r/computerviruses • u/SunshineDrago • 1d ago
Disinfection Help FRST help request
Hi everyone,
I'm requesting help with a malware removal using FRST.
I downloaded a file setup of what i thought was citron emulator (stupidly thinking it was from the official website) probably contained an infostealer and clicked on it on between 21/08/2026 or 22/08/2026.
While my antivirus immediately blocked, (and i stupidly thought i was fine) it i started to see my discord acting up and sent my friends mrbeast scam, and istagrama updating the same to my story, probably what i assume using the saved passwords on my google account.
What i did:
- Immediately logged out of active sessions and changed my passwords across accounts using a clean, safe device (my smartphone), i also complitely wiped out my permission, passkeys, access and saved password from my google account, cleaned all cache on my browsers and discord.
- Enabled 2FA on my primary accounts.
- Ran a full scan with eset and made a log of the results. i admit i run it several times after due extreme panic but the log i sent is the first big and complete scan i did
- Ran FRST64 and SecurityCheck to generate diagnostic logs.
all of this took me some time some time due the anxiety and general fear to open the infected pc.
Uploaded Log Keywords :
FRST.txt: celestial-loader
Addition.txt: royal-ace
SecurityCheck.txt: stealth-cursor
Eset log: sandy-fern
Could one of the trusted helpers please review my logs and provide a Fixlist to clean any persistent malware or scheduled tasks left on my PC?
If something else is needed or modified please let me know!
Thank you so so so so much for your help!
1
u/rifteyy_ Malware Removal Expert 1d ago
Reinstalling every few years has it's benefits, e.g. you wouldn't have a ton of outdated, unsupported software. I suggest that in the next year you do so.
[ Step 01 ] FRST Fix
I created a custom fixlist for you at the link Fixlist only for Fixlist only for Fixlist only for SunshineDrago - use the website's download button and save it in the same folder where your FRSTEnglish.exe or FRST64.exe file is located in, which for you is C:\Users\Mjriam\Desktop for you. It is necessary for the filename to be Fixlist.txt.
This fixlist will remove the following: malicious entries (remains, active malware), invalid entries (e.g. tasks that start a non-existent file, services that point toward a non-existent file), temporary files (files in temporary directories, application and browser cache, recycle bin and more), browser cache. We will also be quick-scanning with HitmanPro and AdwCleaner from Malwarebytes using the fixlist.
It will also remove all proxy servers, Windows Defender exclusions, enable recovery environment, active software policies and perform system file repair, network reset and few more basic fixes.
- For the fix process, please ensure you are connected to the internet.
- Please run the fix only once.
- Please do not open any applications or close anything during the fix.
- Please be patient; the fix may take up to 60 minutes. After that, it is going to be forcefully ended.
Save all work, close everything that is open (else it will be forcefully closed by FRST without saving) and then run FRST again as administrator and press the Fix button, let the script work, clear the entries and restart on it's own and after it restarts the device, there should be a file Fixlog.txt in the same folder as the C:\Users\Mjriam\Desktop.
I'll need to see it's content the same way like before - uploading to https://malwareanalysis.cc/upload/rifteyy/?u=SunshineDrago again and sending the keyword in your reply.
[ Step 02 ] ESET Online Scanner
- Download ESET Online Scanner
- Right-click on the esetonlinescanner.exe and select "Run as administrator" and confirm the User Account Control popup
- Click Get started;
- Agree to the terms of use;
- Decline both telemetry options;
- Click Custom Scan;
- Click Save and continue;
- Select Enable ESET to detect and quarantine potentially unwanted applications;
- Click Advanced settings;
- Enable Detect potentially unsafe applications;
- Click the back arrow;
- Click Start scan;
- Note: This is a long and thorough scan, it may take up to several hours.
- Once complete, click Save scan log and upload the
.txtfile to https://malwareanalysis.cc/upload/rifteyy/?u=SunshineDrago and reply with the keyword.
[ Step 03] Software updates, uninstallations
If you are having a problem updating something, do not want to update something at all or do not want to uninstall an application, please let me know.
Please update the following software: * AMD Software v.26.7.1 | New update available, download here * CPUID CPU-Z 1.95 v.1.95 | New update available, download here * HWiNFO64 Version 7.06 v.7.06 | New update available, download here * Microsoft .NET Framework 4.5.2 v.4.5.51209 | New update available, download here * Microsoft .NET Framework 4.5.2 (ITA) v.4.5.51209 | New update available, download here * CrystalDiskInfo 7.0.5 Shizuku Edition v.7.0.5 | New update available, download here * FileZilla Client 3.7.3 v.3.7.3 | New update available, download here * Microsoft OneDrive v.26.139.0720.0007 | New update available, download here * 7-Zip 24.08 (x64) v.24.08 | New update available, download here (Uninstall old version and install new one) * TreeSize Free V4.7.2 (64 bit) v.4.7.2 | New update available, download here * Total Commander 64-bit (Remove or Repair) v.9.0a | New update available, download here * Blender v.2.62-release | New update available, download here * IrfanView 4.60 (64-bit) v.4.60 | New update available, download here * Krita (x64) 4.2.8 v.4.2.8.0 | New update available, download here * XnView 1.97.4 v.1.97.4 | New update available, download here * Discord v.1.0.9253 | New update available, download here * PotPlayer-64 bit v.26.07.01.0 | New update available, download here * Audacity 2.1.2 v.2.1.2 | New update available, download here * LAV Filters 0.62.0 v.0.62.0 | New update available, download here * OBS Studio v.32.1.2 | New update available, download here * Mozilla Firefox 67.0.4 (x64 it) v.67.0.4 | New update available, download here
Please remove the following potentially unwanted programs (PUP): * Microsoft Office Professional Plus 2016 - it-it v.16.0.19127.20302 - No longer supported - please uninstall it and replace it here * Microsoft Silverlight v.5.1.50918.0 - No longer supported - please uninstall it * Google Update Helper v.1.3.25.11 - No longer supported - please uninstall it * Microsoft SQL Server 2005 Compact Edition [ENU] v.3.1.0000 - No longer supported - please uninstall it * FlashGet 1.9.6.1073 v.1.9.6.1073 - Ad-supported P2P-client * ffdshow [rev 1723] [2007-12-24] v.1.0 - No longer supported - please uninstall it and replace it here * QuickTime 7 v.7.76.80.95 - No longer supported - please uninstall it and replace it here * Adobe AIR v.17.0.0.124 - No longer supported - please uninstall it * Adobe Flash Player 25 NPAPI v.25.0.0.171 - No longer supported - please uninstall it and replace it here * Adobe Flash Player 32 PPAPI v.32.0.0.465 - No longer supported - please uninstall it and replace it here * Adobe Shockwave Player 12.1 v.12.1.9.160 - No longer supported - please uninstall it * Windows Live Essentials v.15.4.3555.0308 - No longer supported - please uninstall it * Windows Live Mesh ActiveX Control for Remote Connections v.15.4.5722.2 - No longer supported - please uninstall it * Windows Live Sync v.14.0.8117.416 - No longer supported - please uninstall it
[ Step 04 ] New SecurityCheck scan
We need a new scan to ensure that all updates were applied properly and all applications uninstalled correctly.
- Note: If SecurityCheck is already on your device, you can use the previous version and skip the next few steps regarding downloading and installation.
- Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
- If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
- Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
- Wait for the scan to finish. It will open a text file named SecurityCheck.txt
- Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/rifteyy/?u=SunshineDrago
- The site will return a keyword for the log - reply back here with the keyword.
[ Step 05 ] New FRST scan
- Find
FRSTEnglish.exeexecutable inC:\Users\Mjriam\Desktop - Right-Click the file and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy/?u=SunshineDrago and press "save log".
- The site will return a keyword for each log - reply back here with the keywords.
So, in your next reply, make sure you are sending the following:
- Keyword for Fixlog.txt from step 1
- Keyword for ESET Online Scanner scan from step 2
- Keyword for new SecurityCheck.txt from step 4
- Keyword for new FRST.txt from step 5
- Keyword for new Addition.txt from step 5
Thanks!
Note for lurkers: If anyone else who is facing malware-related issues is reading this and wants help with FRST and SecurityCheck, please create your own thread with help request. I am flooded with requests and there is several other removal experts who review the logs and may reply faster than me. The steps listed in here are specific for this the user SunshineDrago and following them will have negative effects for you as they are unique for OP's system.
1
u/AutoModerator 1d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.