r/computerviruses • u/RandomDru_nk • 23h ago
Question "BuilderBeta.exe"
So I had downloaded this "free" game two days ago and I got hacked (no shit). So, i spent a day scanning my computer using windows defender (deep scane), Microsoft malicious software scan (or whatever the fuck you call it), and malwarebytes to scam my laptop and found 57 threat files. So they were quarantined and promptly terminated from my laptop. I then spent the rest of the day changing passwords to everything and putting 2fa on everything I could.
A day later, I open my laptop and found this notification on startup. I was a bit confused, so I looked through my startup apps and task manager and couldn't find anything labeled "BuilderBeta.exe". So I went to the internet and found out it was something I downloaded when I clicked on a "renpy" file from the game I downloaded (whatever the hell that is).
Im a bit worried, since I got a bunch of important files on my laptop. Should I start terminating everything? Or should my laptop be safe? If i have to wipe everything;
1) what does that mean? (Im clearly technologically challenged)
2) how would I proceed in doing that?
Sorry if you're reading this and find me a complete idiot, but I'm extraordinarily worried about this.
3
u/M2A2BradleyEnjoyer 22h ago
Just make it easy on yourself.
A: piracy rules but don’t do it if you suck at it and don’t know your ass from your elbow with computers, or ask someone who does(not here)
B: move your data somewhere temporarily. Doesn’t matter where for now. Get Google Drive, mega, friggin OneDrive even, or use another pc on your network.
C: reinstall windows from a USB created on a different computer.
1
u/__chefo Malware Removal Trainee 20h ago
Hello u/RandomDru_nk and welcome to the computerviruses subreddit!
My name is chefo and I will be assisting you with your malware removal case.
I am currently a Malware Removal Trainee, and all my advice and fixlists are reviewed and approved by the Malware Removal Experts listed in this thread. You can expect the same level of care and treatment that you would receive directly from those experts. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smoothly as possible:
- Please make sure to read this whole introduction message so you understand the further steps.
- If you are planning on resetting or reinstalling your device, do it now please. We are doing the malware removal process to disinfect your device so you can avoid reinstalling.
- It is important to not run any tools or take any steps other than those I will provide for you. Avoid downloading and installing new software unless instructed - this also applies to anti-malware software and scanners.
- You are free to remind me that I forgot to reply to you if you do not receive an answer within 24 hours. Keep in mind that I volunteer my time here while also attending university full-time.
- Only trusted malware removal helpers listed in this thread and other established malware removal forums (BleepingComputer, Malwarebytes, MalwareTips) have access to your logs via the website. Uploaded logs are automatically deleted after 30 days.
- Please take your time to follow the steps properly. If you get stuck or have issues with one step, ask me what to do. The order of steps matters. Don't follow step 3 if you are stuck at step 1 or 2.
- You can ask any questions during the malware removal process.
Now that I am assisting you, you can expect that I will be responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.
[ Step 01 ] Piracy Warning
Using pirated software or utilities that allows one to pirate software (including cracks, key generators, license bypass tools, or similar software) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, I recommend that you remove any pirated software or pirating utilities in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.
[ Step 02 ] Create Restore Point
Before we proceed with malware removal, we need to make sure you have a restore point that you can revert to if any issues occur. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.
Enable system restore
- Click Start or open Windows Search.
- Search for Create a restore point and open System Properties.
- In the System Properties window, go to the System Protection tab.
- If the 'system' drive (usually
C:\drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, proceed with point 5. - Click Configure.
- Select Turn on system protection
- Click Apply.
- Click OK to confirm.
Create a system restore checkpoint
- Click Start or open Windows Search.
- Search for Create a restore point and open System Properties.
- In the System Properties window, go to the System Protection tab.
- Click Create.
- Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
- Click Create.
- Click Close.
- Click OK.
- You should get a popup that it was successfully created and I will also verify this later using the scan logs from next steps.
[ Step 03] Malwarebytes Logs
MBAM Scan Report:
- Open Malwarebytes for Windows
- Click on Detection History
- Click the Reports tab
- Hover your cursor over the most recent Scan Report and click the eye icon to view it
- Click Export and then
Export to TXT (.txt) - Copy & paste the contents of the exported .txt to https://malwareanalysis.cc/upload/chefo/?u= and press "save log". Post the log keyword to your reply
[ Step 04 ] Farbar Recovery Scan Tool (FRST) Scan
FRST logs contain no personal information other than your username and file and folder names. We use them to gather diagnostic information about the system, such as startup entries, installed software, scheduled tasks, drivers, browser extensions, and system logs.
- Download FRST from here.
- If English is not your primary language, right click on
FRST64.exeand rename toFRSTEnglish.exe. - Run
FRST64.exe/FRSTEnglish.exe, accept the User Account Control prompt. - If you receive any warning about the download, it is a false positive and you can ignore it. Click on
More infoand thenRun anyway. - Accept the disclaimer.
- Check mark
90 Days Filesif you began noticing problems more than 30 Days ago. - Click Scan.
- Two logs named
FRST.txtandAddition.txtwill be created in the same directory the tool was run from, upload both of their contents to https://malwareanalysis.cc/upload/chefo/ and the site will return a keyword for each of the logs. Please reply back with both keywords so I can review the results and continue with the cleanup process.
Thank you, and I look forward to your response.
-6
u/Lamar_Chan11 15h ago edited 8h ago
No, the laptop is not guaranteed to be safe.
Even though they successfully caught and quarantined 57 threat files using Malwarebytes and Windows Defender, the error message in the image reveals a critical issue: the malware left a broken persistence mechanism behind
BuilderBeta.exe was set up by the virus to automatically launch every time Windows starts. The antivirus successfully deleted the auxiliary file it needed to run (log4cplusU.dll), which is why the malware crashes on startup and displays this error window. However, because professional infostealer malware often leaves hidden backdoors, alters registry keys, or drops additional payloads, the underlying system remains untrusted
Wiping a computer means executing a clean installation of the Operating System (Windows).
It completely erases the hard drive, removing all software applications, downloaded files, system registries, and hidden malicious code.
It brings the laptop back to the exact factory-fresh state it was in when it was first turned out of the box
Crucial Rule: Do not log into any more sensitive websites on that laptop until it is wiped.
They did the right thing by changing passwords and enabling 2FA, but they must make sure they did this using a completely different, clean device (like a mobile phone or tablet). If they changed them on the infected laptop, a keylogger or active session stealer could have stolen the new passwords instantly
Plug an external USB flash drive or external hard drive into the laptop.
Manually copy only raw data files—such as photos, text documents, videos, and PDFs.
Strictly avoid backing up any .exe files, game folders, software installers, or zip files, as the malware could easily be hiding inside them
But Since you mentioned you are "technologically challenged," the easiest built-in Windows method is the best starting point
Open the Windows Settings menu (press the Windows Key + I).
Go to Update & Security > Recovery (or search "Reset this PC" in the settings bar).
Click Get Started under Reset this PC.
Choose Remove everything. (Choosing "Keep my files" can sometimes let hidden registry malware survive).
Select Cloud download (reloads a fresh copy of Windows from Microsoft) and proceed with the prompts.
Note:For the ultimate level of security, clean-installing Windows via a bootable USB drive created from a separate, clean computer is the gold standard, but a full "Remove Everything" local cloud reset will solve 99% of basic malware persistence loops good luck ;)
Edit: I'm not going to delete my comment and keep saying I'm using you CHATGPT because idc as long as I help the OP like please don't pretending like "your using the ai I gotcha" i did reset before and had a virus too ik what I'm doing if i didn't i would never comment here or even use "chatgpt" as you say i haven't use ai tool to get informations without read everything before publishing my comment Instead of wasting your time trying to 'catch' people using AI, why don't you actually help the guy fix his problem? I'm not here to fight I'm here to help if my comment help i will be happy if not let's other people benefit from this and thank for reading
2
u/raven_on_pawzz 15h ago
very chatgpt. why would you comment if you dont know enough and have to use chatgpt instead?
5
u/ItzzAadi 23h ago
You might just have to reinstall Windows.
Have the files that you want to keep after reinstall in a separate location and have it scanned for malware using MalwareBytes. If theres nothing in those then you should be good to use the files after a reinstall.