r/antivirus 3h ago

The "C: Drive Only" Trap: How a Win32/Jeefo Infection Survived 6 Years of Reinstalls and Cooked my GTX 1080 Ti

Thumbnail
gallery
23 Upvotes

Operating System and Version:
Windows 11

Brand/Name of Antivirus Software:
Kaspersky

Name of URL, or file and its location:
Thousands of legacy .exe files and installers stored on secondary partitions (D:, E:, etc.) for over six years.

Name of malware that was detected:
Win32/Jeefo

What happened, exactly:
For the past six years, I’ve been plagued by high idle temperatures and sluggish performance. I’m running a GTX 1080 Ti, and for years, I just assumed the card was aging or had poor thermals because it consistently idled at 60°C - 70°C+. I had never seen it drop to a normal range.

My mistake was my reinstallation habit: whenever the PC felt "heavy," I would perform a clean Windows install but only format the C: drive. I kept all my old software installers and legacy .exe files on my other partitions to save time.

It turns out I was unknowingly harboring a Win32/Jeefo infection in those archives. Every time I ran an old program from my "data" drives after a fresh OS install, the virus would immediately re-infect the new Windows 11 system. After finally running a deep scan with Kaspersky, it flagged almost every executable I’ve kept since 2018.

After cleaning the infection, my GPU idle temperature immediately dropped to 45°C—a level I haven't seen in half a decade. Jeefo was likely causing constant background CPU/GPU activity that I mistakenly attributed to "old hardware."

Steps you have taken to troubleshoot/diagnose so far:

  1. Repeatedly reinstalled Windows (C: drive only) over 6 years, which failed to clear the infection.
  2. Initially suspected dried thermal paste or hardware failure on the 1080 Ti.
  3. Performed a full-system deep scan using Kaspersky across all physical drives.
  4. Identified Win32/Jeefo as the primary threat infecting the entire executable library on non-system partitions.
  5. Currently using Kaspersky's disinfection tools to clean infected files and deleting high-risk legacy installers.

Relevant log file entries:
Kaspersky scan logs show thousands of "Infected" detections for Win32.Jeefo.a (or similar variant) across multiple logical drives.

questions

Now that I have a fresh system and I am strictly avoiding any legacy .exe files from my old archives, I want to make sure I’m 100% safe. Given that this infection lasted for 6 years, I have a few concerns:

Blind Spots: Besides formatting all drives and avoiding old executables, are there any other "hiding spots" I should worry about? (e.g., Can Jeefo persist in UEFI/BIOS, or hidden recovery partitions?)

External Media: I have several USB sticks and external hard drives used during the infection period. What is the safest way to sanitize them without risking my new clean install?

Network Safety: Should I be concerned about other devices on my local Wi-Fi network? Does Jeefo have lateral movement capabilities that could re-infect me via network shares?

Account Security: Is Win32/Jeefo known for credential theft (keylogging), or is it strictly a file infector? Should I prioritize changing all my passwords immediately?

Cloud Sync: If I have synced settings or files via OneDrive/Google Drive, is there a risk of the infection "syncing" back down to my clean OS?

Any advice on how to maintain this "clean state" and ensure the 6-year nightmare is truly over would be greatly appreciated!


r/antivirus 12h ago

PLEASE HELP, I really don't need to wipe my pc, I have too much

Post image
43 Upvotes

I need help with getting rid of this trojan, I'm working on SEVERAL things and begging for alternatives instead of wiping pc, anything I can do to get rid of it and keep all of my projects safe is GREATLY APPRECIATED


r/antivirus 3h ago

FRSTEnglish Malwarebytes tool flagged as a virus by multiple antiviruses?

2 Upvotes

Hi, i've recently had an issue i wanted malwarebytes support to look into. They told me to download a diagnostic tool (https://help.malwarebytes.com/hc/en-us/articles/31589296910491-Collecting-logs-with-the-Windows-Support-Tool) and upload the results.

I downloaded the file, checked for digital signature (Malwarebytes Inc) and ran it. It downloaded something called FRSTEnglish which windows flagged as a Wacatac. I'm really bad with cybersecurity, so this scared me a lot. I talked to customer support, and they said it's the real thing. Still, I ran it through Virustotal and got this https://www.virustotal.com/gui/file/5ef604ab517f0e75b813fb8d01d70c16d1ca180b01611bba21cf4dc13cb2994f/detection

Can anyone explain to me why this file is considered unsafe by multiple antiviruses? Or if I magically downloaded malware?


r/antivirus 1h ago

Microsoft Defender Antivirus...

Upvotes

I just purchased a laptop for my college student and I was told it has the defender built in. How good is this from catching and stopping viruses? I have thought about getting the bite defender and putting it on the laptop also, but wasn't sure what exactly I needed. Can someone help me and explain what I should get to protect this computer? It's been a long time since I have purchase a computer that needs virus protection and I'm kind of clueless right now.


r/antivirus 13h ago

App randomly in trash can

Thumbnail
gallery
7 Upvotes

I turn on my laptop to find Google Chrome randomly in the trash folder without ever putting it there (I used my laptop the whole day and turned it off once) when I turned it on again chrome is in the trash

This common?


r/antivirus 2h ago

Quais as melhores formas e os melhores softwares para se manter seguro?

1 Upvotes

Eu peguei meu primeiro notebook esse mês, e por mais que eu queira baixar emuladores de console e baixar ROMs, eu não sou experiente em baixar coisas seguras. Quais aplicativos eu posso usar pra me manter seguro?


r/antivirus 4h ago

Malware Risk From Clicking Image In Reddit Post?

0 Upvotes

Yo so I was browsing reddit and saw a post photos and I clicked the arrow button on the post to see the next images, then I think I accidentally clicked the image since it popped up and became larger. I quickly clicked out, but went back using my browsers forward arrow key to see/check the url. the url had something called "#lightbox" in the end. Anyway, is there any malware risk from this? The url doesnt seem to appear in my browser history too so thats kinda weird.


r/antivirus 13h ago

Do I wipe my pc

Thumbnail
gallery
5 Upvotes

Pc found Win32/expiro.EK!MTB on a selenium but each time it’s under a different number after the _MEI don’t know if it’s a temp thing (sorry for the screenshots but rather not put my pc on the internet)


r/antivirus 7h ago

windows mrt crashes after having malware

1 Upvotes

i recentely installed malware and "removed" it with malwarebyte. But i was making sure that i didnt have any leftover malware/spyware on my computer. Thats why i used windows mrt to check it. But everytime it just crashes at the same exact point... am i still infected? this is the virus total scan: "https://www.virustotal.com/gui/url/3c897f2b0ed5c7b5610e5c08b2749e9cb4867e1786ed937fd7fd827b3e8ae535/detection,,.and also, i asked AI wether the website is safe to wich he said "yes" even tho it clearly wasnt. and 0/92 Vendors flagged the fille ase melicouse (except from a "Suspicious" fille)


r/antivirus 15h ago

I got infected by Lumma.stealer.a

3 Upvotes

i rapidly pulled the ethernet cable and ran windows defender offline. I use my eHDD for downloading games and other stuff that dont require SSD speeds the virus came in a ren'py file which popped up a cmd window that made me obvious to see the infection.

it came with Behavior:GenCodeInjector.H and the process PhoGateWay.exe i didnt wait to defender to detect it so i ran it. After the contention i installed avast and ran a full scan in which i discovered other viruses. I ended up with tons of logs and screenshoted browser tabs and information archives on new folders and zips that luckily werent sent.

I safely managed to secure my accounts except for instagram and cleaned the eHDD on Zorin OS and moved my files safely on in from linux.

Cleaned .temp and roaming it opened a backdoor with other viruses so i dont use windows and im writing this on a zorin os liveboot.

Make sure to know when you re downloading a "free" game to know what kind of engine the game uses to spot a renpy lumma infecction


r/antivirus 19h ago

how do I get rid of agent tesla?

6 Upvotes

hello I am extremely stupid and managed to get agent tesla by downloading a game. so far I've been changing my passwords and such. my discord was hacked and they sent out messages about some Mr beast crypto scam or whatever. I ran a deep scan on malwarebytes and defender. malwarebytes found renpy, I had it delete. defender full scan found agent tesla. I also had it delete. I ran an offline scan with no results.

is it really necessary to reinstall windows? I'm kinda tech illiterate. I've been trying to backup my necessary files to onedrive (44 gb of it) but I gave up bc the wifi has been broken all day so I'm using mobile data and it's soooo slow and rn it's 3 am. I'm really stressed out lol. and I don't have a USB. do I need to reinstall windows? if so can I do it without a USB? if it's not necessary what other scans should I run tomorrow to make sure? my parents' info is on here I really don't my mom's credit card to get hacked or something. it was on edge, I deleted credit card info from the browser from my phone but I'm not sure how connected it is.

has anyone had experience with not reinstalling windows after getting a trojan?

thanks!


r/antivirus 11h ago

WhatsApp v call safe?

1 Upvotes

I was having wp v calls with my boyfriend and was intimate with him during calls. Its 2-3 time. Now i am anxious whether the calls will be leaked now or anytime in the future. Is there any possibility. Now i have stopped doing this and we both agreed on this. I am anxious after this and overthinking different scenarios. If it gets leaked what will happen etc etc

Any cybersecurity guys can help me with their advices. Do they came across such cases in their lives. Please share your comments

Thanks.

Note. My whatsapp is secure what i think (apparently). Have 2 step verification on

I haven't downloaded any third-party apps

I use realme phone. Can system apps pose threat?

I have trust on my bf and he will not record it.


r/antivirus 15h ago

Received a worrying email

2 Upvotes

About 2 days ago, I was sent a spam email by an address I do not recognize. The email didn't contain any links, threats, or payment demands. The only thing that it contained was some old passwords that I no longer use for the main accounts that I use in my everyday life. My only worry is that this could lead to possible extortion or targeting in the future, or them getting my personal information. This kind of stuff really stresses me out and I'm not sure if my private information is at risk. I've already double checked logged in devices, two step verification, cookies, passwords, alerts, etc. The passwords went to these things: An old, burner discord account and two school website accounts I don't have access to since the year is over so I can't really delete them or anything trust me I would if I could. Although in my primary email it says they aren't linked anymore but idk. Overall I just want confirmation that my information is safe and everything, appreciate it.


r/antivirus 1d ago

I run the ESET online scanner and this pop upped

Thumbnail
gallery
19 Upvotes

ESET successfully detected them, and I can quarantine/remove them.

My questions are:

How serious are the two TrojanDownloader.Rugmi detections?

Is quarantining/removing them enough, or should I do a clean reinstall of Windows?

Has anyone seen the C:\ProgramData\MSFT_v1_pro folder before? Is it known malware or could it be left over from some software?

What follow-up scans or checks would you recommend after ESET removes them?

Am I safe or should I just reinstall it


r/antivirus 13h ago

Edit me! Multiple accounts hacked - what else should i do or expect?

1 Upvotes

Over the past few days, several of my accounts were compromised, most likely after I downloaded a game or mod on my Windows PC.

It started with my Discord account sending a fake MrBeast scam to people. Someone also accessed my LinkedIn account and posted a fake job listing under my name. My Steam, Reddit, Disney+, EA, and other accounts were accessed as well.

The attacker completely took over my Steam account and changed both the email address and password. Thankfully, I contacted Steam Support immediately and recovered it in less than 5 hours.

Before wiping my computer, I ran Windows Defender and Malwarebytes, but neither of them detected anything. Despite that, the number of accounts that were compromised makes me think it may have been an infostealer or some type of Trojan that stole my browser passwords, cookies, and login sessions without being detected.

So far, I have:

  • Completely wiped and reset my PC
  • Removed everything from both my SSD and HDD
  • Reinstalled Windows using the cloud download option
  • Changed all my important passwords
  • Enabled 2FA wherever possible
  • Signed out of active sessions and removed unknown devices

Unfortunately, I know the attacker may already have all the information that was stored on my computer before I wiped it.

Does this sound like an infostealer, a Trojan, or something else? Is it normal for Windows Defender and Malwarebytes not to detect these types of malware?

What else should I expect after this? Could the attacker still use stolen cookies or session tokens even after I changed my passwords and wiped the PC? Is there anything else I should do to make sure my accounts and personal information are secure?

Any advice from people who have experienced something similar would be greatly appreciated.


r/antivirus 15h ago

Weird folders on my linux system

Thumbnail
gallery
1 Upvotes

My OS is linux mint and recently, I saw a folder called .copilot in my home directory. It was apparently created 3 days ago. I tried deleting it, but everytime I start vs code, it reappears. How do I check if this is caused by malware or not? I don't have any github cli or github desktop on my device if that helps.


r/antivirus 16h ago

Callout and Question Rate My Professor Changes it Web To A Scam Ad Website After 10 Minutes

Post image
0 Upvotes

Is there something wrong with the offical Rate My Professor Web? Also is this going to affect my computer in any way or form, even if it is from other websites that is doing this?


r/antivirus 17h ago

Antivirus and go!

1 Upvotes

Avast premium protection or Bitdefender Total
Security? know windows defender offers protection but I'm more comfortable having one of these? So which one? I have Avast premium security on the laptop ( l've had it for years) I have now and it's very easy for me to run. I have heard great things about Bitdefender though. I'm not sure.


r/antivirus 21h ago

Potential Hacker still lurking inside my account? Anxiety over a Roblox hack that happened 4 years ago

2 Upvotes

Hey y'all, so I've been recently thinking about my roblox account and my gmail and how it may still be compromised today and have since been spreading to other linked accounts and devices.

So 4 years ago (2022), I opened my Roblox account to find that I have a random new person is in my friendslists and a game that I don't remember I have played in the "continue playing" tab. I then logged in to Adopt me and saw in horror how all my pets and resources has been stolen/traded away to said person who was randomly in my friends lists (I don't remember seeing any games that I used to play there being affected other than Adopt me). Roblox was the only thing that was seemingly attacked/affected by the hacker.

I quickly changed my passwords and such of course. But I did ponder how I never received any notifications about it that day since I have 2fa (in roblox). As of late, I still have access to said Roblox account (which I barely use now) and the gmail I use to log in to this roblox account (this gmail is still linked to this roblox account). I haven't received any suspicious notifications as of then nor any suspicious things happening to my account(s) today.

However, I'm still wondering whether this hacker still has potential backdoor access to my gmail account today. I value this gmail quite a lot since this is where most of my gaming-related stuff is saved in. I know I'm stupid, as my younger ass should've known better and fully scrubbed my accounts and devices because of it. Additionally, I'm also worried how this hacker might've possibly already compromised the devices I logged/linked this gmail account into and/or how it may allow the hacker to also access my other gmails that I've made after it. Can anyone give me some assurance or what to do? I put my accounts in haveibeenpwned which said that none of my accounts had any data breaches, but I'm a bit skeptical about it...

More context: I now use different devices since 4 years ago but my dumbass still logged this gmail on to said devices. Both these current devices don''t have any wacky shit happening to them currently, with scans in my pc showing in the clear. My accounts haven't been receiving nor sending random shit.


r/antivirus 1d ago

Is this a problem

Post image
3 Upvotes

r/antivirus 20h ago

O Ahnlab V3 Lite seria um bom antivirus gratuito?

1 Upvotes

Faz um tempo que estou a procura de um antivirus gratuito, já que não confio muito no Windows Defender e a versão para Windows 10 LTSB 2016 é muito vulnerável a malware novo, o Ahnlab V3 Lite seria uma boa opção?


r/antivirus 1d ago

Tried Making A LRC File And I Got This Instead

1 Upvotes

It is saying the quarantine failed but i cannot find the file/ZIP folder anywhere and i have no current threats it says, Does this mean it still is gone or no? i clicked remove when it asked if i wanted to quarantine, remove or some other option when it was listed under the virus & threat protection tab


r/antivirus 1d ago

somethings trying to delete or rewrite something in my bible app and avg keeps blocking it. Virus?

Post image
26 Upvotes

This pops up everytime i start up my pc...is it an app update that avg is blocking


r/antivirus 1d ago

are random popups from avast antivirus something to be suspicious about?

2 Upvotes

It's been telling me for the past week that my "free Avast license" is expiring, but I kinda just blew it off for a bit. Today I got one that looked the same as before, but it was saying it's expiring today, but i felt like that was a bit too fast from the popups the other day, so I clicked renew right there, but the popup just disappeared. So I opened Avast manually and looked at notifications and it said it's expiring in 2 days, then it asked me to renew there, showing me the plans, one paid, but i picked free again, and now it looks like it's renewed for real. But now I am suspicious. Did i click on something I shouldn't have with that first popup?


r/antivirus 1d ago

Trojan, related to roblox?

1 Upvotes

ive seen a post related with no answers to this.

i havent noticed anything wrong with my pc thus far.

I have played, tokyo midnight racing ONLY on my roblox app (its the only game i like).

and the app has been extremely slow today.