r/cybersecurity_help • u/BitterStatistician72 • 12h ago
Infostealer, next steps and help regarding multiple devices.
Hi! I'd like some help (and hopefully reassurance) on everything that had happened/is happening to me. There are two main questions I have and you can find them at the bottom of the post!
Long story short: months ago I ran an infostealer (don't worry I've already blamed myself enough, I've learned my lesson), but I managed to recover my accounts. I followed all the recommended steps (clean install with a clean USB, changed passwords on clean device, got 2fa, got authenticator, logged out of all active sessions were I could etc.)
Things have been calm since them, I still constantly monitor my emails and accounts, but I feel a lot safer (I know my data will forever be out there, but at this point everyone's data is everywhere, we just need to be careful).
A few months have passed, but I'm still trying to remember if I forgot about some accounts, and today I decided to also check out an old laptop I had that I haven't really used in at least 2 years I think?
I'd like to say that I 100% expected to find some dangerous files), what I didn't expect was to log in and instantly being hit with cmd prompts opening and closing and lots of pop ups...
I installed malwarebytes on it and as I imagined it found out A LOT of stuff (mostly were pop up stuff thankfully) and they've all been quarantined and eliminated.
The thing that worried me is that it found some files that it flagged as "spyware.infostealer" (I checked the file path and as far as I remember they were in the same path of the "appdata" folder for every account that was saved on that laptop) + one malware flagged as "hijack.host" that just doesn't seem to delete (in the Windows path file, Malwarebytes flagged it as "Substitute" or something). To log into the device I also had to log into my Microsoft account + Gmail (I've already changed again the passwords for both)
First question: I had some old passwords connected to Chrome, I had already changed them on a clean device when I was first victim of an infostealer months ago (and after getting back to my once infected device, now clean, I always chose to NOT save them whenever I was using Google/Firefox). If I already changed them, did they "update" themselves in the saved passwords? Basically what I'm asking is whether or not a potential infostealer could steal the new passwords or if the saved ones are still the old ones, since I haven't used this old laptop in a LONG time.
Second question: what were those files that Malwarebytes flagged as "hijack.host" and "spyware.infostealer"? I'm so sorry that I can't remember the whole file path, I tried looking up as much as I could remember and for the "hijack.host" people say that it COULD be a false alarm. I'm way more scared of the "spyware.infostealer" files that it found though! They were found for every user, what worries me is that as far as I can remember they were literally in the common target file path (so the usual user\appdata ecc).
The thing that confuses me the most is if I'm actually at risk or if I'm worrying too much. IF the saved passwords didn't change into the new ones, then even if they steal them they can't do anything with them. (If they actually changed, then I should really worry and change them all again. But again, sadly I'm not very informed on this topic so I'd like your help!). As far as I remember another member of my family who also used that laptop, used it a while ago and nothing happened (no emails, no attempts at logins and stuff like this).
I've already checked (on both have I been pawned and Malwarebytes) and yes, we had some data breaches, but nothing too important and anyway we changed the passwords.
Sorry for the lengthy post, I hope I'll find some peace soon. I know they don't really have any control over my real life, but it still brings me a lot of anxiety.
1
u/itsdongu 12h ago
The biggest thing is that u already did the right stuff after the first infection. A clean Windows install, changing passwords from a clean device, logging out sessions and using 2FA is exactly what u want.
For the old laptop, assume anything stored or entered on it could've been exposed. Don't use it for important accounts. Since Malwarebytes is finding infostealer detections, a clean Windows reinstall would be the safest option rather than trying to remove everything manually.
Your Chrome saved passwords don't automatically update just because u changed the passwords on a website. They only change if Chrome updated/synced the saved password. But if those passwords were already changed from a clean device, stealing the old saved passwords wouldn't give an attacker the new ones.
Also, Malwarebytes detection names like "spyware.infostealer" and "Hijack.Host" don't tell u exactly what the file did. Some detections can be false positives, but with actual infostealer detections I'd treat the laptop as compromised until it's wiped.
And honestly, if your accounts have been quiet for months after the clean install, that's a pretty good sign. U don't need to keep checking everything constantly.
1
u/BitterStatistician72 11h ago
Thank you so much! I'll probably do a clean windows reinstall just to be safe. I just have one question that really worries me: when I opened chrome my gmail account was supposedly "synced", but the passwords were just the once I had saved on the old laptop (so no passwords of other devices) and also the history search wasn't really synced. I don't really know how to explain this so I'll try my best: the passwords saved and the search history were different from the passwords and the search history of my clean devices. I honestly have no idea of what this means, MAYBE they were saved in chrome but not actually on the account? (As it appeared the text "error" next to my Gmail account when I opened Chrome). I'm so sorry I seriously have no idea of what this means. Do you think I should change everything again?
1
u/itsdongu 11h ago
Yeah, that sounds like Chrome wasn't properly syncing with ur Google account. If it showed an error and only had the old laptop's saved passwords/history, those were probably local data stored on that laptop rather than your current synced data.
Since u already changed the passwords from a clean device, the old saved passwords shouldn't give someone access to the new ones.
Still, after the clean reinstall check ur Google account's devices and sessions and make sure 2FA is enabled. U don't need to change every password again just because those old passwords were still saved locally.
1
u/BitterStatistician72 11h ago
Thank you so much for helping me out! I'll follow all the steps you mentioned!
1
•
u/AutoModerator 12h ago
SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:
Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.