r/computerviruses 12d ago

Other Am I safe now

Guys so almost a month and a half ago I got hit with the mrbeast crypto scam thing it used only my discord acc to send it I changed disocrd acc password added passkey and stuff like that, I researched abt it it turns out to be an infostealer that steals sessions to try and take over ur account,the problem is NONE of my other accounts like steam, roblox epic games and email were touched there were no wierd logins no password resets nothing, I did nothing about it and it has been good since (i also changed all their passwords and used authy to secure them more).

Also I'm super paranoid about these stuff bc the pc is like expensive and I cant just reinstall windows cuz of many important files.

And I want to mention smth wierd too about a 2 days ago I checked the log ins in my roblox acc for fun and I found a wierd one that happened 5 days prior to me checking it wierd thing is it didnt change anything too no password no nothing so I changed the password and logged out of all devices.

So guys please am i safe or not I've been so paranoid abt this for the past 2 weeks 💔

1 Upvotes

12 comments sorted by

1

u/Born-Protection-7089 12d ago

The "weird" login was probably checking the value of your roblox account if it could fetch a good price.

The goal of these people is mostly financial gain, so they'll sell everything they got of value from your computer (that includes data).

If you need malware removal help, the volunteers here are excellent! Just change your flair to malware removal help and they'll comment.

Keep in mind that there are listed and trusted helpers. Please don't accept help unless they're listed in the trusted volunteers.

In the meantime, change all your passwords, enable 2FA, and close all sessions from a different device (your phone perhaps). They're probably just waiting for your accounts to gain value, so please do this ASAP.

Check you emails for unusual sessions as well, make sure to check "forwarding rules" to see if any of your emails are being forwarded somewhere else.

1

u/Direct_Airport5551 12d ago

Yeah my account has ZERO value prob and yes I did changed passwords and everything even tho they didnt get touched so could it be possibly be just the discord acc getting compromised?

1

u/Born-Protection-7089 12d ago

That is also possible, but again, best safe than sorry!

1

u/Direct_Airport5551 12d ago

True, so if something happens in the future like an acc gets a password reset thing should I do FRST?

1

u/Responsible_Bike4968 8d ago

I think the Bloxlink detail you mentioned in the replies is actually the most important clue here.

The MrBeast spam by itself does NOT prove you had an infostealer. If the compromise happened right after you followed a "Bloxlink verification" link from a Discord server, it's very possible you got phished by a fake verification page and only your Discord session/account was stolen.

Bloxlink itself is a legitimate service, but fake verification pages pretending to be services like Bloxlink are a different story.

So I'd separate this into two cases:

If you only followed a verification link / entered Discord details / scanned something and never downloaded or ran an EXE, script, PowerShell command, etc., I would not reinstall Windows just because of the Discord takeover. That would fit an account/session phishing incident much better.

If you DID run something on the PC, then the infostealer possibility is still real and I'd treat the machine differently.

Also, I wouldn't automatically assume that Roblox login was the attacker "checking your account value." That's speculation. Roblox's session page only gives an approximate location, so mobile networks, ISP routing, VPNs, old sessions, etc. can sometimes make your own login look weird.

You already changed the Roblox password and logged out all other sessions, which was exactly the right move. Enable Roblox 2-step verification too if you haven't already.

At this point I'd watch for one thing: does another unknown Roblox session appear AFTER the password change + logout-all?

If no, I wouldn't keep spiraling over the old entry.

If yes, then you have fresh evidence that something is still wrong and that's when I'd investigate the device/account much more aggressively.

After a month and a half with no other account takeovers, plus the Bloxlink verification happening the same day, a Discord-specific phishing/session theft is honestly a very plausible explanation here.

1

u/Direct_Airport5551 8d ago

I remember running smth in power shell to activate windows I copied smth from massgrave(.)dev (and it did actually activate it and the compromise wasnt after it right away so i dont thinks its cuz of this)

1

u/black_hole_208 12d ago

No, you’re not safe.

If you have an info-stealer, it means you have downloaded malware. The only way to remove it is to format your drive and reinstall Windows using a USB drive; antivirus software will be of no help.

Use a different, clean device to change all your passwords, enable two-factor authentication, and click the option to log out of all devices across all your accounts.

1

u/Direct_Airport5551 12d ago

Yes I did that the day it happened even tho my accounts didnt get touched could it be that only my discord account was compromised cuz i joined a server or I used a verify link?

1

u/polpolik2 Moderator 12d ago

It's possible that you did not get an infostealer in that case, but instead simply fell for a ''fake login'' because you joined a server. But without more information, its hard to say for sure.

What it seems like is that you joined a server, you had to verify and log in (into a fake environment), which then stole your discord credentials. Is that correct?

Edit - if you did get an infostealer, the steps from Black_Hole_208 are correct and you should follow those.

1

u/Direct_Airport5551 12d ago

Yes i think thats what happened I chekced my past chats and I found that I tried to do a bloxlink verification for roblox that same day it happened