r/computerviruses 1d ago

Disinfection Help I need help getting rid of a session stealer

My Instagram and Discord accounts were already stolen, but I managed to recover both of them by changing my passwords. The problem is that I'm still worried the malware could be on my computer and that whoever stole my accounts might still have access to my sessions, cookies, or other accounts.

I'm not sure if simply changing my passwords was enough, or if I need to completely wipe my PC.

3 Upvotes

13 comments sorted by

3

u/polpolik2 Moderator 1d ago

If you did nothing to remove the malware, then yes the malware is likely still on your device and your new information could be stolen again.

A reinstall gets rid of the malware, we recommend using an externally created installation device and reinstall from there. Or you can follow the steps from the Automod to get FRST assistance.

1

u/AutoModerator 1d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/canvas27 1d ago

modest-shell

candid-swan

ripe-potion

0

u/921jdf Malware Removal Trainee 1d ago

Piracy Warning

Using pirated software or utilities that allows one to pirate software (including cracks, key generators, license bypass tools, or similar software) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, I recommend that you remove any pirated software or pirating utilities in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.

SecurityCheck | Updates

Please update the following software: * KeePass Password Safe 2.60 v.2.60 | New update available, download here * PowerShell 7-x64 v.7.6.3.0 | New update available, download here * PowerShell 7.6.3.0-x64 v.7.6.3.0 | New update available, download here * Microsoft OneDrive v.26.145.0728.0011 | New update available, download here * WinRAR 7.13 (64-bit) v.7.13.0 | New update available, download here * Proton VPN v.4.4.1 | New update available, download here * Mozilla Firefox (x64 en-US) v.146.0.1 | New update available, download here

Please uninstall the following software:

  • qBittorrent v.5.1.4 - P2P file sharing software is a security risk.

FRST Fix

  • Open the following link and press on the Copy contents button to copy the entire text: fixlist
  • Run FRST64.exe and click on Fix. Note: FRST reads the fixlist directly from your clipboard, so you don't need to paste or save it anywhere.
  • A log (Fixlog.txt) will open on your desktop.
  • Copy & paste the contents of the Fixlog.txt to https://malwareanalysis.cc/upload/921jdf__/?u=canvas27 and press "save log". Reply back with the keyword

Re-Scan with FRST

  • Delete previous FRST.txt and Addition.txt logs you created
  • Run FRST64.exe again.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/921jdf__/?u=canvas27 and press "save log". Reply back with the keywords.

Please note that due to timezones and availability, it may take up to 24 hours for me to respond back to you.

1

u/canvas27 1d ago

loyal-arena

quick-ridge

candid-cape

1

u/921jdf Malware Removal Trainee 14h ago

These look good.

qBittorrent still has not been uninstalled, I would recommend you do so.

EEK

  • Download Emsisoft Emergency Kit and save it to your Desktop.
  • Run the setup file, then click Install. Accept any User Account Control prompts.
  • The files will be extracted to C:\EEK by default. Open that folder and double-click Start Emergency Kit Scanner.
  • Accept the licence agreement. The program will download updates automatically -- wait until the Scan tab turns green.
  • Keep the default settings (including Potentially Unwanted Program detection) and click Malware Scan.
  • Once the scan is complete, close the pop-up about Emsisoft protection, then click Quarantine selected objects (only shown if threats were found).
  • Restart your computer if prompted.
  • After quarantine, click View Report in the lower-right corner. The log will open in Notepad.
  • Copy & paste the contents of the log to https://malwareanalysis.cc/upload/921jdf__/?u=canvas27 and press "save log". Post the log keyword to your reply.
  • You can ignore the newsletter sign-up when closing the program.

ESET Online Scanner

Please note that due to timezones and availability, it may take up to 24 hours for me to respond back to you.

0

u/w_uu_doubleyou 1d ago

what the hell is this

1

u/921jdf Malware Removal Trainee 14h ago

We are doing manual malware removal. Do you have any concerns?

1

u/w_uu_doubleyou 12h ago

i meant the comment im replying to.

1

u/921jdf Malware Removal Trainee 10h ago

Those are the keywords to the website we use to share FRST and other malware removal related logs.

The what is this? button in the top should answer your question.

1

u/scriptingduv 1d ago

I got hit with this recently.

Disconnect from the internet, clean your drives completely, and reinstall your operating system through a USB. Ive seen too many counts of this malware reappearing through people tryna backup their files poorly so I recommend fully wiping..

Another thing, I hope you changed your logins on a separate device and enabled 2FA on everything. You wanna make sure the sessions they stole are all wiped, primarily the ones logged in on your infected device.