeniche 4 жыл бұрын
7:49 "...let's try Nvidia" and almost typed NVindia 😅 Jim is cursed
@feelx92ger
@feelx92ger 4 жыл бұрын
Dear Jim, there's still the services by VMware, however a tiny program called Resource Hacker can be used to rename those. I suggest you put an addendum in the video description. Otherwise, great work as always. :)
@sheechwan
@sheechwan 3 жыл бұрын
Me : Watching this video since I like your style of "anti-scamming" and find it enjoyable Also me : Realized within the first 4 minutes of the video what I was doing wrong for recovering access on my old 'My Passport' external drive so it's no more on 'Read-only'. (Literally just my dumb self writing 'Admin' instead of 'Username' and almost pulling my hair out wondering what else I could do to fix it, without realizing I was at the right place all along...) Tl;dr : I thank you for indirectly fixing a problem of mine, as well as thanking you for your 'anti-scammers' work!
@TechSquidTV
@TechSquidTV 4 жыл бұрын
Had an interesting situation where a scammer connected and was somehow immediately alerted to the fact he was in a VM. What ever "custom" remote tool they used "bogar" had some kind of VM detection.
@mgjk
@mgjk 4 жыл бұрын
Bomgar?
@Gmon750
@Gmon750 3 жыл бұрын
I run a lot of Windows VM's on my Mac, including bare-bone Windows VM's, perfect for scammers to get into. I actually enjoy answering phone calls from scammers, but haven't yet gotten far enough for them to try connecting to my computer as they usually hang up on me the moment they realize I'm not as gullible as they first believe. I like this. May try it down the road.
@firearmretreat
@firearmretreat 7 жыл бұрын
Thank you for all that you do
@Rickety3263
@Rickety3263 4 жыл бұрын
Please do more of these! I’ve discovered proxmox and NoMachine and scam baiting or not, you have a lot to offer viewers with your knowledge of VM’s.
@AERoVALKYRiE
@AERoVALKYRiE 5 жыл бұрын
how to destroy indian economy 101. thank you for the tutorial
@beardymcbeardface69
@beardymcbeardface69 2 жыл бұрын
LOL I've been primarily running my work machines as VM's for the past 18 years! Courtesy of VMware Workstation, then VMware Server, Fusion, ESX and ESXi. The benefit of adhoc, regular and multiple automated snapshots is just WAY too awesome and the performance hit is negligible. I can also move my VM's from physical machine to physical machine via USB or in an automated fashion with syncing over a network or the Internet. Device abstraction means that PC upgrades are completely devoid of driver issues, periodical snapshots eliminates risks associated with upgrades, malware and user errors and VM's being comprised of files for disk image, memory image (for online snapshots) and VM configs, means that offline and offsite backup is absolutely trivial. I'm glad to see that some scammers would think my regular setups are merely to scam trap them. LOL Although I'm never going to chat with them, much less install AnyDecks.
@Walterbgaming
@Walterbgaming 7 жыл бұрын
It would actually be NVIDIA GeForce GTX 1080 -a GTX 1080 owner
@televisionandcheese
@televisionandcheese 6 жыл бұрын
I'd do something more like my video card, AMD X1550 256mb. It's something more likely to be owned, people with a GTX 1080 are not likely going to fall for tech scammers. It's hardware description is 'AMD Radeon X1300/X1550 256 series video accelerator' It is from about 2006, so say it's maybe 10 years old when they ask how old the computer is.
@sayadiyeojhenries.815
@sayadiyeojhenries.815 6 жыл бұрын
Imagine saying NVdia GeForce GTX 9000 Ti Intel Core i15@9999GHz Samsung 90TB ata
@DeRockMedia
@DeRockMedia 6 жыл бұрын
I just went to my main computers info and found what card I use (along with most of the setting changes)...but it prolly doesnt matter too much
@how2pick4name
@how2pick4name 6 жыл бұрын
Yeoj Henrie Sayadi Mine says NVIDIA Geforce GTX 940
@douglaskwdofi6501
@douglaskwdofi6501 5 жыл бұрын
Also, what if the scammer is smart enough to ask to open the NVIDIA control panel?
@WoodyWilliams
@WoodyWilliams 4 жыл бұрын
Love your instruction style. 1st time through I was hooked on every word. Perfect pace.
@RandomPersonBruz
@RandomPersonBruz 4 жыл бұрын
the most technical comment section i have ever seen on youtube
@dylanswearingen7333
@dylanswearingen7333 3 жыл бұрын
We’re living in a great time if you think about it. A majority of scammers are answering the phone and having to check EVERY system they try to scam to make sure they aren’t the ones who are actually being scammed lmao.
@ian22222
@ian22222 7 жыл бұрын
What if the scammer goes into the C:/Program Files folder? Then they'd see the VMware folder and most likely do the same thing.
@EmanuelFrias
@EmanuelFrias 7 жыл бұрын
Then hide it as a system folder
@therealb888
@therealb888 7 жыл бұрын
Yup as simple as that!
@neilbaird2789
@neilbaird2789 6 жыл бұрын
Just manually name the folder something else when you install it.
@jamestor6700
@jamestor6700 6 жыл бұрын
you can hide folders
@GinMacdraugas
@GinMacdraugas 6 жыл бұрын
Make the folder hidden or change its name to replicate something Windows/Microsoft/Office(if VM has Office) related, for example, name it Windows Explorer or Outlook.
@coolblu77
@coolblu77 4 жыл бұрын
I Fear that these type of videos will somehow benefit scammers more. What's to stop them from creating a VM and when Scam baiters conect to their machines they'll be wasting their own time trying to shut down these scammers. We've already seen the scammer (at the start of this video) is catching on and is now looking for the VM machine. Sometimes in our quest to help prevent something/someone from hurting or taking advantage of people, we try to make those people (possible victims) aware of it, but we are invertedly making the scammers better and more aware of our methods. Without these videos we don't realise the scam, but also the scammers learn from them and become better scammers. Scammers stop watching these videos. Lol
@gtxg.
@gtxg. 4 жыл бұрын
Scammer : exists Jim : I know your t location, your ip address, and what you had for breakfast.
@nichderjeniche
@nichderjeniche 4 жыл бұрын
@M P Hello Scammer
@GhostCrypto-tm1tl
@GhostCrypto-tm1tl 3 жыл бұрын
Really first time to see something like this in VM .Thanks a lot for the detailed and comprehensive explanation :) .
@maurogori5425
@maurogori5425 5 жыл бұрын
To make it realistic, download some random files in the vm, so it looks like it's used
@RCFunEveryday
@RCFunEveryday 3 жыл бұрын
Jim, I've literally watched all of your videos and just noticed I am now all the way back in 2017!
@royal__twistt12cringealert91
@royal__twistt12cringealert91 6 жыл бұрын
One thing, if you go to Task Manager and go to Performance, it says “Virtual Machine: Yes”
@randamchills
@randamchills 7 ай бұрын
amazing video .. even though this is 7 years old I just built a computer using old stuff and a fresh hard drive to start scam baiting .. and followed these steps. The only thing you didnt cover was the stupid vmware logo in the my computer area which i've found other videos for but they seem to not work as i can't find the 6006 file that needs to be edited .. thanks for everything you do Jim!!!
@roccoranallo4027
@roccoranallo4027 4 жыл бұрын
Hey Jim question, everything has worked beautifully until I get to the point when I install the Stealthy registry key as Admin and it installs the new file you have titled Microsoft C++ but it does not remove the VM Ware tools form installed programs how do I fix this?
@kadanv8974
@kadanv8974 5 жыл бұрын
Jim you are so smart thank you for making this vid normally I would just prank call the scammers but now I waste there time even more and you should be working with Microsoft you are really intelligent
@proxeIO
@proxeIO 3 жыл бұрын
Scammer that can identify the vm after this, can probably just get a job.
@henrikhansen1023
@henrikhansen1023 3 жыл бұрын
Most of them can - which I told one. Then he hung up
@danejurus69
@danejurus69 5 жыл бұрын
Oh, I'm gonna have so much fun. Thanks a ton, Jim!
@BrianB.-lb8du
@BrianB.-lb8du 6 жыл бұрын
Jim... did you ever do a VBOX/WIn7 version ? If so, I can't seem to find it. Link? Thnx bro
@Lantrex
@Lantrex 6 жыл бұрын
Enjoy your work. Have you toyed with the idea of creating a guide from start to finish? Wireshark, VM setup, a general overview. I think most of us here could kill some time by pestering some scammers too!
@slaaneshnurgle3720
@slaaneshnurgle3720 5 жыл бұрын
I wouldn't pick a 1080 if you gave your VM only 2 gb ram.
@kaydog890
@kaydog890 5 жыл бұрын
Published on Feb 12, 2017
@yannick4425
@yannick4425 5 жыл бұрын
@@kaydog890 lol
@yotoprules9361
@yotoprules9361 4 жыл бұрын
It would make more sense to put it as Intel HD 4000 graphics, or NVIDIA GeForce GT 710, a couple of examples.
@RingZero
@RingZero 6 жыл бұрын
Truly brilliant Jim! Good work 👍🏼
@Freeak6
@Freeak6 6 жыл бұрын
One other thing you want to make stealth are the services. They often ask you to go in services to show you how many services are stopped. But in there you have VMWare services. You can rename them by going to: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services And find the services you want to rename, then change their DisplayName and/or Description. Most of them will be start with vm so they're easy to find. One was in VGAuthService. Otherwise you can just do a right click on the Services folder, and do find, to find services related to VMWare. Once it is done, you have to restart the VM for changes to take effect. After restart, go back to services.msc and sort them by name, and go check you don't see any VM something.
@RayTech70
@RayTech70 5 жыл бұрын
Excellent post-- didn't realize you could do that :)
@TremereTT
@TremereTT 6 жыл бұрын
I love you! This is the real approach. If we want to WIN we need multiplyers !!! There should be whole chanels to help people becomming scambaiters and to make scambaiters more sophisticated in theire game! Populate the whole internate with scambaiters! The world needs: *Scambaiting propaganda -A Brand, as brands form social identities. -A Logo, because the world is all visual nowadays. -A Motto, because visions draw-in like minded people and communicate the spirit of "the movement". *Community -A platform that helps Scambaiters acting "as one" in the public -A platform to share scambaiting techniques -A platform to share and improve modells of monetizing scambaiting -A platform to share best practices to avoid legal problems, while scambating or striking back
@AlphaSQUADofficial
@AlphaSQUADofficial 7 жыл бұрын
wow!!! new video please
@goldencheats23
@goldencheats23 4 жыл бұрын
Wooow grappe
@reedsquint4107
@reedsquint4107 4 жыл бұрын
Want some fries with that?
@FractXD
@FractXD 3 жыл бұрын
Oh wow
@ninjashinobi2413
@ninjashinobi2413 2 жыл бұрын
Fantastic stuff mate, I have time on my hands I may just indulge myself doing this kinda thing, thanks for all you do bro.
@rome0610
@rome0610 4 жыл бұрын
As last step I'd reccomend to rename solitaire.exe to syskey.exe (and delete the original file). So you also can blame the Scammer to play on your computer! :)
@xyzzy-dv6te
@xyzzy-dv6te 4 жыл бұрын
Or rename it to syskey.exe.bak
@Suburp212
@Suburp212 6 жыл бұрын
Love these videos. Very useful. Always makes me realize how little I know about my pc...
@melody_florum
@melody_florum 7 жыл бұрын
uHM... the VMware Tools doesn't dissapear...
@leusmurphy
@leusmurphy 6 жыл бұрын
Hex *You don't use it.*
@crazycomicsincHidden
@crazycomicsincHidden 6 жыл бұрын
the best way (probably not good if you game via vms): dont have vmware tools installed at all.
@scavanger1000
@scavanger1000 6 жыл бұрын
well you probably shouldn't let scammers connect to your main vm
@Blobbo
@Blobbo 6 жыл бұрын
That's why I use VirtualBox oh....... shit it VBox tools :|
@lenders1164
@lenders1164 3 жыл бұрын
Jim you are a gift to humanity my dude. Keep it up good sir.
@UncleKennysPlace
@UncleKennysPlace 4 жыл бұрын
I'd build a VM that was seriously infected, with real viri, to see if the scammers would fix anything if it actually existed.
@black69camaro2344
@black69camaro2344 4 жыл бұрын
only if it infects there network....... lol
@rizones2286
@rizones2286 4 жыл бұрын
They would just straight convince you to buy their "antivirus" program with overpriced price
@jnawk83
@jnawk83 3 жыл бұрын
ask for a free demo "there are scams out there"
@NiftyTrader-Hemanth
@NiftyTrader-Hemanth 7 ай бұрын
You are the best. The rest are just having fun with even innocent call centers
@herossin
@herossin 7 жыл бұрын
Jim, awesome video man. Really helped me out. A couple of notes thought. I found a couple other things that out right say VMWare on my system, I don't know if it's for everybody but if it is they're VMWare VMCI Bus Device and VMWare VMCI Host Device under System Devices (I'll put the driver keys at the bottom) Also, if the scammers are particularly vigilant they may notice you have an NVidia card but don't have Geforce installed as most users often do. And if you'd like help with making your VM look legitimate someone recommended me ninite.com so you can download all you programs at once. Lastly, a question. Do you know how to change it so in task manager under performance tab it does not say "Virtual Machine: Yes"? Driver Keys: VMWare VMCI Host Device Driver Key {4d36e97d-e325-11ce-bfc1-08002be10318}\0133 VMWare VMCI Bus Device Driver Key {4d36e97d-e325-11ce-bfc1-08002be10318}\0132
@herossin
@herossin 7 жыл бұрын
I see, that's a shame but suppose you're right. I do hope anything I said in the comment will be of use to you and thanks for getting back to me so quickly.
@klaus_niemand
@klaus_niemand 7 жыл бұрын
the "yes" is language related and most likely in a localization file, perhaps search them for all "yes" strings to replace these with individual 3 digits so you can identify the one that is displayed in task manger and change it into 4E 6F 20 ?
@semsuddin
@semsuddin 4 жыл бұрын
I literally just wanted to ask the same question. I'm trying to make VM as close as possible to the real machine but that one part is really hindering the success. How to have the same task manager as on host?
@stableianF1oracle
@stableianF1oracle 3 жыл бұрын
I'll try and set up the virtual system based on your help.
@RugtimXII
@RugtimXII 4 жыл бұрын
Jim, how can you make sure that the scammers won't find a way to break out of the virtual machine into your actual computer? I'd be very interested in a video on that topic!
@williamcampbell9859
@williamcampbell9859 4 жыл бұрын
Thats not really possible, you dont know what you're talking about.
@RugtimXII
@RugtimXII 4 жыл бұрын
@@williamcampbell9859 Oops, I'm sorry, William!
@swagar
@swagar 4 жыл бұрын
@@williamcampbell9859 VM escapes aren't impossible at all, actually. Pentesters make quite a lot of money when they find and report them to VMware and the like. So to answer how to prevent it, keep your software on the host side up to date.
@Larry_C_191
@Larry_C_191 6 жыл бұрын
Great tutorial. The registry files need to be changed for VMWare 14. Easy to edit in notepad doing a find and replace. Replace: 43F974C0D0E8C1C4D9CA1C70A1C60570 with A1119D3420AE2864FBC3FECD6BA2980B. Thanks again Jim for all your great videos and help.
@Azrael_Garou
@Azrael_Garou 6 жыл бұрын
The perfect virtual machine would be to just use some old computer you have collecting dust around the house, bonus if it's newer than a Pentium 4. You could also liberate a retro machine from most thrift stores, yard sales, and you may even have friends or families willing to part with an old beater. It's relatively inexpensive to fix up and use an old machine, parts are cheap on ebay or Amazon and best of all, you don't need to put your expensive daily driver in harm's way *and* it takes one more old pre-built off the used market so people are encouraged to donate the newer hardware they won't use and can't really sell so it discourages new purchases, promotes used sales of newer hardware and cuts into the bottom line of maliciously greedy corporations, forcing them to cut inflated prices. Basically, if you want a fail-proof scam bait machine, just buy an older beater so you don't risk your pride & joy.
@Azrael_Garou
@Azrael_Garou 6 жыл бұрын
@@JimBrowning That may be true, but how many amateur scambaiters would you trust to advocate they use their personal system? At least with a physical machine, they don't run the risk of it being destroyed by more tech savvy scammers. The most dangerous narrative to run a scambaiting operation on is the certainty that your mark lacks a certain capacity for intelligence like so many of these cherry-picked videos represent where the scammer appears dumber than the person baiting them. There's no opportunity for viewership and thusly no money in showcasing the more intelligent scammers who caught on to the operation immediately or flipped the script on the baiters. Why not just acknowledge those issues outright instead of immediately dismissing the utility of a physical machine over the lazy convenience of a VM?
@ShenLong991
@ShenLong991 6 жыл бұрын
@@Azrael_Garou If someone access the real hardware even remotely you have a hardtime to restore the machine. With remote PCs you just can take a snapshot and restore. But i do acknowledge that you should run this on a separate Machine where you have remote access to prevent them to outbreak your VM (if able... i mean. there evolving like viruses...)... and i would suggest to put that machine to a different Network as your main-network. because everything is safer than direct access to your real network.
@crazi7144
@crazi7144 6 жыл бұрын
I use real hardware - and when I need to restore, I have CloneZilla. Re-images in about 10 minutes. Also DeepFreeze works good. Laptop is on WiFi VLAN so no risk of other devices getting hit or detected.
@penelopeplimsoul3617
@penelopeplimsoul3617 5 жыл бұрын
Love your vids and you, man! Kudos for all the good work. Enjoying binge watching your vids!!
@syedhassanraza2571
@syedhassanraza2571 3 жыл бұрын
Sir! You should start a course of teaching such stuff! I believe you will earn alot!
@siyacer
@siyacer 3 жыл бұрын
He can't, else he risks giving scammers more information, and what he does is illegal.
Scammers Raided Live!
19:37
Jim Browning
Рет қаралды 7 МЛН
Downloading a scammer's files [Re-upload]
17:17
Jim Browning
Рет қаралды 5 МЛН
Trick-or-Treating in a Rush. Part 2
00:37
Daniel LaBelle
Рет қаралды 7 МЛН
This dad wins Halloween! 🎃💀
01:00
Justin Flom
Рет қаралды 54 МЛН
Osman Kalyoncu Sonu Üzücü Saddest Videos Dream Engine 269 #shorts
00:26
Cool Parenting Gadget Against Mosquitos! 🦟👶 #gen
00:21
TheSoul Music Family
Рет қаралды 34 МЛН
How to create a simple Scambait Virtual Machine
26:58
Revolts
Рет қаралды 17 М.
I Tried Real Augmented Reality Glasses!
20:29
Marques Brownlee
Рет қаралды 3 МЛН
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,6 МЛН
Inside a Pig Butchering Scam
16:33
Jim Browning
Рет қаралды 3,2 МЛН
The Dead Grad Student Problem
1:10:18
BobbyBroccoli
Рет қаралды 753 М.
I bought a freeze dryer so you don't have to
1:00:15
Technology Connections
Рет қаралды 1,1 МЛН
A scammer sends me a virus! - Part 1
16:04
Jim Browning
Рет қаралды 3,8 МЛН
TeamViewer strikes back!
13:49
Jim Browning
Рет қаралды 3,3 МЛН
Almost NOBODY Else Has The World's Best TV
24:24
Linus Tech Tips
Рет қаралды 1,2 МЛН
Trick-or-Treating in a Rush. Part 2
00:37
Daniel LaBelle
Рет қаралды 7 МЛН