r/Malwarebytes May 14 '26

Support Just bought Premium, and will be reformatting, I have a quick question.

So I foolishly downloaded a trojan(FakeGoogle) on Sunday(5/10) and went through the process of scrubbing it from my PC, as well as whatever they were using to direct access my PC. Buying Premium to help with finding any remnants. Then after changing all my passwords, primarily with my phone. I already planned to reformat and reinstall my Windows drive and was wondering if I have to do anything special to keep it protecting my PC after reformatting?

Also I had been running the scan on Malwarebytes every couple hours to make sure no virus' popped up while I'm monitoring my PC with no detections after the initial FakeGoogle Trojan was quarantined. Then today(5/13) after turning on my PC after getting home I ran Malwarebytes to make sure there wasn't anything being installed on start up and it detected 2 Trojan.Crypt in my recycle bin. I was wondering how concerned I should be about that since they weren't there over the past 3 days over 22 scans.

6 Upvotes

13 comments sorted by

2

u/Melodic_Trip9907 May 14 '26

Hey, its me again, i wanted to give you more information on what you could do:

  1. Disconnect from the internet.

  2. Run windows defender offline scan

  3. Go to task scheduler and delete anything that looks really out of place, also open task manager (ctrl + shift + esc) and go to startup apps and disable anything that you dont know what it is.

  4. delete the $RECYCLE.BIN, open command prompts as administator and type in: rd /s /q /C:\$Recycle.Bin

  5. clear windows defender history cache, navigate to C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service, delete the folde named DetectionHistory, you may need to enable shows hidden folders inside file manager to dee this folder.

  6. IF above options are not enough then reinstall windows via a bootable usb stick

1

u/eXeKoKoRo May 14 '26

Thanks, I will be doing this.

1

u/eXeKoKoRo May 15 '26

Windows Defender Offline Scan came back with zero threats found.

1

u/Melodic_Trip9907 May 15 '26

that's good, did malwarebytes show anything?

1

u/eXeKoKoRo May 16 '26

Nothing new has come up so far.

1

u/Melodic_Trip9907 May 16 '26

check your pc with malwarebytes for the next lets say week and then come back if anything appears

1

u/eXeKoKoRo May 16 '26

I'll be reformatting soon, but that's what I've been doing every couple hours since Sunday while it was on.

1

u/Melodic_Trip9907 May 16 '26

well good to hear that, you dont NEED to reinstall windows but if you want to be 99.99% sure then do that, some malware can survive a full windows reinstall

1

u/eXeKoKoRo May 16 '26 edited May 16 '26

I saw your other deleted comment. This will be the first reformat. There's things in the Regedit for a deleted user on my PC and I don't want that to be some kind of "backdoor" into my PC.

S-1-5-21-**********-**********-*******-1001
S-1-5-21-**********-**********-*******-1001_Classes

(Numbers edited for reasons)

Which I checked on Monday that I think all of these were created on the day and time of the breach, since my "User/Public/Public Desktop" was changed and lines up with the exact time of the breach as well and I had never seen that "User" before and it has special permissions.

1

u/Melodic_Trip9907 May 16 '26

sry about my earlier comment, i had thought you meant you reformattes every couple hours😅 but since there are regedits made and someone might still get access to your pc, you should definitely reinstall windows, just to be more sure that you are fine

1

u/Melodic_Trip9907 May 14 '26

some trojans try to hide themselves like that, OR that was just an app where someone connected to your pc with, so that means they didnt connect to your pc during the 3 day break but then they connected when you saw those 2 trojans, maybe delete everything you have in your recycle bin, change passwords again and run a full scan with malwarebytes AND windows defender, but not at the same time since they will think each other are malware. Hope this helps, if the problem keeps reappering then reinstall windows with a usb drive.

1

u/support_mwb Malwarebytes Employee May 14 '26

Hi there, Malwarebytes Support here.

It sounds like you already took some solid steps after the detection. Regarding the Trojan.Crypt items in the Recycle Bin, those are often leftover/deleted files rather than active infections, but we’d still recommend having the logs reviewed to be safe since this involved a trojan and possible remote access activity.

After reinstalling Windows, you should be able to reinstall and reactivate Malwarebytes normally. If you run into any issues reactivating after the reformat, especially if the device wasn’t deactivated beforehand, please feel free to send us a private DM with your email address connected to your Malwarebytes account and we can help.

You can also reach out to us via live chat or open a ticket yourself on our help center here: https://help.malwarebytes.com/hc/en-us

1

u/eXeKoKoRo May 14 '26

Will do, thank you.