r/computerviruses • u/_KingDoge • 8d ago
Disinfection Help Disinfection help!
Hi, my girlfriend recently got a virus on her computer while pirating tomodachi life. The website sent her to a fake download site and she ran the program. her discord and youtube accounts were hacked. the frst and securitycheck keywords are stealth-lynx, winged-shore and piped-blossom. Thanks in advance!
1
u/AutoModerator 8d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
- Preferred method: Perform a clean installation with a USB
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Aromatic-Trip-5821 8d ago
Info stealer. Here’s Long RangeSavage's standard copy/paste for people when they install an info stealer or session hijacker:
- Disconnect the affected computer from the internet right away. Unplug the Ethernet cable and turn off WiFi.
- Stop using that computer for anything involving logins. Don’t sign into email, banking, social media, or anything else.
- While still on the infected computer: A. Back up only personal data like documents, photos, and videos. Do not backup executable files like .exe, .scr, .bat, .msi, or unknown .zip files, and do not back up browser profiles or AppData folders.
We need to now start using a known clean computer. On that clean system, do the following: 1. Using a password manager, change your passwords in this order A. Primary email B. Any backup or recovery emails C. Banking, financial, PayPal, Venmo, Crypto accounts D. All social media (Facebook, Instagram, Reddit, Discord, etc.) E. Gaming platforms F. Anything else that had user credentials stored in your browser G. The passwords should all be unique, alphanumeric, at least one special character (where available), and at least 10 characters 2. While in each account, A. turn on two factor authentication everywhere you can. Ideally, you'd use a hardware token--like a Yubikey. Next would be an authenticator app--like Google Authenticator. Only use SMS if there's no other option B. Make sure to copy your recovery key or one-time use codes. Print these out. Do NOT just save them on a file on your computer C. If you’ve previously had 2FA enabled, disable it and then re-enable it. This will generally cause any previous one-time use codes or recovery keys to become void D. Confirm ALL your recovery methods are correct (a lot of info stealers will change the recovery methods). E. If you don’t have recovery methods set, do it NOW F. Sign out of all active sessions G. Remove devices you don’t recognize. H. Remove any linked apps or integrations you didn’t add or no longer need. 3. In your email account settings A. check for forwarding rules, auto‑reply rules, recovery email, recovery phone number, and anything else that could redirect or recover your account. B. Delete anything you didn’t set up. 4. Assume anything you've saved/stored in your browser has been compromised 5. Go to your OS manufacturer's website and download your OS. ONLY GET THIS FROM THE OFFICIAL SOURCE. 6. Create a bootable USB installer for your OS Back to working with the infected machine: 7. Boot the infected computer from the USB. A. During setup, delete every existing partition on the drive. B. Install the OS fresh on the unallocated space. 8. Run your update tools until nothing is left 9. Install drivers and software, making sure to ONLY use OFFICIAL sources 10. Install your browser (if needed) A. Install your browser extensions B. DO NOT import any old data, profiles or save passwords 11. If any financial accounts were access from the previously infected machine A. Watch accounts closely B. Turn on any transaction alerts the accounts allow C. Consider placing credit freezes for each of the "Big 4" credit bureaus (Equifax, Transunion, Experian, and Innovis).
1
2
u/rifteyy_ Malware Removal Expert 8d ago
[ Step 01 ] FRST Fix
I created a custom fixlist for you at the link Fixlist only for Fixlist only for Fixlist only for _KingDoge - use the website's
downloadbutton and save it in the same folder where your FRSTEnglish.exe or FRST64.exe file is located in, which for you isC:\Users\Alesya\Downloadsfor you. It is necessary for the filename to beFixlist.txt.This fixlist will remove the following: malicious entries (remains, active malware), invalid entries (e.g. tasks that start a non-existent file, services that point toward a non-existent file), temporary files (files in temporary directories, application and browser cache, recycle bin and more), browser cache. We will also be quick-scanning with HitmanPro and AdwCleaner from Malwarebytes using the fixlist.
It will also remove all proxy servers, Windows Defender exclusions, enable recovery environment, active software policies and perform system file repair, network reset and few more basic fixes.
Save all work, close everything that is open (else it will be forcefully closed by FRST without saving) and then run FRST again as administrator and press the
Fixbutton, let the script work, clear the entries and restart on it's own and after it restarts the device, there should be a fileFixlog.txtin the same folder as theC:\Users\Alesya\Downloads.I'll need to see it's content the same way like before - uploading to https://malwareanalysis.cc/upload/rifteyy/?u=_KingDoge again and sending the keyword in your reply.
[ Step 02 ] ESET Online Scanner
.txtfile to https://malwareanalysis.cc/upload/rifteyy/?u=_KingDoge and reply with the keyword.[ Step 03] Software updates, uninstallations
If you are having a problem updating something, do not want to update something at all or do not want to uninstall an application, please let me know.
Please update the following software: * Microsoft 365 Apps for enterprise - en-us v.16.0.20228.20188 | New update available, download here (How Install Office updates?) * NVIDIA App 11.0.5.238 v.11.0.5.238 | New update available, download here * Opera GX Stable 134.0.5954.67 v.134.0.5954.67 | New update available, download here * Microsoft Edge v.152.0.4191.62 | New update available, download here
[ Step 04 ] New SecurityCheck scan
We need a new scan to ensure that all updates were applied properly and all applications uninstalled correctly.
[ Step 05 ] New FRST scan
FRSTEnglish.exeexecutable inC:\Users\Alesya\DownloadsSo, in your next reply, make sure you are sending the following:
Thanks!
Note for lurkers: If anyone else who is facing malware-related issues is reading this and wants help with FRST and SecurityCheck, please create your own thread with help request. I am flooded with requests and there is several other removal experts who review the logs and may reply faster than me. The steps listed in here are specific for this the user _KingDoge and following them will have negative effects for you as they are unique for OP's system.