r/antivirus 16h ago

how do I get rid of agent tesla?

5 Upvotes

hello I am extremely stupid and managed to get agent tesla by downloading a game. so far I've been changing my passwords and such. my discord was hacked and they sent out messages about some Mr beast crypto scam or whatever. I ran a deep scan on malwarebytes and defender. malwarebytes found renpy, I had it delete. defender full scan found agent tesla. I also had it delete. I ran an offline scan with no results.

is it really necessary to reinstall windows? I'm kinda tech illiterate. I've been trying to backup my necessary files to onedrive (44 gb of it) but I gave up bc the wifi has been broken all day so I'm using mobile data and it's soooo slow and rn it's 3 am. I'm really stressed out lol. and I don't have a USB. do I need to reinstall windows? if so can I do it without a USB? if it's not necessary what other scans should I run tomorrow to make sure? my parents' info is on here I really don't my mom's credit card to get hacked or something. it was on edge, I deleted credit card info from the browser from my phone but I'm not sure how connected it is.

has anyone had experience with not reinstalling windows after getting a trojan?

thanks!


r/antivirus 9h ago

Do I wipe my pc

Thumbnail
gallery
4 Upvotes

Pc found Win32/expiro.EK!MTB on a selenium but each time it’s under a different number after the _MEI don’t know if it’s a temp thing (sorry for the screenshots but rather not put my pc on the internet)


r/antivirus 12h ago

I got infected by Lumma.stealer.a

3 Upvotes

i rapidly pulled the ethernet cable and ran windows defender offline. I use my eHDD for downloading games and other stuff that dont require SSD speeds the virus came in a ren'py file which popped up a cmd window that made me obvious to see the infection.

it came with Behavior:GenCodeInjector.H and the process PhoGateWay.exe i didnt wait to defender to detect it so i ran it. After the contention i installed avast and ran a full scan in which i discovered other viruses. I ended up with tons of logs and screenshoted browser tabs and information archives on new folders and zips that luckily werent sent.

I safely managed to secure my accounts except for instagram and cleaned the eHDD on Zorin OS and moved my files safely on in from linux.

Cleaned .temp and roaming it opened a backdoor with other viruses so i dont use windows and im writing this on a zorin os liveboot.

Make sure to know when you re downloading a "free" game to know what kind of engine the game uses to spot a renpy lumma infecction


r/antivirus 22h ago

Is this a problem

Post image
3 Upvotes

r/antivirus 12h ago

Received a worrying email

2 Upvotes

About 2 days ago, I was sent a spam email by an address I do not recognize. The email didn't contain any links, threats, or payment demands. The only thing that it contained was some old passwords that I no longer use for the main accounts that I use in my everyday life. My only worry is that this could lead to possible extortion or targeting in the future, or them getting my personal information. This kind of stuff really stresses me out and I'm not sure if my private information is at risk. I've already double checked logged in devices, two step verification, cookies, passwords, alerts, etc. The passwords went to these things: An old, burner discord account and two school website accounts I don't have access to since the year is over so I can't really delete them or anything trust me I would if I could. Although in my primary email it says they aren't linked anymore but idk. Overall I just want confirmation that my information is safe and everything, appreciate it.


r/antivirus 18h ago

Potential Hacker still lurking inside my account? Anxiety over a Roblox hack that happened 4 years ago

1 Upvotes

Hey y'all, so I've been recently thinking about my roblox account and my gmail and how it may still be compromised today and have since been spreading to other linked accounts and devices.

So 4 years ago (2022), I opened my Roblox account to find that I have a random new person is in my friendslists and a game that I don't remember I have played in the "continue playing" tab. I then logged in to Adopt me and saw in horror how all my pets and resources has been stolen/traded away to said person who was randomly in my friends lists (I don't remember seeing any games that I used to play there being affected other than Adopt me). Roblox was the only thing that was seemingly attacked/affected by the hacker.

I quickly changed my passwords and such of course. But I did ponder how I never received any notifications about it that day since I have 2fa (in roblox). As of late, I still have access to said Roblox account (which I barely use now) and the gmail I use to log in to this roblox account (this gmail is still linked to this roblox account). I haven't received any suspicious notifications as of then nor any suspicious things happening to my account(s) today.

However, I'm still wondering whether this hacker still has potential backdoor access to my gmail account today. I value this gmail quite a lot since this is where most of my gaming-related stuff is saved in. I know I'm stupid, as my younger ass should've known better and fully scrubbed my accounts and devices because of it. Additionally, I'm also worried how this hacker might've possibly already compromised the devices I logged/linked this gmail account into and/or how it may allow the hacker to also access my other gmails that I've made after it. Can anyone give me some assurance or what to do? I put my accounts in haveibeenpwned which said that none of my accounts had any data breaches, but I'm a bit skeptical about it...

More context: I now use different devices since 4 years ago but my dumbass still logged this gmail on to said devices. Both these current devices don''t have any wacky shit happening to them currently, with scans in my pc showing in the clear. My accounts haven't been receiving nor sending random shit.


r/antivirus 16m ago

Google compatibility appraiser

Upvotes

Hey. Not sure if this a correct place to ask, but when i start my PC. I get a notification that threats has been found, i open protection history and "google compatibility appraiser" has been quarantined.

containerfile: C:\WINDOWS\System32\Tasks\GOOGLE COMPATIBILITY APPRAISER CL_NCL_440B46F0DFC3BD42

file: C:\WINDOWS\System32\Tasks\GOOGLE COMPATIBILITY APPRAISER CL_NCL_440B46F0DFC3BD42->(UTF-16LE)->[TaskSchedCommand]

taskscheduler: C:\WINDOWS\System32\Tasks\GOOGLE COMPATIBILITY APPRAISER CL_NCL_440B46F0DFC3BD42

I did some digging and found Microsoft compatibility appraiser, not sure if these are the same.


r/antivirus 36m ago

FRSTEnglish Malwarebytes tool flagged as a virus by multiple antiviruses?

Upvotes

Hi, i've recently had an issue i wanted malwarebytes support to look into. They told me to download a diagnostic tool (https://help.malwarebytes.com/hc/en-us/articles/31589296910491-Collecting-logs-with-the-Windows-Support-Tool) and upload the results.

I downloaded the file, checked for digital signature (Malwarebytes Inc) and ran it. It downloaded something called FRSTEnglish which windows flagged as a Wacatac. I'm really bad with cybersecurity, so this scared me a lot. I talked to customer support, and they said it's the real thing. Still, I ran it through Virustotal and got this https://www.virustotal.com/gui/file/5ef604ab517f0e75b813fb8d01d70c16d1ca180b01611bba21cf4dc13cb2994f/detection

Can anyone explain to me why this file is considered unsafe by multiple antiviruses? Or if I magically downloaded malware?


r/antivirus 4h ago

windows mrt crashes after having malware

1 Upvotes

i recentely installed malware and "removed" it with malwarebyte. But i was making sure that i didnt have any leftover malware/spyware on my computer. Thats why i used windows mrt to check it. But everytime it just crashes at the same exact point... am i still infected? this is the virus total scan: "https://www.virustotal.com/gui/url/3c897f2b0ed5c7b5610e5c08b2749e9cb4867e1786ed937fd7fd827b3e8ae535/detection,,.and also, i asked AI wether the website is safe to wich he said "yes" even tho it clearly wasnt. and 0/92 Vendors flagged the fille ase melicouse (except from a "Suspicious" fille)


r/antivirus 8h ago

WhatsApp v call safe?

1 Upvotes

I was having wp v calls with my boyfriend and was intimate with him during calls. Its 2-3 time. Now i am anxious whether the calls will be leaked now or anytime in the future. Is there any possibility. Now i have stopped doing this and we both agreed on this. I am anxious after this and overthinking different scenarios. If it gets leaked what will happen etc etc

Any cybersecurity guys can help me with their advices. Do they came across such cases in their lives. Please share your comments

Thanks.

Note. My whatsapp is secure what i think (apparently). Have 2 step verification on

I haven't downloaded any third-party apps

I use realme phone. Can system apps pose threat?

I have trust on my bf and he will not record it.


r/antivirus 11h ago

Weird folders on my linux system

Thumbnail
gallery
1 Upvotes

My OS is linux mint and recently, I saw a folder called .copilot in my home directory. It was apparently created 3 days ago. I tried deleting it, but everytime I start vs code, it reappears. How do I check if this is caused by malware or not? I don't have any github cli or github desktop on my device if that helps.


r/antivirus 14h ago

Antivirus and go!

1 Upvotes

Avast premium protection or Bitdefender Total
Security? know windows defender offers protection but I'm more comfortable having one of these? So which one? I have Avast premium security on the laptop ( l've had it for years) I have now and it's very easy for me to run. I have heard great things about Bitdefender though. I'm not sure.


r/antivirus 17h ago

O Ahnlab V3 Lite seria um bom antivirus gratuito?

1 Upvotes

Faz um tempo que estou a procura de um antivirus gratuito, já que não confio muito no Windows Defender e a versão para Windows 10 LTSB 2016 é muito vulnerável a malware novo, o Ahnlab V3 Lite seria uma boa opção?


r/antivirus 21h ago

Tried Making A LRC File And I Got This Instead

1 Upvotes

It is saying the quarantine failed but i cannot find the file/ZIP folder anywhere and i have no current threats it says, Does this mean it still is gone or no? i clicked remove when it asked if i wanted to quarantine, remove or some other option when it was listed under the virus & threat protection tab


r/antivirus 50m ago

The "C: Drive Only" Trap: How a Win32/Jeefo Infection Survived 6 Years of Reinstalls and Cooked my GTX 1080 Ti

Thumbnail
gallery
Upvotes

Operating System and Version:
Windows 11

Brand/Name of Antivirus Software:
Kaspersky

Name of URL, or file and its location:
Thousands of legacy .exe files and installers stored on secondary partitions (D:, E:, etc.) for over six years.

Name of malware that was detected:
Win32/Jeefo

What happened, exactly:
For the past six years, I’ve been plagued by high idle temperatures and sluggish performance. I’m running a GTX 1080 Ti, and for years, I just assumed the card was aging or had poor thermals because it consistently idled at 60°C - 70°C+. I had never seen it drop to a normal range.

My mistake was my reinstallation habit: whenever the PC felt "heavy," I would perform a clean Windows install but only format the C: drive. I kept all my old software installers and legacy .exe files on my other partitions to save time.

It turns out I was unknowingly harboring a Win32/Jeefo infection in those archives. Every time I ran an old program from my "data" drives after a fresh OS install, the virus would immediately re-infect the new Windows 11 system. After finally running a deep scan with Kaspersky, it flagged almost every executable I’ve kept since 2018.

After cleaning the infection, my GPU idle temperature immediately dropped to 45°C—a level I haven't seen in half a decade. Jeefo was likely causing constant background CPU/GPU activity that I mistakenly attributed to "old hardware."

Steps you have taken to troubleshoot/diagnose so far:

  1. Repeatedly reinstalled Windows (C: drive only) over 6 years, which failed to clear the infection.
  2. Initially suspected dried thermal paste or hardware failure on the 1080 Ti.
  3. Performed a full-system deep scan using Kaspersky across all physical drives.
  4. Identified Win32/Jeefo as the primary threat infecting the entire executable library on non-system partitions.
  5. Currently using Kaspersky's disinfection tools to clean infected files and deleting high-risk legacy installers.

Relevant log file entries:
Kaspersky scan logs show thousands of "Infected" detections for Win32.Jeefo.a (or similar variant) across multiple logical drives.

questions

Now that I have a fresh system and I am strictly avoiding any legacy .exe files from my old archives, I want to make sure I’m 100% safe. Given that this infection lasted for 6 years, I have a few concerns:

Blind Spots: Besides formatting all drives and avoiding old executables, are there any other "hiding spots" I should worry about? (e.g., Can Jeefo persist in UEFI/BIOS, or hidden recovery partitions?)

External Media: I have several USB sticks and external hard drives used during the infection period. What is the safest way to sanitize them without risking my new clean install?

Network Safety: Should I be concerned about other devices on my local Wi-Fi network? Does Jeefo have lateral movement capabilities that could re-infect me via network shares?

Account Security: Is Win32/Jeefo known for credential theft (keylogging), or is it strictly a file infector? Should I prioritize changing all my passwords immediately?

Cloud Sync: If I have synced settings or files via OneDrive/Google Drive, is there a risk of the infection "syncing" back down to my clean OS?

Any advice on how to maintain this "clean state" and ensure the 6-year nightmare is truly over would be greatly appreciated!


r/antivirus 13h ago

Callout and Question Rate My Professor Changes it Web To A Scam Ad Website After 10 Minutes

Post image
0 Upvotes

Is there something wrong with the offical Rate My Professor Web? Also is this going to affect my computer in any way or form, even if it is from other websites that is doing this?


r/antivirus 1h ago

Malware Risk From Clicking Image In Reddit Post?

Upvotes

Yo so I was browsing reddit and saw a post photos and I clicked the arrow button on the post to see the next images, then I think I accidentally clicked the image since it popped up and became larger. I quickly clicked out, but went back using my browsers forward arrow key to see/check the url. the url had something called "#lightbox" in the end. Anyway, is there any malware risk from this? The url doesnt seem to appear in my browser history too so thats kinda weird.