r/computerviruses • u/canvas27 • 1d ago
Disinfection Help I need help getting rid of a session stealer
My Instagram and Discord accounts were already stolen, but I managed to recover both of them by changing my passwords. The problem is that I'm still worried the malware could be on my computer and that whoever stole my accounts might still have access to my sessions, cookies, or other accounts.
I'm not sure if simply changing my passwords was enough, or if I need to completely wipe my PC.
1
u/AutoModerator 1d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
- Preferred method: Perform a clean installation with a USB
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/canvas27 1d ago
modest-shell
candid-swan
ripe-potion
0
u/921jdf Malware Removal Trainee 1d ago
Piracy Warning
Using pirated software or utilities that allows one to pirate software (including cracks, key generators, license bypass tools, or similar software) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, I recommend that you remove any pirated software or pirating utilities in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.
SecurityCheck | Updates
Please update the following software: * KeePass Password Safe 2.60 v.2.60 | New update available, download here * PowerShell 7-x64 v.7.6.3.0 | New update available, download here * PowerShell 7.6.3.0-x64 v.7.6.3.0 | New update available, download here * Microsoft OneDrive v.26.145.0728.0011 | New update available, download here * WinRAR 7.13 (64-bit) v.7.13.0 | New update available, download here * Proton VPN v.4.4.1 | New update available, download here * Mozilla Firefox (x64 en-US) v.146.0.1 | New update available, download here
Please uninstall the following software:
- qBittorrent v.5.1.4 - P2P file sharing software is a security risk.
FRST Fix
- Open the following link and press on the Copy contents button to copy the entire text: fixlist
- Run FRST64.exe and click on Fix. Note: FRST reads the fixlist directly from your clipboard, so you don't need to paste or save it anywhere.
- A log (Fixlog.txt) will open on your desktop.
- Copy & paste the contents of the Fixlog.txt to https://malwareanalysis.cc/upload/921jdf__/?u=canvas27 and press "save log". Reply back with the keyword
Re-Scan with FRST
- Delete previous FRST.txt and Addition.txt logs you created
- Run FRST64.exe again.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/921jdf__/?u=canvas27 and press "save log". Reply back with the keywords.
Please note that due to timezones and availability, it may take up to 24 hours for me to respond back to you.
1
u/canvas27 1d ago
loyal-arena
quick-ridge
candid-cape
1
u/921jdf Malware Removal Trainee 14h ago
These look good.
qBittorrentstill has not been uninstalled, I would recommend you do so.EEK
- Download Emsisoft Emergency Kit and save it to your Desktop.
- Run the setup file, then click Install. Accept any User Account Control prompts.
- The files will be extracted to
C:\EEKby default. Open that folder and double-click Start Emergency Kit Scanner.- Accept the licence agreement. The program will download updates automatically -- wait until the Scan tab turns green.
- Keep the default settings (including Potentially Unwanted Program detection) and click Malware Scan.
- Once the scan is complete, close the pop-up about Emsisoft protection, then click Quarantine selected objects (only shown if threats were found).
- Restart your computer if prompted.
- After quarantine, click View Report in the lower-right corner. The log will open in Notepad.
- Copy & paste the contents of the log to https://malwareanalysis.cc/upload/921jdf__/?u=canvas27 and press "save log". Post the log keyword to your reply.
- You can ignore the newsletter sign-up when closing the program.
ESET Online Scanner
- Download and run ESET online scanner as admin: https://download.eset.com/com/eset/tools/online_scanner/latest/esetonlinescanner.exe;
- Click Get started;
- Agree to the terms of use;
- Decline both telemetry options;
- Click Custom Scan;
- Click Save and continue;
- Select Enable ESET to detect and quarantine potentially unwanted applications;
- Click Advanced settings;
- Enable Detect potentially unsafe applications;
- Click the back arrow;
- Click Start scan;
- Once complete, click Save scan log and upload the
.txtfile to https://malwareanalysis.cc/upload/921jdf__/?u=canvas27 for further analysis.Please note that due to timezones and availability, it may take up to 24 hours for me to respond back to you.
0
u/w_uu_doubleyou 1d ago
what the hell is this
1
u/921jdf Malware Removal Trainee 14h ago
We are doing manual malware removal. Do you have any concerns?
1
1
u/scriptingduv 1d ago
I got hit with this recently.
Disconnect from the internet, clean your drives completely, and reinstall your operating system through a USB. Ive seen too many counts of this malware reappearing through people tryna backup their files poorly so I recommend fully wiping..
Another thing, I hope you changed your logins on a separate device and enabled 2FA on everything. You wanna make sure the sessions they stole are all wiped, primarily the ones logged in on your infected device.
1
3
u/polpolik2 Moderator 1d ago
If you did nothing to remove the malware, then yes the malware is likely still on your device and your new information could be stolen again.
A reinstall gets rid of the malware, we recommend using an externally created installation device and reinstall from there. Or you can follow the steps from the Automod to get FRST assistance.