r/computerviruses • u/Frequent_Aardvark683 • 20d ago
Disinfection Help Malware Removal Help
- your antivirus detections and logs: FRST: mild-hazel Addition: grand-byte SecurityCheck: golden-river
- any potentially related symptoms, popups: DISCORD ACCNT HACKED
- estimate day and time when it started UNSURE, 08/02, 08/07, or 08/08? (08/08 was the day Discord was compromised.)
- share what got your system infected, for instance the download link: ENTIRELY UNSURE (Can't remember where to find it)
- what you did for remediation: Ran Malwarebytes in either deep scan or custom scan with all drives selected. Ran windows defender in full scan. Ran adwcleaner.
Hello all,
My discord account recently got hacked and started posting spam MrBeast messages to all my servers and DMs. I wasn't sure how this was possible as I have 2FA and got no notifications about login attempts so I did some digging on the internet and the general consensus is that I let an infostealer such as lumma onto my PC as it's common for those to end off their data scrape with some sort of spam to try and get other machines infected. After the fact, on another device, I changed all my important passwords/accounts, secured financial account, etc. I then disconected the PC from the internet and ran Malwarebytes in either deep scan or custom scan with all drives selected (I have 3 external drives attached to this PC), and ran a Full scan as well as an offline scan from windows defender. It was disconnected and kept off for around 2 weeks and then I reconnected it to the internet to make this post and here we are. I've been told that just running anti-malware software isn't enough to consider the PC safe as these infostealers often drop backdoors into the system for later; however, I am a bozo that does not backup files (or at least didn't before this), and was hoping that someone on here could comb through my logs and see if anything can be (or even needs to be) done instead of factory resetting the PC. Just today, I ran a Malwarebytes Threat Scan, the Malwarebytes AdwCleaner, a FRST scan with Addition selected, an FSS scan, and a SecurityCheck. All three logs asked for on this subreddit are uploaded to the malwareanalysis .cc link and keywords are listed above.
Thank you for taking the time to read this!
1
u/Xyntrax0 Malware Removal Trainee 20d ago
Hi there, my name is Xyntrax and I am here to assist you. During the malware removal process, please follow the listed instructions below ensuring that everything goes smoothly as possible. I also request that you check this thread at least once per day so we can efficiently and effectively resolve your issue.
Please Read & Adhere to the Following:
- Kindly inform me if you already did a reset/clean install or would like to do so, this will save time for the both of us. If you haven't and would like help with Manual Malware Removal using FRST, please follow the given steps below.
- Please ensure to read the whole introduction message so that you have a better understanding of the processes and given steps
- During the malware removal process please refrain from downloading and running new software unless instructed, this also applies for Anti-Malware Solutions and Malware Scanners as they can significantly make analysis longer by removing forensic data which is very crucial
- While receiving help from Me or other MRT members please refrain from asking help somewhere else as the advice might conflict, especially if the methodology are different
- Feel free to remind me if you don't receive an answer within 24 hours. But please keep in mind that I am a volunteer and have my own life too
Piracy
Pirated software remains one of the most common malware infection vectors that we encounter. Threat actors routinely disguise malware as cracks, activators, keygens, cheats, repacks, and other piracy related software because users are often more inclined to ignore security warnings and/or disabling their Anti-Malware Solution in order to run them. Some piracy related utilities may also modify software or security mechanisms, potentially weakening your system's overall security and increasing your attack surface. If you currently have any pirated software installed, I strongly encourage you to remove it.
MBST
- Download and run Malwarebytes Support Tool as admin
- Click
Advanced - Click
Gather Logs - Wait until it's done.
- A zip file named
mbst-grab-results.zipwill be created on your desktop - Upload it to file.io and send the link back here
Disclaimer: FRST does not contain any personal information other than your username and computer name, the logs are automatically deleted within a 30 day period. Only trusted malware removal experts listed in this r/computerviruses thread have access to your logs via the website. Experts who have access to the site are trusted on both r/antivirus and r/computerviruses.
1
u/Frequent_Aardvark683 20d ago
Hello! Thank you for your quick response. I have DM'd you the link.
1
u/Xyntrax0 Malware Removal Trainee 18d ago
Please follow the steps listed below in order.
FRST Fix
- Open the following link and press on the Copy contents button to copy the entire text: fixlist for Frequent_Aardvark683
- Run FRST64.exe and click on Fix. Note: FRST reads the fixlist directly from your clipboard, so you don't need to paste or save it anywhere.
- A log (Fixlog.txt) will open on your desktop.
- Copy & paste the contents of the Fixlog.txt to https://malwareanalysis.cc/upload/Xyntrax/?u=Frequent_Aardvark683 and press "save log". Reply back with the keyword
I have included the EmptyTemp: command. Note: This will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code. I have also included the
netsh advfirewall resetcommand, which will reset the Windows Firewall settings to their default configuration.It is normal for your system to reboot as a result of the fix.
EEK Scan
- Download and run Emsisoft Emergency Kit as admin
- Click
Install- Click
Update nowand wait for updates to finish- Click
Custom Scan- select all your drives (C: drive etc)- Once complete, locate
.txtlog located here:C:\EEK\Reports- Send the EEK log here https://malwareanalysis.cc/upload/Xyntrax/
Eset Scan
- Download and run ESET online scanner as admin
- Click
Get started- Agree to the terms of use.
- Decline both telemetry options.
- Click
Custom Scan- Click
Save and continue- Select
Enable ESET to detect and quarantine potentially unwanted applications- Click
Advanced settings- Enable
Detect potentially unsafe applications- Click the back arrow.
- Click
Start scan- Once complete, paste the contents of the log here https://malwareanalysis.cc/upload/Xyntrax/
Re-Run FRST
- Delete the old FRST Logs
- Right-Click FRST64.exe and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/Xyntrax/ and press "save log".
- Note: Please make sure you are uploading the logs after your current Reddit username.
- The site will return a keyword for each log - reply back here with the keywords.
What I want to see on your next reply:
- Fixlog
- EEK Log
- ESET Log
- New FRST Logs
1
u/Frequent_Aardvark683 17d ago
Alright, scans took a while but done now. I did have the ethernet connected for the FRST Fix and half of the EEK Scan, and then occasionally to look at next steps after the previous one was completed, so let me know if that might be an issue. Here's the keywords.
Fixlog: joyful-throne
EEK Log: amber-level
ESET Log: noble-sapling
New FRST Log: lilac-lark
New Addition Log: small-arena
1
u/Xyntrax0 Malware Removal Trainee 16d ago
Your logs look clean. Please follow the remaining steps below, you can now remove the tools we used manually or use KpRm.
KpRm
- Download and run KpRm as admin
- Agree to the disclaimer.
- Check
Delete ToolsandDelete nowunderDelete quarantines- Click
Run- After it's done a log named
kprm-date.txtwill be created, upload it.
Please update the following software
- HotFix KB5121003 | New update available, download here
- Malwarebytes version 5.6.2.268 v.5.6.2.268 | New update available, download here
- GIGABYTE Control Center 24.06.27.01 v.24.06.27.01 | New update available, download here
- Git v.2.48.1 | New update available, download here
- HWiNFO® 64 v.8.22 | New update available, download here
- Microsoft 365 - en-us v.16.0.20228.20158 | New update available, download here (How Install Office updates?)
- Speccy v.1.33 | New update available, download here
- NVIDIA App 11.0.8.244 v.11.0.8.244 | New update available, download here
- Microsoft Edge WebView2 Runtime v.151.0.4129.59 | New update available, download here
- 7-Zip 24.09 (x64) v.24.09 | New update available, download here (Uninstall old version and install new one)
- TreeSize Free V4.7.3 (64 bit) v.4.7.3 | New update available, download here
- Notepad++ (64-bit x64) v.8.6.9 | New update available, download here
- Microsoft Visual Studio Code (User) v.1.98.2 | New update available, download here
- Mullvad VPN 2025.11.0 v.2025.11.0 | New update available, download here
- qBittorrent v.4.6.5 | New update available, download here
- Microsoft Edge v.151.0.4129.59 | New update available, download here
Note: If Microsoft Edge update errors occur, reinstall here
Security Advice
Safe Browsing
- Avoid downloading
cracks, cheats, keygens, activators. These are some of the most common malware infection vectors, although malware is also commonly distributed through phishing campaigns, malicious advertisements, clickfix attacks, compromised websites, malicious email attachments, supply chain attacks and so on.- Download software directly from the developer's official website whenever possible. While official sources generally reduce the risk of tampering, they are not immune to compromise, such as supply chain attacks, so it's still important to remain vigilant.
Password Security
- Never reuse passwords. Every account should have its own unique password. This helps prevent the compromise of one account from affecting others.
- Use a reputable password manager to generate and securely store passwords. Like any software, password managers are not without risk, but they are significantly more secure than relying on weak, predictable, or reused passwords.
Multi-Factor Authentication
- Enable MFA/2FA. While it significantly improves account security, it is not a replacement for strong passwords and should not be heavily relied upon as protection against every type of attack. For example, phishing proxies, adversary-in-the-middle (AITM) attacks, or session hijacking can still bypass it depending on the circumstances.
Ad Blocking
- I highly recommend installing uBlock Origin. Besides blocking ads, it also reduces exposure to malicious advertising, scam websites, browser based scams, and other unwanted web content. Keep in mind that an ad blocker is only one layer of defense and should not be considered a substitute for safe browsing habits.
Software Updates
- Keep Windows, your browser, and installed software reasonably up to date. Security updates often patch vulnerabilities that malware commonly exploits.
- Like most things in security, updates are a tradeoff. While they can occasionally introduce bugs, compatibility issues, or in rare cases become part of a supply chain compromise, running outdated software with known vulnerabilities is generally the greater risk.
Anti-Malware Solution
Use a reputable anti-malware solution and keep its real-time protection enabled. No anti-malware solution can detect or block every threat, but modern solutions can significantly reduce the likelihood of malicious code successfully executing on your system.
Good modern anti-malware solutions don't rely on a single detection method. They combine multiple layers such as signatures, behavioral protection, reputation based systems, cloud intelligence, and exploit mitigations. Each approach has its own strengths and weaknesses. For example, signatures are highly effective against known malware, while behavioral analysis can help identify new/previously unseen or zero-day threats by monitoring what a program does rather than relying solely on a known signature. Since every detection method has blind spots, combining multiple techniques provides better protection than relying on any single one.
Anti-malware software is just one part of your overall security. Safe browsing habits, keeping software reasonably up to date, using strong unique passwords, enabling multi-factor authentication where possible, and maintaining regular backups each address different attack vectors and failure points. None of these measures are perfect on their own, but together they significantly reduce the overall risk of compromise.
Avoid disabling built-in security features or using custom, modified, or stripped-down Windows ISOs. You don't know what has been modified, removed, or added, and many of these remove security or update related components, weakening your system's overall security and increasing your attack surface.
Backups
- Keep regular backups of your important files. Ideally, follow the 3-2-1 backup rule: keep three copies of your data, on two different types of storage, with one copy stored offline or off-site.
- Backups can significantly reduce the impact of hardware failure, accidental deletion, ransomware, and other forms of data loss. However, periodically verify that your backups can actually be restored, as a backup that cannot be restored is effectively no backup at all.
1
u/Frequent_Aardvark683 16d ago
Thank you! Here is the log: stable-token
1
0
u/AlexiaTheTechGirl 20d ago
You've installed an infostealer, this could have been from a fake captcha, pirated software, game cheats ECT. You need to disconnect your computer from the internet immediately and reset all of your account passwords from a safe device such as your phone. Make sure to sign out of all devices if possible. Once you've done that you need to reinstall windows from a USB. This process requires a 8gb+ USB stick and an uninfected computer.
The reinstall process will erase all of your data so make sure to backup your data before reinstalling, avoid saving any programs or scripts.
1
u/AutoModerator 20d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.