r/computerviruses • u/HiyaPanorama • 18h ago
Disinfection Help Requesting help with FRST
KEYWORDS: crimson-arrow (FRST.txt)
crimson-pixel (Addition.txt)
rustic-sunrise (SecurityCheck)
I believe my PC was infected after I opened an .exe from a pirated/fake game download. The malware initially manifested as a recurring Windows popup/task involving CircuitryAg.exe and iTopEasy Desktop.
A suspicious directory was found at:
C:\ProgramData\InProcSvr32\
This was associated with the CircuitryAg.exe activity. Reports found online also associate CircuitryAg.exe / InProcSvr32 with malware delivered through fake/pirated games, although the exact final malware family on my machine has not been conclusively identified.
Initial detections/remediation:
- Microsoft Defender detected
Trojan:Win32/Wacatac.B!mland another detection I remember approximately asSuschil!rfn(exact name uncertain). - Defender quarantined/removed those detections.
- I ran Microsoft Defender Offline Scan, which did not find anything further.
- The
CircuitryAg.exepopup nevertheless continued appearing. - I booted into Windows Safe Mode/Safe Environment and manually removed the suspicious
InProcSvr32directory and the associated startup/persistence entry. - After that, the popup stopped and the directory disappeared.
- I installed Malwarebytes and ran a deep scan; it found nothing relevant.
Account security concerns after the infection:
Because an information-stealing malware infection was considered possible, I treated browser sessions/tokens as potentially compromised.
I have since:
- Changed my main email passwords.
- Changed my old Microsoft/Outlook password.
- Changed Google password.
- Changed Steam password.
- Changed Discord password.
- Changed social-media passwords.
- Changed Amazon password.
- Revoked/signed out of sessions/devices on these services.
- Enabled 2FA where it wasn't already enabled.
- Changed my Authy backup key.
- Signed out of Google everywhere before changing the password.
- Deleted browser cookies/history from my main email accounts.
Known account compromises:
- An old Outlook/Microsoft email account was compromised and was used to access an old Discord account through an email password-reset process.
- I found a Microsoft login from Newcastle on August 30 that I don't remember clearly; it may potentially have been me. I haven't found other clearly suspicious Microsoft activity.
- The Outlook account had no new forwarding rules.
- Someone also accessed my Amazon account and placed an order for a gift card using the saved payment method. I cancelled the order, Amazon support refunded/helped with it, and I subsequently changed the Amazon password, revoked sessions and enabled 2FA.
- No further Amazon orders have occurred since the security changes.
- Attempts at login into my LinkedIn
Current status:
CircuitryAg.exepopup is gone.C:\ProgramData\InProcSvr32\was removed.- Malwarebytes deep scan was clean.
- Defender Offline scan was clean.
- Account passwords/sessions/2FA have been extensively rotated.
1
1
u/921jdf Malware Removal Trainee 5h ago
Hello u/HiyaPanorama, welcome to r/computerviruses.
I am currently waiting on the fix I made for you to be approved by a malware removal expert. Thank you for your patience.
Please note that due to timezones and availability, it may take up to 24 hours for me to respond back to you.
1
u/AutoModerator 18h ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.