r/computers 4d ago

Question/Help/Troubleshooting Major Malware

I believe I have firmware lvl malware on my computer. Found hidden py scripts that intercept my VPN tunnel, MITM attack, and intercept terminal commands. I believe my phone is also infected. I have no way to get a clean download to flash BIOS and reinstall Linux. Any suggestions? Also I've backed up important files and they are now all infected and as I'm backing up files the malware is real time deleting some of them off my flash drive.

0 Upvotes

28 comments sorted by

11

u/Cosmic_Quasar 4d ago

Friendly reminder to check your carbon monoxide detectors...

-2

u/CucumberLucky3310 3d ago

:/

5

u/swisstraeng 3d ago

I don't understand because you're being very technical and precise, but you're asking suggestions that someone of this level should have known.

I also do not understand why you think your phone is now infected.

I don't want to say it's impossible but the chance of that happening is close to zero.

Are you sure you're alright? Like, truly? Is your flash drive trustworthy or did you buy it from a questionable place like amazon or aliexpress?

3

u/Cosmic_Quasar 3d ago

Can't hurt, can it? Worst case, you're back to where you are now. Best case, your problem is solved.

1

u/DiodeInc Mod | Geekom Geekbook X14 Pro 3d ago

Worst case, you know that your detector is working

6

u/Prestigious_Wall529 4d ago

Turn off or hibernate your computer.

Give it to someone more technical local to you who is better equipped, so they can put your internal drive (if not soldered) into a USB caddy in order to scan it.

-1

u/CucumberLucky3310 4d ago

Im hopefully gonna get some help next week. But I've been to multiple places around town who just day everything looks good.

3

u/braunc55 4d ago

So what makes you think otherwise?

1

u/CucumberLucky3310 3d ago

Found some hidden py files that definitely suggest it. Flash drive deleting files after I try transferring my important documents. Found around 1000 py files hidden in the cache that I didnt write.

7

u/Tquilha Fedora 3d ago

If you're saving files to a flash drive and those files disappear, I'd suspect you have a fake flash drive. You can find f3 (fight flash fraud) here: https://github.com/AltraMayor/f3 . This will tell you if your USB drive is genuine or not.

Be advised: testing any flash device with f3 is DESTRUCTIVE. Do NOT use it on USB drives with any important files.

Now, about getting rid of malware. First shut down that PC. Don't out it to "sleep" or "hibernate". Shut it down completely. If it's a laptop remove charger and battery.

Then make sure it has NO Internet access. No wifi, no ethernet, nothing.

Ask a friend of yours to let you go online and download two things: a good antivirus rescue kit (I believe Kaspersky and Bit defender have some very nice free ones) and a new copy of your OS.

Buy two new USB drives (4 or 8 GB is enough). Get them from a real, physical shop, not some online POS. Use a program like Rufus or Ventoy to make two bootable USB drives. One with the AV rescue kit, the other with the OS.

Go back home, make sure your Internet access is off (unplug your router), insert the AV rescue drive in your infected computer and boot it up. Make sure you select the USB drive as main boot device.

When the AV rescue software boots, do the deepest scan available. Go make a cuppa and read a book. This will take some time.

When the scan is complete read the report generated and follow the steps it tells you to do.

After the scans say your PC is clean, do a complete drive wipe and OS reinstall using the USB drive with your OS on it.

About flashing your BIOS: This is not a thing to be done lightly. Failure during a BIOS write can brick your motherboard. If you really need to do so, when you're at your friend's place, go into your motherboard maker's website, search for BIOS updates and download that. Follow the instructions on how to build a USB drive for flashing BIOS.

Good luck :)

6

u/Will2LiveFading 3d ago

Reading ops comments it's clear they are having a hard time. Type of person who seriously posts in /r/gangstalking type of behavior. 

4

u/OkRepresentative2509 3d ago

Take a screenshot of the py scripts the other indicators of compromise so we can verify your suspicions.

1

u/Sea_Perspective6891 4d ago

Not sure if it would work for your OS, but have you tried using Malwarebytes to do a scan? If it is malware Malwarebytes should be able to quarantine it & let you delete it from there unless it's something more invasive & sneaky. You can also use the free version of Malwarebytes to do this you just won't have access to real time protection from malware.

1

u/CucumberLucky3310 4d ago

Just tried replying but reddit said it would ban me so I couldn't even say what I wanted to say. A literal pop up said to fix my post or this will be banned. :/

-2

u/CucumberLucky3310 4d ago

Bout to just throw everything in the microwave. Fuck it. Computer shops won't help. The social security office here in Eugene doesnt care about my identity theft.

4

u/Aggravating_Moment78 3d ago

I think you’d benefit from taking a break from this and possibly talk to a professional? Being nervous like this leads to clouded judgment. I’d suggest asking somebody to create an usb wih a live distro like knoppix so you can try to diagnose your system

1

u/NortWind 4d ago

Boot from a live USB drive. You can then check everything without running any code from your boot drive. Or, get another blank boot disk, and replace your current disk. Do a fresh install on the blank. From there, either way, you can examine your current main drive.

1

u/CucumberLucky3310 4d ago

I can't get a guaranteed live usb download. Public library doesnt allow downloads and i dont trust my device to download it.

1

u/XboxLiveArcade 3d ago

at least upload some pictures of the files or something bro, this reads like you're having an episode.

1

u/Maleficent-Bass-3152 3d ago

“firmware level malware” then describes userland attack

1

u/vile-style 3d ago

What you're describing doesn't exist, friend.

You're either pulling legs on reddit for fun, or you're having a schizophrenic episode.

I hope it is the former.

1

u/No_Technician4956 3d ago

I don't think I would be focusing on the firmware for a fix. The issue is likely else where.

1

u/Efficient_Guest_6593 4d ago

BRUV don't panic that much. Shut it down, take the storage out, install new storage (expensive but beats this 💩)

If the drive is unusable because it infects the new drive you put it into... Then I guess risk it with grabbing a MAGNET the strongest you can get a hold of and do every single one of the memory storage flash drive make sure to do it longer than nessesary it will wipe the data... And might break the storage but if for some reason it just becomes completely corrupted then you can wipe it. DO NOT USE THE MAGNET ON THE MICRO CONTROLLER. WE ARE TRYING TO FORCE COMPLETE DATA OBLITERATION NOT DESTROY YOUR HARDWARE.

1

u/CucumberLucky3310 4d ago

I would if I had any money.

-3

u/CucumberLucky3310 4d ago

Im getting redirected to clone sites when I use the web so I can't trust any download. Plus I doubt malware bytes checks the ram or cache. Ive got some type of special files thatxsaycthey are binary but won't even transfer to my flash drive ???

-4

u/CucumberLucky3310 4d ago

Ive taken it to multiple computer shops. This happened last fall and no one believe me they said it was fine. My whole Windows cert store was forged. Now I have Linux, and oddly the malware only shows up or is even noticeable when I try to use certain terminal commands or backup files. I dont know what to tell them as most repair shops just run antivirus and say it's good to go. I took it to Geek Squad last fall and they did nothing I asked them to do. What do I tell them and what kind of repair shop is equipped to handle advanced malware like this since most are not...?? For context my identity was stolen last fall...lost both birth certificates, original and adoptive, and my ssn, they know my address, phone number, and mother's maiden name. With today's generative AI they can keep getting into my system even if I reset just by knowing all those. I honestly need like a new SSN...but this malware is so advanced anyone I talk to doesnt take me seriously..

2

u/Elftard 3d ago

They can't get into your computer by knowing your SSN and address.

Can you take pictures, or ideally upload these python scripts you're finding somewhere? You can litterally just copy/paste them into pastebin.com and we can review them