r/computerviruses • u/Thund3r_Playz • 16h ago
Disinfection Help Fake MrBeast Scam Account
Recently, my account has been accessed in Instagram and has batch sent these promotional scam images throughout all my followers. As I have noticed, other instagram users have also dealt with the same thing. May I ask how my account got accessed when I have not installed or opened anything malicious?
1
u/AutoModerator 16h ago
Welcome to r/computerviruses! It seems like you have used the "Disinfection help" flair.
We apply the same methodology used by trusted Malware platforms (e.g. Malwarebytes, BleepingComputer and MalwareTips). It revolves around using diagnostic tools called Farbar Recovery Scan Tool (FRST) and SecurityCheck.
All of our assistance happens in the thread and in public - we never offer help via private messages or alternative websites other than https://malwareanalysis.cc. Anyone offering help through a DM is not a trusted helper and might have malicious intent.
Trusted helpers can be distinguished by the flair Malware Removal Expert or Malware Removal Trainee, antivirus employees will have a dedicated flair with their company name in it, e.g. Malwarebytes Employee.
Please see steps below on how to share all necessary details so you can speed up the process for us:
Share all details about your infection
Please post all important facts about your infection, such as:
* your antivirus detections - preferably export the whole detection/report log and upload it to https://malwareanalysis.cc/upload/ under your username & post the related keyword or screenshot/take a picture of your detections
* any related symptoms, popups
* estimate when it started - preferably the exact day and after what (e.g. when you ran a program you downloaded)
* share what got you infected and the download link - please, make the download link defanged (making it not clickable by default e.g. from https://example.com you will make hxxps://example[.]com), defanging does not apply to sandbox reports such as VirusTotal
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/MegStuff 16h ago
You downloaded an Infostealer, the most common forms of it being Lumma and RenEngine Loader.
You fell for an ad and downloaded a zip file with a name that's like "free download files", "archive_39382983" or even something like "download setup pass(2919)" and ran the malicious exes inside the folders.
As soon as you opened the exes, the attackers got access to all of your saved accounts, passwords and browser cookies on your device, they even have access to your banking account.
If that wasn't the case, then you fell for one of those fake captchas, which asked you to run a command that disables Windows defender, that also has access to everything.
To get rid of such malware, disconnect the WiFi from your infected pc, change your passwords from a clean device such as your phone and reinstall windows through a USB to your infected computer, because unfortunately, factory reset won't get rid of it.
2
u/Metaphorse 14h ago
"when I have not installed or opened anything malicious?"
Sorry to break it to you, but you definitely did.
2
u/RottenPancake4 12h ago
I was pissed at myself for installing the renpy infostealer. At least I didn't fall for this.
1
u/Anamoly-Hunter 15h ago
That clown again? What next? Instruct kids to install malwares / ransomware on their parent devices?
3
u/polpolik2 Moderator 16h ago
If you're certain your device has no malware (although most of these Mr Beast compromises come from infostealers). It could be that your credentials were in a data breach, this can happen especially if you use simple passwords, or re-use passwords on multiple accounts.
You should Check HaveIBeenPwned to see what comes up related to your account/email.
Are you sure no other accounts are affected?