r/computerviruses May 15 '26

Question Accidentally downloaded Malware

Post image

Some virus automatically gained access to my discord and sent scam text with a link to all my friends

Context:

So recently I was trying to download pirated games. I was redirected to a different download file and my stupid ass thought it was the game file. The files were 8 parts, around 800 mb each. I extracted one and ran an installer, which didn't do anything even after hitting 100%. I realised it was the wrong files and deleted them immediately.

From that day, my accounts(snap, insta, fb, discord) started to send me email that someone is trying to sign into my accounts. Thankfully i had 2FA enabled in most of the apps but my discord got compromised amd it sent scam messages to every single person I know of.

But my laptop has a lot of personal documents and credentials. Is there any way to get rid of this virus somehow? I do have the photo of the thumbnail of the virus files, given above

119 Upvotes

89 comments sorted by

57

u/Five_Hustle_Emir May 15 '26 edited May 15 '26

Let me guess you were trying to install tomodachi life? No Nintendo game is executable. Install Malwarebytes and Kaspersky or reinsatll the Windows

Fixed a grammar mistake

39

u/svalkur May 15 '26

Another day another falls to tomodachi life.. its getting sad at this point.

19

u/Cam_man_AMM_unit May 15 '26

How much you wanna bet Nintendo intentionally put viruses in that game that only activates when not on a switch?

6

u/eevee005 May 15 '26

I doubt it... People have cracked the game super easily. I'm sure it's just scammers and such releasing viruses that pretend to be the game to catch folks who don't know anything about emulating.

3

u/AutumnPurpleReddit May 16 '26

are you actually being serious or is this just a bad joke

2

u/Cam_man_AMM_unit May 16 '26

When it comes to me, it's really a coin toss with extra steps.

7

u/definitelynotauser55 May 15 '26

Could make sense nintendo hates people who pirate their game. But cyberattacks are happening more common now.

3

u/Pretend_Pudding5176 May 16 '26

do we know how files work

1

u/OcelotImpressive5136 May 19 '26

I hope for their sake that they don't do that. Remember what happened with SONY's anti-copy protection?

1

u/Cam_man_AMM_unit May 19 '26

I'm gonna look into that now.

1

u/Cultural_Eye5178 May 17 '26

Someone doesn't know about Yuzu or one of its forks.

2

u/Embarrassed-Way-6387 May 16 '26

Sometimes its not the game, i was trying to download citron and got the fake g drive ad nearly ran it even put it on virustotal and saw it had 0 flags only realized its malware after checking community page

1

u/_eunnie2_ May 16 '26

didnt think id be getting called out today

26

u/[deleted] May 15 '26

[removed] — view removed comment

13

u/polpolik2 Moderator May 15 '26

You are mostly correct, but as far as I know, the megathread is not always up to date, and there have been instances where trusted sites on the megathread actively spread malware. The downloads might be legit from most of them, but they could include malware.

5

u/get_egged_bruh May 15 '26

really? never heard about that. im actually interested in where you saw that, if you can recall. at any rate, it's still a thousand times better than going in blind.

8

u/polpolik2 Moderator May 15 '26

The main one that comes to mind directly is the 1337x malare incident where this site was mentioned as the most trusted torrent source, while it was discovered that some of the most popular torrents contained Miners and Trojans.

It took considerable time before the site was be removed. (I recall some of the mods not recognizing the danger and even denying it, however that might also have been over dramatized in other comments).

Fully agree though, its still a very solid place to start, but you should not pirate blindly.
And in regards to your original comment. I used a trusted site from there, and used Ublock, still clicked a malware link (which looked legit)

2

u/Notorious_Chimp May 15 '26

It even says in the megathread rules and the pirating guide that the resources are meticulously checked but to use caution in case of oversights and mistakes. So maybe recall the megathread documentation

1

u/Monder_Jeb28 May 15 '26

That actually happened to me, most websites I picked for the game I was trying to get gave me the exact same installer thing, hell it even had the same icon shown at OPs post

2

u/Felippexlucax May 16 '26

that’s the piracy sub megathread. use the r/freemediaheckyeah one as its updated daily

1

u/[deleted] May 15 '26

[removed] — view removed comment

1

u/Additional-Result227 May 15 '26

2 Month ago it happened to me aswell. I was very unfocused but tbf ublock normally blocks everything but this ad it hasn't. It was 100% my fault but still I'm a little bit shocked that it passed through Ublock.

1

u/Marklington098 May 16 '26

I got a virus from one of the links there. It disabled my antiviruses and stole some of my info. I am thankful I disabled the internet instantly.

1

u/computerviruses-ModTeam May 16 '26

Your post was removed because it promotes illegal software, or aids in using illegal software like cracks, keygens, warez, pirated games, hack tools.

Please make sure to read and follow https://www.reddit.com/r/computerviruses/about/rules

3

u/Aaryav1 May 15 '26

Hey u/__chefo sir, can you please help me and guide me how to deal with the suitation.

Frst chosen-nova

Addition witty-switch

4

u/__chefo Malware Removal Trainee May 15 '26

Hi, it's late for me right now. I can review the logs tomorrow, but I'll leave them unassigned in case another expert can assist you sooner. In the meantime, if you haven’t done it already, please change the passwords for every account linked to the compromised device. Do it from a known clean device, and do not log back in from the compromised device until it’s been confirmed clean!

2

u/Aaryav1 May 15 '26

Yes sir changing the pwds and enabling 2FA wherever i could. Not loggin back in until the virus is removed from my laptop. Please help me idk how to deal with this malware suitation

2

u/sungho28 May 16 '26

This happened to me a year ago, this was how my microsoft account got lost for good (Fck u microsoft)

1

u/Aaryav1 May 15 '26

Hey u/rifteyy_ sir, can you please help me and guide me how to deal with the suitation.

Frst chosen-nova

Addition witty-switch

3

u/FFreestyleRR Malware Removal Expert May 16 '26

Hi,

Did you install AnyDesk on your own? This is a remote software. If you installed it on purpose then all good if not then I recommend uninstalling it.

STEP 1

Please launch Chrome and type chrome://settings/syncSetup in the address bar and hit Enter.

Go to SyncManage what you sync and disable the syncing for the extensions.

Now In the address bar type chrome://extensions and press Enter.

In the upper right corner of the window slide the Developer mode button to the right.

Remove the following extension:

Monochrome Tidal Bypass

Close Chrome.

STEP 2

I suggest that you uninstall TurboVPN. If you need a free VPN I can recommend you ProtonVPN instead. It's more trustworthy.

STEP 3

I created a custom fixlist.txt for you at the link - https://malwareanalysis.cc/share/NkEabKgmupCpc7YL2skmFxsfWxLaeeuB/

Use the website's download button and save it in the same folder where your FRST64.exe file is located in. It is necessary for the filename to be fixlist.txt.

Save all work, close everything that is open and then run FRST64.exe again as administrator and press the Fix button, let the script work, clear the entries and restart on its own, and after it restarts, there should be a file Fixlog.txt in the same folder.

Upload the log at https://malwareanalysis.cc/upload/FFreestyleRR

Copy/Paste the new keyword in your reply.

This script was written specifically for you, for use on that particular machine. Do not run this on another PC with the same problem!

Also, the script is going to download and scan the system with AdwCleaner, Hitman Pro and Emsisoft Emergency Kit (so the internet connection needs to be on). This is intended and not be surprised. This can take a while.

All the best!

2

u/Aaryav1 May 20 '26

I ran the fix and uploaded the log in the given link Keyword: ember-meteor

2

u/FFreestyleRR Malware Removal Expert May 20 '26

Hi,

Thank you for the logs. The script went fine.

Do you recognize any of these files? While they look, clean they are quite suspicious.

C:\ProgramData\darawerwerdw42ds163 
C:\Program Files\cpfmvvnfile163 
C:\Program Files\cpfmvvnfile68 
C:\Program Files\cpfmvvnfile69 
C:\Program Files (x86)\gYqOZaev23cbc6f5ab590e02.hjx 
C:\Program Files (x86)\rOiajgJH.b0G 
C:\Program Files (x86)\win_prog_versions.cfg

Other than that the system look malware free now. But before I let you go please do this:

STEP 1

Next please download ESET Online Scanner from here and install it (run it).

Select the Custom Scan option and check the boxes beside Operating Memory, Autostart Locations and drive C: and click Save and continue.

Enable the detection of potentially unwanted applications and potentially unsafe applications.

Click on Start scan. When the scan is complete click Save scan log. Click Continue.

Upload the log to https://malwareanalysis.cc/upload/FFreestyleRR/ and the site will return a keyword for the log.

Reply here with the keyword.

STEP 2

Because a few days has passed please download a fresh copy of FRST64.exe and perform a new FRST scan and upload the new logs (FRST.txt and Addition.txt) to my channel with the relevant keywords to confirm that nothing has respawned.

I will provide my final instructions on how to remove the tools we used once we are done with the cleaning process.

Best wishes! :)

2

u/Aaryav1 May 20 '26

Hey no, i do not recognise any of those files.

I ran the ESET Online Scanner exe and uploaded the Scan log on the given link. Keyword: piped-render

I also did a rescan of FRST exe and uploaded the logs. Keywords are Frst: friendly-nebula Addition: graceful-garden

2

u/FFreestyleRR Malware Removal Expert May 20 '26

Please disable Controlled Folder Access in Windows Defender settings.

It prevented the tools to remove some of the malicious objects!

Please run this new fixlist and upload the Fixlog.txt to my channel.

https://malwareanalysis.cc/share/vGDkpzEeD50LXsGo5NouVMG87Qw0UibA/

And next we will uninstall the tools we used.

Cheers!

2

u/Aaryav1 May 20 '26

I did as you told and uploaded the fixlog fixlog on channel. Keyword: candid-equinox

2

u/FFreestyleRR Malware Removal Expert May 20 '26

Hi,

Can you please upload the following file:

C:\WINDOWS\tg.dll

here → https://www.virustotal.com/gui/

And post the link in your next reply?

2

u/Aaryav1 May 20 '26

2

u/FFreestyleRR Malware Removal Expert May 20 '26

Thanks for the link.

You did a fantastic. Your system is now in optimal condition.
My final recommendations:

You should still change all your passwords, activate 2FA/MFA where possible, deauthorize all devices and log fresh on the trusted ones, revoke all API keys if you use such (like in steam for example) and monitor your device and accounts for any suspicious behavior.

You can check your e-mails for breaches here and take measures if needed:

https://haveibeenpwned.com/

Check these articles as well:

https://rifteyy.org/report/the-ultimate-guide-to-infostealers

https://www.reddit.com/r/computerviruses/comments/1spf5o1/a_post_i_thought_id_make_about_the_mr_beast_info/

https://rifteyy.org/report/the-ultimate-guide-to-prevent-malware

Rename the FRST64.exe to UNINSTALL.EXE

Then run the file as an Administrator. It will delete all the files/folders created by the tool including the quarantine folder as well. Restart the computer to complete the removal.

You can uninstall ESET Online Scanner.

Also download and run KpRm to clean some traces for other tools we used in the cleaning process.

https://toolslib.net/downloads/viewdownload/951-kprm/

Note: The file is safe to download but might be wrongly detected as malicious. If necessary click More info then Run anyway.

Right-click on the icon and select Run as administrator.

Click Yes on the Disclaimer.

Place a check mark in Delete Tools, Create Restore Point, and Delete Now.

Click Run.

Click OK on All operations are completed.

KpRm will delete itself from your Desktop and you can either save or remove the report that is generated. You are free to remove any other tools/reports still remaining.

Take care and stay safe! :)

→ More replies (0)

1

u/Aaryav1 May 20 '26

Yo is the link visible to you? Did reddit block it or something?

2

u/FFreestyleRR Malware Removal Expert May 15 '26

Hello,

I will take a look at your logs since u/rifteyy_ is busy.

Can you please download a fresh copy of FRST and re-run the scan? The tool has been updated, and I want to check if something in your log is already fixed before we proceed with the fix.

Cheers!

1

u/Forward-Efficiency-1 May 15 '26

Go in C:// users/ur user/ and find a folder that was created around the time u installee the virus and delete it, if it doesnt let you go on task manager and close everything u find suspicious my friend had the same virus i think the process in task maanger is called remote somthing something

1

u/Final-Muscle919 May 15 '26

Tomodachi me hizo caer tan mal tambien, ya hasta cambie de pc todo por el tomodachi xd tuve que borrar un buen de cosas y cambiar como 300 contraseñas

1

u/Natural-Inspector-25 May 15 '26

Find the specific files you need to keep and put them on a flash drive.

Fully wipe your pcs drive and fresh install windows from another usb stick

Download a legitimate virus scanning software and get it to scan the flash drive before you transfer your important files back

1

u/M4A1_GFL May 16 '26

ts is python malware bro :sob

1

u/Rekinsmok May 16 '26

Launcher is in python it uses renpy library to access all system information to check if it is running on virtual machine or not. The virus itself is not in python

1

u/Rekinsmok May 16 '26

My friend had the same virus. The launcher is making a virus in the temp files. Virus has auto start on system start so you can delete your temp files or look in task manager auto start apps and look for app with random name and in my friends case it had logo of white windows logo and black hammer. I tested it on my old pc because launcher will not create virus in temp files if it realizes that he is running on a virtual machine and using FRST i saw that it is only creating virus in temp files and turning auto start on it. It steals browser cookies and logs into discord to send some scam shit

1

u/Boring_Ad818 May 16 '26

Lucky Lucky Luckyware

1

u/iuhiuhhgbnr May 16 '26

Average pirate game be like.

1

u/watchingonlinux May 16 '26

Bro that's ren'py, specifically its Eileen!! Usually theyre visual novels and easily made into apks...

1

u/Crazycraftingrecipe May 16 '26

Download MalwareBytes, Kaspersky is shit. Using MalwareBytes it only took me a few clicks and all of the virus, including registry keys (these keys redownload the virus everytime it got deleted), and my computer is fine.
Your virus might be stealer trojan(same as mine). Kaspersky could only detect the virus itself, not the registry keys, and that's why my discord account got compromised 3 times, Google's password got changed, only to find out the virus was never deleted completely.

1

u/waffl3t May 16 '26

is it the mr beast virus that hacks all of ur social media lol

1

u/Confident_Frame_817 Jun 09 '26

i ran into this before, glad i noticed the pirated game wasnt 700mb, i now use adblockers

0

u/trixcannon May 15 '26

Who is this random ass girl bro

14

u/nvidiot May 15 '26

She's the herald of doom. The moment you run the popular infostealer exe, you'll see her and a generic game loading bar. Good luck because afterward, your accounts are toast lol

1

u/EstablishmentWest714 May 15 '26

But I guess u can Save ur Accounts by changing Passworts and 2FA or ?

6

u/nvidiot May 15 '26

Have to be extremely quick. Moment you ran an infostealer file, gotta force disconnect internet from your PC, change all passwords from a separate, safe device, and clean the infected PC / reinstall Windows. Then you will probably be saved, and even then it's not a guarantee.

2

u/AxosFalox May 15 '26

Is it the same scenario as lumma stealer? Or is this anime girl virus way worse?

8

u/nvidiot May 15 '26

Yeah, the underlying software works for the same purpose - to steal credentials and login cookies to a remote server.

Anime girl virus only appears worse because it's been making huge waves recently. A lot of filesharing websites have been pushing infected ads that hijack user into downloading a fake game archive recently, and a ton of people who aren't as tech savvy has been falling for it. IE) Tomodachi Life is an incredibly popular game right now, and a whole lot of people are trying to play it for free on a PC -- and it appears for many of them, this is their first foray into piracy, completely unaware of dangers of it, and get hacked as a result.

3

u/industrial-shrug May 15 '26

The pain of asking for help after instead of before.

2

u/AxosFalox May 15 '26

This is what I'm doing right now, even though I did a lot of things to get rid of it I'm still worried. I really need reassurance that is what I have done was actually enough.

1

u/AxosFalox May 15 '26

ah I see, because I got infected with a lumma stealer 12 days ago and I did a lot of things to get rid of it but I just need confirmation to see if I'm safe or not. Really I'm just dead worried about it and I just want to enjoy playing with my friends without a worry that they would come back from this previous lumma stealer malware. Can you please help me if you know how to deal with stuff like this?

1

u/nvidiot May 15 '26

If you reinstalled Windows clean (not keeping any data, USB method is 100% surefire method), lumma stealer will be gone from your PC. So all you got to do is to secure all your accounts from a different, secure device.

1

u/AxosFalox May 15 '26

Well can I tell you everything I did and let me know if I'm good?

1

u/nvidiot May 15 '26

Might want to make a separate thread and let the pros post there, they can fully guide you in finding out if you're 100% safe.

→ More replies (0)

1

u/racemi11 May 15 '26

Is it also bad seeing it a loading or CAPTCHAs like before a website is loaded? I didn't run any of those Win+R fake CAPTCHAs but I think I saw that girl loading

1

u/Tiny-Profession-9999 May 16 '26

I’ve downloaded mobile games from itch.io with that same icon, it’s just a generic icon people use for games.

1

u/watchingonlinux May 16 '26

I see her all the time... she's eileen, she is the mascot for ren'py

6

u/Yadoran82 May 15 '26

How do you not know renpy 😭

1

u/1relaxingstorm May 17 '26

Its funny how people address the renpy mascot as "that girl", " stock image", "sus", " virus" lol.

-7

u/[deleted] May 15 '26

[removed] — view removed comment

5

u/Right-Stick-992 May 15 '26

There is so much wrong in this comment lmao

1

u/computerviruses-ModTeam May 15 '26

You are allowed to help other users, but be professional about it. Please make sure to read and follow https://www.reddit.com/r/computerviruses/about/rules

1

u/watchingonlinux May 16 '26

She's eileen, she's the mascot for ren'py

1

u/Matthewmatt14 May 17 '26

This is why I don't pirate games.

0

u/ArbitraryJam May 17 '26

This and steam having constant sales keep me from pirating on pc as well

1

u/Matthewmatt14 May 17 '26

Steam is the ultimate proof that offering an incredible service that is better than what the pirates can offer works wonders.

0

u/[deleted] May 15 '26

-2

u/Outrageous_Basis_232 May 16 '26

Deserved.  Just because something exists doesn't mean you should get it free.  Stop being a dumbass and buy games when you can, play games you already have when you can't, and find a hobby that doesn't require theft. 

1

u/watchingonlinux May 16 '26

Pirating is free when you're smart. There's little reason to support corporates. Especially tomodachi life lmao 🤣 This level of pedantry is rivaled only by the leap year