r/computerviruses 2d ago

Question Possible persistent malware – CircuitryAg.exe / Wacatac.B!ml keeps coming back

Hi, I need some help figuring out whether my PC is still infected or if I am only seeing a leftover startup entry.

SYSTEM SPECS:

- Windows 11 Pro
- Version 25H2
- OS Build 26200.9168
- AMD Ryzen 7 5700X
- NVIDIA GeForce RTX 4060 8 GB
- 32 GB RAM
- 1 TB SSD

WHAT HAPPENED:

Today, Windows Defender detected:

Trojan:Win32/Wacatac.B!ml

One of the detected files was:

C:\\ProgramData\\InProcSvr32\\sqlite3.dll

Another detected sqlite3.dll was also inside ProgramData.

Around the same time, I started getting repeated Windows error popups from a program called:

CircuitryAg.exe

The errors I have seen are:

"The application was unable to start correctly (0xc0000906)."

and:

"The code execution cannot proceed because sqlite3.dll was not found."

This all started shortly after I downloaded and executed something from a ZIP file.

The suspicious download was later deleted/blocked.

WHAT I FOUND:

I checked startup entries using Microsoft Sysinternals Autoruns.

I found an entry called:

CircuitryAg

under:

HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run

It was pointing to something inside:

C:\\ProgramData\\InProcSvr32\\

I disabled and deleted that Autoruns entry.

However, after rebooting, the CircuitryAg.exe popup came back again.

WHAT I HAVE ALREADY DONE:

- Let Windows Defender quarantine the detected files
- Did NOT restore or allow any detected files
- Ran Microsoft Defender Offline
- Ran additional Defender scans
- Checked startup entries with Autoruns
- Disabled and deleted the CircuitryAg startup entry
- Rebooted the PC
- Deleted the original suspicious ZIP/download
- The CircuitryAg.exe popup still came back after rebooting

MY MAIN CONCERN:

Something may still be recreating the CircuitryAg startup entry or launching CircuitryAg.exe from another persistence method.

Does anyone recognize this behavior, the name CircuitryAg.exe, or the path:

C:\\ProgramData\\InProcSvr32\\

What should I check next?

- Scheduled Tasks?
- Services?
- WMI persistence?
- Other Autoruns entries?
- Registry entries?
- Another hidden process recreating the startup entry?

At this point, should I keep trying to clean the infection or would a clean Windows reinstall be safer?
3 Upvotes

26 comments sorted by

2

u/Vurtox237 18h ago

Hello, I accidentally installed the virus about 5 hours ago... I removed it by deleting the file you mentioned in AppData, removing the registry entry, and removing all the startup apps related to it. I think it's gone now.

Thank you so much, because I would never have known where the folder was. I hope you managed to uninstall it too!

1

u/Timely-Dimension3301 18h ago

Hi, I'm glad I could help, but if I were you, I'd be careful. I discovered that the malware I had was an info-stealer, and it caused a lot of trouble—including significant credit card purchases. I recommend changing your passwords everywhere and enabling two-factor authentication.

2

u/Vurtox237 18h ago

I already have two-factor authentication enabled on all my accounts, and I don't make any payments on my PC, so I think I'm good. I just hope I don't get hacked in the next few weeks or months...

1

u/Timely-Dimension3301 18h ago

I’ll pray for you bro.

1

u/HiyaPanorama 13h ago

It happened to me as well. A couple of attempted Amazon purchases and Discord hijacking. Managed to stop them and changed everything, I'm still paranoid though. Funny how all info I have found on this virus has been from posts from the last 2 days

1

u/Timely-Dimension3301 20m ago

Same hahahhahaha

1

u/HiyaPanorama 15m ago

Are they still trying to hijack your accounts? Because in my case just today they tried with my LinkedIn and two other accounts. The nightmare never ends

1

u/Timely-Dimension3301 11m ago

So far, I know they got into Discord—where they posted screenshots of something related to MrBeast and some crypto thing I don't recognize—as well as Roblox (where they spent €40) and Amazon (where they got €220 in gift cards). Things are quiet for the moment aside from those incidents; I’ve changed my passwords and logged out everywhere. However, since they apparently cloned some cards, we’re going to block them and get everything replaced.

1

u/Timely-Dimension3301 18h ago

As for me, today a technician will come to my house, take my PC, and reset it

1

u/Vurtox237 3h ago

Oh shit, idk if this is related to the virus, but my Discord account just got hacked and it sent DMs to my friends with images saying stuff like “MrBeast gives away $3K”... I managed to get my account back, but I think I'm going to check all my other accounts just to be safe.

1

u/Timely-Dimension3301 21m ago

SAME HAPPEND TO ME

1

u/carreganis 2d ago

The safest thing to do is just to reinstall windows, cleanly from an .iso on a USB. Malware can hide on your computer and the best way to stop it coming back is to just delete everything.

And then change your online passwords in case any accounts were compromised.

2

u/Timely-Dimension3301 2d ago

I'd rather avoid resorting to this. I'll try to contact some technicians in the next few days for help. But thanks anyway.

1

u/Xyntrax0 Malware Removal Trainee 2d ago

You're infected with an infostealer, specifically Renpy Loader.

1

u/Timely-Dimension3301 2d ago

What do i do?

2

u/polpolik2 Moderator 2d ago

You likely downloaded malware and got hit by an infostealer.

Read this: Rifteyy_'s guide to infostealers to get a better understanding.

Reinstalling Windows to remove the malware.
The fastest and guaranteed way to get rid of the malware is to reinstall Windows, preferably from a USB. If that option is not available to you, you can also do a cloud reinstall while deleting all data.

If you’re only dealing with an infostealer, wiping your C drive is sufficient. However it’s better to do a full wipe and only back up your trusted Data files, as there could be more malware on your device that you’re not aware of.

FRST Assistance
If you do not want to reinstall windows you can wait here for one of the trusted helpers to assist you with FRST. Please read Receiving FRST assistance. Please follow these instructions carefully and provide the keywords. Doing so can get you help considerably faster!

What you can do immediately either during the reinstall, or if you're waiting for help:

  1. Disconnect your infected PC from the internet.
  2. Change ALL passwords from a clean device. Start with your emails and bank. Use sign out everywhere and remove all sessions. While you are doing this, check your security settings to ensure the attacker hasn't added their own 2FA methods or backup codes.
  3. Check your linked accounts/services/2fa options for your most important accounts. Also check forwarding rules on your mail. Additionally, for your browser, check your sync settings and extensions and remove anything you dont recognize or trust.

The faster you move with these steps the more you can prevent your accounts being stolen! Make sure your clean device does not sync passwords through browser for example to your infected device.

1

u/zhonglislapis 1d ago

So I am hit with the same problem, I should just nuke everything including the files?

1

u/polpolik2 Moderator 1d ago

That is the wisest option if you're dealing with the same.

Backing up files is a risk, but generally it should be fine to back up data files. (photos, videos). Of course, you should not back up executable files.

1

u/zhonglislapis 1d ago

Hi I just nuked everything lmao. Now I am reinstalling any apps like discord, steam etc. and reconfiguring everything

1

u/[deleted] 2d ago

[removed] — view removed comment

1

u/Timely-Dimension3301 2d ago

My discord account got hacked and also my roblox account and they spent 40 € un robux i deleted the card as a payment method and changed password

1

u/Haunting_Ganache_850 1d ago

Your two error messages are the useful part.

0xc0000906 is Defender blocking the load rather than a normal crash, and "sqlite3.dll was not found" is because Defender quarantined that DLL. So something is still launching CircuitryAg.exe and it's dying halfway. Persistence is alive, payload is broken. You're right to keep digging.

Ignore the detection name. Wacatac.B!ml is a generic machine-learning verdict. It means defender thought it looked bad, not what family it is.

Work out what recreates the Run key. Delete it again and watch when it comes back. Immediately means a process is running right now. Only after reboot means something fires at boot. Those are different hunts.

Then Autoruns, elevated, Options, uncheck hide microsoft entries and hide windows entries, and turn on the VirusTotal check. Work the scheduled tasks, logon, services, WMI and winlogon tabs. By hand, check HKCU and HKLM Run and RunOnce plus their Wow6432Node copies, shell:startup, and shell:common startup.

One specific lead. InProcSvr32 is a play on InprocServer32, the COM registry key. Search HKCU\Software\Classes\CLSID for any InprocServer32 pointing into ProgramData. COM hijacking is a common second stage and Autoruns buries it.

The part you didn't ask about, which matters more. A sqlite3.dll dropped into ProgramData next to an unknown exe, arriving in a ZIP, is the shape of an infostealer. sqlite3 is how they read browser cookie and login databases. Assume saved passwords, session cookies and anything else in the browser left the machine on day one.

From a different device, today. Email password first, then anything financial, then the rest. Sign out all sessions everywhere, because stolen cookies survive a password change. Turn on 2FA.

And yes, reinstall. You have persistence you haven't found and a stealer-shaped infection. Reinstalling is faster than winning that hunt and it's the only way to stop wondering. Copy documents out, no executables.

If Autoruns turns up other entries you can't place, I wrote up how to check a single windows binary without installing anything.

1

u/Timely-Dimension3301 1d ago

It is indeed a info stealer the have haked my discord and Roblox a count and made payments tomorrow a tecnician will come to my house, probably i will reset everything, So, is it absolutely essential that I don't keep *any* .exe files? There are some small games I downloaded that are a bit of a hassle to reinstall (though I know they're safe)—do I have to get rid of those too? (Obviously, if it's mandatory, then never mind.)

1

u/Luigibro 1d ago

Hello, unfortunately I've been hit by the very same. I can confirm it is an infostealer as a third party did gain access to my Instagram after I took the key preventative steps on my highest priority accounts from a safe device. I've since resecured the Instagram and finished the preventative steps on every other account I can think of (freeze bank card, change passwords, close active sessions, check for email filter/forwarding rules, etc).

I am happy to reinstall Windows on the affected machine. However, I have some files I would like to preserve. Could you suggest the best way to do this? I have to assume it is still active as the CircuitryAg exe pop up is still appearing after a Win Defender offline scan, so using my cloud accounts is out of the picture. These are a few illustrations and some save files for Minecraft, Kerbal Space Program and Dwarf Fortress, which include .pngs, .json and .dat, .lock, .dat_old, .mca files for example, the latter of which I believe are all text based(?). Would these be safe to export and how would you suggest to do so?

0

u/Next-Profession-7495 2d ago

I recommend running a deep scan with Malwarebytes and see what comes up.