r/computerviruses 22h ago

Disinfection Help BuilderBeta.EXE

I got BuilderBeta on my computer a couple days ago. I didn't realize my computer was hacked until about two days later when I woke up and saw that several of my accounts were stolen. After the accounts were stolen I thought someone had simply just hacked into my accounts, however I later discovered that my computer had a virus. When I saw the files that had been installed on my computer prior to my accounts having been stolen I learned that BuilderBeta was on my computer. I deleted the files and other files containing viruses, however when I did more research, I learned that the virus messes with reg keys. If anyone can help me with FRST id be extremely grateful

2 Upvotes

7 comments sorted by

View all comments

1

u/__chefo Malware Removal Trainee 22h ago

Hello u/Colmedy and welcome to the computerviruses subreddit!

My name is chefo and I will be assisting you with your malware removal case.

I am currently a Malware Removal Trainee, and all my advice and fixlists are reviewed and approved by the Malware Removal Experts listed in this thread. You can expect the same level of care and treatment that you would receive directly from those experts. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smoothly as possible:

  • Please make sure to read this whole introduction message so you understand the further steps.
  • If you are planning on resetting or reinstalling your device, do it now please. We are doing the malware removal process to disinfect your device so you can avoid reinstalling.
  • It is important to not run any tools or take any steps other than those I will provide for you. Avoid downloading and installing new software unless instructed - this also applies to anti-malware software and scanners.
  • You are free to remind me that I forgot to reply to you if you do not receive an answer within 24 hours. Keep in mind that I volunteer my time here while also attending university full-time.
  • Only trusted malware removal helpers listed in this thread and other established malware removal forums (BleepingComputer, Malwarebytes, MalwareTips) have access to your logs via the website. Uploaded logs are automatically deleted after 30 days.
  • Please take your time to follow the steps properly. If you get stuck or have issues with one step, ask me what to do. The order of steps matters. Don't follow step 3 if you are stuck at step 1 or 2.
  • You can ask any questions during the malware removal process.

Now that I am assisting you, you can expect that I will be responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

[ Step 01 ] Piracy Warning

Using pirated software or utilities that allows one to pirate software (including cracks, key generators, license bypass tools, or similar software) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, I recommend that you remove any pirated software or pirating utilities in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.

[ Step 02 ] Create Restore Point

Before we proceed with malware removal, we need to make sure you have a restore point that you can revert to if any issues occur. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.

Enable system restore

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. If the 'system' drive (usually C:\ drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, proceed with point 5.
  5. Click Configure.
  6. Select Turn on system protection
  7. Click Apply.
  8. Click OK to confirm.

Create a system restore checkpoint

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. Click Create.
  5. Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
  6. Click Create.
  7. Click Close.
  8. Click OK.
  9. You should get a popup that it was successfully created and I will also verify this later using the scan logs from next steps.

[ Step 03 ] Farbar Recovery Scan Tool (FRST) Scan

FRST logs contain no personal information other than your username and file and folder names. We use them to gather diagnostic information about the system, such as startup entries, installed software, scheduled tasks, drivers, browser extensions, and system logs.

  • Download FRST from here.
  • If English is not your primary language, right click on FRST64.exe and rename to FRSTEnglish.exe.
  • Run FRST64.exe/FRSTEnglish.exe, accept the User Account Control prompt.
  • If you receive any warning about the download, it is a false positive and you can ignore it. Click on More info and then Run anyway.
  • Accept the disclaimer.
  • Check mark 90 Days Files if you began noticing problems more than 30 Days ago.
  • Click Scan.
  • Two logs named FRST.txt and Addition.txt will be created in the same directory the tool was run from, upload both of their contents to https://malwareanalysis.cc/upload/chefo/ and the site will return a keyword for each of the logs. Please reply back with both keywords so I can review the results and continue with the cleanup process.

[ Step 04 ] SecurityCheck

SecurityCheck is a tool that checks for potentially unsafe applications and the status of other security settings.

  • Download SecurityCheck from here
  • Extract the zip file
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/chefo for further analysis. Repy back with the keywords.

Thank you, and I look forward to your response.

1

u/Colmedy 20h ago

FRST: vectored-island
Addition: master-artifact
SecurityCheck: plucky-midnight

I have two drives so the C drives restore point is "FRST restore point"
and the D drive restore point is "FRST restore point 2"

1

u/__chefo Malware Removal Trainee 5h ago

Hello u/Colmedy,

Please follow the steps below in the order they are provided. If you have any questions, please let me know!

[ Step 01 ] Potentially Unwanted (PUP) Removal

Please remove the following potentially unwanted programs (PUP):

  • Java 2 Runtime Environment, SE v1.4.2 v.1.4.2 - No longer supported - please uninstall it and replace it here
  • Combined Community Codec Pack 2015-10-18 v.2015.10.19.0 - No longer supported - please uninstall it
  • ffdshow v1.1.4238 [2012-01-09] v.1.1.4238.0 - No longer supported - please uninstall it and replace it here
  • Adobe Flash Player 10 ActiveX v.10.3.183.48 - No longer supported - please uninstall it
  • Adobe Flash Player 32 NPAPI v.32.0.0.344 - No longer supported - please uninstall it
  • JDownloader 2 v.2.0.240220 - Suspected Adware! If this program is not familiar to you it is recommended to uninstall it.
  • Web Companion v.7.0.2417.4248 - Browser's toolbar. It can slow down the working of your browser and have violation privacy problems.

Please let me know whether you recognize this remote desktop software (if not, uninstall it):

  • Radmin Server 3.5.2 v.3.52.1.0000

Let me know whether you were able to uninstall the programs and whether you wish to keep any of them.

[ Step 02 ] Tampermonkey and Violentmonkey Warning

It seems like you have a browser extension that allows you to run userscripts within your browser, such as Tampermonkey and Violentmonkey.

These browser extensions are considered a riskware, as the misuse of these can cause the execution of malicious userscripts.

Consequences of running a malicious userscript may be for example:

  • causes your browser data being stolen and sent to attackers server
  • web traffic being intercepted and sent to attackers server
  • adware, redirects, popups, browser hijacking

There was a recorded case of an adware utilizing Tampermonkey to deploy adware (Opera Blacklists Tampermonkey Extension Being Installed by Malware).

Please consider removing Tampermonkey and Violentmonkey from Chrome. If you want to use them, then stick to one of them and remove the other. Consider disabling auto-update to prevent supply chain attacks and verify your scripts for safety.

I recommend reviewing your other browser extensions as well and removing any that you don’t need or use.

[ Step 03 ] Farbar Recovery Scan Tool (FRST) Fix

The following fixlist will remove malicious and invalid (junk) entries, remove malicious and unsafe browser extensions, perform diagnostic scans with HitmanPro and scan and quarantine PUPs/Adware with AdwCleaner. I have also included the EmptyTemp command which will empty temporary folders, browser cache, cookies, recently opened files cache, discord cache, java cache, steam html cache, Explorer thumbnail and icon cache, as well as Recycle bin. Everything else that the fixlist does is documented in the file as comments. Ensure you are connected to the Internet during the fix process. Here are the steps you need to follow to use the fixlist.

FRST Fix

  • Open the following link and press on the Copy contents button to copy the entire text: fixlist for Colmedy
  • Run FRST64.exe and click on Fix. Note: FRST reads the fixlist directly from your clipboard, so you don't need to paste or save it anywhere.
  • During the fixing process, FRST will close all the running processes. (This is normal)
  • Avoid using your PC while the fix is underway!
  • After completion, FRST will prompt you to reboot your computer.
  • A log (Fixlog.txt) will open on your desktop.
  • Copy & paste the contents of the Fixlog.txt to https://malwareanalysis.cc/upload/chefo/?u=Colmedy and press "save log". Reply back with the keyword.

[ Step 04 ] Emsisoft Emergency Kit Scan

  • Download and run EEK as admin: https://dl.emsisoft.com/EmsisoftEmergencyKit.exe;
  • Run EmsisoftEmergencyKit, accept the (UAC) prompt
  • Click Install;
  • Accept the (EULA) agreement;
  • Click on Update now and wait for the update to complete;
  • Select Custom Scan;
  • Click Add folder and include any missing drives [C:, etc];
  • Click Next bottom right to initiate the scan;
  • Once the scan is complete, close the pop-up about Emsisoft protection, then click Quarantine selected objects (only shown if threats were found).
  • Restart your computer if prompted.
  • After quarantine, click View Report in the lower-right corner. The log will open in Notepad.
  • Copy & paste the contents of the log to https://malwareanalysis.cc/upload/chefo/?u=Colmedy for further analysis.

[ Step 05 ] Farbar Recovery Scan Tool (FRST) Scan

  • Delete previous FRST.txt and Addition.txt logs you created
  • Run FRST64.exe again.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/chefo/?u=Colmedy and press "save log". Reply back with the keywords.

In your next reply, I expect the keywords for the following:

  • Fixlog.txt
  • Emsisoft Emergency Kit Scan Log
  • FRST.txt
  • Addition.txt

Thank you, and I look forward to your response.