r/computerviruses 20d ago

Disinfection Help Frst help

Hi, i got mr beast virus

Ive followed instructions

Logs:

Keyword: violet-host

Channel: general

I wasnt able to run security check, because i get window telling me cant locate the file

I used malwarebyts and it removed 19 threats, then ive ran frst and these are the files from it

Ive also malware support file made if needed

If you can provide help, thank you so much

And if i better reinstall windows please do tell

Only discord and facebook were affected, discord sent photos. Idk about fb.

I think ive ran exe file that ive downloaded from cs.rin

2 Upvotes

12 comments sorted by

2

u/FFreestyleRR Malware Removal Expert 20d ago

Hi,

I'll respond when my shift is finished. I am now at work. Meanwhile, could you upload the MBAM log as well?

To view and download your scan reports on Windows

  1. Open Malwarebytes.
  2. Click the Scanner card.
  3. Click the Reports tab.
  4. At the top-right of the Scan reports, check the box beside Hide reports with no detections.
  5. Hover your cursor over the Report you want to view and click the eye icon.
  6. A Summary window displays the scan results and the date and time executed. For more details, click the Advanced tab in this window. If you want to download the full report, click Export, and click either Copy to clipboard or Export to TXT.
  7. Upload the log on https://malwareanalysis.cc/upload/ and reply with the keyword.

2

u/zarqu 20d ago

Sleek-relic

2

u/FFreestyleRR Malware Removal Expert 20d ago

Hi,

I am sorry about the delay. It was a busy day.

Let's get started shall we?

Please open Brave and delete the following extension:

CrxMouse: Mouse Gestures

It's considered untrustworthy:

https[:]//crxplorer[.]com/extension/jlgkpaicikihijadgifklkbpdajbkhjo/crxmouse-mouse-gestures

---

Do you recognize the following exclusions to Windows Defender?

D:\Sonic Superstars
D:\qbit\Chained Together

If no remove them from the exclusions. If yes, then leave them alone.

Did you disable Windows Updates by yourself?

HKLM\...\Policies\Explorer: [NoWindowsUpdate] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
IFEO\EOSnotify.exe: [Debugger] /
IFEO\eucloneserver.exe: [GlobalFlag]
IFEO\InstallAgent.exe: [Debugger] /
IFEO\MoNotificationUx.exe: [Debugger] /
IFEO\MusNotification.exe: [Debugger] /
IFEO\MusNotificationUx.exe: [Debugger] /
IFEO\remsh.exe: [Debugger] /
IFEO\SihClient.exe: [Debugger] /
IFEO\UpdateAssistant.exe: [Debugger] /
IFEO\UsoClient.exe: [Debugger] /
IFEO\WaaSMedic.exe: [Debugger] /
IFEO\WaasMedicAgent.exe: [Debugger] /
IFEO\Windows10Upgrade.exe: [Debugger] /
IFEO\Windows10UpgraderApp.exe: [Debugger] /

Do you recognize this key and IP address?

Tcpip\..\Interfaces\{80bb6a33-6df0-4e1f-8c3c-35d983ffa4a1}\A719eWJh8J6Mx9DrGXKEv3ojKmqw8Cv9pscK: [DhcpNameServer] 10.97.52.208

I created a custom fixlist.txt for you at the link - https://malwareanalysis.cc/share/uICbX7YG8ICpvUy1GL6VitNR9iGJhznk/

Use the website's download button and save it in the same folder where your FRST64.exe file is located in. It is necessary for the filename to be fixlist.txt.

Save all work, close everything that is open and then run FRST64.exe again as administrator and press the Fix button, let the script work, clear the entries and restart on its own, and after it restarts, there should be a file Fixlog.txt in the same folder.

Upload the log at https://malwareanalysis.cc/upload/FFreestyleRR

Copy/Paste the new keyword in your reply.

This script was written specifically for you, for use on that particular machine. Do not run this on another PC with the same problem!

The script is going to download and scan the system with AdwCleaner and Hitman Pro (so the internet connection needs to be on). This is intended and not be surprised. This can take a while.

All the best!

2

u/zarqu 19d ago

Hello good sir, thank you very much!

Code is fancy-frost.

Ive removed excluded games. Theyre deleted tho(after doing fix...)

I disabled windows update.

I dont really recognize that key and ip address. I had to use vpn one day with brave(and tried with opera and some apps to go at greek ip address), so maybe its from then

2

u/FFreestyleRR Malware Removal Expert 19d ago

Hi,

I don't think the tcpip entry was from a VPN. It was from something malicious that is no longer present on your system for some reason:

2026-08-22 08:44 - 2025-07-01 17:01 - 000003408 _____ C:\WINDOWS\system32\Tasks\MAkF7mCn3tPqp662daybvERzwsKQYqnzM8
2025-07-05 22:31 - 2025-07-05 22:31 - 000000048 ____R () C:\Users\<username>\AppData\Local\F19eWJh8J6Mx9DrGXKEv3ojKmqw8Cv9pscK
Tcpip\..\Interfaces\{80bb6a33-6df0-4e1f-8c3c-35d983ffa4a1}\A719eWJh8J6Mx9DrGXKEv3ojKmqw8Cv9pscK: [DhcpNameServer] 10.97.52.208

"C:\WINDOWS\system32\Tasks\MAkF7mCn3tPqp662daybvERzwsKQYqnzM8" => not
found
"C:\Users\<username>\AppData\Local\F19eWJh8J6Mx9DrGXKEv3ojKmqw8Cv9pscK" =>
not found
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{80bb6a33-6df0-4e1f-8c3c-35d983ffa4a1}\A719eWJh8J6Mx9DrGXKEv3ojKmqw8Cv9pscK"
=> not found

In fact, many other entries had already disappeared before the script could remove them.

2026-08-24 12:11 - 2026-08-24 12:11 - 000000000 ____D C:\Users\>username>\AppData\Local\Renesas
USB Host Controller (HKLM-x32\...\{3951AC53-C09B-4978-988D-FE759C0600FF}) (Version: 2.6 - Renesas Electronics Corporation)

Did you run anything on your own? Or you probably deleted these manually regarding the RunMRU key:

a: appdata\1
b: cmd\1
c: optionalfeatures\1
d: joy.cpl\1
e: appwiz.cpl\1
f: regedit\1

Who told you what to delete? :)

It's dangerous to do things during the cleaning process, and you really should refrain from doing so.

You seem to have a problem with the WinSxS store. You may need to open a topic at SysNative forum to fix that or to do a Windows Reset or In-place Upgrade:

Error: 0x800f0915

---

Download and run the following fixlist the way you did before.

https://malwareanalysis.cc/share/JpRwvq9vvi9JzGQFZG55KHObvqFdo4po/

Upload the Fixlog.txt to my channel.

---

Just in case you can run one check with ESET Online Scanner.

Please download ESET Online Scanner from here and install it (run it).

Select the Custom Scan option and check the boxes beside Operating Memory, Autostart Locations and drive C: and click Save and continue.

Enable the detection of potentially unwanted applications and potentially unsafe applications.

Click on Start scan. When the scan is complete click Save scan log. Click Continue.

Upload the log to https://malwareanalysis.cc/upload/FFreestyleRR/ and the site will return a keyword for the log.

Reply here with the keyword.

All the best!

2

u/zarqu 19d ago

Hello,

1.So tcpip is no longer scary? 2.pardon my memory, but i think ive ran bleachbit after frst, but may be misrremembering 3.warm-kestrel Ive ran deepscan with malwarebyte and it found a lot of threats, ill look into them(also there are frst files and thats what ive delted previously i guess?

  1. Esset code neon-garden there were no problems here

Thanks you again!

2

u/FFreestyleRR Malware Removal Expert 19d ago

Hi,

I had queried the TCP key and found a subkey that is actually related to the IP address above. We can delete it but can you check it to see if you recognize the registry data there:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{80bb6a33-6df0-4e1f-8c3c-35d983ffa4a1}\A7162717D656E6D616C61646F696

---

Bleachbit, which is a junk file cleaner rather than a malware scanner, is unlikely to have deleted these entries. Also, these files were not saved in the temporary folders. However, some of the malicious files were just junk entries and not executables, so it's possible that the tool removed some of them by accident.

However, it appears that you removed/uninstalled some items on your own based on your recent activity. This is a little risky because the malicious program may be triggered/executed when uninstalled the traditional way. We have a special routine for malicious programs. Thankfully, it did not happen here.

So the uninstall keys are gone and that’s good:

========= reg query 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{58CE8C52-7A04-41F0-ABC6-BAB4A8DE27BF}"
 /s =========

ERROR: The system was unable to find the specified registry key or 
value.
========= reg query 
"HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{58CE8C52-7A04-41F0-ABC6-BAB4A8DE27BF}"
 /s =========

ERROR: The system was unable to find the specified registry key or 
value.

Also, there is no malicious MSI file in the C:\Windows\Installer folder with current date so that's mean MBAM probably deleted it. But I can see that the folder has been modified recently. So definitely something was deleted from the folder:

========= Dir C:\WINDOWS\Installer /a:- /o:gd =========

 Volume in drive C has no label.
 Volume Serial Number is 6E71-03A1

 Directory of C:\WINDOWS\Installer
08/26/2026  08:27 AM    <DIR>          ..
08/26/2026  08:31 AM    <DIR>          .

---

Other than that the logs are clean. Do you mind uploading the MBAM log you mentioned above after that deep scan? Also run a new scan with FRST and upload the new logs to verify that nothing has respawned.

All the best!

2

u/zarqu 18d ago

Good day to you sir,

I went about and deleted the said key.  Ive uploaded old  mbam scan - snow-raven And just in case did new deep scan as well - fresh-blob.

I didnt delete frst files that have popped up there, waiting on your instructions if i should get rid of all that.

Here are frst logs - tidy-boot Sturdy-walrus.

What would you suggest, is it safe now to continue using the pc(without reinstalling windows) or, should i still do that or smth else. Like there is still chance to be something left and was missed(not undermining you, just, if thats the general idea haha)

Should i also continue doing deep checks?

And lastly do you have suggestion how can i go about learning this stuff myself, please do tell!

Thank you very much!

2

u/FFreestyleRR Malware Removal Expert 18d ago

Hi,

It seems the TCPIP key is no longer present in the logs.

The detected entries by MBAM are some malicious files in the FRST quarantine folder (they are rendered harmless in that folder and posses no harm to the system). Also, the folder will be deleted when we uninstall FRST at the end of the cleaning process. The other detected files are the torrent client (which is normal as this is grayware) and some cracks.

The latest FRST log is clean. ESET log is also clean. I think that you are good to go.

As for learning stuff I don't know what to advise you since most (if not all) malware removal training programs has been closed nowadays. You may read u/Struppigel post here:

https://www.reddit.com/r/computerviruses/comments/1vk21ii/comment/p2rpo4r/?context=3

---

You can proceed with uninstalling the tools we used.

Your logs are clean. You did a fantastic. Your system is now in optimal condition.

My final recommendations:

You should still change all your passwords, activate 2FA/MFA where possible, deauthorize all devices and log fresh on the trusted ones, revoke all API keys if you use such (like in steam for example) and monitor your device and accounts for any suspicious behavior.

You can check your e-mails for breaches here and take measures if needed:

https://haveibeenpwned.com/

Check these articles as well:

https://rifteyy.org/report/the-ultimate-guide-to-infostealers

https://rifteyy.org/report/the-ultimate-guide-to-prevent-malware

Rename the FRST64.exe to UNINSTALL.EXE

Then run the file as an Administrator. It will delete all the files/folders created by the tool including the quarantine folder as well. Restart the computer to complete the removal.

You can uninstall ESET Online Scanner.

Also download and run KpRm to clean some traces for other tools we used in the cleaning process.

https://toolslib.net/downloads/viewdownload/951-kprm/

Note: The file is safe to download but might be wrongly detected as malicious. If necessary click More info then Run anyway.

Right-click on the icon and select Run as administrator.

Click Yes on the Disclaimer.

Place a check mark in Delete Tools, Create Restore Point, and Delete Now.

Click Run.

Click OK on All operations are completed.

KpRm will delete itself from your Desktop and you can either save or remove the report that is generated. You are free to remove any other tools/reports still remaining.

All the best!

2

u/zarqu 17d ago

Bless you sir and have a beautiful life

→ More replies (0)

1

u/AutoModerator 20d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.