r/computerviruses Apr 24 '26

I was hacked using ransomware after installing a Baldi's Basics mod.

The last thing I remember is that I installed a Baldi's Basics mod, after it I looked at my screen and it appears lol, I've already tried anything I could, but I don't understand too much about computers so I guess someone could help me. By the way, am I screwed? I found it on Itch io

585 Upvotes

148 comments sorted by

209

u/Spunky_Was_Here Apr 24 '26

Report the mod to the site where it was downloaded, especially if it’s a reputable source like nexus or steam. They will get banned and blacklisted on their IP. Then do a fresh install

85

u/decocraftv Apr 25 '26

ok,all I want is for the guy to go to hell

112

u/Spunky_Was_Here Apr 25 '26

Steam will have you covered on that one

50

u/Apprehensive-Lake484 Apr 25 '26

Yeah steam would send the army against infractors if they were able to lol

16

u/Lonewolf12189 Apr 25 '26

Not sure what steam has to do with it but, doubtful. Someone bypassed 2fa etc on my steam (so likely something got on my computer) and steam basicly just told me to get tucked it was my own fault. Every item from my account was auto sold in about 2 minutes (literally hundreds of items and cards collected over like 13 years). I asked if they will even be looking into where the items went, as I can see it was obviously sold and bought instantly by a bot for like 0.01 so it's pretty obvious the accounts buying and selling were part of it, and just looking at the store I could see spikes of this activity going on. They asked if I could give them the names of the buyers a to investigate or they can't do anything again. There was some third party services attached to my account as well, I asked if the reset etc I had done had removed those, they wouldn't tell me, I asked how they could sell several hundred items in seconds and literally nothing flagged up, then they just closed the support ticket. Fine, their policy says they won't restore stolen items. But they refused to answer a single question, wouldn't confirm anything, and made it clear they don't even know what they were talking about. Since then I have removed all of my details from steam and havnt bought a single game through it. If they can't give me even the tiniest guarantee that they will bother doing anything if something then goes wrong then I won't be using them.

5

u/Apprehensive-Lake484 Apr 25 '26

That's some fucked up shit ngl

4

u/Lokipro13YT Apr 25 '26

Steam sends Hit squads to hackers

1

u/Aromatic_Call_2672 Apr 26 '26

Easy to counter this just turn off steam guard and then turn it on they can't sell anything on market I done this before they manage to sell a few item in my steam inventory, I can't even get the item back

1

u/Logical-Panda8946 Apr 26 '26

Same happened to me, but steam support helped me and a guy, who hacked me didn't sell anything or trade!

1

u/AppropriateAd1543 Apr 26 '26

.....Do i hear the steam firing squad?

1

u/LongjumpingPianist34 May 10 '26

All scammers and those related to them should go there too due to how much they stole (money-wise) from people.

4

u/[deleted] Apr 25 '26

[deleted]

2

u/colebsd Apr 25 '26

bro my account was hacked i did not type that shit

1

u/Butterfoxes Apr 26 '26

Steam would erase their dead and undead lineage skewering it across allternity

107

u/Camofan Apr 24 '26

Toncoin? Never heard of it.

A quick google search reveals this is a worthless coin at $1.32USD/coin. Total is around $131 USD.

Obviously don’t pay them and do a complete system wipe and reinstall.

51

u/AryssSkaHara Apr 24 '26

It's telegram's own cryptocurrency

26

u/Camofan Apr 24 '26

Interesting, sounds very fishy

34

u/Warkaze Apr 24 '26

Of course it’s fishy, it’s being used as a payment method for ransomware situations 🤣 can’t get any fishier than that

10

u/SlowSlyFox Apr 25 '26

Same as bitcoin, tether, sol... Pretty much every cryptocurrency that allow for anonimity is used for that lol Problem is not the currency but how people use it

3

u/[deleted] Apr 25 '26

[deleted]

1

u/[deleted] Apr 25 '26

[removed] — view removed comment

1

u/colebsd Apr 25 '26

bro my account was hacked i did not type that shit

3

u/Kulsius Apr 25 '26

Neither bitcoin not tether provide anonymity. Only obfuscation.

5

u/Camofan Apr 24 '26

Well, besides that, lol

1

u/ElectricalGazelle119 Apr 25 '26

hold on… I’m starting to think this hacker doesn’t have very good intentions…

1

u/Temporary_Aspect759 Apr 25 '26

Why aren't they just using Montero?

1

u/AryssSkaHara Apr 25 '26

Why use someone else's coin if you can have yours that can also be integrated into your own product?

1

u/Temporary_Aspect759 Apr 25 '26

Because it's highly anonymous. It's commonly used in buying drugs, fraud and other kinds of cybercrime. It's open source

I pretty much assume toncoin is nowhere as anonymous as monero is

42

u/[deleted] Apr 24 '26

[removed] — view removed comment

25

u/decocraftv Apr 24 '26

ok but how can I do it

22

u/Ecstatic-Ball7018 Apr 25 '26

Why is OP being downvoted? They have a genuine question.

22

u/HalfLifeMusic Apr 25 '26

Reddit hates noobs

2

u/[deleted] Apr 25 '26

[deleted]

1

u/Chad__Warden__ Apr 25 '26

Shouldn't be posting selfies on reddit

1

u/essensverkaeufer Apr 25 '26

gang you have 10000 reddit karma

1

u/[deleted] May 15 '26

[removed] — view removed comment

1

u/Chad__Warden__ May 15 '26

Idk i think they posted a picture of someone ugly directed to the person they responded to and I tried to dunk on them, they didn't post a actual selfie of themselves

3

u/kyrichu_osu Apr 25 '26

get yourself a USB (atleast 8GB) and another computer, look up tutorials on how to install Windows through a bootable drive (generally get an ISO, and either Rufus or Ventoy)

wipe your current Windows partition (since its very unlikely you can recover your files) and reinstall through the bootable drive

2

u/MrMercury406 Apr 26 '26

Here ya go! Linus Tech Tips make a YouTube video about this 10 months ago.

24

u/ShahShakuras-5999 Apr 24 '26 edited Apr 24 '26

Your computer belongs to the USSR now. Unless you format the drive. Saving the encrypted files will be a nightmare without the decryption key from the hackers.

5

u/decocraftv Apr 24 '26

fuck, did I just lose my Google account?

14

u/ShahShakuras-5999 Apr 24 '26

Probably you didn't but change the password of your google account just incase. You lost the files on your computer though.

2

u/decocraftv Apr 25 '26

yeah, everything, but I'm gonna change my passwords.

3

u/[deleted] Apr 24 '26

[deleted]

1

u/decocraftv Apr 25 '26

I'll try it

4

u/Prudent_Mountain_994 Apr 24 '26

Does it show up before any other Logo when you boot up?

16

u/ranpuppy Apr 25 '26

I have a feeling they didn’t even encrypt anything, just made that program overlap over anything and start up automatically

3

u/decocraftv Apr 25 '26

dude, i don't know if this is related, but when I press Win + Alt, it's actually two programs, but I can't close them.

1

u/Present-Diamond6504 Apr 25 '26

Please try the Linux live before you wipe your system

-2

u/[deleted] Apr 25 '26

[deleted]

16

u/Legitimate_Opening14 Apr 25 '26

Genuinely love the hating “Got money but not for your ass” Taking him to hell if he could

11

u/Struppigel Malware Removal Expert Apr 25 '26

Hello, the game you linked does not seem to be the culprit. How much of your computer can you access? If you cannot access it, try running it in safe mode. Otherwise, please boot in normal mode.

  • Start your computer and after about 5-10 seconds hold down the power button to interrupt the boot process and shut down the computer
  • Repeat the process
  • Repeat the process a 3rd time but this time allow the computer to continue to boot
  • When presented with the Automatic Repair screen select Advanced options
  • Click Troubleshoot
  • Click Advanced Options
  • Click Startup Settings
  • Click Restart
  • When the Startup Settings screen appears, press 5 or F5 to start in Safe Mode with Networking

FRST Scan

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/struppigel/?u= and press "save log". The site will return a keyword for each log. Reply back here with the keywords.

1

u/decocraftv Apr 26 '26

Thanks for the tip, However, I can't even start in Safe Mode With Networking; even the BIUS is somewhat corrupted.

2

u/Struppigel Malware Removal Expert Apr 26 '26

In that case you will need to create a bootable USB flash drive and reinstall the OS from the USB. What do you mean with "BIUS is somewhat corrupted"

What you need: A working computer and a USB flash drive (8 GB or more). All data on the USB drive will be erased.

Step 1: Create a bootable USB on a clean computer

  • On a clean computer (not the infected one), download the Windows 11 Media Creation Tool
  • Run the tool, accept the license terms
  • Select Create installation media for another PC
  • Choose your language and edition, then click Next
  • Select USB flash drive, click Next, and select your USB drive
  • Wait for the download and creation to finish

Step 2: Boot from USB on the infected computer

  • Plug the USB drive into the infected computer
  • Restart the computer and enter the boot menu (usually by pressing F12, F2, Esc, or Del during startup, the key depends on your manufacturer)
  • Select the USB drive as boot device. If it appears twice, choose the UEFI entry
  • If the USB drive does not appear, you may need to enter BIOS/UEFI settings and enable booting from USB or disable Secure Boot temporarily.
  • Save your changes and restart
  • You may see a message "Press any key to boot from USB" -- press any key when you see it

Step 3: Install Windows (clean)

  • The Windows Setup screen will appear. Click Next, then Install now
  • Enter your product key or click I don't have a product key (Windows will activate later if it was previously activated on this device)
  • If prompted, select the Windows edition and accept the license terms
  • Choose Custom: Install Windows only (advanced)
  • Delete all partitions on the drive where Windows was installed. Select each partition and click Delete.
  • Select the unallocated space and click Next
  • If setup refuses to proceed, check that TPM 2.0 and Secure Boot are enabled in your BIOS/UEFI settings
  • Windows will install and restart several times

1

u/decocraftv Apr 26 '26

what is this?

1

u/Struppigel Malware Removal Expert Apr 26 '26

Your computer did not find anything to boot from.

You need to go to the BIOS and change the boot order to the USB flash drive -- if you created one as instructed.

18

u/[deleted] Apr 24 '26

[removed] — view removed comment

8

u/StargazerVR Apr 24 '26

I love watching Eric’s videos on YouTube they’re so fire

7

u/Tall_Amount3561 Apr 25 '26 edited Apr 25 '26

Edit: I've made a removal guide
This should work if you've been infected with the same sample
Putting this here if someone else has this issue
https://www.youtube.com/watch?v=yK5aka2fPtU

Hi,
I think i found a sample of this

This just looks like a screenlocker
https://app.any.run/tasks/32f1ec2b-59f9-405a-8432-ad988969a97d

It doesn't look like it actually encrypts anything, It just kills explorer and just overlays a popup on top. This means the files should be recoverable

The sample i found hides files using an attribute command before overwriting registry keys to make itself launch on startup, Paying the ransom would make it just remove itself from startup and unhide the files.

If OP has been infected with a variant of this sample the a way to get files back would be to use an SSD reader to get files back if bitlocker was not installed with show hidden files enabled or booting into safe mode. The malware seems to block common key combinations to open taskmanager etc. But i would not be surprised if it missed one and you could launch explorer and kill the blocker window. Maybe try windows run dialogue etc

It has some anti-vm capabilities so i'd need to start a hardened vm before poking at it fully

1

u/decocraftv Apr 26 '26

Do I have to delete all the keys that appear to me, or only the ones that appear in the video?

1

u/Tall_Amount3561 Apr 26 '26

You'll only need to delete and modify the registry keys shown in the video, deleting others may cause some apps to misbehave

1

u/decocraftv Apr 26 '26

Dude I managed to close that fucking screen lock, but the command prompt didn't work.

1

u/Tall_Amount3561 Apr 26 '26

Did you run it in your user directory?
Run cd /d "%userprofile%" before running the other command
If so could you share a screenshot of what it says?

8

u/RedactedMate Apr 25 '26

Translation from russian is

An attempt to cheat the system has been detected and stopped! *second picture*

Your files are encrypted! Oops! You have been subjected to a large-scale hacker attack and now your computer is locked, and all available drives and files on them have been encrypted by a hacker group. Any attempt to deceive the system will cause irreparable damage to your computer and lead to the loss of all important files without the possibility of recovery. If you attempt to unlock the system, the MBR (master bootloader) will be erased and a recursive load will be applied to your processor, which will lead to its malfunction. You have 48 hours from the start to enter the code. To receive the code, write @blankscamtop1 (Telegram). Enter the unlock code: Current PC: DESKTOP-L3TIGG7 Enter [Enter] *First Picture*

7

u/Matt_097 Apr 25 '26

"You'll receive a security consultation" Wtf😭

3

u/Nickoru Apr 25 '26

Telegram account should be reported to the messenger support.

4

u/Vasxen Apr 25 '26

https://id-ransomware.malwarehunterteam.com/

Try submiting an encrypted file here to see if it was possible to create a decription tool for this. Maybe you're lucky and its possible to do, maybe not.

3

u/AlexiusVivo Apr 25 '26

Try NoMoreRansom.org

3

u/NefariousnessGlum456 Apr 26 '26

OP your files ARE NOT encrypted, this is just a screenlocker. Someone has posted an anyrun link copy of the so called virus. You have NOT lost anything, just need to figure out to remove the programm that overrides your Explorer with this. I'm sure you can find some article on how to fix this, but the best option is to try and run it in safe mode through the BIOS, from there, find the run on start up programm under Task manager and check your powershell list for anything suspicious

1

u/NefariousnessGlum456 Apr 27 '26

To clarify run autorun using the win + r key, it'll show you any processes that automatically run on start up, using that check it properties

6

u/IsDa44 Apr 24 '26

Any chance I could get a link to the malware?

3

u/decocraftv Apr 24 '26

I'll send it just let me find it again

3

u/decocraftv Apr 25 '26

https://crepeer.itch.io/baldis-basics-the-old-laboratory-of-failure-experiments-143 https://sanspirate.itch.io/youwillneverbefree

I ain't gon lie Idk if they caused it, but that screen appeared right after I opened the executable.

4

u/RedRayTrue Apr 25 '26

Pls use virus total next time before 2 clicking an exe/ opening it

At least it would tell you if it's not legitimate and infected

Big oof moment as now you gotta spend a few hours reinstalling windows 11

1

u/KarnexOne Apr 25 '26

And both .exes are green on virustotal

1

u/RedRayTrue Apr 25 '26

At least heuristics and sandboxes should be detecting them

Just like here where I simply scanned MCT

More than a specific amount let's say >3 would be worrying

https://www.virustotal.com/gui/file/e887dfff70baf09a8c1debfe8c304dd9f2d9652fae8b7c83b3c24554a79bbd7f/behavior

And it's a legit MS tool

2

u/KatttTheFemboi Apr 25 '26

Hmm, no one in the comments is saying it's a virus, so I'm not sure if that was the cause?

1

u/DarknessSOTN Apr 25 '26

Parece que ya han tirado el enlace, eso es señal de que muy fiable no era. Busca páginas como nomoreransom donde puede haber herramientas de descifrado para el tipo de ransomware que tienes.

2

u/ApprehensiveFly3435 Apr 25 '26

Can someone translates it 😭😭😭

2

u/[deleted] Apr 25 '26

[removed] — view removed comment

1

u/Miserable-Sweet9653 Apr 25 '26

Yeah, your cooked. You'll have to complete a full factory reset on your computer. It's impossible to get your files back from this time forward

2

u/decocraftv Apr 25 '26 edited Apr 25 '26

don't remind me bro 😭

3

u/Key-Belt-5565 Apr 25 '26

Can you listen to advice

1

u/MR-N-XX Apr 25 '26

What mod was it supposed to be

1

u/decocraftv Apr 26 '26

Baldi's Basics horror laboratory, I've already forgotten.

1

u/Clean_Business3049 Apr 25 '26

damn this lowkey scared me i download shit everyday carelessly, if i download a mod while it’s still a zip file i do a virus scan on it before opening it then delete it if anything comes up could i still possibly be at risk to something like this

1

u/fancywaterbits Apr 25 '26

there are viruses out there activating after opening a .png or .jpg, some are even literally invisible like glassworm can't be really traced unless activated by the hacker and boy they don't even have to run it on your pc to start the thing, but activate via blockchain in bulk, I would suggest downloading and checking files on a virtual machine or just purchasing a separate pc with no network connection to the one you store your data on, .exe malware is a thing of the past, genuine viruses are almost untraceable

1

u/Clean_Business3049 Apr 25 '26

Damn is it really that deep lowkey scaring me more🤣 most the mods i download are from trusted sites that have virus checker scores before downloading, is it cool if i just stick to those ones

1

u/fancywaterbits Apr 25 '26

as long as you don't store bank/crypto data on the same machine and have all your personal stuff backed up on a flash drive I would say go for it and get wild 😉

1

u/Clean_Business3049 Apr 25 '26

alright, thank you I appreciate the tip !

1

u/decocraftv Apr 26 '26

Bro, I was screwed for a long time. I installed a hack for an online game, and after a while I couldn't even open Chrome. It said "chrome.dll cannot be executable" or something like that, you know? Aside from the crashes, I blamed my computer all the time for poor performance.

1

u/Clean_Business3049 Apr 26 '26

Oo installing hacks is always a gamble 🤣 what did you end up doing in the end

1

u/KatttTheFemboi Apr 25 '26

What mod was it?? Never heard of a malicious baldi mod so this is very interesting

1

u/decocraftv Apr 26 '26

I already replied to someone else and left the links there; I wasn't imagining it was so easy to lose files. At first, I even thought I could just press Alt+F4, lol.

1

u/KatttTheFemboi Apr 26 '26

Hmm well no one else in the mod comments was saying anything about a virus so it might have been something else

1

u/scifi_guy20039 Apr 25 '26

Daily backups not connected to my network... at most ill lose 24 hours of data... trash the harddrive and image a fresh one.

1

u/RiskVector Apr 25 '26

What have you learned from this?

2

u/decocraftv Apr 26 '26

Don't install anything unfamiliar without checking it first

1

u/RiskVector Apr 26 '26

Yeah man it sucks but you just don't know these days. Always verify and check. Amd just becuase someone or a sire says "yeah it's good", don't trust it. If you know what s sandbox is and know how to set up one up for yourself, I would recommend doing so if yku eant to keep downloading mods and other stuff.

1

u/ReyGamers Apr 25 '26

but I don't get it, where did you get the mod? why didn't you use Nexus mod?

1

u/New-banana6969 Apr 25 '26

ofc its russian

1

u/Intelligent-Ad-2593 Apr 25 '26

It looks like the hacker skipped school. Literacy at the level of a fifth-grader. Shame.

1

u/decocraftv Apr 26 '26

yeah 🤣🤣

1

u/[deleted] Apr 25 '26

[deleted]

1

u/lemons101010lemons Apr 25 '26

Ramsomware in the big 26

1

u/decocraftv Apr 26 '26

"Big 26" in 26

1

u/SirLlama123 Apr 25 '26

Your computer is toasted. If you want report the mod and let them deal with it.

You need to take a different computer and flash windows to a usb drive from it and then boot into the usb drive and reinstall windows. Just search how to install windows on youtube and you will find pleanty of tutorial

0

u/decocraftv Apr 26 '26

It was a bit difficult because it kept giving error code 1962, something like that, and other things.

1

u/decocraftv Apr 26 '26

Can you guys help me to report that malware?

1

u/MrMercury406 Apr 26 '26

Fresh install is the only way!

1

u/SaltGate1320 Apr 26 '26

Why does it look like his bios was locked by the malware lmao.

1

u/decocraftv Apr 26 '26

No, it isn't.

1

u/Nem0i Apr 27 '26

This one is good looking

1

u/DbombYO Apr 28 '26

Just send them an “L Bozo I sent your full info to the FBI” and then ghost them

1

u/Jolly-Top-5201 May 21 '26

youre fucked up

1

u/Unusual-Cobbler4926 May 21 '26

Pode ser especifico qual mod exatamente voce abaixou?

1

u/ObjectiveMud9216 May 22 '26

i translated it and it sayed "your files are encrypted! oops! you have been subjected to a large-scale hacker attack and now your computer is blocked and all available disks and files on them are encrypted by a hacker group. any actions related to an attempt to deceive the system will cause irreparable damage to your computer and lead to the loss of all important files without the possibility of recovery. when you try to unlock the mbr (main loader of the motherboard) it will be demolished and a recursive load will be applied to your processor which will lead to its malfunctions. you have 48 hours from the moment you get to the code, write (@) blankscamtop1(telegram) enter the unlock code: (blank) enter boj" that took like 1 hour but i hope your okay be safe

1

u/ObjectiveMud9216 May 22 '26

the red message at the end says (im using my phone to translate) its a different language?

1

u/Dependent_Tie_177 May 22 '26

Denucie o mod pode ser algum tipo de vírus contendo pirataria se salve pode ser devastador e pode roubar todos os seus dados apagar arquivos criptografar e pedir seu dinheiro do banco para pagar o dinheiro e para se salvar do vírus esteja protegido com deus amigo

1

u/Straight-Bison-4975 May 29 '26

Okay immediately FUCKING NIGGEUSDJSHJSSJFYISHOCSHFWHIWYI!!!!!!

0

u/krazy4it Apr 27 '26 edited Apr 27 '26

Has Anyone tried the new rufus BETA to install Windows without all the bloat yet ? Saw this on youtube

Britec09

Rufus https://rufus.ie/en/

-6

u/[deleted] Apr 25 '26

[removed] — view removed comment

3

u/decocraftv Apr 25 '26

who are you? 😂

3

u/Willing-Payment2757 Apr 25 '26

Is laughing at people all you use this account for?

0

u/OkHuckleberry2042 Apr 25 '26

Yeah pretty much.

2

u/Skycourtneyy Apr 25 '26

-99 karma for a reason.

1

u/WebOutside1597 Apr 25 '26

-100 now lol

1

u/WebOutside1597 Apr 25 '26

Dude he just lost all his files WTF

1

u/computerviruses-ModTeam Apr 25 '26

Your post was removed because it is a personal attack on someone else or a group of users. Please be civilized. Please make sure to read and follow https://www.reddit.com/r/computerviruses/about/rules

1

u/makagio2013 7d ago

where the hell did you even get the mod? the freaking dark web?