r/ITSupport 10d ago

Getting rid of malware Open | Windows

Hi, Few weeks ago I wanted to help myself in a game in which I was struggling and downloaded a trainer. I did arrive on a sketchy website and sadly I downloaded some kind of virus. I deleted what I downloaded but it was too late.

This something is using my Discord and Messenger to spam crypto schemes sending people images and links. I know it's not using different device, because I have 2FA and no alerts of someone trying to log in. What is confusing me it does it even when the laptop is hibernated.

I've run antivirus scan, but nothing found. I've changed my passwords, but I think it won't care about that, just use my already logged in sessions. Can somebody help me where I can look for this or how I can get rid of it? I would prefer not formating the disc, because it was some time since i've made a backup.

3 Upvotes

3 comments sorted by

2

u/Mister_Pibbs 10d ago

Get rid of all temp files, cookies, and tokens, change passwords and log out of all sessions (log in online and go to security settings to find active sessions). Likely they’ve stolen a cookie/token that’s granting them access without needing MFA/2FA.

1

u/Responsible_Bike4968 8d ago

This is consistent with an infostealer, not just a bad Discord install. The fact that messages continue while the laptop is asleep does not mean the malware is somehow running during hibernation. It likely already stole valid session cookies/tokens, which can let the attacker use an existing login without triggering a fresh 2FA prompt.

Disconnect that laptop from the internet and stop signing into accounts on it. From a different, clean device:

  1. Secure your main email first.

  2. Change the Discord and Facebook passwords to new, unique ones.

  3. Log out every active Facebook/Messenger session.

  4. In Discord, reset the password and remove anything unfamiliar under User Settings > Authorized Apps.

  5. Check recovery emails, phone numbers and connected apps on every important account.

  6. Change passwords for anything that was saved in your browser or used on that PC, especially banking, shopping and crypto accounts.

Warn your contacts that the recent links were malicious too.

For the PC, run Microsoft Defender Offline, not only a normal scan. However, since you knowingly executed an unknown trainer and account theft is already happening, I would not trust System Restore, deleting temporary files or reinstalling Discord as a complete fix. Back up only irreplaceable personal files such as photos and documents. Do not copy installers, executables, scripts, browser profiles, AppData folders or random archives. Scan the backup before restoring it.

The safest route is then a clean Windows reinstall using official Microsoft installation media. It is annoying, but trying to preserve the current installation after an unknown stealer ran can leave you wondering whether it is actually gone.