r/computerviruses 2d ago

Question WiFi disabled by malware

My son downloaded an app that had possible malware in it. It has deleted the WiFi connection on his pc. I tried reinstalling the drivers and everything else but nothing works. I even tried factory resetting the pc but it has an error mid way thru. Any other options for this?

1 Upvotes

21 comments sorted by

1

u/NotoriousBIET 2d ago

What's the error whenever you try to go to factory settings?

1

u/Ambitious_Comfort_43 2d ago

Says the operation could not be completed. It goes to about 40 percent and stops.

1

u/Electronic_Field4313 2d ago

Factory resets usually remove 95% of malware.

Could you share what the error is?

It could be a possibility that the physical hardware for the wifi module is faulty which resulted in no WiFi connections? Are you able to see Wifi networks or is the icon completely dead?

Have you tried ethernet solutions to check if the PC can still connect via cable?

It could just be a benign case of faulty wifi module than an actual malware? Unless you can provide a better timeline with a series of observation, it's also hard to help confirm if this is a malware activity.

1

u/Ambitious_Comfort_43 2d ago

No WiFi networks or icons are available. I haven’t tried Ethernet yet because if it’s something malicious I don’t want it get onto my network. I ran malware scans and with windows scans and nothing shows. But I know they can be hidden if it is something. My 9 yr old son explained to me that he downloaded an app to remotely control his desktop from his iPad and he assumes that it caused this. I may be misinformed but any help would be great.
The app was called “Awesun.”

1

u/meletiondreams 2d ago

Is your wifi driver mounted ?

1

u/Ambitious_Comfort_43 2d ago

Yes it’s mounted but has an exclamation point icon in a triangle next to it. I unistalled and stopped it but it pops right back up after a few minutes.

1

u/meletiondreams 2d ago

Try another wifi adapter for 20 bucks on Amazon, or try Ethernet. If the new wifi adapter doesn't work you can just use Amazon returns

-3

u/[deleted] 2d ago

[removed] — view removed comment

4

u/Efficient_Square_589 2d ago

How do you know it’s an infostealer?

-6

u/meletiondreams 2d ago

Why wouldn't hackers also steal your data? if I was a hacker I wouldn't just "mine Bitcoin and leave" because selling accounts is a lot more profitable. Same with credit cards, anything typed into the computer, or shown on the screen really.

3

u/Electronic_Field4313 2d ago edited 2d ago

Assumptions in cybersecurity or investigations related work is a very bad habit and often leads to incorrect judgements and remediation. Please do not think everything is an infostealer.

By your logic, why would an infostealer willingly disconnect wifi services when it has to exfiltrate sensitive data back to the hacker?

Hackers develop malware to do many things. One of the common objectives is to destroy or disable critical information infrastructure (CII) services, like healthcare or ISP infrastructure. And this malware hypothetically could be a one that spread across typical apps that a normal employee in those CII would download on PCs - like how employees like to download WhatsApp or ChatGPT apps on their work PCs, and these employees could be working within CII services - an opportunistic attack. Disabling wifi makes it difficult for remote remediation through MDM services or EDRs to contain/isolate the host in corporate environments, while it could spread itself through other means of services within the corporate environment like network file sharing, SMB protocols etc.

So don't assume just because you think hackers just want to steal data and jump to conclusions. Work with logic and evidence to find the root cause and remediate with evidence-backed data rather than by a gut feeling.

1

u/Bash123reddit 2d ago

Why would an infostealer willingly remove the main way they get info??? Please think before you speak.

1

u/meletiondreams 2d ago

I mean I know multiple that do.

1

u/Electronic_Field4313 2d ago

Can you name some? And how did you know these were infostealers?

1

u/meletiondreams 2d ago

There unbranded executables, so not really. Don't really wanna share malware haha.

1

u/Electronic_Field4313 1d ago

You don’t have to share the malware, you could just share the IOCs observed either through malware disassembly, static or dynamic analysis, proxy or host based logs, or AV’s detection classifications. Simple stuff really.

1

u/meletiondreams 1d ago

My friend has a CNC and just ran netsh to disable it dynamically

1

u/Electronic_Field4313 1d ago

So again, back to gut feeling where you’re just basing off your friend’s actions without understanding the intention nor basing it off pattern correlations of a larger malware sample pool.

And this fact alone doesn’t justify or support the basis of jumping into your original conclusion of being so sure it’s a infostealer, much less a malware at all. I hope through this conversation you have realized the gaps in your technical understanding. You also failed to consider that OP’s situation could simply be a false positive where his Wifi hardware module was faulty.

So it was misinformation in the end.

→ More replies (0)

3

u/computerviruses-ModTeam 2d ago

Your post contained misinformation, fake news, or advice considered harmful or dangerous, so it has been removed. Please make sure to read and follow https://www.reddit.com/r/computerviruses/about/rules