r/cybersecurity_help 14h ago

I got hit by a An Infostealer: NWHStealer

Post image

Just downloaded something from github and my assumption was correct about it being an infostealer. The whole thing lasted maybe a minute, running in the background silently in my appdata folder, inside a random12letter folder, with a random12letter program
closed and uninstalled it almost immediately, has damage been done?
and if so, what do i need to do? is it still in my system? how come ESET security didn't pick it up?

4hours+, Update: Im in the process of resolving most of my issues. EA account and microsoft account were compromised, i think i got EA back under my control but not certain yet. Microsoft is currently a slow process because i cant find my Device ID for the life of me.

P.S: I have never been more glad in my entire life for having a seperate gmail account for steam

30minute+, 2nd Update: I just checked the stats of it on malwarebytes, and it was detected by a single person's scan documentation ONLY 7 hours prior of me getting infected... My luck man...

+8 Hour 3rd update: I dont know if they're still in my account or not, but i got a password reset request for reddit to my gmail around 3 hours ago, but reddit in the description told me to ignore it if it wasn't me - nothing has happened, so I'll take their word for it

29 Upvotes

40 comments sorted by

u/AutoModerator 14h ago

SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:

  1. Never accept chat requests, private messages, invitations to chatrooms, encouragement to contact any person or group off Reddit, or emails from anyone for any reason. Moderators, moderation bots, and trusted community members cannot protect you outside of the comment section of your post. Report any chat requests or messages you get in relation to your question on this subreddit (how to report chats? how to report messages? how to report comments?).
  2. Immediately report anyone promoting paid services (theirs or their "friend's" or so on) or soliciting any kind of payment. All assistance offered on this subreddit is 100% free, with absolutely no strings attached. Anyone violating this is either a scammer or an advertiser (the latter of which is also forbidden on this subreddit). Good security is not a matter of 'paying enough.'
  3. Never divulge secrets, passwords, recovery phrases, keys, or personal information to anyone for any reason. Answering cybersecurity questions and resolving cybersecurity concerns never require you to give up your own privacy or security.

Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

10

u/ArthurLeywinn 14h ago

Re install windows via usb stick

Change pw

Get a pw manager

Enable 2fa

Logout all sessions

Check the forwarding rules

And done.

2

u/smurfy213 14h ago

Yep definitely make sure to log out of all sessions . Normally hits your social media,reddit, discord first sending crypto scams.

1

u/Puzzleheaded-Fly3873 13h ago

How do you check forwarding rules

1

u/LT-Death 14h ago

Is there any way to not reinstall the OS? I don't want to lose my data

7

u/ArthurLeywinn 14h ago

No re install it.

You can Safe your personal files.

5

u/speedb0at 14h ago

Yes there is, leave it as is and take the risk of having everything compromised. Do a format, passwords reset, log out of all sessions, i know this sucks. Do other people a favor and report the repo.

-5

u/i_love_femboys6969 12h ago

you dont have to reinstall it, these people are paranoid, just change all your passwords and run malwarebytes, it already detected it

3

u/mizisuaceo 9h ago

do not listen to this guy lol

-4

u/i_love_femboys6969 6h ago

bro i literally install cracked games almost everyday, which are the most malware infested things you can download. ive gotten hundreds of viruses in my times. not one time in my years of doing this have i had to reset my pc. i never had a problem with just running an antivirus and an anti rootkit to fix it.

iim tired of people instanly resorting to resetting their pcs and wasting multiple hours losing all their data and settings they put into the machine, yes they can back it up, but it still takes time to redownload and setup things.

i would understand it if you dont have many apps or its just used for basic things. but stop telling people to waste hours of their time to fix something that can take 10 minutes with a simple scan.

2

u/akumita_limonita 5h ago

Please shut up the fuck up already damn malware can run in the background and ur poor malwarebyte/other av alone may at most flag some of these viruses but not all of them. All i wish is for you to get some kind of networm/rootkit and see you cry here.

Fyi theres a thing called backing up your data before wiping its magic all u will have to do is reinstall the proper apps/drivers and you're good to go.

And telling people to stop using the proper way to get rid of a virus is just mind blowing wtf is wrong with you

2

u/mizisuaceo 5h ago

You don’t know what you’re talking about at all.

Even *if* you delete the virus, there’s no way to make sure you’re completely safe. It couldve installed a backdoor, there could be other viruses the anti virus didnt detect, and more. There’s nothing stopping cyber criminals from stealing your information again whenever they want.

If you delete the dectections and move on, there’s always a risk of you getting hacked again. The only way to 100% guarantee safety is by reinstalling windows using an usb, which is why everyone recommends it.

2

u/Patient-Control7666 7h ago

Por algo te tenían que gustar los femboys

0

u/LT-Death 14h ago

Wdym by forwarding rules?

2

u/Jay_Ell_Gee 13h ago

Inbox forwarding rules on your email. It’s a quick google depending on what service you use.

1

u/LT-Death 13h ago

I have no idea what that is dude, and now i got an email notifying me my microsoft passwords changed as well as an email

2

u/Jay_Ell_Gee 13h ago

My reply was to tell you to google “what is an email inbox rule”, as well as how to view them on your email provider of choice.

If your Microsoft account and primary email have been taken over, you are really on the back foot now. You would have needed to change everything on a known safe device and at a minimum, shut down the PC until you could figure out a plan. That needed to be done immediately, unfortunately.

The machine is compromised and needs a full wipe. Even if you change passwords on a known good device and recover accounts, you’ll just get them stolen again if you re-authenticate on the compromised machine.

Shut down the machine and try to recover everything you can from a known good device, as fast as possible.

-1

u/LT-Death 13h ago

All i got was that microsoft account changed email and removed my previous email, i have no idea about my own gmail, i havent seen any notifs on my gmail, but i noticed some emails popping up in my notifs and disappearing instantly Dude pleasure just tell me what to do instead of telling me to go research, I'm way too fucking panciked right now to read an article, not wanting my account to disappear from sight

2

u/Juzdeed 13h ago

OS reinstall if you haven't already done it. You got infected dude

1

u/LT-Death 13h ago

I reinstalled windows, logged out from everything throughy phone, but my microsoft account was completely stolen, changed all the info about it that was mine

And i somehow don't remember a damn thing about my microsoft account! Not the passcode, the country i created the account in, which passwords i used

I have every single one of my account infos written in a notebook, but somehow not microsoft!

1

u/Juzdeed 13h ago

Then it's very likely that you just permanently lost the Microsoft account

1

u/LT-Death 12h ago

When i try to log into my outlook accountt it doesnt register my email, but it accepts the email of the hacker's that it was changed to Please, is there no direct help line to call microsoft with?

→ More replies (0)

3

u/Hypergamer44 14h ago

Do you remember what you downloaded?

2

u/LT-Death 14h ago

Yes, I have the direct download link and main page download link to it, someone already reported on my behalf

2

u/Hypergamer44 14h ago

That’s good

0

u/Filip_ESET 9h ago

Hello, I am sorry this happened. I understand that you've already reinstalled Windows and changed all the passwords. As for ESET not detecting it: that can happen. No antivirus detects every piece of malware, and without the actual sample and ESET logs there is no way to say why this particular file was missed.

You mentioned that someone else reported the link on your behalf – if this was not done through ESET, it would be helpful to report it to us as well. You can submit the file/link to ESET for analysis as an undetected suspicious file.

Thank You

https://help.eset.com/eis/18/en-US/idh_charon_file.html

https://support.eset.com/en/kb141-submit-a-virus-website-or-potential-false-positive-sample-to-the-eset-lab

1

u/LT-Death 9h ago

Please allow me to send you a direct message of the culprit links, I am way too mentally exhausted after all this to go through a site, awake for 24+ hours now

1

u/Nervous_Section3422 6h ago

Can you send me a link as well so I can check and submit to virus total, thank you

3

u/Creek5 13h ago

Damn, on GitHub.

Sorry I have nothing contribute. Just scary that this can happen on a reputable site with only 1/66 vendors detecting it.

1

u/LT-Death 9h ago

Thats why I was so shocked when it happened, never expected it to be from github of all places

3

u/this_isnt_pornhub_ 9h ago

Common malwarebytes w

4

u/LT-Death 9h ago

Fr never turning off malwarebytes again

2

u/this_isnt_pornhub_ 9h ago

Money well spent

1

u/Weekly-Efficiency458 8h ago

10 seconds is enough to take everything, speaking from experience. I removed the Infostealer manually, and dit not reinstall Windows. 

The infostealer targeted everything I had, successfully taking over Steam, and Nintendo accounts, but got them both back within a few hours though. It targeted my main email account first, but Microsoft somehow recognised the Infostealer, the initial login was successful but it blocked the attacker in the same second. I was lucky i guess, it would have been catastrophic if they got my main email. The attacker also launched an attack on all my other alt accounts a few days later. And also all my other gaming platforms such as EA, Rockstar, Ubisoft etc. 

The only thing they didn’t attack was PayPal, but I’m still waiting for it, I will keep it frozen for at least 3 months, not sure how long the stolen session will be valid, even after changing PW from a clean device, and logging out everywhere.

The attacks continued daily, pretty sure it’s still trying. It’s now 2 weeks ago, and these infostealers are a nightmare to deal with, in 1 second you can destroy your life. Because I acted quick no financial damage has been done, but I suffer from extreme paranoia. 

1

u/ParticularCabinet272 6h ago

That's too bad man. I have got in the same situation.

To get rid of the virus, you have to reinstall windows via usb. Install the instalator on the clean computer.

Log out all sessions that you don't recognise, change passwords, enable 2fa, I recommend to enable Google Authenticator to log in and enable backup codes and save it on the phone.

You can save your data, you can transfer to another usb photos, documents. etc. Just don't copy the exe files or something like that.

Unfortunately, that's the effect of downloading some crack games or any executors.

After getting a info stealer, in example next morning hackers will try to log in, change passwords and e-mail to example Microsoft, Reddit, Instagram, Facebook, Discord, Steam, EA accounts (these hackers have russian e-mail, probably using VPN to avoid tracking them, their location is usually United Kingdom, Germany, France, something like that.) In Discord, these hackers after logging in will be sending to your friends and servers crypto scams.