#Virus on my PC

520 messages · Page 1 of 1 (latest)

molten birch
#

yep, looks like it

#

I suggest you turn the pc off

#

if its not already bricked

simple nova
#

Alr

#

Then what

#

Do I just reopen it orrr?

molten birch
#

try to boot safemode

simple nova
#

turn it back on*

#

alr

#

ty

molten birch
#

then we will download autoruns

simple nova
#

alr ty

molten birch
#

and at the same time download a malware checker thing

#

safemode with networking*

simple nova
#

alr

#

Im not that smart on pcs

#

So I boot saf mode

#

and then what

#

e

molten birch
#

did you boot safemdoe with networkin

#

or tell me when you get there

#

also ping me if its been a few

simple nova
#

alr

#

i will now

#

Yo

#

I

#

Where do u go now

#

@molten birch

molten birch
simple nova
#

Alr

#

It’s doing it now

#

With networking right?

#

@molten birch

molten birch
simple nova
#

Alr

#

Alr now what

molten birch
#

dose it boot correctly

simple nova
#

If

molten birch
#

with small text in the corners

simple nova
#

Ig

#

Yes

molten birch
#

ok, login

simple nova
#

I did

molten birch
#

do you have the file you ran

simple nova
#

Wdym

#

The fake cons prompt one

molten birch
#

the program that you ran

#

the virus thingy

simple nova
#

Oh

#

I think I deleted it

molten birch
#

😦

#

why

#

deleating smth dose not stop it

simple nova
#

Oh

molten birch
#

it just makes it harder to debug

simple nova
#

Well no

#

The app didn’t work

#

So I had to deleted it

#

And realized it was a virus

molten birch
#

how did you download it

#

from discord?

simple nova
#

Yep

molten birch
#

uggggg

#

ofc

#

yeah its a virust

#

prob a rat

#

also change all your passwords

#

RIGHT NOW

#

change your discord password

#

asap

#

then come back

simple nova
#

I did

#

I already have

molten birch
#

ok, do you do banking on it

#

*the pc

simple nova
#
  • I got 2fa on everything
#

Nah I’m broke as shit

molten birch
simple nova
#

So it don’t matter

molten birch
#

2fa wont stop anyone

#

they are loged in as you

simple nova
#

True

molten birch
#

so change password / logout of all accs

simple nova
#

I chanted pass

#

Changed

#

All

molten birch
#

ok

#

wait

#

on the pc

#

while it was still running

#

when most likely you had a rat installed

#

so they could see all your keyboard presses

#

🤦

#

change important ones on phone rq

#

not sure if google will work properly rn

simple nova
#

Alr

molten birch
#

can you open what ever browser you use tho (when your dowe)

#

*done

simple nova
#

Yes

molten birch
#

lmk when your done

simple nova
#

I am

#

I only have like 4 accs anyways

molten birch
#

ok bud

simple nova
#

!

#

?

molten birch
#

so now can you download

autoruns from sysinternals (microsofts tools (to see what runs when your pc starts))
and check your downloads, then send the file that you ran

#

also, we have to download another av

#

also we will download malware bytes in a few mins

simple nova
#

I don’t have internet

molten birch
#

💀

#

ok

#

did you select with networking

simple nova
molten birch
simple nova
#

?

molten birch
simple nova
#

Oh

molten birch
#

ok

#

so

#

no internet but you did networking

#

can you connect to network

#

or just no

simple nova
#

No

molten birch
#

also do you have ethernet or do you use wifi

simple nova
#

Ethernet

molten birch
#

hummmm

#

that should work then

#

se

simple nova
#

Should I retry

#

?

molten birch
#
Open the Device Manager in Safe Mode (press Win + X keys and select Device Manager).
In the Device Manager, expand the Network adapters branch.
Right-click on your network driver and select Enable device. You will see the Enable device option only if the driver is disabled.```
#
Scroll down and look for WLAN Auto Config Service.
Its status should show Running. If it is stopped, right-click on it and select Start.```

or this
simple nova
#

They are both enabled

molten birch
#

huh can you disconnect and reconnect etherent

simple nova
#

Alr

#

Still doesn’t work

molten birch
#

let me think

#

read this and try

#

In search, type Troubleshooting

Click on network and internet option.

Click Internet connection

Run the troubleshooter.

Follow the on screen suggestions.

simple nova
#

Yo

#

Ima retry the option rq

molten birch
#

sup

#

kk

simple nova
#

To make sure I chose the right one

molten birch
#

cool

#

amazing

#

umm so wifi bugged

#

ok

#

lets just run defender

#

then boot normaly

#

then install those

#

ok, open defender

simple nova
#

Windows security?

molten birch
#

prob

simple nova
#

Alr

molten birch
#

select scan type

simple nova
#

It’s js a black screen

molten birch
#

oh

#

did the malware uninstall defender

#

did you run it as admin or not

#

the malware

simple nova
#

Not

#

Well

#

Actually

#

oh shot

#

Shit

#

😭

molten birch
#

you did didnt you

simple nova
#

I remember now

#

Yep

molten birch
#

lol idiot

#

ok

#

so

#
  1. never do that
#
  1. lets try to fix some of this
simple nova
#

Alr

molten birch
#

can you send the file to me in dms

simple nova
#

I left the server

molten birch
#

or did he deleat it

#

ko

#

cool

simple nova
#

I deleted it

molten birch
#

we have to get the url from the downloads on google

simple nova
#

Alr

molten birch
#

can you open your browser

simple nova
#

One sec

#

Go back to normal?

molten birch
#

NO

#

dont do that

#

if you can open browser without plz

simple nova
#

Alr

molten birch
#

no internet needed

#

dont boot normal

simple nova
#

Alr

molten birch
#

do you play video games or anything?

simple nova
#

Ye

#

Found it

molten birch
#

steam or roblox or mc

molten birch
simple nova
#

Roblox

molten birch
simple nova
simple nova
molten birch
#

can you tell me what compelled you to download this? so like was it roblox cheats, free movies, hacks, a dudes game he "made" or smth else 😐

simple nova
#

Img logger 😭

molten birch
#

as in..... like a fake discord ip stealer from a image?

#

or what

simple nova
#

Ye

molten birch
#

yep, those dont exist

#

100% fake

simple nova
#

Rip

molten birch
#

rip

#

do you have important things on your pc

#

also do you have 2 usb drives?

#

or anoyther pc?

simple nova
#

2 usb drives

#

I have the C: drive and a D: drive

simple nova
#

Yep

molten birch
#

but failin

simple nova
#

Oh

#

I’ll try

molten birch
# simple nova 2 usb drives

so you have 2 usb drives, but do you have anything on them? we need 1 clean usb drive for us to reinstall windows with and 1 for backup of your files you wana put back afterwards

#

the install usb will have to be wiped compleatly

#

also if you have a diff pc this will be easier

simple nova
#

One has. Couple things

#

I think

molten birch
molten birch
simple nova
#

It didn’t work member

#

Remember

#

Yo

molten birch
#

oh yeah this malware is bad

#

Matches rule Vulnerable WinRing0 Driver Load by Florian Roth (Nextron Systems) at Sigma Integrated Rule Set (GitHub)

simple nova
#

I really don’t need any backups

molten birch
#

it has kernal drivers installed

#

so your f**ed

simple nova
#

So what does that mean…

molten birch
molten birch
simple nova
#

Damn

molten birch
#

it would have also killed any anti-virus

#

and could encrypt the whole drive in seconds

simple nova
#

Damn

molten birch
#

fun 🙂

simple nova
#

So does that mean my pc is fuc*ed?

molten birch
#

oh look at that 🙂

it runs with every exe file
HKU\S-1-5-21-4270068108-2931534202-3907561125-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids\exefile

molten birch
simple nova
#

Would I have to rebuy it

#

Or whatever

#

To active it?

molten birch
simple nova
#

Alr

molten birch
#

"%windir%\system32\schtasks.exe" /create /f /sc onlogon /rl highest /ru System /tn GoogleUpdateTaskMachineQC /tr "'%ProgramFiles%\Google\Chrome\updater.exe'" this means the malware inject into google, also it runs with system privlages at login every login

#

also anti-debuging stuff 🙂 Calls Highlighted GetAdaptersAddresses GetSystemMetrics GetTickCount IsDebuggerPresent Sleep

simple nova
#

I a really understand anything ur saying lol

#

Hardly

molten birch
#
Domain patterns found in the memory of an executed sample.
pool.hashvault.pro
Memory Pattern Urls
tcp://pool.hashvault.pro:80```
#
131.153.76.130:80 (TCP)
142.202.242.43:80 (TCP)
192.229.211.108:80 (TCP)
20.99.184.37:443 (TCP)
20.99.185.48:443 (TCP)
23.209.116.9:443 (TCP)
23.216.147.64:443 (TCP)
37.203.243.102:80 (TCP)
8.253.139.121:80 (TCP)
8.8.8.8:53 (UDP)
95.179.241.203:80 (TCP)```
#

funny numbers

#
blank-inavq.in
blank-o4glp.in
blank-rwlwt.in
cdn.globalsigncdn.com.cdn.cloudflare.net
crl.globalsign.net
dns.msftncsi.com
global.prd.cdn.globalsign.com
pool.hashvault.pro```
simple nova
#

Bro wtf

molten birch
#
blank-inavq.in
blank-o4glp.in
blank-rwlwt.in``` domains assosiated with the program and prob command and control servers
simple nova
#

Bro how u know all this

molten birch
simple nova
#

Nice

#

So does reinstalling windows work

#

Does it fix everything

molten birch
#

<#eek#>Add-MpPreference <#yms#> -ExclusionPath @($env:UserProfile,$env:SystemDrive) <#fqw#> -Force <#dqs#> oh cool, it blocks defender from running on the drive first

molten birch
#

but we will make sure it dose

#

rn can you plug in the backup drive

#

we will start backing up files

#

just copy anything important

#

anything else will go bye bye

simple nova
#

Alr

#

What should I keep

#

Idk tbh

#

lol

#

I don’t need any of my download

#

None of my desktop

molten birch
simple nova
#

I don’t need anything

molten birch
#

ok sec

molten birch
simple nova
#

There’s 2 E drives

molten birch
#

look at the indent

simple nova
#

Yep

#

I see it

molten birch
#

ok so now we do stuffs 🙂

simple nova
#

Alr

#

One sec

molten birch
#

umm with no wifi this is kinda hard

simple nova
#

My parents gonna freak out prob

#

If I say

molten birch
#

I mean........ I could do a stupid to fix

simple nova
#

?

molten birch
simple nova
#

Oh hey mom I reinstalled windows

#

😭

#

Yes

#

Ywk

molten birch
# simple nova ?

with wifi we could get rufus and be done, but without or any other pc mac or chromebook its harder

simple nova
#

I’m not gonna say anything

molten birch
#

also what phone do you have android or apple

simple nova
#

Apple

molten birch
#

😐

#

ok, and no other pc or mac or anythin

simple nova
#

No

molten birch
#

ugggg

#

umm well,

#

how many drives do you have in the system

#

1 or 2

simple nova
#

I have 2

molten birch
#

like is D a partition or a diff drive

simple nova
#

Idk what those e drives are

molten birch
#

ok, remove the non boot drive

simple nova
#

D

molten birch
#

after you turn off

simple nova
#

Non boot drive?

#

Oh the D one?

molten birch
#

the one with data sh*t

molten birch
#

boot I mean C drive

simple nova
#

Alr

#

So power it off

#

Correct

molten birch
#

ok, can you connect the phone to the usb drive

#

or no

simple nova
#

wdym

molten birch
#

just wondering

#

so like

#

phone -> apple spoopie adapter -> usb -> usb flash drive

simple nova
molten birch
#

we wana write files from internet but I dont wana boot your pc to normal mode

molten birch
# simple nova

wait, do you have usb flash drives and that, or just that

simple nova
#

Js that

molten birch
#

what is on it?

simple nova
#

Js a couple of folders

molten birch
#

not to be mean, but I think you need a empty flash drive for this part 😦

simple nova
#

Should I delete the stuff

#

Or nah

molten birch
#

also I suggest you remove all unneeded drives then boot safemode

simple nova
#

I don’t need any of it

molten birch
#

I mean if you really dont

#

but rember you cant get it back

simple nova
#

Done

#

It’s empty

molten birch
#

ok......

#

can you connect it to your phone? or nah

#

just so we dont have to boot pc to normal mode

#

like use phone to download files onto it

simple nova
#

Uh

#

Idk how to

#

Tbh

molten birch
#

ummmmmmm

#

ummmmmmm

#

do you have a lightning to usb female adapter?

simple nova
#

Nah

molten birch
#

😦

#

ok

#

lets do the stupid

#

remove all unneded drives (leave only C:)

#

including all usb drives

simple nova
#

Alr

#

Done

molten birch
#

open browser

simple nova
#

Alr

molten birch
#

download rufus

simple nova
#

Remember

#

No internet

molten birch
#

and download the windows 10 iso file from microsofts website

molten birch
simple nova
#

Alr

simple nova
#

They got one for windows 11

molten birch
#

you may need to right click and inspect element on the downloads page

#

find network connections at the top or bottom

#

uncheck the user agent box

#

then select a linux or android option in the list

#

then reload

simple nova
#

What do I do her

molten birch
#

just close that

#

re download the file

simple nova
#

Alr

molten birch
#

and remove that one

#

the malware I think injected into running exes

simple nova
molten birch
#

so I dont want to run that

molten birch
#

oh wait

#

I cant

#

because dont sign into any acc on that pc

#

or you will have to change pass again

#

AHHHHHH
I was explode

simple nova
#

Should I log out of everything

molten birch
simple nova
#

Ok

molten birch
#

change pass on phone not on pc

#

or anythin else

#

because pc prob has a keylogger nr

#

ok here

simple nova
#

Alr

molten birch
#

goto the microsoft download page for 11

#

then open inspect element

#

at the top find the 2 arrows and click on them

#

now find network

simple nova
#

Pop

molten birch
#

click on that

simple nova
#

Wrong thing

#

I’m on here

molten birch
#

now click on the wifi gear option then find the useragent option

simple nova
#

Alr

molten birch
#

WAIT did they add the iso option 🙂

#

windows 10 you had to do that inspect thing

#

but 11 looks to have the iso option iwhtout that

#

find this

simple nova
#

Download it?

molten birch
#

ye

#

its gonna be big

simple nova
#

Alr

molten birch
#

also, if you have rufus open

#

find the sha hash of the rufus and this .iso sha(256) hash

#

we will need to verrify it

#

so we know its good

simple nova
#

I’m here

molten birch
#

not the installer

#

I trust rufus more

simple nova
#

Alr

#

I’m on it

molten birch
#

also get the image hash

#

like you see in that one

simple nova
#

Wtf is a image hash

molten birch
# simple nova Wtf is a image hash

ok so;

big file (raw data) -> math sh*t -> funny numbers called a hash

website shows funny numbers so when you run the program, if the funny numbers when you run the big math stuffs match; you know the file was not edited

simple nova
#

Nice

#

So how do I get the image hash

molten birch
#

we will do it in abit

#

ok, once you have the .iso file and rufus

#

reboot safe mode (no networking)

simple nova
#

Alr I’m back

#

What am I suppost to put as path

molten birch
simple nova
#

Alr

#

I wish there was a easier way to do this

molten birch
#

so I am going with the one that is trusted

simple nova
#

Alr so what do I put as path

molten birch
#

drag in rufus exe

simple nova
#

Yo

#

It didn’t save

#

I downloaded it

#

But it’s not there

molten birch
#

ig redownload it

simple nova
#

Alr

molten birch
#

u good?

simple nova
#

There multiple paths btw

#

What do I put for the 2nd path

#

@molten birch

molten birch
#

screenshot

#

I think you pressed tab too many times

simple nova
#

I js hit enter

molten birch
simple nova
molten birch
simple nova
#

It worked

molten birch
#

dose the hash match

#

dose it equal any of these

simple nova
#

?

molten birch
#

what is the hash?

#

screenshot

#

or send last few digets

simple nova
molten birch
#

add to the end of the git-fileHAsh -algorithm md5

simple nova
#

?

molten birch
#

we need a diff math equ to run for this program

#

so run with -algorithm md5

#

to get a diff one

simple nova
molten birch
#

it will take a bit

#

but I need it

simple nova
#

Yo

molten birch
#

sup

simple nova
#

Is it good?

molten birch
#

ye that one is, can you hash the iso file (without md5)

simple nova
#

Bro it didn’t download 😭

#

Can we do this tmr

#

I’m bored asf

molten birch
#

sure, but dont boot your pc to normal mode other than to download that

simple nova
#

K

molten birch
#

just leave it off

simple nova
#

Bye

simple nova
#

Yo @molten birch

molten birch
#

In school 😦 wait 6 hours