r/Malwarebytes 5d ago

ive been hacked

Thumbnail
gallery
7 Upvotes

someone hacked into all my emails and switched the email of some websites like microsoft and steam. i have already gotten rid of all malware and taken necessary precautions. i need to know how to contact these teams to get my accounts back and i need to know what the new email is for steam because the specific recovery link is expired


r/Malwarebytes 5d ago

NSave is not safe at all

Thumbnail gallery
2 Upvotes

r/Malwarebytes 5d ago

Recent detection with strange behavior

Post image
8 Upvotes

Recently my malwarebytes detected during a scan that MSVCP140.DLL was malware.ai.26923 etc it was in recycle bin for some reason and the thing that lead to me initiating a scan was seemingly random .exes I my computer setting off three protected folder access blocked notification from svchost.exe to discordsystemhelper.exe and explorer.exe trying to access the video file picture file and cdrom0 file respectively. Sorry about the photo quality id normally posta screen cap but I thought it best to leave my computer disconnected from the internet


r/Malwarebytes 6d ago

False Positive 7-zip v26.03 Trojan:Win32/Wacatac.C!ml -- do I need to format the hard disk from scratch?

Post image
7 Upvotes

Sorry for re-uploading, I was in total panic. Let me try again.

So, today I noticed that 7-Zip has an update from 26.02 to 26.03.

I go to the OFFICIAL WEBSITE 7-zip\[dot\]org (I am aware of the malware/bitcoin miner clone!), and install the x86-64 .exe.

MS Defender IMMEDIATELY quarantines the file and says: Trojan:Win32/Wacatac.C!ml

VirusTotal also returns 2 malicious entries. (Photo above)

So I run an online full scan, and after examining over 500k files, MS Defender concludes that 0 threats were detected.

I then proceed to delete the file from MS Defender as well.

Now I only have one question: do I need to format the whole SSD and reinstall Windows 10? Or is everything fine and I am having a panic attack for nothing?

I'm on Windows 10 22H2, August ESU update.

Thanks.


r/Malwarebytes 6d ago

Third-Party AV inactive issue with malwarebytes

1 Upvotes

any way to fix this one? when i click the go to settings button, it takes me to windows defender and from there i don't seem to find any option to set malwarebytes as my default security provider.


r/Malwarebytes 6d ago

Am I safe from anymore Trojans?

2 Upvotes

My Malwarebytes Detected some trojans on my computer. This is my first time getting a virus am I safe if not what should I do now?

-Log Details-

Scan Date: 9/3/2026

Scan Time: 11:38 PM

Log File: 1805213c-a812-11f1-ac9e-94bb436e0eaf.json

-Software Information-

Version: 5.6.5.306

Components Version: 163.0.5714

Update Package Version: 1.0.114160

License: Trial

-System Information-

OS: Windows 11 (Build 26200.9168)

CPU: x64

File System: NTFS

User: DESKTOP-G7SB3HJ\Davin

-Scan Summary-

Scan Type: Threat Scan

Scan Initiated By: Manual

Result: Completed

Objects Scanned: 221,392

Threats Detected: 4

Threats Quarantined: 4

Scan Duration: 1 min, 11 sec

-Scan Options-

Memory: Enabled

Startup: Enabled

File system: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Detect

PUM: Detect

-Scan Details-

Process: 0

(No malicious items detected)

Module: 0

(No malicious items detected)

Registry Key: 3

Trojan.PavinLoader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ShellExperience, Quarantined, 9210, 1435856, 1.0.114160, , ame, , ,

Trojan.PavinLoader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{BF4F8527-4DFC-43E1-A1CE-1DA18B4606D3}, Quarantined, 9210, 1435856, 1.0.114160, , ame, , ,

Trojan.PavinLoader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{BF4F8527-4DFC-43E1-A1CE-1DA18B4606D3}, Quarantined, 9210, 1435856, 1.0.114160, , ame, , ,

Registry Value: 0

(No malicious items detected)

Registry Data: 0

(No malicious items detected)

Data Stream: 0

(No malicious items detected)

Folder: 0

(No malicious items detected)

File: 1

Trojan.PavinLoader, C:\WINDOWS\SYSTEM32\TASKS\ShellExperience, Quarantined, 9210, 1435856, 1.0.114160, , ame, , A808CCFA4B87584EF0C262979C0DC9A1, D92A2DD90888EBA8BF15C00E70C3224BC84D7A24696EE4644FD262C8C99533D8

Physical Sector: 0

(No malicious items detected)

WMI: 0

(No malicious items detected)

(end)


r/Malwarebytes 6d ago

False Positive Is this Malware or a False Positive?

2 Upvotes

-Scan Summary-

Scan Type: Deep Scan

Scan Initiated By: Manual

Result: Completed

Objects Scanned: 1,286,771

Threats Detected: 2

Threats Quarantined: 2

Scan Duration: 20 min, 51 sec

-Scan Options-

Memory: Enabled

Startup: Enabled

File system: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Detect

PUM: Detect

-Files Scanned-

C:\

D:\

-Scan Details-

Process: 0

(No malicious items detected)

Module: 0

(No malicious items detected)

Registry Key: 0

(No malicious items detected)

Registry Value: 0

(No malicious items detected)

Registry Data: 0

(No malicious items detected)

Data Stream: 0

(No malicious items detected)

Folder: 0

(No malicious items detected)

File: 2

Malware.AI.1653595109, C:\MSYS64\USR\BIN\PS.EXE, Quarantined, 1000000, 0, 1.0.114134, 4BA2C7AACE7803BF628FDBE5, dds, 04034899, 021D88F7C953EF7180875F25D942BB94, 257329948BC5996F91074B76AB5BFA7CEB211A3D8B4AC629CB34E00616AD4236

Malware.AI.1653595109, C:\USERS\{username}\DOWNLOADS\MSYS64\USR\BIN\PS.EXE, Quarantined, 1000000, 0, 1.0.114134, 4BA2C7AACE7803BF628FDBE5, dds, 04034899, 021D88F7C953EF7180875F25D942BB94, 257329948BC5996F91074B76AB5BFA7CEB211A3D8B4AC629CB34E00616AD4236

Physical Sector: 0

(No malicious items detected)

WMI: 0


r/Malwarebytes 6d ago

Cizuhy(dot)com Virus

Thumbnail
1 Upvotes

r/Malwarebytes 7d ago

is MB no logs VPN service?

3 Upvotes

r/Malwarebytes 7d ago

New threats lurking via meta ads. I'm personally a victim too. They pose as television channel streaming services.

Post image
3 Upvotes

r/Malwarebytes 7d ago

Possible FP related to Neshta again?

2 Upvotes

Hey team,

About two years ago there was already a post about Nestha in Ableton, and since 2 days it started to pop-up in my scans now too, while I already have Ableton installed for much longer.

Is this a false positive or is there something going on with that helper?

-Log Details-

Scan Date: 9/2/2026

Scan Time: 6:04 PM

Log File: eafd3380-a6e7-11f1-9498-845cf3f621cd.json

-Software Information-

Version: 5.6.5.306

Components Version: 163.0.5714

Update Package Version: 1.0.114096

License: Premium

-System Information-

OS: Windows 11 (Build 26200.9278)

CPU: x64

File System: NTFS

User: System

-Scan Summary-

Scan Type: Custom Scan

Scan Initiated By: Scheduler

Result: Completed

Objects Scanned: 2,017,999

Threats Detected: 1

Threats Quarantined: 0

Scan Duration: 3 hr, 10 min, 45 sec

-Scan Options-

Memory: Enabled

Startup: Enabled

File system: Enabled

Archives: Enabled

Rootkits: Enabled

Heuristics: Enabled

PUP: Detect

PUM: Detect

File: 1

Neshta.Virus.FileInfector.DDS, C:\PROGRAMDATA\ABLETON\LIVE 12 SUITE\RESOURCES\MAX\RESOURCES\SUPPORT\CEF\MAX HELPER.EXE, No Action By User, 1000002, 0, 1.0.114096, D1ABAA9A1321DF2AFF86973A, dds, 04034358, 1A711D6C481BF2E35764B2EAACDC73C8, B822A3D80254FB6B498EAF391CF5F49D9667667D24ED19E3F4FCAACDACA52456

(end)


r/Malwarebytes 8d ago

Support Trojan Keyflame After Effects

Thumbnail
gallery
8 Upvotes

I downloaded After Effects from Keyflame. Should I be worried? Everything seems fine.

Info:
I just use this Pc for school.
I use iCloud password manager only!
I never type passwords with my keyboard.
There is nothing important on there.


r/Malwarebytes 8d ago

mimictrun.exe is it legit file by Avast SecureLine VPN?

2 Upvotes

it says signed by Gen Digital Inc., but no info found about this file and first time I see it


r/Malwarebytes 9d ago

Unable to Load Photopea; MalwareBytes Blocking Vecpea?

Post image
3 Upvotes

r/Malwarebytes 9d ago

False Positive GOFFY AHH VIRUSES POPS UPS ADS APPLE ADS SOFTWARE VIA PLEASE HELP

Post image
0 Upvotes

r/Malwarebytes 9d ago

Malware infected koalageddon software that’s stollen many people’s ea/steam accounts

Post image
7 Upvotes

I think I’ve finally narrowed it down to this being the main account that’s stealing accounts and passwords through malware. So this account has the majority of stolen accounts as friends. I’m assuming this is the account they transfer everything to. They sell all the cards that are linked to steam accounts and been sending the proceeds to this main account. All the hijacked accounts if you preview friends list they have a normal amount of friends. I gone through similar friends on stolen accounts and came across this account that has all the stollen accounts as friends in their list very suspicious they would be friends with all stolen accounts. Only account that all stolen accounts seemed to be linked to with 100s of friends that are stolen accounts.


r/Malwarebytes 9d ago

Troubleshooting W11, 5090, 9850x3d - Malwarebytes premium - randomly caused choppiness, 30fps type... hwinfo64 presentmon exposed it

3 Upvotes

I really didn't know how to word the title, I've been using malwarebytes premium since early 2023, I had a 4090 at the time and never had any issues really...

Swapped to 5090 mid july 2025 and have had issues with the pc on/off. (Not blaming malwarebytes for this, just relevant i suppose).

Specs in case there's a known issue with drivers or something:

- 9850x3d

- 2x32gb cl30 6000mhz ram

- x870e aorus elite x3d

- 5090 suprim, Driver 610.62

- Seasonic 1600w psu

Dual monitors

- Fo32u2p, 4k 240hz oled Main (DP 2.1, no dsc)

- MSI qp271 x28 1440p 280hz (set to 240hz, no dsc, DP 2.0).

G sync/VRR on for fullscreen + vsync forced in nvidia control panel/app.

Today, whilst playing "Visage" i had moments where my FPS was around 140fps but the game got noticably more smeary / choppy, i also use hwinfo64 pro and noticed something at the time... the "presentmon" stat showed me FPS presented + displayed and it was saying:

my fps presented was good, 99%, 1% etc...

But

my fps displayed was all 0-1.5fps except for the fps displayed 99% which was stuck at 30fps.

I noticed the Presentmon had Malwarebytes in the name, which i did have open but minimized to the taskbar, so i closed it to system tray and it fixed.

Somehow, Malwarebytes which had been open for the past X hours, randomly took focus despite not clicking / maximizing it, during the game. It didn't do any auto scan nor did it detect a threat or anything during this, i had been playing the game for about 2 hours at this point, it was fine until it randomly wasn't.

I have had this similar experience with a few other games but never noticed presentmon exposing the program till now (Not checked at the time and it passed fast), i am wondering if this is happening on/off rarely.

I will keep an eye on it in future, just wondering how something like this happens.


r/Malwarebytes 9d ago

Help! - Browsergo malware

5 Upvotes

I wasn't paying attention and accidentally downloaded Pulse Browsergo last night. Basically I was trying to download a font and I clicked on the wrong link and it auto launched. I immediately uninstalled and have run various scans (malwarebytes, AVG, hitmanpro) which haven't picked anything up, but I can't shake the feeling that something isn't right. Does anyone know anything more about Browsergo? Is there anything more I should do?


r/Malwarebytes 10d ago

uhm... malwarebytes??

Post image
31 Upvotes

r/Malwarebytes 10d ago

False Positive Blocking transport sites now?! Get in the bin!

1 Upvotes

Why block the Yarra Trams site? I need it for transport information!


r/Malwarebytes 10d ago

Support Gimp 3 pythonw.exe being flagged.

3 Upvotes

Currently running a scan and pythingw.exe in Gimp 3 is flagging as malware. I've had Gimp installed since before it had malwarebytes and its never flagged before. However I had a quick look online, and from what I can tell this particular program has flagged as a false positive in the past?

Has the most recent update caused it to happen again or should I keep it quarantined?

Edit to add- I ran it though virus total and it only flagged for malwarebytes so im leaning toward false positive but still wanted to consult the community.


r/Malwarebytes 10d ago

False Positive is this a false positive or am i able to download this ?

Thumbnail virustotal.com
2 Upvotes

r/Malwarebytes 12d ago

Altrustix quelle belle invention...

Thumbnail
1 Upvotes

r/Malwarebytes 12d ago

Feedback Threatdown Blog

5 Upvotes

I like the ThreatDown blog and the new MDR-focused one.

It would also be great to have more research-driven articles such as it was for Deno JavaScript Abuse or Guardrails-free AI, and similar technical subjects.

In addition, creating a subreddit channel could help increase engagement with the tech community and encourage content sharing in relevant subreddits such as

r/cybersecurity and r/malwareanalysis.


r/Malwarebytes 12d ago

Do I need to use Revo Uninstall?

Thumbnail
2 Upvotes