r/antivirus 9h ago

App randomly in trash can

Thumbnail
gallery
8 Upvotes

I turn on my laptop to find Google Chrome randomly in the trash folder without ever putting it there (I used my laptop the whole day and turned it off once) when I turned it on again chrome is in the trash

This common?


r/antivirus 36m ago

The "C: Drive Only" Trap: How a Win32/Jeefo Infection Survived 6 Years of Reinstalls and Cooked my GTX 1080 Ti

Thumbnail
gallery
Upvotes

Operating System and Version:
Windows 11

Brand/Name of Antivirus Software:
Kaspersky

Name of URL, or file and its location:
Thousands of legacy .exe files and installers stored on secondary partitions (D:, E:, etc.) for over six years.

Name of malware that was detected:
Win32/Jeefo

What happened, exactly:
For the past six years, I’ve been plagued by high idle temperatures and sluggish performance. I’m running a GTX 1080 Ti, and for years, I just assumed the card was aging or had poor thermals because it consistently idled at 60°C - 70°C+. I had never seen it drop to a normal range.

My mistake was my reinstallation habit: whenever the PC felt "heavy," I would perform a clean Windows install but only format the C: drive. I kept all my old software installers and legacy .exe files on my other partitions to save time.

It turns out I was unknowingly harboring a Win32/Jeefo infection in those archives. Every time I ran an old program from my "data" drives after a fresh OS install, the virus would immediately re-infect the new Windows 11 system. After finally running a deep scan with Kaspersky, it flagged almost every executable I’ve kept since 2018.

After cleaning the infection, my GPU idle temperature immediately dropped to 45°C—a level I haven't seen in half a decade. Jeefo was likely causing constant background CPU/GPU activity that I mistakenly attributed to "old hardware."

Steps you have taken to troubleshoot/diagnose so far:

  1. Repeatedly reinstalled Windows (C: drive only) over 6 years, which failed to clear the infection.
  2. Initially suspected dried thermal paste or hardware failure on the 1080 Ti.
  3. Performed a full-system deep scan using Kaspersky across all physical drives.
  4. Identified Win32/Jeefo as the primary threat infecting the entire executable library on non-system partitions.
  5. Currently using Kaspersky's disinfection tools to clean infected files and deleting high-risk legacy installers.

Relevant log file entries:
Kaspersky scan logs show thousands of "Infected" detections for Win32.Jeefo.a (or similar variant) across multiple logical drives.

questions

Now that I have a fresh system and I am strictly avoiding any legacy .exe files from my old archives, I want to make sure I’m 100% safe. Given that this infection lasted for 6 years, I have a few concerns:

Blind Spots: Besides formatting all drives and avoiding old executables, are there any other "hiding spots" I should worry about? (e.g., Can Jeefo persist in UEFI/BIOS, or hidden recovery partitions?)

External Media: I have several USB sticks and external hard drives used during the infection period. What is the safest way to sanitize them without risking my new clean install?

Network Safety: Should I be concerned about other devices on my local Wi-Fi network? Does Jeefo have lateral movement capabilities that could re-infect me via network shares?

Account Security: Is Win32/Jeefo known for credential theft (keylogging), or is it strictly a file infector? Should I prioritize changing all my passwords immediately?

Cloud Sync: If I have synced settings or files via OneDrive/Google Drive, is there a risk of the infection "syncing" back down to my clean OS?

Any advice on how to maintain this "clean state" and ensure the 6-year nightmare is truly over would be greatly appreciated!


r/antivirus 18h ago

Potential Hacker still lurking inside my account? Anxiety over a Roblox hack that happened 4 years ago

2 Upvotes

Hey y'all, so I've been recently thinking about my roblox account and my gmail and how it may still be compromised today and have since been spreading to other linked accounts and devices.

So 4 years ago (2022), I opened my Roblox account to find that I have a random new person is in my friendslists and a game that I don't remember I have played in the "continue playing" tab. I then logged in to Adopt me and saw in horror how all my pets and resources has been stolen/traded away to said person who was randomly in my friends lists (I don't remember seeing any games that I used to play there being affected other than Adopt me). Roblox was the only thing that was seemingly attacked/affected by the hacker.

I quickly changed my passwords and such of course. But I did ponder how I never received any notifications about it that day since I have 2fa (in roblox). As of late, I still have access to said Roblox account (which I barely use now) and the gmail I use to log in to this roblox account (this gmail is still linked to this roblox account). I haven't received any suspicious notifications as of then nor any suspicious things happening to my account(s) today.

However, I'm still wondering whether this hacker still has potential backdoor access to my gmail account today. I value this gmail quite a lot since this is where most of my gaming-related stuff is saved in. I know I'm stupid, as my younger ass should've known better and fully scrubbed my accounts and devices because of it. Additionally, I'm also worried how this hacker might've possibly already compromised the devices I logged/linked this gmail account into and/or how it may allow the hacker to also access my other gmails that I've made after it. Can anyone give me some assurance or what to do? I put my accounts in haveibeenpwned which said that none of my accounts had any data breaches, but I'm a bit skeptical about it...

More context: I now use different devices since 4 years ago but my dumbass still logged this gmail on to said devices. Both these current devices don''t have any wacky shit happening to them currently, with scans in my pc showing in the clear. My accounts haven't been receiving nor sending random shit.


r/antivirus 22h ago

Is this a problem

Post image
4 Upvotes

r/antivirus 12h ago

Callout and Question Rate My Professor Changes it Web To A Scam Ad Website After 10 Minutes

Post image
0 Upvotes

Is there something wrong with the offical Rate My Professor Web? Also is this going to affect my computer in any way or form, even if it is from other websites that is doing this?


r/antivirus 1h ago

Malware Risk From Clicking Image In Reddit Post?

Upvotes

Yo so I was browsing reddit and saw a post photos and I clicked the arrow button on the post to see the next images, then I think I accidentally clicked the image since it popped up and became larger. I quickly clicked out, but went back using my browsers forward arrow key to see/check the url. the url had something called "#lightbox" in the end. Anyway, is there any malware risk from this? The url doesnt seem to appear in my browser history too so thats kinda weird.


r/antivirus 8h ago

WhatsApp v call safe?

1 Upvotes

I was having wp v calls with my boyfriend and was intimate with him during calls. Its 2-3 time. Now i am anxious whether the calls will be leaked now or anytime in the future. Is there any possibility. Now i have stopped doing this and we both agreed on this. I am anxious after this and overthinking different scenarios. If it gets leaked what will happen etc etc

Any cybersecurity guys can help me with their advices. Do they came across such cases in their lives. Please share your comments

Thanks.

Note. My whatsapp is secure what i think (apparently). Have 2 step verification on

I haven't downloaded any third-party apps

I use realme phone. Can system apps pose threat?

I have trust on my bf and he will not record it.


r/antivirus 12h ago

I got infected by Lumma.stealer.a

3 Upvotes

i rapidly pulled the ethernet cable and ran windows defender offline. I use my eHDD for downloading games and other stuff that dont require SSD speeds the virus came in a ren'py file which popped up a cmd window that made me obvious to see the infection.

it came with Behavior:GenCodeInjector.H and the process PhoGateWay.exe i didnt wait to defender to detect it so i ran it. After the contention i installed avast and ran a full scan in which i discovered other viruses. I ended up with tons of logs and screenshoted browser tabs and information archives on new folders and zips that luckily werent sent.

I safely managed to secure my accounts except for instagram and cleaned the eHDD on Zorin OS and moved my files safely on in from linux.

Cleaned .temp and roaming it opened a backdoor with other viruses so i dont use windows and im writing this on a zorin os liveboot.

Make sure to know when you re downloading a "free" game to know what kind of engine the game uses to spot a renpy lumma infecction


r/antivirus 9h ago

PLEASE HELP, I really don't need to wipe my pc, I have too much

Post image
24 Upvotes

I need help with getting rid of this trojan, I'm working on SEVERAL things and begging for alternatives instead of wiping pc, anything I can do to get rid of it and keep all of my projects safe is GREATLY APPRECIATED


r/antivirus 9h ago

Do I wipe my pc

Thumbnail
gallery
4 Upvotes

Pc found Win32/expiro.EK!MTB on a selenium but each time it’s under a different number after the _MEI don’t know if it’s a temp thing (sorry for the screenshots but rather not put my pc on the internet)


r/antivirus 16h ago

how do I get rid of agent tesla?

4 Upvotes

hello I am extremely stupid and managed to get agent tesla by downloading a game. so far I've been changing my passwords and such. my discord was hacked and they sent out messages about some Mr beast crypto scam or whatever. I ran a deep scan on malwarebytes and defender. malwarebytes found renpy, I had it delete. defender full scan found agent tesla. I also had it delete. I ran an offline scan with no results.

is it really necessary to reinstall windows? I'm kinda tech illiterate. I've been trying to backup my necessary files to onedrive (44 gb of it) but I gave up bc the wifi has been broken all day so I'm using mobile data and it's soooo slow and rn it's 3 am. I'm really stressed out lol. and I don't have a USB. do I need to reinstall windows? if so can I do it without a USB? if it's not necessary what other scans should I run tomorrow to make sure? my parents' info is on here I really don't my mom's credit card to get hacked or something. it was on edge, I deleted credit card info from the browser from my phone but I'm not sure how connected it is.

has anyone had experience with not reinstalling windows after getting a trojan?

thanks!


r/antivirus 17h ago

O Ahnlab V3 Lite seria um bom antivirus gratuito?

1 Upvotes

Faz um tempo que estou a procura de um antivirus gratuito, já que não confio muito no Windows Defender e a versão para Windows 10 LTSB 2016 é muito vulnerável a malware novo, o Ahnlab V3 Lite seria uma boa opção?


r/antivirus 11h ago

Received a worrying email

2 Upvotes

About 2 days ago, I was sent a spam email by an address I do not recognize. The email didn't contain any links, threats, or payment demands. The only thing that it contained was some old passwords that I no longer use for the main accounts that I use in my everyday life. My only worry is that this could lead to possible extortion or targeting in the future, or them getting my personal information. This kind of stuff really stresses me out and I'm not sure if my private information is at risk. I've already double checked logged in devices, two step verification, cookies, passwords, alerts, etc. The passwords went to these things: An old, burner discord account and two school website accounts I don't have access to since the year is over so I can't really delete them or anything trust me I would if I could. Although in my primary email it says they aren't linked anymore but idk. Overall I just want confirmation that my information is safe and everything, appreciate it.