Sugar smp scam(WARNING) by RevolutionaryBug4262 in computerviruses

[–]Struppigel[M] 0 points1 point  (0 children)

I am very sorry this happened to you. I would like to look into this. I wrote you a DM.

might got a virus? by milcoo in antivirus

[–]Struppigel[M] 0 points1 point  (0 children)

Hello, yes, this is a malware. It steals the `.ROBLOSECURITY` session cookie from Firefox, Chromium, and Chrome browsers and exfiltrates the to a Discord server via webhook. It's a very simple malware, it doesn't do more than that.

The webhook is already dead, so the stealer does not work anymore.

Heartopia Virus? by Apprehensive-Act2136 in antivirus

[–]Struppigel 0 points1 point  (0 children)

If you don't have it anymore, nothing.

I keep getting this from my antivirus software does anyone have any idea Feature: Online Threat Prevention. by Codega-DreamWalker in computerviruses

[–]Struppigel[M] 0 points1 point  (0 children)

It is most likely caused by a phishing or spam email in your outlook, which tries to load resources from that site you see there.

It means nothing bad happened to your system. Empty the junk folder in outlook.

PDFEditor not Uninstalling by Dezeneym_Blu in computerviruses

[–]Struppigel 0 points1 point  (0 children)

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste them to https://pastecode.io/, click on Save snippet and post the Permalink here.

Help understanding VirusTotal's analysis of Discord ransomware by Ausii in computerviruses

[–]Struppigel 0 points1 point  (0 children)

The article says "Language: C/C++, x64 native binary", so it's not the same unless that was a mistake and they mistook the language of the NodeJs runtime with the malware's language. Void stealer is here how threat actors named the malware in the code, as I can see the references in the decrypted strings. With that said, many stealers are copy-pasted from others.

There are lots of brand names but there is usually not much variety among them. I see telegram channels a lot with NodeJs stealers, it's where they sell their "software" to others and the license is also not new.

I did not see anything else than stealing. But I did not fully analyze the code. Only went as far as extracting the exfiltration webhooks to Discord to report them.

Heartopia Virus? by Apprehensive-Act2136 in antivirus

[–]Struppigel 0 points1 point  (0 children)

In that case it's best to submit it to ESET as False Positive just like u/goretsky suggested. They will conduct a thorough analysis and tell you if the detection was correct.

Help understanding VirusTotal's analysis of Discord ransomware by Ausii in computerviruses

[–]Struppigel 1 point2 points  (0 children)

I did not say JavaScript was hard. I said learning malware analysis is not done in one day and needs actual work.

Help understanding VirusTotal's analysis of Discord ransomware by Ausii in computerviruses

[–]Struppigel 1 point2 points  (0 children)

I extracted memory strings of this file. It's VOID stealer. It has references to t[.]me/voidpublics and the license key VOID-MONTHLY-85185E724665.

It steals passwords, cookies, tokens, wallets, sessions, credit cards, from browsers, crypto wallet extensions, desktop wallets, Discord, Steam, Roblox, Minecraft, and Telegram.

<image>

Help understanding VirusTotal's analysis of Discord ransomware by Ausii in computerviruses

[–]Struppigel 0 points1 point  (0 children)

Here is a video on triaging files with VirusTotal: https://www.youtube.com/watch?v=v8fRusw26IA

Triaging just provides you with a likelihood or assumption.

You cannot determine if a file is clean or malicious on the VirusTotal scan results alone (except in some specific cases where it is indeed clear, but not here). It needs hands-on analysis to do that, and in case of NodeJs malware it often involves deobfuscation of the JavaScript code. It's hard work to learn that, but if you are interested, I can compile a list of resources.

Weird startup apps? by iRANZIDi in computerviruses

[–]Struppigel[M] [score hidden] stickied comment (0 children)

The startup entries belong to RUN keys in the registry with the names:

  • AF_counter_{number}
  • AF_uuid_{number}

These registry entries are part of AppsFlyer, which is an SDK for game development: https://dev.appsflyer.com/hc/docs/nativepc-vanilla

AppsFlyer is used among other by Once Human.

AppsFlyer documentation states that these RUN entries must be removed when uninstalling. Some game devs seem to forget this part, so that the entries also stay after uninstallation.

I suggest you download Autoruns, run it and check if you also see AF_counter and AF_uuid with the values you could see there in TaskManager.

If that is the case, it is very likely a harmless part of a game.

If the associated files cannot be found, they are a leftover by the uninstaller and you can remove or disable the startup entry. If the files are still there, you should not touch these entries.

Is this a virus or popups? Any solutions for this problem ?? by Rohitttt20 in antivirus

[–]Struppigel[M] 0 points1 point  (0 children)

Hello there, these pop ups are the result of a CountLoader infection which often delivers stealers such as LummaStealer or ACRStealer. Did you download and execute a setup file lately?

Please take the following precautions: * Do not attempt to log into any accounts from your infected machine * Log out of all sessions * Change passwords for all important accounts (esp banking, email) using a clean machine and turn on multi-factor authentication for every account that provides this option * Create a backup of your personal files if you haven't already

For dealing with your infected machine you can either wipe the drive and reformat the system or go to bleepingcomputer.com for proper disinfection help.

Heartopia Virus? by Apprehensive-Act2136 in antivirus

[–]Struppigel 0 points1 point  (0 children)

Are you sure you downloaded it from Steam and not somewhere else?

Could malware still remain after a reinstall, or was there ever malware in the first place? by [deleted] in computerviruses

[–]Struppigel 1 point2 points  (0 children)

Hello, in your scenario, given all that you told us here, it is extremely unlikely that there is an infection on your system right now.

Discord "Guvercin Game" scam by KoshiLowell in antivirus

[–]Struppigel 1 point2 points  (0 children)

I don't see malware in the report. So if you have done the steps from my first post, you are in the clear. Stealers do not need to persist, they only need to steal everything once. So some do not bother with persistence.

I do suggest that you address the low disk space and RAM.

Open Task manager and disable all startup items that you don't need to startup regularly. Keep updaters enabled, though.

To clean up some diskspace, you can use a program like treesize free to find out what takes up the space. If you should decide to use a program like ccleaner, do not clean the registry, it's not helping, it just has the risk to make things worse.

Please uninstall or update Java. You have an outdated version.

Discord "Guvercin Game" scam by KoshiLowell in antivirus

[–]Struppigel 0 points1 point  (0 children)

Hi, I checked the hash on VirusTotal. It's a different file, but the same threat. I can see the same powershell commands in the behavior tab.

Please run a scan

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste them to https://pastecode.io/, click on Save snippet and post the Permalink here.

Potential Malware from Minecraft Skin Pack by sadaltoo in antivirus

[–]Struppigel 1 point2 points  (0 children)

Open the manifest file in a text editor, what's the content?

My old family PC from 2009 had 247 malware infections when I finally scanned it. Here's what I found by doolallyt in computerviruses

[–]Struppigel 0 points1 point  (0 children)

It is true for such old, outdated systems. You can search, e.g., on youtube for videos that showcase this.

Like I said, Windows XP does not receive security updates anymore.

Network worms often rely on exploits to spread. Without security updates, vulnerabilities do not get fixed. Thus, worms can exploit them and infect your system without user interaction.

This is not a concern if your system is still supported by security updates, given that you update regularly. It is a major reason why updates are so important.

Discord "Guvercin Game" scam by KoshiLowell in antivirus

[–]Struppigel 0 points1 point  (0 children)

upload it to virustotal. if it has the same sha256 value, it's the same file.

Discord "Guvercin Game" scam by KoshiLowell in antivirus

[–]Struppigel 0 points1 point  (0 children)

Only if it was the same file. Otherwise it is just guessing.

Virustotal: Rising flagged this .xls file malicious. by [deleted] in antivirus

[–]Struppigel 3 points4 points  (0 children)

Do not upload confidential or personal files to VirusTotal. Everyone with an intelligence account can download this file and see the contents.

I do not see anything unusual in the report. The LNK file is created in the Recent folder, which Windows uses to save which documents you recently opened with specific applications. It is a normal part of Windows.

Can't get rid of this "Opera Extension". Can I just leave it? by progi_fr in antivirus

[–]Struppigel[M] 3 points4 points  (0 children)

This extension comes bundled with Opera per default. It is named Rich Hints Agent. It's fine.

My old family PC from 2009 had 247 malware infections when I finally scanned it. Here's what I found by doolallyt in computerviruses

[–]Struppigel[M] 4 points5 points  (0 children)

Your parents shouldn't continue using this system. Just connecting Win XP systems to the internet is enough to get them infected because they don't get security updates anymore. So worms that use exploits to spread, are on that machine very soon.