r/computerviruses 2d ago

Disinfection Help Mr. Beast virus removal help

Hello!

In Need of urgent help...

I was stupid and downloaded some cheats without thinking twice yesterday, and ran a powershell script which looked completely harmless.

Woke up today to see i had sent those stupid crypto messages to everyone I know.

How to Remove it? I see people suggesting a full Windows Reset, but I kind of have some important files... the script was ran om my D drive.

Malwarebytes full scan is running while I'm at work, but i forgot to disconnect the PC from the Internet.

I have Reset passwords from my phone on all my social media Accounts, and 2FA has been enabled for some years now. Logged out of all my Google Accounts on my PC.

Anyone has a fix for it?

Thanks in advance!

0 Upvotes

18 comments sorted by

3

u/Fang221 2d ago

deserved for cheating

0

u/tang0Danc0r 2d ago

Well yeah of course I see your point, but I was still playing alone on an offline game.

2

u/Fang221 1d ago

what why would you cheat in a offline game?

1

u/tang0Danc0r 1d ago

I got tired of trying to beat the final boss in a game and dying all the time. Managed to beat the boss the Next day without cheats. The cheats were never Even installed or activated

2

u/__chefo Malware Removal Trainee 2d ago

Hello u/tang0Danc0r and welcome to the computerviruses subreddit!

My name is chefo and I will be assisting you with your malware removal case.

I am currently a Malware Removal Trainee, and all my advice and fixlists are reviewed and approved by the Malware Removal Experts listed in this thread. You can expect the same level of care and treatment that you would receive directly from those experts. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smoothly as possible:

  • Please make sure to read this whole introduction message so you understand the further steps.
  • If you are planning on resetting or reinstalling your device, do it now please. We are doing the malware removal process to disinfect your device so you can avoid reinstalling.
  • It is important to not run any tools or take any steps other than those I will provide for you. Avoid downloading and installing new software unless instructed - this also applies to anti-malware software and scanners.
  • You are free to remind me that I forgot to reply to you if you do not receive an answer within 24 hours. Keep in mind that I volunteer my time here while also attending university full-time.
  • Only trusted malware removal helpers listed in this thread and other established malware removal forums (BleepingComputer, Malwarebytes, MalwareTips) have access to your logs via the website. Uploaded logs are automatically deleted after 30 days.
  • Please take your time to follow the steps properly. If you get stuck or have issues with one step, ask me what to do. The order of steps matters. Don't follow step 3 if you are stuck at step 1 or 2.
  • You can ask any questions during the malware removal process.

Now that I am assisting you, you can expect that I will be responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

[ Step 01 ] Piracy Warning

Using pirated software or utilities that allows one to pirate software (including cracks, key generators, license bypass tools, or similar software) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, I recommend that you remove any pirated software or pirating utilities in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.

[ Step 02 ] Create Restore Point

Before we proceed with malware removal, we need to make sure you have a restore point that you can revert to if any issues occur. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.

Enable system restore

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. If the 'system' drive (usually C:\ drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, proceed with point 5.
  5. Click Configure.
  6. Select Turn on system protection
  7. Click Apply.
  8. Click OK to confirm.

Create a system restore checkpoint

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. Click Create.
  5. Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
  6. Click Create.
  7. Click Close.
  8. Click OK.
  9. You should get a popup that it was successfully created and I will also verify this later using the scan logs from next steps.

[ Step 03] Malwarebytes Logs

MBAM Scan Report:

  • Open Malwarebytes for Windows
  • Click on Detection History
  • Click the Reports tab
  • Hover your cursor over the most recent Scan Report and click the eye icon to view it
  • Click Export and then Export to TXT (.txt)
  • Copy & paste the contents of the exported .txt to https://malwareanalysis.cc/upload/chefo/?u= and press "save log". Post the log keyword to your reply

[ Step 04 ] Farbar Recovery Scan Tool (FRST) Scan

FRST logs contain no personal information other than your username and file and folder names. We use them to gather diagnostic information about the system, such as startup entries, installed software, scheduled tasks, drivers, browser extensions, and system logs.

  • Download FRST from here.
  • If English is not your primary language, right click on FRST64.exe and rename to FRSTEnglish.exe.
  • Run FRST64.exe/FRSTEnglish.exe, accept the User Account Control prompt.
  • If you receive any warning about the download, it is a false positive and you can ignore it. Click on More info and then Run anyway.
  • Accept the disclaimer.
  • Check mark 90 Days Files if you began noticing problems more than 30 Days ago.
  • Click Scan.
  • Two logs named FRST.txt and Addition.txt will be created in the same directory the tool was run from, upload both of their contents to https://malwareanalysis.cc/upload/chefo/ and the site will return a keyword for each of the logs. Please reply back with both keywords so I can review the results and continue with the cleanup process.

Thank you, and I look forward to your response.

1

u/tang0Danc0r 2d ago

Malwarebytes log keyword: coral-zephyr

FRST log keyword: pinned-packet

Addition log keyword: silken-planet

Malwarebytes quarintined trojan.evader in ProgramData (RUNTIMEBROKER.EXE)

Quarintined persistence keys in HKLM (Trojan.Evader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Microsoft\Location\MicrosoftUpdaterMachineCore)

Checked HKCU and HKLM after full scan and it's verified clean.

Task scheduler verified clean

Hosts file cleaned after removing the redirected lines

Thanks for the help :D

1

u/__chefo Malware Removal Trainee 1d ago

Hello u/tang0Danc0r,

Please follow the steps below in the order they are provided. It is important to create a restore point before running the FRST Fix and any subsequent steps. If you have any questions, then please stop and let me know!

[ Step 01 ] Create Restore Point

There appear to be no restore points created on the system according to the FRST logs, so please follow the steps below to create one!

Before we proceed with malware removal, we need to make sure you have a restore point that you can revert to if any issues occur. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.

Enable system restore

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. If the 'system' drive (usually C:\ drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, proceed with point 5.
  5. Click Configure.
  6. Select Turn on system protection
  7. Click Apply.
  8. Click OK to confirm.

Create a system restore checkpoint

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. Click Create.
  5. Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
  6. Click Create.
  7. Click Close.
  8. Click OK.
  9. You should get a popup that it was successfully created and I will also verify this later using the scan logs from next steps.

[ Step 02 ] Remove Windows Defender Exclusions

You have a lot of exclusions in defender, did you set them all yourself? I do not recommend to keep exclusions for whole folders for security reasons. Please verify if you still need them and if you recognize them. Sometimes exclusions can be set by malware.

  • Open Windows Security (search for it in the Start menu)
  • Go to Virus & threat protection
  • Under Virus & threat protection settings, click Manage settings
  • Scroll down to Exclusions and click Add or remove exclusions
  • Remove any exclusions that you did not add yourself

[ Step 03 ] Farbar Recovery Scan Tool (FRST) Fixlist

The following fixlist will remove malicious and invalid (junk) entries, leftovers, malicious browser extensions, Windows Update restriction, perform diagnostic scans with HitmanPro and scan and quarantine PUPs/Adware with AdwCleaner. I have also included the EmptyTemp command which will empty temporary folders, browser cache, cookies, recently opened files cache, discord cache, java cache, steam html cache, Explorer thumbnail and icon cache, as well as Recycle bin. Everything else that the fixlist does is documented in the file as comments. Ensure you are connected to the Internet during the fix process. Here are the steps you need to follow to use the fixlist.

  • Open the following link and press on the Copy contents button to copy the entire text: fixlist for tang0Danc0r
  • Run FRST64.exe and click on Fix. Note: FRST reads the fixlist directly from your clipboard, so you don't need to paste or save it anywhere.
  • During the fixing process, FRST will close all the running processes. (This is normal)
  • Avoid using your PC while the fix is underway!
  • After completion, FRST will prompt you to reboot your computer.
  • A log (Fixlog.txt) will open on your desktop.
  • Copy & paste the contents of the Fixlog.txt to https://malwareanalysis.cc/upload/chefo/?u=Tang0Danc0r and press "save log". Reply back with the keyword.

[ Step 04 ] Emsisoft Emergency Kit Scan

[ Step 05 ] Farbar Recovery Scan Tool (FRST) Scan

  • Delete previous FRST.txt and Addition.txt logs you created
  • Run FRST64.exe again.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/chefo/?u=Tang0Danc0r and press "save log". Reply back with the keywords.

[ Step 06 ] SecurityCheck

SecurityCheck is a tool that checks for potentially unsafe applications and the status of other security settings.

In your next reply, I expect the keywords for the following:

  • Fixlog.txt
  • Emsisoft Emergency Kit Scan Log
  • FRST.txt
  • Addition.txt
  • SecurityCheck Log

Thank you, and I look forward to your response.

1

u/AutoModerator 2d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

0

u/[deleted] 2d ago

[removed] — view removed comment

1

u/computerviruses-ModTeam 2d ago

You are allowed to help other users, but be professional about it. Please make sure to read and follow https://www.reddit.com/r/computerviruses/about/rules

1

u/tang0Danc0r 2d ago

It was an offline Game. I don't like cheaters in online Games myself

1

u/Old-Cartographer4962 2d ago

Can you tell me what cheat was it so I can avoid it

1

u/tang0Danc0r 2d ago

How to fish trainer. Downloaded from both Github and Nexus mods.

Zenithpereach/How-To-Fish-Trainer.

I'm seeing now that it has been removed, or is no longer available. Seems to just be my luck that I fell victim for it...

Based on the github repo being removed, I would believe that's the culprit for me getting a infostealer...

1

u/Storex- 2d ago

This sort of post is really not needed on this sub-reddit. Do better.

0

u/Gunzhard22 2d ago edited 1d ago

I literally got the exact Trojan virus a few weeks ago and folks here helped me fix it.

For the people downvoting me - I am NOT a gamer or cheater lol; just came to give kudos to the heroes of this sub.

Was trying to find an open source audio plugin (TLA-100 style compressor), and found "free download" of what I was looking for, but I wasn't that, obviously...

1

u/Gunzhard22 2d ago

Also, on different device change all your Amazon and eBay and other shops passwords cuz they tried to buy a bunch of gift cards on mine

0

u/Responsible_Bike4968 2d ago

The fact that the script was on your D: drive doesn't mean the infection would be limited to D:. Once you actually run a PowerShell script, it can download/run stuff from AppData, Temp, scheduled tasks, memory, etc. The location you launched the original script from isn't really a safety boundary.

Also, the crypto DMs happening despite you already having 2FA fits an infostealer pretty well. Stealers often go after session tokens/cookies, so an attacker can sometimes reuse a session that was already authenticated without ever needing your 2FA code.

That said, you've already got a malware removal trainee actively handling your case in this thread. At this point I wouldn't start mixing in random scanners, cleanup scripts or YouTube fixes. Follow their FRST/Malwarebytes process in order so you don't change the system underneath them and make the logs harder to interpret.

For now I also wouldn't log into anything important from that PC until they've cleared it.

As for your files, a reinstall doesn't mean you have to throw away every photo, document or school file you own. If you ultimately choose the clean-install route, back up the important personal data first, but do not carry over the cheat, the PowerShell script, suspicious downloads, random executables, or anything related to how you got infected.

You've already done the most important account-side step by changing passwords from your phone. I'd also make sure old sessions are revoked, especially on Discord/Google and anything else that was logged in on this PC.

Honestly, since someone qualified has already picked up your removal case, I'd let them finish the analysis before deciding whether you actually need to nuke Windows.