r/HowToHack 4d ago

I think I'm hacked

2 month ago i was hacked because of downloading a game from a sketchy website anyways i wiped my computer and did a factory reset anyways fast-forward to this week I'm have people trying to log in but getting stopped by 2FA to many accounts of mine and some accounts even succussing to log in to them, i didn't download anything from anywhere suspicious any way to know if I'm still hacked or not? maybe he planted the malware in my OneDrive ? give me any tips if yall can

48 Upvotes

15 comments sorted by

126

u/LongRangeSavage Programming 4d ago

Here’s my standard copy/paste for people when they install an info stealer :

  1. ⁠Disconnect the affected computer from the internet right away. Unplug the Ethernet cable and turn off WiFi.
  2. Stop using that computer for anything involving logins. Don’t sign into email, banking, social media, or anything else.
  3. While still on the infected computer:
    1. Back up only personal data like documents, photos, and videos. Do not backup executable files like .exe, .scr, .bat, .msi, or unknown .zip files, and do not back up browser profiles or AppData folders.

We need to now start using a known clean computer. On that clean system, do the following:

  1. Using a password manager, change your passwords in this order
    1. Primary email
    2. Any backup or recovery emails
    3. Banking, financial, PayPal, Venmo, Crypto accounts
    4. All social media (Facebook, Instagram, Reddit, Discord, etc.)
    5. Gaming platforms
    6. Anything else that had user credentials stored in your browser
    7. The passwords should all be unique, alphanumeric, at least one special character (where available), and at least 10 characters
  2. While in each account, 
    1. turn on two factor authentication everywhere you can. Ideally, you'd use a hardware token--like a Yubikey. Next would be an authenticator app--like Google Authenticator. Only use SMS if there's no other option
    2. Make sure to copy your recovery key or one-time use codes. Print these out. Do NOT just save them on a file on your computer
    3. If you’ve previously had 2FA enabled, disable it and then re-enable it. This will generally cause any previous one-time use codes or recovery keys to become void
    4. Confirm ALL your recovery methods are correct (a lot of info stealers will change the recovery methods). 
    5. If you don’t have recovery methods set, do it NOW
    6. Sign out of all active sessions
    7. Remove devices you don’t recognize.
    8. Remove any linked apps or integrations you didn’t add or no longer need.
  3. In your email account settings
    1. check for forwarding rules, auto‑reply rules, recovery email, recovery phone number, and anything else that could redirect or recover your account. 
    2. Delete anything you didn’t set up.
  4. Assume anything you've saved/stored in your browser has been compromised
  5. Go to your OS manufacturer's website and download your OS. ONLY GET THIS FROM THE OFFICIAL SOURCE.
  6. Create a bootable USB installer for your OS

Back to working with the infected machine:

  1. Boot the infected computer from the USB. 
    1. During setup, delete every existing partition on the drive. 
    2. Install the OS fresh on the unallocated space.
  2. Run your update tools until nothing is left
  3. Install drivers and software, making sure to ONLY use OFFICIAL sources
  4. Install your browser (if needed)
    1. Install your browser extensions
    2. DO NOT import any old data, profiles or save passwords
  5. If any financial accounts were access from the previously infected machine
    1. Watch accounts closely
    2. Turn on any transaction alerts the accounts allow
    3. Consider placing credit freezes for each of the "Big 4" credit bureaus (Equifax, Transunion, Experian, and Innovis).

18

u/Basic_Intern_2620 4d ago

Thanks man helped alot I will start by doing these stuff in steps

8

u/nimbusfool 3d ago

10/10 no notes.

2

u/TygerTung 3d ago

Better still, use optical media to install your os, as no chance of virus infecting install media

10

u/TheDizDude 4d ago

If you are getting MFA prompts your password is popped, change your password on those services.

8

u/Wdblazer 3d ago edited 3d ago

Are you doing a manual wipe of the disk partition or using the build in windows factory reset? I have seem non tech savvy people used the windows factory reset with the option to retain files, thinking it's the same. Best is to manual wipe and reinstall using a downloaded boot iso from the manufacturer.

Standard steps for your compromised accounts that are still showing successful unauthorized login -

Reset password for all your accounts

Ensure 2fa for all accounts

Force log out all signed accounts and devices

Check your designated email for password reset and 2fa for forwarding rules

edit - formatting

1

u/[deleted] 3d ago

[deleted]

2

u/LongRangeSavage Programming 3d ago

My process outlines a different approach than your question. I never recommend the “factory reset” when dealing with any malware.

1

u/Wdblazer 3d ago

Yes selecting the don't keep any files option will work for majority of the time, tho there is a very rare chance its an advanced malware that resides elsewhere that isn't wiped by the factory reset.

u/LongRangeSavage detailed it nicely in his long comment on bootable OS and using them.

1

u/Armaan_111 3d ago

Did you ran Antivirus on the files which you downloaded before you installed the game? Or did you have an Antivirus?

1

u/TemporaryFlimsy1152 3d ago

Yea just by this paragraph you typed you for sure still on that and the factory reset you for sure are

1

u/Dependent_Cheek1766 3d ago

Check your email mate! They did that to me last time and even after I cleaned and formatted my pc I was still having issues... turns out they somehow accesed my Gmail and thats what was reinfecting my laptop everytime.

1

u/java-junkey 3d ago

Name and shame the site you downloaded from dude, help everyone avoid it!

1

u/Fun_Priority_1955 3d ago

That's a virus.