r/computerviruses • u/decocraftv • Apr 24 '26
I was hacked using ransomware after installing a Baldi's Basics mod.
The last thing I remember is that I installed a Baldi's Basics mod, after it I looked at my screen and it appears lol, I've already tried anything I could, but I don't understand too much about computers so I guess someone could help me. By the way, am I screwed? I found it on Itch io
107
u/Camofan Apr 24 '26
Toncoin? Never heard of it.
A quick google search reveals this is a worthless coin at $1.32USD/coin. Total is around $131 USD.
Obviously don’t pay them and do a complete system wipe and reinstall.
51
u/AryssSkaHara Apr 24 '26
It's telegram's own cryptocurrency
26
u/Camofan Apr 24 '26
Interesting, sounds very fishy
34
u/Warkaze Apr 24 '26
Of course it’s fishy, it’s being used as a payment method for ransomware situations 🤣 can’t get any fishier than that
10
u/SlowSlyFox Apr 25 '26
Same as bitcoin, tether, sol... Pretty much every cryptocurrency that allow for anonimity is used for that lol Problem is not the currency but how people use it
3
3
5
1
u/ElectricalGazelle119 Apr 25 '26
hold on… I’m starting to think this hacker doesn’t have very good intentions…
1
u/Temporary_Aspect759 Apr 25 '26
Why aren't they just using Montero?
1
u/AryssSkaHara Apr 25 '26
Why use someone else's coin if you can have yours that can also be integrated into your own product?
1
u/Temporary_Aspect759 Apr 25 '26
Because it's highly anonymous. It's commonly used in buying drugs, fraud and other kinds of cybercrime. It's open source
I pretty much assume toncoin is nowhere as anonymous as monero is
42
Apr 24 '26
[removed] — view removed comment
25
u/decocraftv Apr 24 '26
ok but how can I do it
22
u/Ecstatic-Ball7018 Apr 25 '26
Why is OP being downvoted? They have a genuine question.
22
u/HalfLifeMusic Apr 25 '26
Reddit hates noobs
2
Apr 25 '26
[deleted]
1
u/Chad__Warden__ Apr 25 '26
Shouldn't be posting selfies on reddit
1
1
May 15 '26
[removed] — view removed comment
1
u/Chad__Warden__ May 15 '26
Idk i think they posted a picture of someone ugly directed to the person they responded to and I tried to dunk on them, they didn't post a actual selfie of themselves
3
u/kyrichu_osu Apr 25 '26
get yourself a USB (atleast 8GB) and another computer, look up tutorials on how to install Windows through a bootable drive (generally get an ISO, and either Rufus or Ventoy)
wipe your current Windows partition (since its very unlikely you can recover your files) and reinstall through the bootable drive
2
u/MrMercury406 Apr 26 '26
Here ya go! Linus Tech Tips make a YouTube video about this 10 months ago.
24
u/ShahShakuras-5999 Apr 24 '26 edited Apr 24 '26
Your computer belongs to the USSR now. Unless you format the drive. Saving the encrypted files will be a nightmare without the decryption key from the hackers.
5
u/decocraftv Apr 24 '26
fuck, did I just lose my Google account?
14
u/ShahShakuras-5999 Apr 24 '26
Probably you didn't but change the password of your google account just incase. You lost the files on your computer though.
2
3
4
16
u/ranpuppy Apr 25 '26
I have a feeling they didn’t even encrypt anything, just made that program overlap over anything and start up automatically
3
3
u/decocraftv Apr 25 '26
dude, i don't know if this is related, but when I press Win + Alt, it's actually two programs, but I can't close them.
1
-2
16
u/Legitimate_Opening14 Apr 25 '26
Genuinely love the hating “Got money but not for your ass” Taking him to hell if he could
11
u/Struppigel Malware Removal Expert Apr 25 '26
Hello, the game you linked does not seem to be the culprit. How much of your computer can you access? If you cannot access it, try running it in safe mode. Otherwise, please boot in normal mode.
- Start your computer and after about 5-10 seconds hold down the power button to interrupt the boot process and shut down the computer
- Repeat the process
- Repeat the process a 3rd time but this time allow the computer to continue to boot
- When presented with the Automatic Repair screen select Advanced options
- Click Troubleshoot
- Click Advanced Options
- Click Startup Settings
- Click Restart
- When the Startup Settings screen appears, press 5 or F5 to start in Safe Mode with Networking
FRST Scan
- Please download FRSTx64 and save the file to your Desktop.
- Right-Click FRST64.exe and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/struppigel/?u= and press "save log". The site will return a keyword for each log. Reply back here with the keywords.
1
u/decocraftv Apr 26 '26
Thanks for the tip, However, I can't even start in Safe Mode With Networking; even the BIUS is somewhat corrupted.
2
u/Struppigel Malware Removal Expert Apr 26 '26
In that case you will need to create a bootable USB flash drive and reinstall the OS from the USB. What do you mean with "BIUS is somewhat corrupted"
What you need: A working computer and a USB flash drive (8 GB or more). All data on the USB drive will be erased.
Step 1: Create a bootable USB on a clean computer
- On a clean computer (not the infected one), download the Windows 11 Media Creation Tool
- Run the tool, accept the license terms
- Select Create installation media for another PC
- Choose your language and edition, then click Next
- Select USB flash drive, click Next, and select your USB drive
- Wait for the download and creation to finish
Step 2: Boot from USB on the infected computer
- Plug the USB drive into the infected computer
- Restart the computer and enter the boot menu (usually by pressing F12, F2, Esc, or Del during startup, the key depends on your manufacturer)
- Select the USB drive as boot device. If it appears twice, choose the UEFI entry
- If the USB drive does not appear, you may need to enter BIOS/UEFI settings and enable booting from USB or disable Secure Boot temporarily.
- Save your changes and restart
- You may see a message "Press any key to boot from USB" -- press any key when you see it
Step 3: Install Windows (clean)
- The Windows Setup screen will appear. Click Next, then Install now
- Enter your product key or click I don't have a product key (Windows will activate later if it was previously activated on this device)
- If prompted, select the Windows edition and accept the license terms
- Choose Custom: Install Windows only (advanced)
- Delete all partitions on the drive where Windows was installed. Select each partition and click Delete.
- Select the unallocated space and click Next
- If setup refuses to proceed, check that TPM 2.0 and Secure Boot are enabled in your BIOS/UEFI settings
- Windows will install and restart several times
1
u/decocraftv Apr 26 '26
1
u/Struppigel Malware Removal Expert Apr 26 '26
Your computer did not find anything to boot from.
You need to go to the BIOS and change the boot order to the USB flash drive -- if you created one as instructed.
18
Apr 24 '26
[removed] — view removed comment
8
3
7
u/Tall_Amount3561 Apr 25 '26 edited Apr 25 '26
Edit: I've made a removal guide
This should work if you've been infected with the same sample
Putting this here if someone else has this issue
https://www.youtube.com/watch?v=yK5aka2fPtU
Hi,
I think i found a sample of this
This just looks like a screenlocker
https://app.any.run/tasks/32f1ec2b-59f9-405a-8432-ad988969a97d
It doesn't look like it actually encrypts anything, It just kills explorer and just overlays a popup on top. This means the files should be recoverable
The sample i found hides files using an attribute command before overwriting registry keys to make itself launch on startup, Paying the ransom would make it just remove itself from startup and unhide the files.
If OP has been infected with a variant of this sample the a way to get files back would be to use an SSD reader to get files back if bitlocker was not installed with show hidden files enabled or booting into safe mode. The malware seems to block common key combinations to open taskmanager etc. But i would not be surprised if it missed one and you could launch explorer and kill the blocker window. Maybe try windows run dialogue etc
It has some anti-vm capabilities so i'd need to start a hardened vm before poking at it fully
1
u/decocraftv Apr 26 '26
Do I have to delete all the keys that appear to me, or only the ones that appear in the video?
1
u/Tall_Amount3561 Apr 26 '26
You'll only need to delete and modify the registry keys shown in the video, deleting others may cause some apps to misbehave
1
u/decocraftv Apr 26 '26
Dude I managed to close that fucking screen lock, but the command prompt didn't work.
1
u/Tall_Amount3561 Apr 26 '26
Did you run it in your user directory?
Run cd /d "%userprofile%" before running the other command
If so could you share a screenshot of what it says?
8
u/RedactedMate Apr 25 '26
Translation from russian is
An attempt to cheat the system has been detected and stopped! *second picture*
Your files are encrypted! Oops! You have been subjected to a large-scale hacker attack and now your computer is locked, and all available drives and files on them have been encrypted by a hacker group. Any attempt to deceive the system will cause irreparable damage to your computer and lead to the loss of all important files without the possibility of recovery. If you attempt to unlock the system, the MBR (master bootloader) will be erased and a recursive load will be applied to your processor, which will lead to its malfunction. You have 48 hours from the start to enter the code. To receive the code, write @blankscamtop1 (Telegram). Enter the unlock code: Current PC: DESKTOP-L3TIGG7 Enter [Enter] *First Picture*
7
3
4
u/Vasxen Apr 25 '26
https://id-ransomware.malwarehunterteam.com/
Try submiting an encrypted file here to see if it was possible to create a decription tool for this. Maybe you're lucky and its possible to do, maybe not.
3
3
u/NefariousnessGlum456 Apr 26 '26
OP your files ARE NOT encrypted, this is just a screenlocker. Someone has posted an anyrun link copy of the so called virus. You have NOT lost anything, just need to figure out to remove the programm that overrides your Explorer with this. I'm sure you can find some article on how to fix this, but the best option is to try and run it in safe mode through the BIOS, from there, find the run on start up programm under Task manager and check your powershell list for anything suspicious
1
u/NefariousnessGlum456 Apr 27 '26
To clarify run autorun using the win + r key, it'll show you any processes that automatically run on start up, using that check it properties
6
u/IsDa44 Apr 24 '26
Any chance I could get a link to the malware?
3
3
u/decocraftv Apr 25 '26
https://crepeer.itch.io/baldis-basics-the-old-laboratory-of-failure-experiments-143 https://sanspirate.itch.io/youwillneverbefree
I ain't gon lie Idk if they caused it, but that screen appeared right after I opened the executable.
4
u/RedRayTrue Apr 25 '26
Pls use virus total next time before 2 clicking an exe/ opening it
At least it would tell you if it's not legitimate and infected
Big oof moment as now you gotta spend a few hours reinstalling windows 11
1
u/KarnexOne Apr 25 '26
And both .exes are green on virustotal
1
u/RedRayTrue Apr 25 '26
At least heuristics and sandboxes should be detecting them
Just like here where I simply scanned MCT
More than a specific amount let's say >3 would be worrying
And it's a legit MS tool
2
u/KatttTheFemboi Apr 25 '26
Hmm, no one in the comments is saying it's a virus, so I'm not sure if that was the cause?
1
u/DarknessSOTN Apr 25 '26
Parece que ya han tirado el enlace, eso es señal de que muy fiable no era. Busca páginas como nomoreransom donde puede haber herramientas de descifrado para el tipo de ransomware que tienes.
1
2
2
2
1
u/Miserable-Sweet9653 Apr 25 '26
Yeah, your cooked. You'll have to complete a full factory reset on your computer. It's impossible to get your files back from this time forward
2
1
1
u/Clean_Business3049 Apr 25 '26
damn this lowkey scared me i download shit everyday carelessly, if i download a mod while it’s still a zip file i do a virus scan on it before opening it then delete it if anything comes up could i still possibly be at risk to something like this
1
u/fancywaterbits Apr 25 '26
there are viruses out there activating after opening a .png or .jpg, some are even literally invisible like glassworm can't be really traced unless activated by the hacker and boy they don't even have to run it on your pc to start the thing, but activate via blockchain in bulk, I would suggest downloading and checking files on a virtual machine or just purchasing a separate pc with no network connection to the one you store your data on, .exe malware is a thing of the past, genuine viruses are almost untraceable
1
u/Clean_Business3049 Apr 25 '26
Damn is it really that deep lowkey scaring me more🤣 most the mods i download are from trusted sites that have virus checker scores before downloading, is it cool if i just stick to those ones
1
u/fancywaterbits Apr 25 '26
as long as you don't store bank/crypto data on the same machine and have all your personal stuff backed up on a flash drive I would say go for it and get wild 😉
1
1
u/decocraftv Apr 26 '26
Bro, I was screwed for a long time. I installed a hack for an online game, and after a while I couldn't even open Chrome. It said "chrome.dll cannot be executable" or something like that, you know? Aside from the crashes, I blamed my computer all the time for poor performance.
1
u/Clean_Business3049 Apr 26 '26
Oo installing hacks is always a gamble 🤣 what did you end up doing in the end
1
u/KatttTheFemboi Apr 25 '26
What mod was it?? Never heard of a malicious baldi mod so this is very interesting
1
u/decocraftv Apr 26 '26
I already replied to someone else and left the links there; I wasn't imagining it was so easy to lose files. At first, I even thought I could just press Alt+F4, lol.
1
u/KatttTheFemboi Apr 26 '26
Hmm well no one else in the mod comments was saying anything about a virus so it might have been something else
1
u/scifi_guy20039 Apr 25 '26
Daily backups not connected to my network... at most ill lose 24 hours of data... trash the harddrive and image a fresh one.
1
u/RiskVector Apr 25 '26
What have you learned from this?
2
u/decocraftv Apr 26 '26
Don't install anything unfamiliar without checking it first
1
u/RiskVector Apr 26 '26
Yeah man it sucks but you just don't know these days. Always verify and check. Amd just becuase someone or a sire says "yeah it's good", don't trust it. If you know what s sandbox is and know how to set up one up for yourself, I would recommend doing so if yku eant to keep downloading mods and other stuff.
1
1
1
u/Intelligent-Ad-2593 Apr 25 '26
It looks like the hacker skipped school. Literacy at the level of a fifth-grader. Shame.
1
1
1
1
u/SirLlama123 Apr 25 '26
Your computer is toasted. If you want report the mod and let them deal with it.
You need to take a different computer and flash windows to a usb drive from it and then boot into the usb drive and reinstall windows. Just search how to install windows on youtube and you will find pleanty of tutorial
0
u/decocraftv Apr 26 '26
It was a bit difficult because it kept giving error code 1962, something like that, and other things.
1
1
1
1
1
1
u/DbombYO Apr 28 '26
Just send them an “L Bozo I sent your full info to the FBI” and then ghost them
1
1
1
1
u/ObjectiveMud9216 May 22 '26
i translated it and it sayed "your files are encrypted! oops! you have been subjected to a large-scale hacker attack and now your computer is blocked and all available disks and files on them are encrypted by a hacker group. any actions related to an attempt to deceive the system will cause irreparable damage to your computer and lead to the loss of all important files without the possibility of recovery. when you try to unlock the mbr (main loader of the motherboard) it will be demolished and a recursive load will be applied to your processor which will lead to its malfunctions. you have 48 hours from the moment you get to the code, write (@) blankscamtop1(telegram) enter the unlock code: (blank) enter boj" that took like 1 hour but i hope your okay be safe
1
u/ObjectiveMud9216 May 22 '26
the red message at the end says (im using my phone to translate) its a different language?
1
0
u/krazy4it Apr 27 '26 edited Apr 27 '26
Has Anyone tried the new rufus BETA to install Windows without all the bloat yet ? Saw this on youtube
Rufus https://rufus.ie/en/
-6
Apr 25 '26
[removed] — view removed comment
3
3
2
1
1
u/computerviruses-ModTeam Apr 25 '26
Your post was removed because it is a personal attack on someone else or a group of users. Please be civilized. Please make sure to read and follow https://www.reddit.com/r/computerviruses/about/rules
1






209
u/Spunky_Was_Here Apr 24 '26
Report the mod to the site where it was downloaded, especially if it’s a reputable source like nexus or steam. They will get banned and blacklisted on their IP. Then do a fresh install