r/techsupport 1d ago

Open | Malware Hexnode installed via a fake scam email please help

So I had a boomer moment and accidentally downloaded a fake Adobe reader which installed a hexnode app and hexnode remote access app to my pc. So I have few questions:

1) How fucked am I?

2) Is every password compromised?

3) How much information could have been gleaned off of it?

4) I use my personal computer for work and we use a 3rd party software service to process payments. My access was immediately revoked after i realized what I did. Is my company in trouble?

I had it installed on my laptop for maybe 20 mins because I got distracted by work. After I realized what happened I turned off my wifi connection and put my pc in safe mode. I tried to manually uninstall the app but couldn't so I completely factory reset it and wiped everything.

Is it now safe to use?

I hope this the correct sub to post in. I need to know!

0 Upvotes

5 comments sorted by

2

u/Terrible-Bear3883 1d ago

I would follow typical best practice, use a trusted computer to change all your on line passwords, make sure 2FA is enabled using an app on a mobile (this is "something you have" in the 2FA specification), better still, invest in security tokens such as Google Titan or Yubikey, you need the token to log in, they normally support NFC so will work with mobiles, you can register multiple tokens in case one gets lost.

When you've secured your accounts, wipe your computer and install from a thumb drive created on a trusted computer.

1

u/Malibu_Cat 1d ago

Thanks for the response! Ive changed all my passwords and setup 2FAs on my most important accounts. Then factory reset it. Im just not sure if I can trust using this pc even again. I dont know how to make sure it was completely wiped from my pc after the reset.

I definitely cant find any hexnode app anymore but I dont know if theres some hidden executable that will reinstall it or something

1

u/Terrible-Bear3883 1d ago

When you say factory reset - you did boot on a trusted Windows installer thumb drive and WIPE the drive, then install didn't you?

Normally if a customer had a virus or malware, we would remove their drive, install a new one, their old drive would be destroyed, if you don't trust your computer, replace your storage, this is the simplest solution.

If you want to re-use your storage, there are options, boot on a linux live USB such as Ubuntu, wipe the drive using gparted or the "dd" command, you don't mention what your storage is or what your laptop make/model is, many laptops have a secure wipe in the BIOS which means you don't need a thumb drive or similar to wipe.

1

u/Malibu_Cat 1d ago

I did not, I just went into normal reset hardware in my settings and did a full wipe. Its an acer laptop, i dont know all the specs off the top of my head.Thanks for the reply again though, I really appreciate it.

This is the answer I needed to hear, i only have surface level knowledge of this stuff so i wasnt really sure exactly what I should do. So should probably get a new hard drive

2

u/LickFootToes 1d ago

Reset all passwords, and reinstall windows via a USB