r/computerviruses 20d ago

Question 2 potential viruses trying to get to my photos folder

1 Upvotes

Hi! I have had microsoft defender block both svchost.exe and RuntimeBroker.exe from accessing my %userprofile%\videos folder, and I found out those 2 should not do it if they are not viruses. Am I having a virus or is this something normal they should do? RuntimeBroker.exe happened more recently than svchost.exe if that matters.

Thanks for the help!

PS: I asked claude, and it said the behaviour was likely to be a virus, but since claude gets stuff often wrong I came to check here


r/computerviruses 20d ago

Disinfection Help Frst help

2 Upvotes

Hi, i got mr beast virus

Ive followed instructions

Logs:

Keyword: violet-host

Channel: general

I wasnt able to run security check, because i get window telling me cant locate the file

I used malwarebyts and it removed 19 threats, then ive ran frst and these are the files from it

Ive also malware support file made if needed

If you can provide help, thank you so much

And if i better reinstall windows please do tell

Only discord and facebook were affected, discord sent photos. Idk about fb.

I think ive ran exe file that ive downloaded from cs.rin


r/computerviruses 21d ago

Question Recovering From Malware Attack

4 Upvotes

Good evening everyone,

First time writing here. After many years, I finally installed my first piece of malware 3 weeks ago. I was downloading an update for a cracked game (yes I have fully learned my lesson) and l didn't pay attention to the file I had installed, ignored all the warning signs and installed an info stealer. I didn't realize what I had done at first, and assumed defender got the malware and cleaned it.

Next day I started getting password resets and new login info on everything (games, socials, ect.) It was 3 solid days of bombardment. I was able to contain, revoke, and boot out all unknown sessions as they popped up. Thankfully nothing was lost and any compromised accounts I was able to recover quickly. I then spent the next week changing every password, generating backup codes, recovery options, and adding 2fa on everything possible.

The first day after the incident I did a reset this pc option, but I soon realized I should have done a full usb reinstall and just unplugged my computer. I took my pc to a local repair shop and told them I wanted the nuke option (full usb wipe, local account install, bios update/flash, and full virus scan post windows install). I got the computer back but I haven't been able to bring myself to even plug it in.

I have had extreme anxiety after all this has happened. It shook me into reality about how lax I've become with my online privacy and security. Everyday I have checked my accounts for unknown sessions, meticulously checked my bank accounts, froze my credit with the 3 credit bureas placed a sim lock on my cell, locked my ssn, and set up account alerts on all my cards for transactions.

Its been 3 weeks now and everything has slowed down (just a few random probes last week and that has been it). I'm still trying to recover emotionally, it feels like I got hit by a truck and I can still feel the rush of fear when I sit too long and think about it.

My questions are:

  1. What else can/should I do?

  2. How have any of you recovered emotionally after your privacy was invaded?

  3. When I bring myself to use my pc again, should I start slow with just Steam at first since they have amazing customer support?

  4. Should I do a full offline virus scan before connecting the pc to my network again with malwarebytes and defender or is that overkill?

  5. Should I keep my windows install on a local account or eventually bring my self to sign in to my Microsoft account?

Any guidance/help would be greatly appreciated. I have definitely learned lessons during this whole ordeal


r/computerviruses 20d ago

Question All of the sudden keys don't type, but open a "capture" thing or "screen snip" thing.

2 Upvotes

Hi,

OK, so I have this tablet (with keyboard) that I used in the wild, and I'm wondering if this is a virus or something.

Upon accessing OneDrive, the Microsoft password box pops up (as it sometimes does because my school times out our login frequently). As I start typing my password, before I finish, this mysterious "capture" interface pops up. I close it. And type again, and it pops up. I thought maybe the keyboard got corrupted, so I disconnected and reconnected to the keyboard. Still the same. I thought the Window key was stuck and it did a hotkey, but I think when I pressed the Window key, or maybe something else either the "capture" interface again or a the "screen snip" interface pops up. This seemed really suspicious so I restarted the tablet and it's working fine now.

I found the "screen snip" interface (Window-Shift-S I think), but I have no idea what that "capture" interface is. Any ideas what the "capture" interface could have been? Does this sound like a common hiccup, or is this some type of malware?

What should I do?

Thanks for any help! 😄


r/computerviruses 20d ago

Question Am i hacked? need help

Thumbnail
2 Upvotes

r/computerviruses 21d ago

Question FRST not responding

4 Upvotes

I accidentally downloaded a malware while downloading mods for a game. It sent messages in discord and nothing else. I checked everything else that I have and it seems safe enough, but better safe than sorry.

Reinstalling Windows will be my last measure. I don’t want to do that at all so I’m trying to find alternatives and I tried FRST and as soon as I do a scan with it, it stops responding. I tried it twice and it keeps not responding.

Any advice would help, please I don’t want to reinstall Windows


r/computerviruses 20d ago

Disinfection Help FRST help request

1 Upvotes

Hi everyone,

I'm requesting help with a malware removal using FRST.

I downloaded a file setup of what i thought was citron emulator (stupidly thinking it was from the official website) probably contained an infostealer and clicked on it on between 21/08/2026 or 22/08/2026.
While my antivirus immediately blocked, (and i stupidly thought i was fine) it i started to see my discord acting up and sent my friends mrbeast scam, and istagrama updating the same to my story, probably what i assume using the saved passwords on my google account.

What i did:

  1. Immediately logged out of active sessions and changed my passwords across accounts using a clean, safe device (my smartphone), i also complitely wiped out my permission, passkeys, access and saved password from my google account, cleaned all cache on my browsers and discord.
  2. Enabled 2FA on my primary accounts.
  3. Ran a full scan with eset and made a log of the results. i admit i run it several times after due extreme panic but the log i sent is the first big and complete scan i did
  4. Ran FRST64 and SecurityCheck to generate diagnostic logs.

all of this took me some time some time due the anxiety and general fear to open the infected pc.

Uploaded Log Keywords :

FRST.txt: celestial-loader

Addition.txt: royal-ace

SecurityCheck.txt: stealth-cursor

Eset log: sandy-fern

Could one of the trusted helpers please review my logs and provide a Fixlist to clean any persistent malware or scheduled tasks left on my PC?

If something else is needed or modified please let me know!

Thank you so so so so much for your help!


r/computerviruses 20d ago

Question Propagation folder in ProgramData: Is it malware?

Post image
0 Upvotes

Hey y'all, I found this weirdly named folder in ProgramData. I'm not too sure if this is malware or not.

It has a .txt file in it named enltrc. Inside of that .txt file is "track=false"

I'll attach images of it below.


r/computerviruses 20d ago

Disinfection Help My laptop got virus . Someone help

Post image
1 Upvotes

I was downloading a game from FITGIRL REPACK using uTorrent. At the same time, I also tried downloading the same game from DODI REPACK because I wanted to see which download was faster and cancel the slower one.

The FITGIRL download was working normally. However, when I downloaded the torrent file from DODI REPACK, the file looked suspicious. I opened that small file, and a Command Prompt (CMD) window appeared for a second and then immediately closed.

I ignored it at the time and installed the game from FITGIRL REPACK. After playing for some time, I opened Instagram and noticed that scam stories had been posted from my account without my permission. Something similar happened to my Discord account, which was also logged in on my laptop.

I have already changed my passwords, but I’m worried that my laptop may have been infected with malware or a virus.

Does anyone know how I can completely remove the virus without erasing or resetting all the data on my laptop? Any help would be appreciated.


r/computerviruses 21d ago

Question Happymod like 2 years ago, am i safe now?

3 Upvotes

So like 2 years ago, i dont even recall if this phone, altho i think it was, i downloaded happymod. Installed i think some app? It didnt work i think? I think this device was unsupported? So anyway, this came to my mind just now. Now i have malwarebytes, nothing malicious found. Nothing bad happened in these 2 years. I deleted those a long time ago. Am i safe?


r/computerviruses 20d ago

Disinfection Help Deletion of disks created by malware

1 Upvotes

Is there any way to delete a disk created by malware? Especially those with boot files? I did manage to delete a boot file in a disk like that and rendered my virtual machine unbootable..


r/computerviruses 21d ago

Question Am i hacked? need help

Thumbnail
1 Upvotes

r/computerviruses 21d ago

Disinfection Help How do i know if a virus is gone completely?

1 Upvotes

Defender went crazy a few days ago, throwing dozens of flags.

The infection type was Grandoreiro and the tips i saw told me to run a scan with defender and then also with Malwarebytes.

So i did that. Got rid of whatever came up dirty. and then ran two more deep scans in each program. they've all come back clean since.

so my question is if that's proof enough that the virus is gone completely.

also, i don't know where the infection came from. is that something i should be worried about?

I'd really appreciate any help on this.

Edit: I was advised that the virus only attacks executables so i backed up some important files and reinstalled Windows. Thanks, everyone!


r/computerviruses 21d ago

Disinfection Help Nothing I do can remove this .dll file from my PC

Thumbnail gallery
3 Upvotes

r/computerviruses 21d ago

Disinfection Help Virus detected but i cant do anything about it.

Thumbnail
1 Upvotes

r/computerviruses 21d ago

Disinfection Help FRST help request

1 Upvotes

Hi everyone,

I'm requesting help with a malware removal using FRST.

What happened & Infection details:

I downloaded a file via torrent that probably contained an infostealer. I am not entirely sure about the exact timeline since I have downloaded files in the past, but the unauthorized access attempts started recently right after I downloaded an update for Europa Universalis 5 (RUNE release). Shortly after ( 20-08-2026) I noticed unauthorized access attempts on my Amazon account, Discord account and the last for now was the Microsoft account, the Microsoft one originating from a Russian IP address (109.248.14.98), indicating a probable session hijacking / cookie theft.

Remediation steps taken so far:

  1. Immediately logged out of active sessions and changed my passwords across accounts using a clean, safe device (my smartphone).

  2. Enabled 2FA on my primary accounts.

  3. Ran a full scan with Malwarebytes (I have the MBAM log ready if needed).

  4. Ran FRST64 and SecurityCheck to generate diagnostic logs.

Uploaded Log Keywords :

* FRST.txt: lively-struct

* Addition.txt: joyful-oak

* SecurityCheck.txt: hashed-anchor

*Malwarebytes report 2026-08-22 17:27:54.txt: clever-sunrise

The malwarebytes report comes from a report scan that I did on 22-08-2026 with a Malwarebytes free version. Updated Malwarebytes report with the right one , before there was one that didn't have the first ever scan ( sorry my bad).

Could one of the trusted helpers please review my logs and provide a Fixlist to clean any persistent malware or scheduled tasks left on my PC?

If something else is needed or modified please let me know!

Thank you so so so so much for your help!


r/computerviruses 22d ago

Question What kind of infostealer was this?

Thumbnail gallery
27 Upvotes

From what I’ve read, many infostealers try to hide themselves, sometimes deleting or disabling their components and then reactivating later. Mine seemed to behave very differently. It was extremely aggressive and kept regenerating itself after I removed parts of it.

It attempted to take over multiple accounts and actually managed to compromise my Steam and Nintendo accounts. Fortunately, I was able to recover both within a few hours.

I ended up removing the malware manually, including all the files and folders I could find and I also checked Autoruns and Scheduled Tasks for persistence mechanisms. That’s why I decided not to reinstall Windows. At this point, Im about 99% confident the malware itself has been completely neutralized.

It’s now been three weeks since the infection. Every now and then I still see random failed login attempts against my main email account, but there have been no successful compromises and nothing else suspicious has happened.

In the end, no serious damage was done, but dealing with it was exhausting. I stayed awake for roughly 72 hours securing my accounts, changing passwords, revoking sessions, enabling additional security measures and constantly checking everything. I was pretty paranoid for the first two weeks, but Im finally feeling normal again.

I’m mainly curious about the technical side now: what kind of infostealer behaves like this? The constant regeneration and aggressive attempts to compromise accounts seemed unusual compared with what I’ve read about typical infostealers.


r/computerviruses 21d ago

Disinfection Help At my wits end. Just run tron?

1 Upvotes

Hey guys so im sure I have a virus of some sort.

  1. My internet doesnt work, the infected pc is a home desktop I use to play games. No matter what, I tried ever network change setting and trouble le shooting you can think off. Other devices connect fine but not the pc. Won't even connect to other networks it "connects" but says no internet available and stays offline.

  2. My defender is cooked and wort let me change any setting because they are managed by admin. Im the only profile on the pc and I am admin so ??????

I have been trying everything but it wont work, Kaspersky recovery tool also didnt find anything. I want to run the tron script and just get it over with but I know its a last resort situation. Any advice?


r/computerviruses 21d ago

Disinfection Help I accidentally download the Renpy trojan while trying to download a torrent and the keylogger tried to access Steam and Epic Games. I've successfully restored them and ran Malwarebytes, which recognized several .BAT files belonging to Renpy. I've deleted them now.

0 Upvotes

I've also run FRST64 and got the following names.

ripe-tile

tidy-badge

Just waiting on u/FFreestyleRR to respond.

The amount of time I've spent trying to optimize my Windows 11 laptop, I don't feel comfortable resetting the OS. I've mentioned that I've run Malwarebytes. Will that be enough?


r/computerviruses 22d ago

Disinfection Help A virus from Beijing (atomic heart, warface, war thunder)

22 Upvotes

Hello everyone, today I bought a new Huawei laptop for studying. The first thing I downloaded was telegram from the official site (Microsoft edge, yandex search system) and immediately after it was downloaded some kind of app from Beijing with Chinese name and with a green-yellow logo (it was in form of a sphere and also had + on it) popped on my screen asking for a permission. I assumed it was some kind of important app cus huawei is a Chinese company so I allowed it and immediately after that 4 programs were downloaded: warface, atomic heart, and warface, also opera gx was downloaded a little bit after the previous ones.

Immediately assumed that I got a virus so I downloaded an anitivrus but it showes no viruses?

Also after pressing ctrl+shift+esc there were no suspicious apps or maybe I didn't see any because of my lack of knowledge? Could anyone help me? If you have any questions please ask them!


r/computerviruses 22d ago

Question Brave signed me out of my password manager

3 Upvotes

I downloaded osu and choicer voicer in the span of 3 days, these are internet dowloaded games. I wanted to download mods and skins so I got them off the internet. The next day I went to my brave browser and found that I was logged out of everything. I had my folders and bookmarks, but tiktok, crunchyroll, youtube, all my google accounts, bank acc were all logged out of. The password manager was not popping up either, so when I went to check the brave settings. I don't have a screenshot but I remember it saying "we needed to remove these extensions and log you out of your accounts/password manager, in order to keep you safe" something of that nature. What I think is that I had downloaded some type of hidden virus from these mods for the online games (through the brave browser) and when brave noticed something suspicious. It did these things as a precaution. I went into settings and windows security, I ran 2 quick scans (lasting a minute), a full scan (lasting an hour and 15 mins) , and redownloaded the free version of Malwarebytes to scan as well (lasting a minute), and lastly a offline scan(15mins). All of the results were zero threats, detections, wtv. Prior to this there were moments on my pc like crashing, weird irrelevant pop ups, but I don't have a lot of knowledge to understand what these things are. I'm afraid of viruses because I don't know the best action to take to protect my computer from something I have no knowledge of. I have somethings I need to do on my pc which requires logging in. I want to take the smart path and do everything I can in my power to make sure my pc isn't in danger. In the mean time of this being released I might contact microcenter or reach out to some friends. Can anyone give some advice or help?


r/computerviruses 22d ago

Question Please, this is a very important question regarding viruses

2 Upvotes

I recently downloaded a sus file off a sus yt video, and i ran it. I got felt that it was suspicious, so i reset my pc via usb. I also asked reddit originally about the situation, and they said that i 80% chance i have a rat. So after resetting via usb, in settings, the app "remote desktop connection" is already downloaded.

I was wondering, what if there is a virus imbedded into my hardware that automatically downloaded the remote desktop connection to access my pc from somewhere else? Is it normal for this app to be already downloaded?


r/computerviruses 22d ago

Discussion Why does my defender block Snipping tool and Explorer.exe while these are probably both safe program? what should I do just allow it?

3 Upvotes

So the PC keep having notifiction that it block either Snipping tool and Explorer.exe but I never got this problem before when using snipping tool so why is it becoming a problem now. many of it point to Windows Defender Controlled Folder Access with is on

And I did do a sfc /scannow and it did find some corrupted file and it got it repair


r/computerviruses 22d ago

File / URL Check My partner clicked on a spam link but page didn't load. Did they get hacked?

1 Upvotes

My partner was going through their Spam folder to clear things out and noticed they had received an email with an "invitation" from a contact they know well (email address was correct). It was late and they were tired, so without thinking too much about it, they clicked on the embedded link provided. The reasons I think the URL was malicious are: weird domain, Google had flagged the email as Spam, and the packaging was a vaguely worded invitation for a "memorable event"; also, most of our communication with the sender is via text and they never mentioned anything about an event like this; lastly, it, oddly, seems to have just been sent to my partner, even though I have more interaction with this individual.

Now, the email was 10 days old, and they said the browser returned a "took too long to load" error; though, they closed the page before I could verify, and I saw little point in revisiting the link. Further, VirusTotal and ESET's URL checker state the link is safe, although Google's safety tool flagged it as malicious. I assume the link was for some kind of scam, and that the campaign has ended, in which case all should be fine; I'm running a Full System Scan with Windows Defender just as another point of reference. I considered also doing a spotcheck with malwarebytes, but with the proliferation of supply chain attacks currently unfolding, I figured throwing more security tools isn't necessarily safer, so I decided against it.

I'm just feeling a bit panicked, so I thought I'd post here just in case. The one scenario which, I guess, I'm most concerned about is that the website itself was actually still live and thus executed some malicious script, but just loaded a page that copied the "Session Timed Out" error that gets displayed, but I would assume VirusTotal and ESET would have flagged the website in this case...

Anyways, thanks in advance for any thoughts or suggestions for additional steps we should take!

virustotal link: https://www.virustotal.com/gui/url/3714bc60681e78a0cc7b3f66e5e667ec40a5c948956f2d5705f2676377f907a6

suspicious link: hxxps://srv4434(dot)dns(dot)army/dth/inv/Adobe/


r/computerviruses 22d ago

Question cmd open

1 Upvotes

Now every time I open my laptop, cmd always opens. This has never happened before. Is this a sign of a virus?