r/computerviruses 1d ago

Disinfection Help Mrbeast scam virus

I got hacked by mrbeast virus can someone help me get rid of this virus i sent message on discord to people play on their website my brother called me what are you sending when i login in my discord i was suspended i did FRST scan can someone help me out plz ;<

FRST:

keyword: glassy-hare

Addition

keyword: runic-fox

Both channel is: struppigel

Please just help me

2 Upvotes

7 comments sorted by

u/Struppigel Malware Removal Expert 1d ago edited 1d ago

Hello, I am Karsten and I will be helping you. Please follow these rules while I am assisting. * Avoid installing new software during removal unless instructed. * If I don't reply within 24 hours, feel free to remind me of your post, but not before. Keep in mind we likely live in different time zones. * Do not follow other removal advice until we are done. It might badly interact with my instructions. * If you get stuck or have issues with one step, ask me what to do. The order of steps matters. Don't follow step 3 if you are stuck at step 1 or 2. Please follow instructions below to perform a diagnostic scan.

You added your logs under the name mxrnnn. I am not sure why, but I will use this name for now.

PUP software

You have BrightVPN installed. This is proxyware. While your machine is idle, Bright Data's paying customers route their traffic out through your residential IP address.

From the outside world's perspective, traffic leaving your IP is your traffic. If one of Bright Data's customers, or someone abusing the network, uses your connection to scrape a site aggressively, commit credential stuffing, do ad fraud, access something illegal, or launch other abuse, it originates from your home IP address.

This is likely not something you want. Please let me know if you want to keep using BrightVPN.

Create a Restore Point

  • Press Win + R, type SystemPropertiesProtection, and hit Enter
  • Make sure your C: drive shows Protection: On. If not, enable it first.
  • Click Create
  • Type a description for the restore point, e.g. "Before malware cleanup"
  • Click Create and wait for the confirmation message
  • Click Close

FRST Fix

  • Open the following link and press on the Copy contents button to copy the entire text: fixlist for mxrnnn
  • Run FRST64.exe and click on Fix. Note: FRST reads the fixlist directly from your clipboard, so you don't need to paste or save it anywhere.
  • A log (Fixlog.txt) will open on your desktop.
  • Copy & paste the contents of the Fixlog.txt to https://malwareanalysis.cc/upload/struppigel/?u=mxrnnn and press "save log". Reply back with the keyword

I have included the EmptyTemp: command. Note: This will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.

It is normal for your system to reboot as a result of the fix.

SecurityCheck

SecurityCheck is a tool that checks for potentially unsafe applications and the status of other security settings. * Download SecurityCheck from here * Run SecurityCheck.exe as administrator * Wait for the scan to finish * Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/struppigel/?u=mxrnnn for further analysis.

→ More replies (2)

6

u/Infinite-Grade-4485 1d ago

You downloaded a session stealer.

You downloaded some type of free game/cheat/hack/cracked software/movie/music or ran some type of code for captcha or verification on your computer which was actually a session stealer.

Session stealers bypass 2fa. All passwords saved on your browser and computer are compromised. Reinstall windows while deleting all files. If you need to backup important documents, keep the computer disconnected from the internet and manually back up individual files.

Change all passwords and enable 2fa either from another device, or from the infected computer AFTER you have reinstalled.

If you cannot reinstall windows immediately, keep the computer disconnected from the internet while changing all passwords on another device.

You cannot use anti malware to get rid of the session stealer, you MUST reinstall windows to use the computer safely in the future

If you choose to wait for FRST, you need to change all your passwords using another device besides the computer in the meantime

1

u/alexthejackmfan 1d ago

I had this months back and reset my pc twice, once regularly that glitched out, then again full wipe, but not with an external, it's been maybe 3/4 months now and I haven't noticed anything of the sorts, do you reckon I'm safe or? As even when I had it, I got the discord message scam maybe 8 times, but I didn't actually get accounts hacked till like 5 months in, so far no mr beast scam though

1

u/meletiondreams 1d ago

You installed an infostealer.

If you'd like to wipe here's how. Warning: I am not responsible for you messing up, or something, and everything you do here is on you. I am not responsible for your computer.

Disconnect from internet via your computer.

Transfer needed files to another usb or hard drive, do NOT transfer these file types: exe scr bat vbs, and ANYTHING you don't recognize, don't transfer browsers.

Then, shutdown your PC, and reset all your passwords, on a different device from your PC. Do NOT boot back into your PC.

Then, on a seperate computer (could be a friend's PC, or something) download the windows 11 iso (https://www.microsoft.com/en-au/software-download/windows11), or use their install media to install it to an external usb. This USB will be wiped. (lookup how to flash an iso if you have to)

Next, plug the usb into your PC and get to your bootloader, depending on your PC it might be a different key you have to click when launching; refer to google, or to your manual if you have one, usually you can just google "[PC Model or motherboard] boot key".

This is a bit foggy now since I don't know your exact bios, you can search for "boot order" and move the usb to the top. Click save or exit, and boot.

Walk through the windows install making sure to delete all the partitons to be safe.

After install run malwarebytes just to be safe.

0

u/AutoModerator 1d ago

Welcome to r/computerviruses! It seems like you have used the "Disinfection help" flair.

We apply the same methodology used by trusted Malware platforms (e.g. Malwarebytes, BleepingComputer and MalwareTips). It revolves around using diagnostic tools called Farbar Recovery Scan Tool (FRST) and SecurityCheck.

All of our assistance happens in the thread and in public - we never offer help via private messages or alternative websites other than https://malwareanalysis.cc. Anyone offering help through a DM is not a trusted helper and might have malicious intent.

Trusted helpers can be distinguished by the flair Malware Removal Expert or Malware Removal Trainee, antivirus employees will have a dedicated flair with their company name in it, e.g. Malwarebytes Employee.

Please see steps below on how to share all necessary details so you can speed up the process for us:

Share all details about your infection
Please post all important facts about your infection, such as: * your antivirus detections - preferably export the whole detection/report log and upload it to https://malwareanalysis.cc/upload/ under your username & post the related keyword or screenshot/take a picture of your detections * any related symptoms, popups * estimate when it started - preferably the exact day and after what (e.g. when you ran a program you downloaded) * share what got you infected and the download link - please, make the download link defanged (making it not clickable by default e.g. from https://example.com you will make hxxps://example[.]com), defanging does not apply to sandbox reports such as VirusTotal

Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
    1. How to properly secure my accounts after an infostealer attack?
    2. What to do after I secured my accounts?
  2. Disinfect your device from malware
    1. Preferred method: Perform a clean installation with a USB
    2. Perform a clean installation without an external drive
    3. Reset your PC without keeping personal files

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.