Jump to content

I tried to install a pirate copy of a game and my pc was ultra infected


Recommended Posts

hi to all guys, a few days ago i install elden ring pirate game from pivigames page and my pc was literally attacked by a hacker, 

i use a most of tools (script tron and all tools of that for example) but nothing of results... with difficult i read a most of forums of cybersecurity but i didnt find nothing like this. I even formatted my pc more than once but the infections are still there. Apparently, they have infected the pre-installed drivers of my system, this is the only way i can explain why they remain even after a too many hard resets. in the last reset, i was able to add folder protection to the local disk in windows defender, that was blocked amount of processes of some like "Hijack", i cant remember exactly... anyway, i need help please... i so depressed by this, i only want to try elden ring and my pc now is rapted XD

i use the malwarebytes support tool to share my logs (frst and others)

(note: my native languague is spanish, sorry if my english is bad, i trying all i can) 

mbst-grab-results.zip

Link to post
Share on other sites

  • Root Admin

Hello  and  :welcome:    

 

My screen name is AdvancedSetup and I will assist you with your system issues.
 

Let's keep these principles as we proceed. Make sure to read the entire post below first.

  • Removing pesky malware can be an involved set of tasks over separate runs. Have much patience. Follow my directions. 
  • Please follow all steps in the provided order and post back all requested logs.
  • Please attach all log files to your post, unless otherwise requested.
  • Temporarily disable Microsoft SmartScreen to download software below if needed. Make sure to turn it back on once the scans are completed.
  • Searching, detecting, and removing malware isn't instantaneous and there is no guarantee to repair every system.
  • Before we start, please make sure that you have an external backup of all private data.
  • Do not run online games while your case is ongoing. Do not do any free-wheeling of risky web-surfing.
  • Only run the tools I guide you to use. Please don't run any other scans, download, install or uninstall any programs while I'm working with you unless requested.
  • Cracked, Hacked, or Pirated programs are not only illegal but also can make a computer a malware victim.
    Having such programs installed is the easiest way to get infected. It is the leading cause of ransomware encryption. It is at times also a big source of current Trojan infections. 
    If there are any on the system you should uninstall them before we proceed.  
  • If your system is running Discord, or P2P Torrent software, please be sure to Exit out of it while this case is on-going.


Do these two steps so that ALL Folders & Files are set to SHOW, plus also, Turn OFF Windows Fast start.

Show-Hidden-Folders-Files-Extensions
https://forums.malwarebytes.com/topic/299345-show-hidden-folders-files-extensions/

Disable-Fast-Startup
https://forums.malwarebytes.com/topic/299350-disable-fast-startup/
 

  • Next, please restart Windows

  • Please be patient and stick with me until I give you the "all clear" or otherwise indicate all is good

 

 

Let's go ahead and run a couple of scans and get some updated logs from your system. Please read the entire post below before starting so that you're more familiar with the process

Then follow each step in the order provided. Unless otherwise asked, please attach all logs

 

Please make the following system changes:

  • If you have not done so already - Enable System Protection and create a NEW System Restore Point
  • Temporarily disable your antivirus real-time protection or other security software first only if it blocks or interferes with the scans or downloads.. Make sure to turn it back on once the scans are completed
  • Temporarily disable Microsoft SmartScreen to download software below only if needed. Make sure to turn it back on once the downloads are completed
  • Disable-Fast-Startup
  • Show-Hidden-Folders-Files-Extensions

Please run the following scans:

  1. Click the following link and run a  Scan with AdwCleaner
  2. Click the following link and run a  Scan with Malwarebytes 
       RESTART the computer
  3. Click the following link and run a  Scan with Farbar Recovery Scan Tool 
     

Example image of where to click to attach files when posting your reply

image.thumb.png.e208c182ff570799c53bcf57

 

Thank you

 

Link to post
Share on other sites

Hello AdvancedSetup, i am very grateful for your help, you dont know how happy i am that there are people willing to help others n.n 

malwarebytes found two pup that disables MRT, additionally i read in the logs that my registry is completely adulterated, desactivating the security features of my pc and replacing all the  microsoft applicatons to a infecteds versions. (i never see that, im interested in these topics, i am learning a lot with this conflict jaja) i attatch the logs of the processes requested. 

Addition.txt FRST.txt AdwCleaner[C00].txt

Link to post
Share on other sites

  • Root Admin

Please run the following fix

 

NOTE: Please read all of the information below before running this fix.

  • NOTICE: This script was written specifically for this user, for use on this particular machine.
  • Running this on another machine may cause damage to your operating system that cannot be undone.

Once the fix has been completed, please attach the file FIXLOG.TXT to your next reply

Farbar program:   FRSTEnglish.exe

Save the attached file:  FIXLIST.TXT to this folder C:\Users\survivor\Desktop\frstenglish

NOTE. It's important that both files, FRSTEnglish.exe, and fixlist.txt are in the same location or the fix will not work.

Please make sure you disable any real-time antivirus or security software before running this script. Once completed, make sure you re-enable it.

 

 

Run the Farbar program with Admin rights and press the Fix button just once and wait.

The fix may possibly take up to 60 minutes to complete

If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart.
The tool will make a log named Fixlog.txt in the same folder you ran the Farbar program from. Please attach that log on your next reply.

 

  1. NOTE:  This fix will run a scan to check that all Microsoft operating system files are valid and not corrupt and attempt to correct any invalid files. It will also run a disk check on the restart to ensure disk integrity.
  2. NOTE: As part of this fix all temporary files will be removed. If you have any open web pages that have not been bookmarked please make sure you bookmark them now as all open applications may be automatically closed.
                Also, make sure you know the passwords for all websites as cookies may possibly be removed in some cases, but not all cases.
  3. NOTE: As part of this fix, it will also reset the network to default settings including the firewall. If you have custom firewall rules you need to save please export or save them first before running this fix.

The following directories are emptied:

  • Windows Temp
  • Users Temp folders
  • Edge, IE, FF, Chrome, and Opera caches, HTML5 storages, Cookies and History
  • Recently opened files cache
  • Discord cache
  • Java cache
  • Steam HTML cache
  • Explorer thumbnail and icon cache
  • BITS transfer queue (qmgr*.dat files)
  • Recycle Bin

Important: items are permanently deleted. They are not moved to quarantine. If you have any questions or concerns please ask before running this fix.

The system will be rebooted after the fix has run.

fixlist.txt

Thanks

 

Link to post
Share on other sites

  • Root Admin

Thank you that looks good.

Please run the following

 

SecurityCheck by glax24              


I would like you to run a tool named SecurityCheck to inquire about the current security update status of some applications.
CheckSecurity is a utility for quickly checking for the presence of vulnerable applications

  • Temporarily disable Microsoft SmartScreen to download the software
  • Download SecurityCheck by glax24: https://tools.safezone.cc/glax24/SecurityCheck/SecurityCheck.exe
  • If SmartScreen blocks the file from running click on More info and Run anyway
  • This tool is safe.   Smartscreen is overly sensitive. You can check the VirusTotal scan of the tool from here
  • Right-click  with your mouse on the Securitycheck.exe  and select "Run as administrator"  and reply YES to allow to run & go forward
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt Close the file.  Attach it with your next reply.
  • You can find this file in a folder called SecurityCheckC:\SecurityCheck\SecurityCheck.txt

Items checked:

  1. User Account Control (UAC).
  2. Service pack.
  3. IE version.
  4. Automatic OS update. Sets of critical KB patches when updating is disabled.
  5. Antivirus, firewall, other security utilities.
  6. Versions of Java, Oracle Virtualbox.
  7. Version of Adobe Flash Player, Adobe AIR.
  8. Versions of Adobe Reader, Acrobat Reader DC, Foxit Reader.
  9. Versions of media players (iTunes, AIMP, foobar2000).
  10. Versions of messengers (Skype, Pidgin).
  11. Versions of installed browsers (Chrome, Opera, Firefox, Yandex, SeaMonkey).
  12. Versions of mail programs (The Bat, Thunderbird).
  13. Checking running processes and security program services
  14. Searching for installed Adware programs and optimizer programs (More than 5000).

Thank you

 

Link to post
Share on other sites

At start, my pc ventilation system sounds like industrial machine (very loud at start, rlly), but now with all the changes thats dissapear, im so glad with all your help :) 

in all case, i have a detail... maybe you need to know it. 

i found in task manager a six processes with a strange direction

Process: Intel(R) Management Engine WMI Provider Registration 

(ubication C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6) - (the file appear at WMIRegistrationService.exe)

Process: Start (Appear at Inicio) StartMenuExperienceHost.exe
(ubication C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy) - (the file appear at StartMenuExperienceHost.exe)

Process: NVIDIA Container
(ubication C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_866484083fc526af\Display.NvContainer)

and there are so weird because the file extension

Process: Microsoft Text Input Application /  this isnt suspended
(ubication C:\Windows\SystemApps) - (Archives File (.CBS_cw5n1h2txyewy)

Process: Search  (Appear at Búsqueda) / this is suspended
(ubication C:\Windows\SystemApps) - (Archives File (.Search_cw5n1h2txyewy)

Process: Configuration (Appear at Configuración) this is suspended
(ubication C:\Windows\ImmersiveControlPanel ) - (the file appear at systemsetting.exe)

and i have a question, i have two other computers with these same types of files... with my friends we had downloades games via torrent haha ¿what i can do for them?

SecurityCheck.txt

Link to post
Share on other sites

  • Root Admin

The file is valid and normal. As you can see it's on my system as well

Directory of C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6

07/25/2021  04:54 AM           538,736 WMIRegistrationService.exe

It is called at various times depending on when it's needed

 

The Security Check log looks good.

 

Let's go ahead and run another scanner to double-check the system.

 

 

Let's go ahead and run a couple of scans and get some updated logs from your system. Please read the entire post below before starting so that you're more familiar with the process

[ 1 ]

Please make the following system changes.

  • Temporarily disable your antivirus real-time protection or other security software first only if it blocks or interferes with the scans or downloads.. Make sure to turn it back on once the scans are completed.
  • Temporarily disable Microsoft SmartScreen to download software below only if needed. Make sure to turn it back on once the scans are completed.
  • Disable-Fast-Startup
  • Show-Hidden-Folders-Files-Extensions

[ 2 ]

I suggest a new scan for viruses & other malware. This may take several hours, depending on the number of files on the system and the speed of the computer.

The Microsoft Safety Scanner is a free Microsoft stand-alone virus scanner that can be used to scan for & remove malware or potentially unwanted software from a system. 

The download links & the how-to-run-the tool are at this link at Microsoft 

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download

 

Look on the Scan Options & select the FULL scan.

Then start the scan. Have lots of patience. It may take several hours.

  • Once you see it has started, take a long long break;  walk away.  Do not pay credence if you see some intermediate early flash messages on the screen display.  The only things that count are the End result at the end of the run.
  • The scan will take several hours.  Leave it alone. It will remove any other remaining threats as it goes along.  Take a very long break, do your normal personal errands .....just do not use the computer during this scan.

This is likely to run for many hours as previously mentioned  ( depending on the number of files on your machine & the speed of the hardware.)

The log is named MSERT.log  and the log will be at C:\Windows\debug\msert.log

Please attach that log with your next reply.

 

It is normal for the Microsoft Safety Scanner to show detections during the scan process.

It is scanning for basically all bread crumbs or traces of files and registry entries that "might" be or have been part of some infection or previous infection.

That DOES NOT mean the computer is infected. Once the scan has been completed it uploads the log to their Cloud service which then uses Artificial Intelligence to determine if in fact any of the traces are an infection or not.

Then it writes into the log on your computer what it found.

 

Thank you

Link to post
Share on other sites

and because i so detailist, i found in C:\ProgramData\NVIDIA a lot of logs... maybe of the guy was attacking me XD 

the attach is the first, but a lot of "MessageBus" are in the folder. 

 

in the same programdata folder i found these folders: "Microsoft" and a lot of files that i cant see due to lack of permissions. Is funny, because the first folder is called "Crypto" jjajaja

The same with the nvidia folder and another nvidia folder that name "NVIDIA Coportation"

and another that names "PLUG", "USOPrivate" and "USOShared"


 

DisplaySessionContainer1.log

Link to post
Share on other sites

  • Root Admin

The act of torrenting itself is not illegal. However, downloading and sharing unsanctioned copyrighted material is illegal, and there is always a chance of prosecution if caught by the authorities.
Torrenting non-copyrighted material is perfectly fine and is allowed. However, be aware that we have seen increased malware bundled with software downloads over P2P.

Recent Ransomware infections have been seen to encrypt user data so that no one can decrypt the data without the private key.
When sharing files, please keep in mind that you're increasing your system's attack surface area, which can increase the risk of infection.

Scan all files before running them. https://www.virustotal.com

If you don't need or use the P2P software, you should uninstall it.

P2P File-Sharing: Know the Risks
https://www.bankinfosecurity.com/p2p-file-sharing-know-risks-a-737

 

Hidden risks in pirated software https://news.microsoft.com/apac/2019/01/08/hidden-risks-in-pirated-software/
Why You Shouldn't Use Pirated Software (But Why People Still Do) https://www.computer.org/publications/tech-news/trends/why-you-shouldnt-use-pirated-software

Why You Shouldn't Use Pirated Software
https://www.computer.org/publications/tech-news/trends/why-you-shouldnt-use-pirated-software

Torrenting: Know What Risks You Take
https://informationsecuritybuzz.com/torrenting-know-risks-take/

Don't Fall for the Money-Saving Lure of Cracked Software
https://scambusters.org/crackedsoftware.html

 

 

 

 

 

 

Link to post
Share on other sites

 

Thanks for the articles, I will read them all... I never really expected this would happen to me, I just wanted to play something with my friends without spending too much... but sometimes, cheap ends up being expensive.

Attached the log. 
 

note: before resorting to this forum, the virus infection took place on an SSD that I used exclusively for Windows, I formatted it to remove it and use the HDD that I currently use, thinking that would fix things, but the viruses continued . Now that we are cleaning the system, Is it safe to reinstall windows on that disk? If it is safe, what means do you recommend to do it? Now that I understand my very serious mistake of downloading piracy, I no longer want to make a mistake like that again, I don't want to risk my PC or my friends' PCs. The truth is we are just looking for fun and one of my friends ended up very sad because his PC was infected. I will help them repair their equipment, but, if it is not too much trouble, I would like to know if you could guide me a little with the installation of clean Windows, please :(

 

and thank you so much, i am very grateful with you, honestly, this whole topic scared me but I felt safe in this forum (I think I'll buy mw premium and join the comunity haha)

msert.log

Link to post
Share on other sites

  • Root Admin

We're not done yet. We still have a few things to run and check to make sure the system is safe.

Please go ahead and run the following

 

 

Please download and run the following Kaspersky Virus Removal Tool 2020 and save it to your Desktop.

(Kaspersky Virus Removal Tool version 20.0.10.0 was released on November 9, 2021)

Download: Kaspersky Virus Removal Tool

https://devbuilds.s.kaspersky-labs.com/devbuilds/KVRT/latest/full/KVRT.exe

How to run a scan with Kaspersky Virus Removal Tool 2020
https://support.kaspersky.com/15674

How to run Kaspersky Virus Removal Tool 2020 in the advanced mode
https://support.kaspersky.com/15680

How to restore a file removed during Kaspersky Virus Removal Tool 2020 scan
https://support.kaspersky.com/15681

 


Select the  image.png  Windows Key and R Key together, the "Run" box should open.

user posted image

Drag and Drop KVRT.exe into the Run Box.

user posted image

C:\Users\{your user name}\DESKTOP\KVRT.exe will now show in the run box.

image.png

add -dontencrypt   Note the space between KVRT.exe and -dontencrypt

C:\Users\{your user name}\DESKTOP\KVRT.exe -dontencrypt should now show in the Run box.
 
image.png


That addendum to the run command is very important, when the scan does eventually complete the resultant report is normally encrypted, with the extra command it is saved as a readable file.

Reports are saved here C:\KVRT2020_Data\Reports and look similar to this report_20210123_113021.klr
Right-click direct onto that report, select > open with > Notepad. Save that file and attach it to your reply.

To start the scan select OK in the "Run" box.

A EULA window will open, tick all confirmation boxes then select "Accept"

image.png

In the new window select "Change Parameters"

image.png

In the new window ensure all selection boxes are ticked, then select "OK" The scan should now start...

user posted image

When complete if entries are found there will be options, if "Cure" is offered leave as is. For any other options change to "Delete" then select "Continue"

user posted image

When complete, or if nothing was found select "Close"

image.png

Attach the report information as previously instructed...
 
Thank you
 
 

 

 

Link to post
Share on other sites

  • Root Admin

Nothing found, which is good.

Let me have you run a Sophos scan as well.

The instructions might not be fully up to date as I believe Sophos has changed their UI a little but should be similar.

 

 

Sophos Scan & Clean

Download Sophos Free Virus Removal Tool and save it to your desktop.

  • If your security alerts to this scan either accept the alert or turn off your security to allow Sophos to run and complete.....
  • Please close all other open applications and Do Not use your PC whilst the scan is in progress... This scan is very thorough so it may take several hours to complete, please be patient...

Double click the icon and select Run

Click Next

Select I accept the terms in this license agreement, then click Next twice

Click Install

Click Finish to launch the program

  • Once the virus database has been updated click Start Scanning

If any threats are found click Details, then View log file... (bottom left hand corner)

 

Attach the results in your next reply

  • Close the Notepad document, close the Threat Details screen, then click Start cleanup

Click Exit to close the program

 

If no threats were found please confirm that result...

  • The Virus Removal Tool scans the following areas of your computer:
  • Memory, including system memory on 32-bit (x86) versions of Windows
  • The Windows registry
  • All local hard drives, fixed and removable
  • Mapped network drives are not scanned.

Note: If threats are found in the computer memory, the scan stops. This is because further scanning could enable the threat to spread. You will be asked to click Start Cleanup to remove the threats before continuing the scan.

 

Saved logs are found under this sub-folder: C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs 

Please attach that log on your next reply

Thank you

 

Link to post
Share on other sites

On 1/16/2024 at 5:39 PM, RenatoKorr said:

note: before resorting to this forum, the virus infection took place on an SSD that I used exclusively for Windows, I formatted it to remove it and use the HDD that I currently use, thinking that would fix things, but the viruses continued . Now that we are cleaning the system, Is it safe to reinstall windows on that disk? If it is safe, what means do you recommend to do it? Now that I understand my very serious mistake of downloading piracy, I no longer want to make a mistake like that again, I don't want to risk my PC or my friends' PCs. The truth is we are just looking for fun and one of my friends ended up very sad because his PC was infected. I will help them repair their equipment, but, if it is not too much trouble, I would like to know if you could guide me a little with the installation of clean Windows, please :(

 

 is safe to download a new windows image and install in the previous ssd? 

Link to post
Share on other sites

my friends have laptops, we are students what live together, so lucky we all gamers JAJAJAJA but, the games are expensive and we intent to save cash for now XD at diference of my guys i have a good pc gamer, you understand my preocupation with this... anyway

the first laptop i try to save quickly, literallly a moment later of infection, because hes draftsman, all the archives are in her laptom. I enter in security windows, ransomware protection and protect the principal disk. I think was a good play because in the historial of blocks... a lot of blocked processes like "cmd" "powershell" "policygroups" and another a lot of internal windows programs... The hostile operator invades the security of PCs through group policy, removing the user's permissions to give them to another user under his command that he controls remotely through a host, right? My question is, how is it that when I reinstall Windows on a drive that I just completely formatted, including the partitions and, well, literally erased EVERYTHING, three times (as it was before coming here) a virus can still be on the reinstalled system? I would like to be able to format and reinstall a clean Windows on my friends' PCs, they have original copies of Windows unlike me, it's ironic XDDDD I spent a lot and less on an original Windows... but hey, I don't want to do anything until be sure that the virus is under control. Understanding how he works will help me counteract his movements. Payday is coming soon so I'll buy windows and mw premium, it's the only way to really thank you

Link to post
Share on other sites

The second laptop was more revealing... I protected the local drive as before, it had some old games downloaded by utorrent, the exes of those programs and a very annoying utorrentweb that I couldn't delete, the tab stopped working when I tried to remove it, I resorted to adw cleaner and malwarebytes, everything was clean. Then, I realized that it had webcompanion and two other malwares that I don't remember anymore haha, I was able to eliminate them without any problem. Clean browsers and delete programs you don't use regularly. They both agree to format, so if you give me the green light, I will proceed. Thank you again for reading and for all your time, I really value your work n.n

Link to post
Share on other sites

i tried to install steam and this appear 🧐🧐🧐 

%temp%\nss2438.temp

and steam installer print me 

 

“Steam is already installed in this system, please close and etc” 

so rare…

 As i saw that i had already downloaded the steam installer before, i used it and it installed so quickly, without the previous messages…

to wait your response now im playing Risk Of Rain 2 without problems 🤔
when i start the game, another anti ransomware message appear in blocked acctions two times at same time 

%localappdata%\temp 

this time the VC_redist.x86.exe

 

When i install MalwareBytes Browser Guard, same message type but in %progam_files%\malwarebytes\anti-Malware\ 🧐 

This is normal?

image.jpg

image.jpg

image.jpg

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.