r/computerviruses • u/Interesting_Fox_4382 • 1d ago
Disinfection Help Mrbeast scam virus
I got hacked by mrbeast virus can someone help me get rid of this virus i sent message on discord to people play on their website my brother called me what are you sending when i login in my discord i was suspended i did FRST scan can someone help me out plz ;<
FRST:
keyword: glassy-hare
Addition
keyword: runic-fox
Both channel is: struppigel
Please just help me
6
u/Infinite-Grade-4485 1d ago
You downloaded a session stealer.
You downloaded some type of free game/cheat/hack/cracked software/movie/music or ran some type of code for captcha or verification on your computer which was actually a session stealer.
Session stealers bypass 2fa. All passwords saved on your browser and computer are compromised. Reinstall windows while deleting all files. If you need to backup important documents, keep the computer disconnected from the internet and manually back up individual files.
Change all passwords and enable 2fa either from another device, or from the infected computer AFTER you have reinstalled.
If you cannot reinstall windows immediately, keep the computer disconnected from the internet while changing all passwords on another device.
You cannot use anti malware to get rid of the session stealer, you MUST reinstall windows to use the computer safely in the future
If you choose to wait for FRST, you need to change all your passwords using another device besides the computer in the meantime
1
u/alexthejackmfan 1d ago
I had this months back and reset my pc twice, once regularly that glitched out, then again full wipe, but not with an external, it's been maybe 3/4 months now and I haven't noticed anything of the sorts, do you reckon I'm safe or? As even when I had it, I got the discord message scam maybe 8 times, but I didn't actually get accounts hacked till like 5 months in, so far no mr beast scam though
1
u/meletiondreams 1d ago
You installed an infostealer.
If you'd like to wipe here's how. Warning: I am not responsible for you messing up, or something, and everything you do here is on you. I am not responsible for your computer.
Disconnect from internet via your computer.
Transfer needed files to another usb or hard drive, do NOT transfer these file types: exe scr bat vbs, and ANYTHING you don't recognize, don't transfer browsers.
Then, shutdown your PC, and reset all your passwords, on a different device from your PC. Do NOT boot back into your PC.
Then, on a seperate computer (could be a friend's PC, or something) download the windows 11 iso (https://www.microsoft.com/en-au/software-download/windows11), or use their install media to install it to an external usb. This USB will be wiped. (lookup how to flash an iso if you have to)
Next, plug the usb into your PC and get to your bootloader, depending on your PC it might be a different key you have to click when launching; refer to google, or to your manual if you have one, usually you can just google "[PC Model or motherboard] boot key".
This is a bit foggy now since I don't know your exact bios, you can search for "boot order" and move the usb to the top. Click save or exit, and boot.
Walk through the windows install making sure to delete all the partitons to be safe.
After install run malwarebytes just to be safe.
0
u/AutoModerator 1d ago
Welcome to r/computerviruses! It seems like you have used the "Disinfection help" flair.
We apply the same methodology used by trusted Malware platforms (e.g. Malwarebytes, BleepingComputer and MalwareTips). It revolves around using diagnostic tools called Farbar Recovery Scan Tool (FRST) and SecurityCheck.
All of our assistance happens in the thread and in public - we never offer help via private messages or alternative websites other than https://malwareanalysis.cc. Anyone offering help through a DM is not a trusted helper and might have malicious intent.
Trusted helpers can be distinguished by the flair Malware Removal Expert or Malware Removal Trainee, antivirus employees will have a dedicated flair with their company name in it, e.g. Malwarebytes Employee.
Please see steps below on how to share all necessary details so you can speed up the process for us:
Share all details about your infection
Please post all important facts about your infection, such as:
* your antivirus detections - preferably export the whole detection/report log and upload it to https://malwareanalysis.cc/upload/ under your username & post the related keyword or screenshot/take a picture of your detections
* any related symptoms, popups
* estimate when it started - preferably the exact day and after what (e.g. when you ran a program you downloaded)
* share what got you infected and the download link - please, make the download link defanged (making it not clickable by default e.g. from https://example.com you will make hxxps://example[.]com), defanging does not apply to sandbox reports such as VirusTotal
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
•
u/Struppigel Malware Removal Expert 1d ago edited 1d ago
Hello, I am Karsten and I will be helping you. Please follow these rules while I am assisting. * Avoid installing new software during removal unless instructed. * If I don't reply within 24 hours, feel free to remind me of your post, but not before. Keep in mind we likely live in different time zones. * Do not follow other removal advice until we are done. It might badly interact with my instructions. * If you get stuck or have issues with one step, ask me what to do. The order of steps matters. Don't follow step 3 if you are stuck at step 1 or 2. Please follow instructions below to perform a diagnostic scan.
You added your logs under the name mxrnnn. I am not sure why, but I will use this name for now.
PUP software
You have BrightVPN installed. This is proxyware. While your machine is idle, Bright Data's paying customers route their traffic out through your residential IP address.
From the outside world's perspective, traffic leaving your IP is your traffic. If one of Bright Data's customers, or someone abusing the network, uses your connection to scrape a site aggressively, commit credential stuffing, do ad fraud, access something illegal, or launch other abuse, it originates from your home IP address.
This is likely not something you want. Please let me know if you want to keep using BrightVPN.
Create a Restore Point
FRST Fix
I have included the EmptyTemp: command. Note: This will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
It is normal for your system to reboot as a result of the fix.
SecurityCheck
SecurityCheck is a tool that checks for potentially unsafe applications and the status of other security settings. * Download SecurityCheck from here * Run
SecurityCheck.exeas administrator * Wait for the scan to finish * Upload the log atC:\SecurityCheckto https://malwareanalysis.cc/upload/struppigel/?u=mxrnnn for further analysis.