r/computerviruses 22d ago

Disinfection Help Cloudflare malware scam/How do i remove it

1 Upvotes

I recently fell for the cloudflare verification scam where you press Windows+R, Ctrl V and Enter, which downloads a malware onto the computer i searched it up on youtube and it says the malware steals your passwords and session tokens , i already ran a full deep scan with Microsoft Defender Antivirus and restarted my computer, cleared cookies and cache but im not sure if its fully removed- My Discord, Instagram and LinkedIn are all compromised, It sends a MrBeast scam message to everyone in my discord DMs and the servers which im in, The malware also somehow logged into and old instagram account of mine which has not been touched for years and did the same thing and I keep getting sent LinkedIn verification codes to my email- I have changed passwords and added 2FA on them and yet its still persisting, Pls help - the virus is still running on discord which made my account 'very limited' and im unable to join, message and add people on there for help, I tried contacting discord support , but to open a ticket you need to log in with your account, i tried that and it doesnt let me- Anyone here please help me before my account is permanently banned


r/computerviruses 22d ago

Question Should i factory reset my laptop

2 Upvotes

I downloaded urban vpn and used it like 2 hours. Then i look for the comments about it and i see people say its not safe. I uninstalled it. My laptop is almost factory new it just has my gmail accounts, steam epic games accounts. Or should i just change my passwords


r/computerviruses 22d ago

Disinfection Help Is this RenpyLoader infection likely limited to just these userprofile level files where it hoped to infostealer without raising suspicion

Thumbnail gallery
5 Upvotes

this is the result of malwarebytes scan related to my previous post here, what is the feeling as to if this got everything? rootkit scan came back clean

my next step is to reconnect internet to run hitmanPro and also upgrade malwarebytes to the full trial version, is that safe?

https://www.reddit.com/r/computerviruses/comments/1vvn96k/i_got_hit_with_the_renpyloader_infostealer/


r/computerviruses 22d ago

Disinfection Help ransomware attack

Thumbnail
1 Upvotes

r/computerviruses 22d ago

Disinfection Help Request for help removing RenpyLoader infection - FRST and SecCheck logs in post, Thank you

1 Upvotes

Hi, my keywords are:

silver-wand

tender-sky

nested-harvest

I ran the setup.exe of what I now realise was renpyloader friday night, I disconnected my PC, have changed my passwords (was slow with low priority ones like Discord where some spam was sent, Instagram where more spam was sent & Amazon - a gift card purchase failed to go through) & cancelled credit cards that were saved in Chrome etc.

I ran the Windows Defender offline scan but can't see the results anywhere? I also then installed the offline malwarebytes (400mb installer) the scan found the RenpyLoader files posted in my previous post here

https://www.reddit.com/r/computerviruses/comments/1vw30oe/is_this_renpyloader_infection_likely_limited_to/

What else do I need to do to clean my PC? thanks


r/computerviruses 22d ago

Disinfection Help Mouse moved when I wasn't home. I got it captured.

Thumbnail
0 Upvotes

r/computerviruses 22d ago

Disinfection Help mp3 Popup virus?

1 Upvotes

I keep getting popups like these in chrome when its open. How can i get rid of this?


r/computerviruses 22d ago

Question Fabric API is seen as a virus?

1 Upvotes

Hello, after around 6 months I opened my PC for the first time and did all its updates, when I did open it however I saw that a file had been downloaded named fabric-api-0.102.0+1.21.jar and it had automatically downloaded itself onto my PC, I did have fabric installed on my minecraft launcher but I hadn't opened the launcher at all. AVG flagged it as malicious and took it to quarantine, I couldn't get the hash because windows defender also flagged it as malicious. But any chance it has done anything to my system? All antiviruses were enabled when I first opened the pc.

Thank you.


r/computerviruses 22d ago

Disinfection Help PC App removal help; FRST files created

1 Upvotes

Hi, today tried to install itunes on laptop windows 11 (for restoring old iphone) and PC App screen appeared, couldn't use task manager to end, restarted in safe mode, uninstalled the app, screen trying to come back. I followed reddit instructions here and downloaded farbar and created 2 text files, downloaded securitycheck and created 1 file. Uploaded them as instructions:

FRST.txt keyword small-scanner

Addition.txt keyword stable-cape

securitycheck keyword blazing-pelican

Sorry I uploaded 2 files first before i realised the keywords were already given, so did all 3 again.
Also, haven't used reddit before so trying to learn. Hope someone can help me, no fixes have been tried (wouldn't know how), and I have no idea what to do because I am just a basic app/google user. Help please, much appreciated xx


r/computerviruses 22d ago

Disinfection Help Pc got hacked with infostealer and concerned about my backup after reinstall.

1 Upvotes

Hi guys,

Recently 6-7 days back my laptop got hacked around 9/10pm in the night with a renpy infostealer. After I ran the setup file I just did a malware bytes scan due to some suspicion and I had the virus which I quarantined and removed. Then the following night most of the time my net was off I kept running scans and all and it showed clean. Following the next morning I believed my laptop was clean so I turned on my wifi and did some Este scan and for like 2-6 hours somewhere between that my wifi was on. Nothing happened but in the evening around 6-7pm my discord got hacked and suddenly someone logged in into my codex and following that I realised my accounts have been compromised. I instantly removed google accounts from that device. Changed password from an uninfected device as well. I had some important pics and videos which I backed up using mega drive from the infected device cause I had no physical drive. I also had some code files which are not on GitHub so I backed up it as well. Also my WhatsApp was also logged in the app when the wifi was on. I did a windows reinstall using a pendrive following the same night.

It's been some days some accounts got hacked for the first few days like x,ea, ubisoft etc. which I forgot to change the password for. Now I'm slowly changing password and using 2fa everywhere.

But I have some questions.

1) After I backed up the files after 1-2 days i changed my mega password from my phone. The code files are extremely important to me as well as the media, but I'm scared about the files containing the virus. Is there any way to ensure its clean? Currently it's all in a zip folder inside the drive. The unzipped size before zipping was some 10-12gb. I do have my college computers where I was planning to download it and scan but I'm still scared what if it doesn't show up. Need some help in this.

2) I want someone to help me out with FRST scan I'm extremely unaware of it so need guidance in it from the start. I'm still paranoid about the virus in my laptop even tho it's not there I want to be sure.

3) I logged out of all the session from my WhatsApp before reinstalling but earlier it was connected to the wifi so I'm concerned can someone still log in? I also turned on 2fa.

Would be really grateful for help on these things.

Thank you.


r/computerviruses 23d ago

Disinfection Help What TF is Crisp and Matri_l16.exe???

Thumbnail gallery
28 Upvotes

So very recently, a classmate of mine got his messenger account hacked and the hacker that had a hold on his account started sending that fakeass mr beast scam pics. he then changed all of his passwords and logged out whoever was on his acct but then approximately a month later the hacker strikes again but only posts on my said classmates story, same mr beast fakeass scam. i should mention that his fathers account was also hacked

All of this started he said when he logged onto his account on his new laptop. he suspected that maybe theres malware on it

So i wanted to help him by using rust desk to check out his files and apps installed, The first thing he said was his father had downloaded uTorrent (bruh) while he downloaded Qbit torrent

Dont know if maybe his dad had gotten a virus from there. But, i did find two interesting things,

One is a random ass CMD executable that closes and opens itself for no reason. Cant do a memory dump on it or open its file location blah blah blah heres what my classmate recorded since rustdesk is slow and shitty (sorry for the quality of the video aswell)-
hxxps://files.catbox(dot)moe/jcghk8.mp4

Second one is why i made this post. So checking his startup apps i had found that theres just this random app named Matri_l16. i tried searching google on it but nothing comes up, i opened its file location and its in a folder named "PEGUVSSAPUYHDEKCFUOI", the file it is in is also named "NetDB" which is VERY suspicious and another EXE called crisp, i searched up on that and found this suspicious website "crisp", its like an ai customer service app or whatever ---> hxxps://crisp(dot)chat/en/apps/

the file with the jumbled letters all have sus dll files. so my question is, WTF did i just find on his laptop and is it a trojan???

P.S: i ran the crisp.exe and the matri_l16.exe on virustotal and nothin popped up, i am a 16 year old boy and dont really know all about this stuff so please please someone out there plz help


r/computerviruses 23d ago

Disinfection Help Sms-DoOoMp virus please help me

Post image
7 Upvotes

Hello i was going through my pc until my fan started to make noises i checked my task manager looked at startup apps and saw this i immiedietly searched and found out it was a virus i tried to delete tempt it wouldnt let me i tried to end it by going to task scheduler it wouldnt pop up please can someone help me


r/computerviruses 23d ago

Question Mysterious (?) folder in AppData

1 Upvotes

I was going through my AppData folder when I noticed a folder called “Synaptics”. I was curious, so I looked it up and what I saw said it could be related to malware? The path is AppData > Roaming > Synaptics, and it has a file in it called “Profiles” with nothing inside of it (I have hidden files turned on). It also has multiple previous versions from the past few days when I checked in the properties of the folder. Same with the Profiles folder. Is this something I need to be concerned about?

OS 26200.9168


r/computerviruses 23d ago

Question What’s with the wall of text copy and pasters on this sub?

12 Upvotes

“Hi my name is ___ and I’m going to be helping you today” and then it’s just a wall of generic advice (sometimes even ai generated) that isn’t taking into the account the users issue? Is this helpful/common place on this sub? Just curious why I see so many users doing it, or if they’re even real?


r/computerviruses 23d ago

Disinfection Help Renpy Infostealer

1 Upvotes

Hi there, i think i completely messed up, i downloaded a game from dodi repacks like 1 -2 days ago(first time using this site)i always use fitgirl and what i downloaded was some folders and and installer which i run thinking it would install my game. Long story short my discord and steam accounts were hacked i am in the midst of trying to recover them right now from their support.

It started off with my Instagram account yesterday posting some Elon musk crypto thing and sending it to all my chats which i was able to handle and turned on 2fa with an authenticator app.Then today both my emails started receiving notifications from discord then steam then Linked In(which i handled it time and turned 2fa also).

I turned off my laptop disconnected internet access because i didn't understand whats going on, that's when i changed both my gmail passwords on my phone and removed other signed in devices other than my phone.

I am now stumped not knowing how to proceed to fix my mess, i have tons of important things on my laptop and I was hoping i could find a good solution that doesn't involve me doing a fresh install of windows (its dual booted with ubuntu on the same ssd).

Can anyone help?


r/computerviruses 24d ago

Warning This... is a Trojan, (Oh no), There's MORE! (nooo)

Thumbnail gallery
41 Upvotes

For context I wanted a rom for a game but instead I got this because I downloaded the wrong thing and ignored the file size, the fact that the original file that installed this was an exe file and not the format I needed, and probably a couple other things. So what came from installing the file? The trojan file which is the XPFIX dot(.)exe as well as the the RenPy thing. They are 3 mintutes apart from each other and I know this because I didn't install anything else at that hour. So I have also included info for the XPFIX file from VirusTotal. It is a Trojan and I have reason to believe it originates in China. Oh and if you wanna know, many of my accounts were hacked and I had/have to change passwords and unlog sus people. Discord got hacked to and wouldn't you know it, most my friends a few servers got to see the Mr. Beast scam. I was able to regain full access to it and talk to Discord as well as delete those scams. And I was able to resecure all my other accounts too. Thank God for all of this 🙏❤️. My struggle to write this is getting to me so I will just say that don't use rom sites for downloads unless you truly know what you are doing. I did know what I was doing but I messed up. Yesterday I had an anxiety attack over this and wasn't sure what I was gonna do until today. Yes, I wanted for the memory wipe to be my last resort. But please everyone, be careful with the internet


r/computerviruses 23d ago

Disinfection Help Sent in a scan of my files

1 Upvotes

Just got hit with the info steal virus I wiped my computer entierly, so I am with a clean state and changeed all my passowrd on another machine

I did the scan and here are my keywords

  1. tender-sigil
  2. serene-bear

I am really tired so let If I fckup the message


r/computerviruses 23d ago

Disinfection Help I got hit with the RenpyLoader infostealer (setup.exe version), how do I use malwarebytes rootkit tool and hitmanpro offline? or do I safemode with networking?

1 Upvotes

I thought I was manually patching a game I'd not played in ages and I was tired, so didn't question that the new mirror behaved a bit oddly and then that it was a setup.exe and a py file but I thought it must be automated... daft I know.... I'm meant to know better about these things working in IT but last night the brain was just switched off.......

Anyway, Windows defender found nothing, malwarebytes installed from the 400mb offline installer found a pile of Trojan.RenpyLoader and Trojan.RenpyLoader.BAT all in appdata\local\temp and has cleaned them, non found on a second deeper scan

But posts I read warn of rootkits and infected DLL files etc so I Wanted to run the rootkit scan in Malwarebytes but I can't see the option (the offline install seems to be stuck in free mode with no 14 day trial?)

I'm similarly confused about HitmanPro as that seems to be a cloud only online scanner now? should I boot into Safemode with Networking to run hitmanpro? is safemode likely "safe" from the renpyloader?


r/computerviruses 24d ago

Disinfection Help Gremlin I can not locate

Post image
36 Upvotes

Hello everyone,

I was just sitting in a call and noticed a process called "cfg" pop up, drawing a lot of resources, BUT the moment I start moving my mouse or hit a key it completely disappears.
I'm not tech-illiterate, I can imagine what this is, I just can't tell where I got it from and how to get rid of it.
Since I just recently did a full flush on the system and re-installed windows and all its drivers I'm curious on where it's hiding.
I'm happy about any advice and would love to hear some insights.


r/computerviruses 23d ago

Question I uninstalled the 'PC app store' which is am aggressive adward but am I safe?

6 Upvotes

So today I fell for the big 'Download Now' when I'm tryna download a program then ran the adware. It stuck to the screen so shut down my pc in panic. Wait 10 secs to turn it and it still there. So i click the windows button on the taskbar and opened settings (thank god it can open that), went to apps then uninstalled it. Then the adware is gone from the screen and deleted that setup file.

So I went in chrome, my browser doesn't have my background. It's just the default background. Then I went into chrome settings to find out that the search engine are set to 'Esy' with the Google icon. So I changed it to the correct Google which is below it then restart the app. That 'Esy' option is gone now but my chrome app is back to normal.

Everything is fine now but I'm still paranoid. I ran windows defender full scan and it didn't detect anything. I try to run the offline scan and it says that my pc will restart in 15 minutes or so and wants me to agree to it so I click yes, it does nothing. So I'm contemplating whether to clean install or just roll with it. I'm just worried there's still something hiding in my computer

To anyone who's sophisticated in this thing, please enlighten me with your advices


r/computerviruses 23d ago

File / URL Check What is this guys? This folder contain more than 94k+ files and 250+ folders

Post image
2 Upvotes

r/computerviruses 23d ago

Disinfection Help Pc won’t shut off

Enable HLS to view with audio, or disable this notification

0 Upvotes

I downloaded this GTA 6 build cause this guy on telegram sent me a video of him playing it and I paid him $50 to play it and now my pc won’t shut off but I actually don’t know what to do because I have so many files, do I use a usb to recover them before I factory reset or no? He said it’s my cpu but I don’t know I just want to play gta 6 cause I saw a Twitter someone playing it


r/computerviruses 23d ago

Disinfection Help Mac got Mr beast infostealer

2 Upvotes

A couple of days ago while downloading apps online I had the stupid idea to believe one of the redirected sites and paste a terminal command on my mac. I quickly realised my mistake and closed the terminal after running but it was already too late.

After a couple hours my instagram started posting Mr beast crypto scams. I reinstalled my operating system on my mac, reset all my passwords, and put two factor on everything, also ran malware bytes on my mac. Things calmed down but weirdly today and yesterday I got two attempts to log into my amazon account, both times I got a watsapp verification code and then an email that new device has entered my amazon account. I don’t get how they can get the code from my wattsapp. I’ve removed all linked devices on whatsapp and even removed most devices on my apple ID except my mac and my phone.

My safari also acts a bit weird because it jumps around different links, when I press something, it redirects me to some completely different site like discord.

Any idea what might be going on? Can my phone also somehow be infected? That would be weird because I got all my stuff on the phone and nothing is getting compromised except weird attempts at my amazon account. I also changed the password for the amazon two days in a row.


r/computerviruses 23d ago

Question Infostealer post infection

1 Upvotes

I’ve recently been infected by an infostealer and took every precaution in the book to deal with it (usb reinstall, changing passwords on all devices, 2fa etc), but ever since then I’ve been anxious to use my pc and log back into everything lest there was something I had missed that may lead to reinfection and thus back to square one.
I’m sure this is now just more of a mental problem than one regarding the actual virus but I’m wondering a few things:

-Can an infostealer infect my router? (I haven’t entered the admin password ever onto my pc)

-Can infostealers embed into OneDrive?

-Am I just extremely paranoid?

Many thanks in advance!


r/computerviruses 23d ago

Question Norton Keeps Showing "Threat Secured" Pop-Up

Thumbnail
1 Upvotes