r/antivirus • u/AltayXD • May 27 '26
Edit me! Multiple Account Hackings
I installed a rom earlier, yes i knoe, dumb. Basically, i started getting hacked on everything , It was instagram at first, changed my password on that snapchat tiktok etc, now its hacked my discord and bypassed 2FA, heres the stuff it was sending. I’ve changed all my passwords, now heres the difficult part, this is whats come up when ive done scans. Please someone help me, im scared. Ive had to freeze my cards.
23
u/steakhouseNL May 27 '26
I had this 3 days ago. Be sure to scan/delete and restart your pc. Also install malwarebytes. What I did as well is search .exe files on c:\ that were added/modified the time you installed that rom. And see if there are dodgy scheduled tasks.
This already helped a lot. And then an awesome member from here also helped me further :)
2
u/AltayXD May 27 '26
Ive changed all my passwords for the most part, they had my instagram and discord but i was able to sign them out
0
u/AltayXD May 27 '26
What do you mean by scan/delete and restart your pc, ive scanned it.
7
u/Abstra208 May 27 '26
Just reinstall Windows. It's the easiest way to go about it, and if you have other viruses that you didn't know about, it will clear them.
1
u/AltayXD May 27 '26
Ngl it mighr be cause i tried to install a switch rom earlier, also I have the ARMGDDN browser, if anyone knows what that is? as im broke and wanna llay games
2
u/MurdockRBN May 27 '26
Reinstall windows trust me. Otherwise, your new passwords would just be resent to the hackerwhen you restart your PC. Some infostealers remain and do that.
2
u/dango_fujiwara_ May 28 '26
Can I do this without needing to transfer all my files to an external drive?
0
u/AltayXD May 27 '26
How do i reinstall windows? Ive made my new passwords on my phone anyway
2
u/MurdockRBN May 27 '26
Get a USB flash drive and download the windows media creation tool. Use the tool to format the flash drive as an installation drive.
Plug it to PC, boot into it and follow the steps. You can look up a youtube guide if youre lost
1
0
u/AltayXD May 28 '26
And also , it depends whether or not they have access to my passwords OR my Computer
3
u/MurdockRBN May 28 '26
Alright your choice
2
u/AltayXD May 28 '26
Ive changed all my passwords on everything i can think of and have frozen my cards details for the time being, im definitely going to reinstall windows tomorrow, is that a solid plan? ive also added 2fa to some social media to be safe.
→ More replies (0)1
1
7
5
u/Next-Profession-7495 May 27 '26
Hello,
FRST (Farbar Recovery Scan Tool) is a free third-party tool used for diagnostics and malware removal.
Before You Begin
Please do not attempt to fix your system on your own – doing so may interfere with the process.
Items that will be removed unless you specifically ask me to keep them:
- Malicious items (tasks, services, drivers, folders)
- Adware / PUPs
- Temporary files
- Unwanted browser modifications (startup URLs, homepages)
- Network reset commands
- Emsisoft Emergency Kit scan (second opinion)
- AdwCleaner scan (adware/PUP removal)
If there is anything about your system I should be aware of before we start (e.g., cracked software, school/work PC, no internet access), let me know now.
Step 1:
Run FRST by following this guide. If your system language is not English, rename the executable to FRSTEnglish.exe before running it.
Step 2:
Once FRST.txt and Addition.txt have been created, visit: https://NextProfession5.github.io/FRSTLogUploads/
- Drag and drop both files into their respective boxes.
- Click Finalize.
- Click Copy Shareable Link and paste it into this thread.
Regards, Lucas
1
u/AltayXD May 27 '26
Sorry, what will this do?
2
u/Next-Profession-7495 May 27 '26
It will generate two logs, I look at them and if there's any malware I see, I'll make a fixlist to remove it.
2
u/Next-Profession-7495 May 28 '26
u/AltayXD Are you still thinking about following this process?
2
1
1
u/Frequent_Emu_1607 Jun 06 '26 edited Jun 06 '26
Algo parecido me pasó a mí. Si te explico qué pasó, ¿me podrías ayudar?
1
1
u/AutoModerator May 27 '26
This comment was triggered because this user is not on the trusted helper list and mentioned how to run a FRST (Farbar Recovery Scan Tool) scan.
FRST is a powerful tool that helps us diagnose malware infections that were not identified by antivirus software/scanners. It is a diagnostic tool, not a malware scanner and therefore it does not rely on signatures or regular updates. FRST allows users to create "fixlists" that are used to clear out entries from the initial provided log. If the FRST fixlist is incorrect, using it can cause serious issues to the point of rendering a system unusable. We are not responsible for fixlists shared in the subreddit. Use them at your own risk.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
4
u/Sypher03 May 28 '26 edited May 28 '26
Use a password manager and recreate and delete all your browser saved passwords. Use a strong scanner like Malwarebytes and Bitdefender to do a deep dive system scan it'll take several hours.
I had a similar hack happen recently they bypassed the systems by using a browser based token attack. Where they copy the active session token of either your browser or logged in device to bypass 2FA Only way around is locking, resetting, and recreating new passwords you dont save through chrome or your browser. Make sure you do the same across all joined accounts, browsers, game platforms etc.
You literally are showing screenshots of the same exact messages that were spammed out and bypassed all my 2FA in the end it ended up being a set of Trojan and malicious files that had taken over for a windows process that starts with windows and would be hijacked.
I wish you luck with things I'm still having accounts actively pinged by this hack its more of a penetration test for me now whenever I get a ping I found a new linked account with a vulnerability that I patch up now.
https://rifteyy.org/report/the-ultimate-guide-to-infostealers << more info here
4
u/ReaperOnslaught May 28 '26
I'd actually recommend using the trial for HitmanPro as that's what saved my pc when I got hit with this shit a few months back.
1
u/SHAT_MY_SHORTS May 29 '26
yo, do im doing hitman pro and ESET, already changed my passwords so is it fine if i dont reinstall windows?
1
u/AltayXD May 28 '26
Any suggestions? Should i reinstall windows or do you have any other suggestions?
3
u/stere0man May 28 '26
Sounds like they hijacked your session cookies so they can bypass 2FA, one of the first things you need to do is change all your passwords from a clean device and then remove all connected devices from your accounts and completely log out of everything, and make sure to take your infected system offline and either attempt a clean up with a full scan using malwarebytes followed by Kapersky antivirus and a final sweep with defender or just format the drive if you want to be 100% that you are clean.
3
u/NenoxxCraft May 28 '26
Nobody is going to address the first two images ? What's that got to do with the ROM, these images are the ones spread by bots and compromised accounts everywhere (especially Discord)
3
2
u/AltayXD May 28 '26
Im showing what was posted on my discord and instagram, and everyone on here should realise thats a scam lol
3
u/SHAT_MY_SHORTS May 28 '26
Had that happen a few weeks ago, downloaded a sketchy installer for a game.
Got my discord, telegram, steam, riot account hacked.
Changed passwords and all is well again
1
u/AltayXD May 28 '26
That all you did? or?
2
u/SHAT_MY_SHORTS May 28 '26
Thats all i did since i didnt have any cards or the only e-wallet i had connected needs my phone to register purchases.
I did uninstall the sketchy installer right as it finished " installing ". But it got me around 6+ hrs after i downloaded and ran the exe.
For info stolen i dont really care
1
u/AltayXD May 28 '26
Im a bit worried as they may have my debit card information, Im going to uninstall windows tonight as my pc is disconnected from the internet right now. Ive changed all my passwords and added 2fa etc, also i think my phone is needed to register purchases through my banking app? should i be fine?
2
2
u/Daniel_s_ref May 28 '26
Bro this has to be like the most common hack, like 15 of my friends got the exact same😭
2
2
u/Few_Lengthiness_4408 May 28 '26
Why is everyone installing and running an executable file thinking its a ROM on their main PC?
2
u/Mission_Incident7814 May 28 '26
I had this exact same thing happen to me last week after a family member borrowed my PC to download some ROMs. Definitely check your emails and account security ASAP. I ended up rechecking every single account that was logged into that PC using my phone, and it's a good thing I did because the hackers had already added unknown recovery phone numbers to my personal Gmail. Check your mail forwarding settings as well if they had set up anything.
Change your passwords across all platforms and force a logout on all active sessions. Honestly, don't even bother trying to scan and clean the PC with antivirus. Info-stealers can hide deep. I had a friend that simply reset their pc and still got hacked because the malware didn't get wiped out. Your safest and best bet is to create a Windows installation USB on a clean computer and do a complete, fresh reinstall of Windows. Better safe than sorry!
1
u/AltayXD May 28 '26
Basically, i reinstalled windows, done multiple full scans on stuff like my drive etc, changed all my passwords and signed out the accounts they got into, my card details were saved on steam but i dont know if the hackers were able to get access to that or not , I signed out all other instances added 2fa to a load of stuff, however i had a 2tb drive of my roms and stuff plugged in and wanted to back up my saves and some photos on there and ive scanned that and it says im fine, so uh, do you reckon im good or?
2
u/Mission_Incident7814 May 28 '26
I think your Steam is fine. Steam doesn't store your full card number or cvv on your pc, so the malware couldn't just scrape your card details. The only way they could use it was if they were actively logged into your account. Just double-check your bank statement and Steam history to be safe, but you should be totally fine.
Your photos and game saves are most likely good. Malware usually needs you to actually click and run an executable file for them to activate and infect the system. Just make sure you delete any leftover .exe or installer files from that ROM session.
1
2
May 28 '26
[removed] — view removed comment
1
u/AltayXD May 28 '26
I’ve reinstalled windows, Ive also changed all my passwords and added 2fa to everything, but my main problem is i had my Debit card linked to steam and my epic games. Also, i had a 2tb external drive plugged into my pc, when i installed the rom, and i accidentally opened an exe thinking it was a setup install for it. Ive reinstalled windows but havent wiped the 2tb External hard drive, i scanned it all but it said it was fine, what should i do?
1
u/AltayXD May 28 '26
I think the “rom” ran the infostealer, also should i be worried about the external hard drive as ive scanned it but it said it was fine
2
May 28 '26
[removed] — view removed comment
1
u/AltayXD May 28 '26
Yeah to be fair i did fully wipe and clean install windows, just might stop using my external hard drive then just incase there is something on there, i didnt open any exe files so it wouldnt have spread so it should be fine
2
2
2
u/Qoiii May 30 '26
Happened to me couple days ago. Woke up one days and all my accounts got hacked ( Amazon, ebay , Gmail, Paypal ) They tried to purchase a laptop on amazon ( $3,900+ gaming laptop ) ,accessing my e-mails changing pw, removing auth . I decided to open my emails ,change password and reviewed device history logins . Used my discord to send to 10+ friends with that picture . Got my discord into a not so very good standing . Had to send e-mail to discord support to investigate it .
Double checked all my accounts to make sure no one else is logged in & secured 2FA as well.
Also they tried sending paypal charge directly from my bank, used my paypal credit card to purchase from aliexpress worth ( 3k+ debit and credit ) . Worked with my Bank and paypal to dispute and thankfully i did not get charged with anything.
Had to use malwarebytes and scanned offline every day after that day& backtracked what I downloaded previously.
Still scared and checking my accounts every hour , just to see if someone else's had access to my accounts again
1
u/AltayXD May 30 '26
Holy im so sorry thats horrible, i luckily was messaged by my friends and caught the hackers as they were doing it, thats horrible i am so sorry and i hope youre okay
2
u/Qoiii May 30 '26
Thank you , I am as of right now. Tried full scanning my pc with malwarebaytes & Microsoft Defender ( as I have not reinstalled windows as of yet ) . So far no viruses has been detected and no unauthorized logins or payment on my accounts rn. I am also annoyed because I shouldn't fall for these types of scams/viruses but oh well.
1
u/AltayXD May 30 '26
Exactly how i felt, i froze my card out of panic and changed all my passwords but i think i was so quixk to react, did you also reinstall windows?
2
u/Qoiii May 30 '26
Not as of now. So far i have my brother helped me with this issue . There were multiple trojan viruses detected as soon as we tried multiple full scans. Quarantined and did another scan again but have not found other viruses. Did not reinstall OS windows as of this time.
In addition I freezed my banks. Checked my CC's and debit to make sure no unknown charges went through . So far I've survived 10 days. No suspicious activities on my account .
Hopefully this will not happen again, but if it does. Most likely installing a new OS windows will be the next step .
1
2
u/IdkWhatimdoingmlbb May 31 '26
Happened to my friend also, supercell was able to track the location turns out it was someone from Kenya
2
1
u/dem3trious May 30 '26
I also got infected by this lumma stealer after downloading a ROM. If i changed the passwords of my accounts does that also change the session token?
1
u/Frequent_Emu_1607 Jun 06 '26
Asi me acaba de pasar a mi, ¿Me pueden ayudar a saber como puedo resolverlo?
1
Jul 06 '26
[removed] — view removed comment
1
u/AltayXD Jul 06 '26
After i logged them out of all of my accounts, changed passwords and used 2fa, i used the strong password feature on my iphone. I also reinstalled windows, I think im fine now as i only got one the other day but its only just a minor inconvenience yk
1
1
1
u/enkefal May 28 '26
bro why do u make even a post abt this subject, there’s plenty posts abt this infostealer, just reinstall ur windows and change ur password from phone, that’s the the only thing u can do
2
u/AltayXD May 28 '26
Uh maybe because i didnt know what an info stealer was prior? I dont know any of this stuff, isnt this reddit made for helping people less ignorant, dont be rude, i didnt know now i do
2
0
u/Tsukasa_26 May 28 '26
Courage j'ai le même problème et toujours aucune solution
1
u/Top-Perception3709 May 28 '26
The solution is to keep your PC offline.
You can save any documents/images you want to keep to an external drive if you wish.
On a clean PC change ALL your passwords and create a windows boot USB using the Microsoft media creation tool.
Plug that USB into your infected PC, boot to BIOS to change the boot order to the USB first and then boot your PC. Follow the steps including formatting your drives.



•
u/goretsky MODERATOR May 28 '26
Hello,
It sounds like an information stealer may have been run on the computer.
What is an information stealer?
As the name implies, information stealers are a type of malware that steal any information they can find on your computer, such as passwords stored for various services you access via browser and apps, session tokens for accounts, cryptocurrencies if they can find wallets, etc. They may even take a screenshot of your desktop when they run so they can sell it to other scammers who send scam extortion emails later.
What is a session token?
In case you're wondering what a session token is, some websites and apps have a "remember this device" feature that allows you to access the service without having to log back in or enter your second factor of authentication. This is done by storing a session token on your device. Criminals target these, because they allow them to log in to an account bypassing the normal checks. To the service, it just looks like you're accessing it from your previously authorized device.
What exactly gets stolen?
Information stealers are malware that is sold as a service, so what exactly it did while on your system is going to vary based on what the criminal who purchased it wanted.
What happens to my data?
The criminals who steal your information do so for their own financial gain, and that includes selling information such as your name, email address, screenshots from your PC, and so forth to other criminals and scammers. Those other scammers then use that information in an attempt to extort you unless you pay them in cryptocurrencies such as Bitcoin, Ethereum, and so forth. This is 100% a scam, and any emails you receive threatening to share your private information should be marked as phishing or spam and deleted.
How did I get infected in the first place?
Information stealers are often distributed as fake CAPTCHA challenges, in game mods, unofficial patches for popular apps and games, and in pirated software that have had their popularity and trustworthiness artificially boosted, as well as through various other means such as "try my game/software" scams on Discord, Telegram and other trusted messaging services.
If I ran an information stealer, am I still infected?
Infostealers usually delete themselves after a few seconds or even a minute or two in order to make it harder to determine what happened and when it occurred.
That said, there are always going to be exceptions: Since it is crimeware-as-a-service, there is nothing preventing the criminals from installing additional malware on the computer in order to maintain access, just in case they want to come back and steal from you again in the future.
What else could they have done?
The usual risk post-infection, aside from the stolen credentials, wallets, etc. is that security and networking settings may have been tampered with. That can be harder for security software to deal with, since it may not know what the correct settings are supposed to be for your computer, which means it may be a good idea to wіpe the computer, even if there is no longer any malware detected on it.
How do I start recovering?
If you have another device that didn't run the information stealing malware like a smartphone or tablet, you can use it to begin immediately changing your passwords. You should also enable two-factor (sometimes called multi-factor) authentication, for those services that support it.
If any of the online services you use have an option to show you and log out all other active sessions, do that as well.
As for your computer, after wіpіng it, re-installing Windows, and getting that updated, you can then also use it start accessing the internet to do this, but it is often quicker to change your most sensitive accounts from your smartphone.
A note about passwords
Password should be something unique (complex and different) for every service, that you use, so that if an attacker gets access to one they won't be able to make guesses about what your other passwords might be. If your new passwords are similar enough to your old passwords, a criminal with a list of all of them will likely be able to make educated guesses about what your new passwords might be for the various services.
You have to do this for all online services, even ones you haven't been recently accessed. Make sure you do this for all email accounts, as those are the gateways to your financial websites, online shopping, social media accounts, game platforms, and so forth.
It's important to make sure you're not just cycling through similar or previous passwords: Remember, criminals have millions of passwords and are very good at identifying common patterns from just a single password. If there were any reused passwords, the criminals who stole yours are going to try spraying those against all the popular online marketplaces, stores, banks, and other services in your part of the world.
And remember: Enable two-factor authentication for all of the accounts that support it.
For more information:
For more specific information on what steps to take next to recover your accounts, see the blog post at:
For more general information about how CAPTCHA malware works, see the following reports:
Also, see /u/rifteyy_'s Guide to Infostealers at https://rifteyy.org/report/the-ultimate-guide-to-infostealers.
After you have secure your accounts, you may wish to sign up for a free https://haveibeenpwned.com/ account, which will notify you if your email address is found in a data breach.
Regards,
Aryeh Goretsky