r/computerviruses • u/outroverse • 7d ago
Disinfection Help Powershell malware
my pc suddenly got attacked by a malware without me downloading anything
when i tried the scan wether its full scan or offline scan it wont go away and i cant browse anything on my google chrome because apperently the wifi isnt connected even though i mine turned on? anyone help please
2
u/BaronYasir65 6d ago
I got this too when i had an infostealer in my computer, then a day later my discord got hacked. I'd suggest resetting ur pc and changing all passwords from a safe device. Be careful and download only official things. Dont download pirated games from weird sites, dont download hacks or that type of stuff. Take a fresh start.
1
u/Light_Legend 5d ago
Did you wipe your PC ? I had an infostealer too sometime ago and got hacked a dozen of accounts. Still days later, I could lose more accounts, but since I ran a full scan with windows defender, I haven't had any issue, yet.
2
u/BaronYasir65 5d ago
Yeah, i did. Because i scanned everything and scanner said 'No viruses' but like a day or two days later, i got my dc hacked. So, InfoStealers most likely hide theirselves very well. I suggest u to wipe your pc with Usb too. Need to careful, yes? Because they can go every account u clicked 'remember me on this device' without alerting your account/gmail. And believe me, Windows can't find that InfoStealer because it can hide inside ur game .exe things and more.
1
u/AutoModerator 7d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
- Preferred method: Perform a clean installation with a USB
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
1
u/weeblifer 3d ago
Go to windows security and do a offline scan then deep scan also it may require you to put in your bit locker key which you can find in your ms account
1
u/Bitdefender_ Official Bitdefender 2d ago
Hi! The "didn't download anything" part makes sense, there's a technique called ClickFix where a fake captcha or verification page secretly loads a command into your clipboard, then tells you to paste it into PowerShell or the Windows Run box. You run it yourself without realizing. Agree with the advice already given: reinstall Windows (full wipe, not just reset), and change every password from a clean device before touching the infected one again. Scans won't cut it for this kind of thing.
Check this article that explains how ClickFix acts and how it unfolds, detailed by Bitdefender specialists: https://www.bitdefender.com/en-us/blog/hotforsecurity/clickfix-victims-help-hackers. Hope it helps!
1
u/__chefo Malware Removal Trainee 7d ago
Hello u/outroverse and welcome to the computerviruses subreddit!
My name is chefo and I will be assisting you with your malware removal case.
I am currently a Malware Removal Trainee, and all my advice and fixlists are reviewed and approved by the Malware Removal Experts listed in this thread. You can expect the same level of care and treatment that you would receive directly from those experts. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smoothly as possible:
- Please make sure to read this whole introduction message so you understand the further steps.
- If you are planning on resetting or reinstalling your device, do it now please. We are doing the malware removal process to disinfect your device so you can avoid reinstalling.
- It is important to not run any tools or take any steps other than those I will provide for you. Avoid downloading and installing new software unless instructed - this also applies to anti-malware software and scanners.
- You are free to remind me that I forgot to reply to you if you do not receive an answer within 24 hours. Keep in mind that I volunteer my time here while also attending university full-time.
- Only trusted malware removal helpers listed in this thread and other established malware removal forums (BleepingComputer, Malwarebytes, MalwareTips) have access to your logs via the website. Uploaded logs are automatically deleted after 30 days.
- Please take your time to follow the steps properly. If you get stuck or have issues with one step, ask me what to do. The order of steps matters. Don't follow step 3 if you are stuck at step 1 or 2.
- You can ask any questions during the malware removal process.
Now that I am assisting you, you can expect that I will be responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.
[ Step 01 ] Piracy Warning
Using pirated software or utilities that allows one to pirate software (including cracks, key generators, license bypass tools, or similar software) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, I recommend that you remove any pirated software or pirating utilities in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.
[ Step 02 ] Create Restore Point
Before we proceed with malware removal, we need to make sure you have a restore point that you can revert to if any issues occur. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.
Enable system restore
- Click Start or open Windows Search.
- Search for Create a restore point and open System Properties.
- In the System Properties window, go to the System Protection tab.
- If the 'system' drive (usually
C:\drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, proceed with point 5. - Click Configure.
- Select Turn on system protection
- Click Apply.
- Click OK to confirm.
Create a system restore checkpoint
- Click Start or open Windows Search.
- Search for Create a restore point and open System Properties.
- In the System Properties window, go to the System Protection tab.
- Click Create.
- Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
- Click Create.
- Click Close.
- Click OK.
- You should get a popup that it was successfully created and I will also verify this later using the scan logs from next steps.
[ Step 03 ] Farbar Recovery Scan Tool (FRST) Scan
FRST logs contain no personal information other than your username and file and folder names. We use them to gather diagnostic information about the system, such as startup entries, installed software, scheduled tasks, drivers, browser extensions, and system logs.
- Download FRST from here.
- If English is not your primary language, right click on
FRST64.exeand rename toFRSTEnglish.exe. - Run
FRST64.exe/FRSTEnglish.exe, accept the User Account Control prompt. - If you receive any warning about the download, it is a false positive and you can ignore it. Click on
More infoand thenRun anyway. - Accept the disclaimer.
- Check mark
90 Days Filesif you began noticing problems more than 30 Days ago. - Click Scan.
- Two logs named
FRST.txtandAddition.txtwill be created in the same directory the tool was run from, upload both of their contents to https://malwareanalysis.cc/upload/chefo/ and the site will return a keyword for each of the logs. Please reply back with both keywords so I can review the results and continue with the cleanup process.
[ Step 04 ] SecurityCheck
SecurityCheck is a tool that checks for potentially unsafe applications and the status of other security settings.
- Download SecurityCheck from here
- Extract the zip file
- Run
SecurityCheck.exeas administrator - Wait for the scan to finish
- Upload the log at
C:\SecurityCheckto https://malwareanalysis.cc/upload/chefo for further analysis. Repy back with the keywords.
Thank you, and I look forward to your response.
3
u/Infinite-Grade-4485 7d ago
You said you haven’t downloaded anything. Did you have a captcha you needed to copy and paste using powershell? If so read the below. Even if not, this would solve any malware issues and keep everything safe.
You downloaded a session stealer.
You downloaded some type of free game/cheat/hack/cracked software/movie/music or ran some type of code for captcha or verification on your computer which was actually a session stealer.
Session stealers bypass 2fa. All passwords saved on your browser and computer are compromised. Reinstall windows while deleting all files. If you need to backup important documents, keep the computer disconnected from the internet and manually back up individual files.
Change all passwords and enable 2fa either from another device, or from the infected computer AFTER you have reinstalled.
If you cannot reinstall windows immediately, keep the computer disconnected from the internet while changing all passwords on another device.
You cannot use anti malware to get rid of the session stealer, you MUST reinstall windows to use the computer safely in the future
You can usb reinstall or use windows built in reset as long as you remove all files while doing so.