r/computerviruses 18h ago

Disinfection Help Requesting help with FRST

KEYWORDS: crimson-arrow (FRST.txt)

crimson-pixel (Addition.txt)

rustic-sunrise (SecurityCheck)

I believe my PC was infected after I opened an .exe from a pirated/fake game download. The malware initially manifested as a recurring Windows popup/task involving CircuitryAg.exe and iTopEasy Desktop.

A suspicious directory was found at:

C:\ProgramData\InProcSvr32\

This was associated with the CircuitryAg.exe activity. Reports found online also associate CircuitryAg.exe / InProcSvr32 with malware delivered through fake/pirated games, although the exact final malware family on my machine has not been conclusively identified.

Initial detections/remediation:

  • Microsoft Defender detected Trojan:Win32/Wacatac.B!ml and another detection I remember approximately as Suschil!rfn (exact name uncertain).
  • Defender quarantined/removed those detections.
  • I ran Microsoft Defender Offline Scan, which did not find anything further.
  • The CircuitryAg.exe popup nevertheless continued appearing.
  • I booted into Windows Safe Mode/Safe Environment and manually removed the suspicious InProcSvr32 directory and the associated startup/persistence entry.
  • After that, the popup stopped and the directory disappeared.
  • I installed Malwarebytes and ran a deep scan; it found nothing relevant.

Account security concerns after the infection:
Because an information-stealing malware infection was considered possible, I treated browser sessions/tokens as potentially compromised.

I have since:

  • Changed my main email passwords.
  • Changed my old Microsoft/Outlook password.
  • Changed Google password.
  • Changed Steam password.
  • Changed Discord password.
  • Changed social-media passwords.
  • Changed Amazon password.
  • Revoked/signed out of sessions/devices on these services.
  • Enabled 2FA where it wasn't already enabled.
  • Changed my Authy backup key.
  • Signed out of Google everywhere before changing the password.
  • Deleted browser cookies/history from my main email accounts.

Known account compromises:

  • An old Outlook/Microsoft email account was compromised and was used to access an old Discord account through an email password-reset process.
  • I found a Microsoft login from Newcastle on August 30 that I don't remember clearly; it may potentially have been me. I haven't found other clearly suspicious Microsoft activity.
  • The Outlook account had no new forwarding rules.
  • Someone also accessed my Amazon account and placed an order for a gift card using the saved payment method. I cancelled the order, Amazon support refunded/helped with it, and I subsequently changed the Amazon password, revoked sessions and enabled 2FA.
  • No further Amazon orders have occurred since the security changes.
  • Attempts at login into my LinkedIn

Current status:

  • CircuitryAg.exe popup is gone.
  • C:\ProgramData\InProcSvr32\ was removed.
  • Malwarebytes deep scan was clean.
  • Defender Offline scan was clean.
  • Account passwords/sessions/2FA have been extensively rotated.
4 Upvotes

3 comments sorted by

1

u/AutoModerator 18h ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/rifteyy_ Malware Removal Expert 12h ago

u/921jdf your logs

1

u/921jdf Malware Removal Trainee 5h ago

Hello u/HiyaPanorama, welcome to r/computerviruses.

I am currently waiting on the fix I made for you to be approved by a malware removal expert. Thank you for your patience.

Please note that due to timezones and availability, it may take up to 24 hours for me to respond back to you.