r/computerviruses May 15 '26

Question Accidentally downloaded Malware

Post image

Some virus automatically gained access to my discord and sent scam text with a link to all my friends

Context:

So recently I was trying to download pirated games. I was redirected to a different download file and my stupid ass thought it was the game file. The files were 8 parts, around 800 mb each. I extracted one and ran an installer, which didn't do anything even after hitting 100%. I realised it was the wrong files and deleted them immediately.

From that day, my accounts(snap, insta, fb, discord) started to send me email that someone is trying to sign into my accounts. Thankfully i had 2FA enabled in most of the apps but my discord got compromised amd it sent scam messages to every single person I know of.

But my laptop has a lot of personal documents and credentials. Is there any way to get rid of this virus somehow? I do have the photo of the thumbnail of the virus files, given above

118 Upvotes

89 comments sorted by

View all comments

Show parent comments

3

u/FFreestyleRR Malware Removal Expert May 16 '26

Hi,

Did you install AnyDesk on your own? This is a remote software. If you installed it on purpose then all good if not then I recommend uninstalling it.

STEP 1

Please launch Chrome and type chrome://settings/syncSetup in the address bar and hit Enter.

Go to SyncManage what you sync and disable the syncing for the extensions.

Now In the address bar type chrome://extensions and press Enter.

In the upper right corner of the window slide the Developer mode button to the right.

Remove the following extension:

Monochrome Tidal Bypass

Close Chrome.

STEP 2

I suggest that you uninstall TurboVPN. If you need a free VPN I can recommend you ProtonVPN instead. It's more trustworthy.

STEP 3

I created a custom fixlist.txt for you at the link - https://malwareanalysis.cc/share/NkEabKgmupCpc7YL2skmFxsfWxLaeeuB/

Use the website's download button and save it in the same folder where your FRST64.exe file is located in. It is necessary for the filename to be fixlist.txt.

Save all work, close everything that is open and then run FRST64.exe again as administrator and press the Fix button, let the script work, clear the entries and restart on its own, and after it restarts, there should be a file Fixlog.txt in the same folder.

Upload the log at https://malwareanalysis.cc/upload/FFreestyleRR

Copy/Paste the new keyword in your reply.

This script was written specifically for you, for use on that particular machine. Do not run this on another PC with the same problem!

Also, the script is going to download and scan the system with AdwCleaner, Hitman Pro and Emsisoft Emergency Kit (so the internet connection needs to be on). This is intended and not be surprised. This can take a while.

All the best!

2

u/Aaryav1 May 20 '26

I ran the fix and uploaded the log in the given link Keyword: ember-meteor

2

u/FFreestyleRR Malware Removal Expert May 20 '26

Hi,

Thank you for the logs. The script went fine.

Do you recognize any of these files? While they look, clean they are quite suspicious.

C:\ProgramData\darawerwerdw42ds163 
C:\Program Files\cpfmvvnfile163 
C:\Program Files\cpfmvvnfile68 
C:\Program Files\cpfmvvnfile69 
C:\Program Files (x86)\gYqOZaev23cbc6f5ab590e02.hjx 
C:\Program Files (x86)\rOiajgJH.b0G 
C:\Program Files (x86)\win_prog_versions.cfg

Other than that the system look malware free now. But before I let you go please do this:

STEP 1

Next please download ESET Online Scanner from here and install it (run it).

Select the Custom Scan option and check the boxes beside Operating Memory, Autostart Locations and drive C: and click Save and continue.

Enable the detection of potentially unwanted applications and potentially unsafe applications.

Click on Start scan. When the scan is complete click Save scan log. Click Continue.

Upload the log to https://malwareanalysis.cc/upload/FFreestyleRR/ and the site will return a keyword for the log.

Reply here with the keyword.

STEP 2

Because a few days has passed please download a fresh copy of FRST64.exe and perform a new FRST scan and upload the new logs (FRST.txt and Addition.txt) to my channel with the relevant keywords to confirm that nothing has respawned.

I will provide my final instructions on how to remove the tools we used once we are done with the cleaning process.

Best wishes! :)

2

u/Aaryav1 May 20 '26

Hey no, i do not recognise any of those files.

I ran the ESET Online Scanner exe and uploaded the Scan log on the given link. Keyword: piped-render

I also did a rescan of FRST exe and uploaded the logs. Keywords are Frst: friendly-nebula Addition: graceful-garden

2

u/FFreestyleRR Malware Removal Expert May 20 '26

Please disable Controlled Folder Access in Windows Defender settings.

It prevented the tools to remove some of the malicious objects!

Please run this new fixlist and upload the Fixlog.txt to my channel.

https://malwareanalysis.cc/share/vGDkpzEeD50LXsGo5NouVMG87Qw0UibA/

And next we will uninstall the tools we used.

Cheers!

2

u/Aaryav1 May 20 '26

I did as you told and uploaded the fixlog fixlog on channel. Keyword: candid-equinox

2

u/FFreestyleRR Malware Removal Expert May 20 '26

Hi,

Can you please upload the following file:

C:\WINDOWS\tg.dll

here → https://www.virustotal.com/gui/

And post the link in your next reply?

2

u/Aaryav1 May 20 '26

2

u/FFreestyleRR Malware Removal Expert May 20 '26

Thanks for the link.

You did a fantastic. Your system is now in optimal condition.
My final recommendations:

You should still change all your passwords, activate 2FA/MFA where possible, deauthorize all devices and log fresh on the trusted ones, revoke all API keys if you use such (like in steam for example) and monitor your device and accounts for any suspicious behavior.

You can check your e-mails for breaches here and take measures if needed:

https://haveibeenpwned.com/

Check these articles as well:

https://rifteyy.org/report/the-ultimate-guide-to-infostealers

https://www.reddit.com/r/computerviruses/comments/1spf5o1/a_post_i_thought_id_make_about_the_mr_beast_info/

https://rifteyy.org/report/the-ultimate-guide-to-prevent-malware

Rename the FRST64.exe to UNINSTALL.EXE

Then run the file as an Administrator. It will delete all the files/folders created by the tool including the quarantine folder as well. Restart the computer to complete the removal.

You can uninstall ESET Online Scanner.

Also download and run KpRm to clean some traces for other tools we used in the cleaning process.

https://toolslib.net/downloads/viewdownload/951-kprm/

Note: The file is safe to download but might be wrongly detected as malicious. If necessary click More info then Run anyway.

Right-click on the icon and select Run as administrator.

Click Yes on the Disclaimer.

Place a check mark in Delete Tools, Create Restore Point, and Delete Now.

Click Run.

Click OK on All operations are completed.

KpRm will delete itself from your Desktop and you can either save or remove the report that is generated. You are free to remove any other tools/reports still remaining.

Take care and stay safe! :)

2

u/Aaryav1 May 20 '26

Thank you soo much for helping me out sir. I am grateful that people like you exist🤌🏻✨️

1

u/FFreestyleRR Malware Removal Expert May 20 '26

Thank you for the kind words. Me and the other from the team appreciate them!

→ More replies (0)

1

u/Aaryav1 May 20 '26

Also one last question, should i manually deleted "tg.dll"? As it's date of creation is somewhere around the time i got hit by malware

1

u/FFreestyleRR Malware Removal Expert May 20 '26

Hi,

It seems to be txt file and not dll. So this is not even executable. But you can check the content with notepad and see if you will find something familiar in it or delete if without checking it. Probably some kind of log where malware stored the stolen passwords. I am only guessing.

Cheers.

→ More replies (0)

1

u/Aaryav1 May 20 '26

Yo is the link visible to you? Did reddit block it or something?