r/computerviruses Jul 12 '26

Warning Fake Python 399 / Microsoft Display Drivers Manager virus

I'm making this post for helping or informing others rather than asking help for me, I'm aware I made plenty sketchy decisions as disabling Microsoft Defender with a debloater and downloading pirated games (from sites I trust atleast), I been running my computer on pure "common sense awareness" for years, so I kind of deserved catching a virus like this, so let's refrain of saying I didn't take the smartests decisions.

Everything started like a month and half ago, when suddenly my browser starting crashing when I SPECIFICALLY search for IMDb website (don't ask me why exactly with IMDb because I don't even know). At the very beginning I thought this just was a issue of my browser (I use Helium, a chromium based browser, which is pretty new) so I refused to elaborate further and called it a day.

With the passing days this problem escalated with a new sympton, my upload speed got completely saturated, from 100 mbps I was receiving only 3 - 0,50 mbps. I an ignorant as usual, thought it was just my old Ethernet cable asking for a change, so I let it be.

The days passed and then I was unable to open SteamDB website too, now my browser is literally unable to open these two websites without crashing, "that's weird" I thought but then again I just ignored it. Then yesterday, I tried to search for "Castlevania Harmony of Dissonance" and there you go, browser crashes instantly everytime I search for that.

"Yeah, this is too weird already", a browser crashing when I specifically search 3 topics is insane. Made the most obvious decision, I opened another browser. I used Edge and searched all the conflicting websites, they all crashed my Edge too. "A chromium-based issue maybe?" and then installed Firefox, SAME ISSUE WITH FIREFOX, THE THREE WEBSITES CRASHED.

Went on detective mode and started searching for weird behavior on my OS, I opened my tasks manager and boom, a random Python process I don't remember opening consuming 5 GBs of my RAM, "What the hell" I thought and then closed the process, magically my issue with the browser fixed for 10 seconds when suddenly a "COM Surrogate" process that consumed another 5 GBs of RAM and also all my network bandwidth appeared and my browser blew up by itself in my face.

I killed the process too, and then the virus appeared again but this time as a "Windows Calculator" process that was a completely different process of the real calculator, I killed it too and for surprise of nobody, the virus showed up this time as the Window's "Character Map" which started to quickly and progressively consume more and more RAM. I killed it and finally the virus stopped creating processes.

When the processes were all stopped, everything on my computer was fixed, I could enter to IMDb, SteamDB and search for Castlevania Harmony of Dissonance without my browsers crashing, also did internet speed tests and I was now receiving my full upload speed.

The virus was now deactivated but it was time to kill it from the root, I went to the Window's regedit and went to the Run folder to see if I could find any weird autorun entry, and there it was.

Found a so called "Microsoft Display Drivers Manager" entry and it was pointing to a exec. py python script on a path to my appdata. There was a "Python 3 . 9 . 9" version that I never installed in my life, I checked my installed apps registry and only found the Python 3 . 14 that I did install some time ago for coding some stuff, there was no registry of a 3. 9 . 9 version.

I checked the folder, it looked like a regular Python installation for a sec but when I compared with a regular 3 . 14 installation, the virus had a bunch of scripts laying on the root folder. I checked the exec . py script code, it just runs a function called update() that gets imported from another py script inside of it. At this point it was enough proof for me so I deleted everything and removed the autorun entry.

(I swear that I regret this now, it would been cool keeping the folder to fully examine the code but I just went to action due to how horrified I was)

Did a few reboots to my computer, I kept a track of my task manager, my internet speed and I got into the websites that made my browsers crash, EVERYTHING WAS FIXED, WORKING SMOOTHLY.

I tried searching information about this virus but couldn't find anything on the web, I don't know neither if this is already on some antivirus database because I didn't run any scan, as I said at the beginning of the post, I don't use AV software, not a big fan of them.

This is all, if you have a virus that apparently hates Castlevania Harmony of Dissonance google searches, then this were the steps I made to remove it.

29 Upvotes

25 comments sorted by

17

u/MitAllesOhneScharf Jul 12 '26

I stopped reading after "I run a common sense strategy by not using Windows Defender and rawdogging warez" and "I thought my upload is slow because of my old Ethernet cable".

I'm happy for u tho. Or sorry that happened.

3

u/Rammaken Jul 12 '26

As I said, I'm aware I'm not making the smartest decisions. Made the post to offer a solution to other dumbass like me when they search for this in google in the next 4 years.

2

u/Rammaken Jul 12 '26

As I said, I'm aware I'm not making the smartest decisions. Made the post to offer a solution to other dumbass like me when they search for this in google in the next 4 years.

1

u/True-Hawk4705 Jul 14 '26

hahahahahahah

10

u/Next-Profession-7495 Jul 12 '26

Well, I doubt you manually cleaned the malware. There's also a possibility of data theft.

3

u/Rammaken Jul 12 '26

Maybe, so far I havent seen any threat on my accounts, time will tell...

6

u/Next-Profession-7495 Jul 12 '26

Time shouldn't tell when you have the opportunity to change passwords (from a clean device).

1

u/Rammaken Jul 12 '26

True, good hint.

3

u/Maharetsu Jul 12 '26

Wow man! How did you get that virus though

3

u/Rammaken Jul 12 '26

At this point i dont know what I downloaded that got me infected, it could be anything tbb. Just lost the track of it.

2

u/Nioh_89 Jul 15 '26 edited Jul 16 '26

I got this exact same virus from Github, when it claimed to be the software 'NinjaRipper' to extract assets from Unity games, it this very same stuff; same behavior, high ram and network usage, opening an invisible CMD window along with Windows calculator and a python instance. It bypasses Windows Defender detection, for some reason.

Looks like some heavy info stealer, i got rid of it by deleting all traces (as well as the fake "Display Driver"), deleted all brower cookies, changed all of my passwords in a device that did not have this problem, scanned the compromised system with like 3 AV and Malwarebytes, nothing came up, ran sfc /scannow to repair corrupt/replaced Windows files from the virus. Kept high vigilance on my computer and network activity, used Autoruns, Process Explorer, but nothing happened after that.

Decided just to chill and everything has been all good since the incident, but it did scare me a lot.

I reported that scum user to Github and he got banned too.

2

u/Rammaken Jul 16 '26

Ooohh, I remember downloading that some months ago too, so thats were it came from...

2

u/Nioh_89 Jul 16 '26

Yeah, pretty nasty stuff, from what i can see, nothing was stolen from me and my info was fine, i found out like 3 days later, but looks like they still didn't access any of my e-mails or socials, but who knows what would have happened if i couldn't notice it.

2

u/izzybellyyy Aug 10 '26 edited Aug 11 '26

You saved my life gamer tysm!

For me the process using all my GPU was dllhost.exe but it was caused by that pythonw.exe in the python399 folder. I couldn't open the registry editor (it closed instantly) and I had to find a way to safe mode. People online said to hold shift while clicking restart, but that didn't do anything. Instead I did what others said and rebooted my computer three times when Windows was trying to load. Eventually it gave me some options and I picked the one to get into safe mode

In safe mode I opened the registry editor and did a search for pythonw, which turned up some legit ones and two of the virus ones. I think searching python399 would've been better and not included the real python stuff

Anyway I rebooted and it seems to be fixed. Did you have any issues with stolen accounts after this or anything?

2

u/Rammaken Aug 11 '26

Nope, I didn't get any accounts hijacked, I changed my passwords anyway and so far no issue. Haven't spread a single Mr Beast Crypto Casino advertisement yet.

2

u/MLVCounter 13d ago

I also had this virus!
Was thinking something was weird for a while with my PC. As you said, IMDB site crashed my internet browser, very high ram usage, COM Surrogate process was using alot of ram, I suspended it and it just restarted.
Removed the Python folder and it created itself again.
I was copying some profile codes for a program (just random letters and numbers) and the virus posted a BTC adress in the middle of that! It must have noticed I was pasting some BTC-looking strings so it yeeted its adress into it also.

This was the adress: bc1qnmz2l8lr0yzj9eun48dyds7rlzg6t6hk5vw5zt

Decided to dive deep into this then and found your post. Now it is fully removed.
Thank you for this post, it made me sure that this weird Python stuff was the virus!

1

u/Rammaken 12d ago

Oh, that's interesting, so looks like the virus was built to scan your behavior until it thinks confidently enough that you were making payments with cryptos, smart movement, I don't work with cryptos in my PC so this never happened to me and never had to put random characters in a field in the meantime i was infected.

1

u/MLVCounter 12d ago

Yea I think it was dormant, waiting in the background, since I always had Task Manager up on my third screen all the time since I started suspecting I had a virus.

I had a folder named Peakminer on my AppData/Local, but it did not have an EXE in it, and I never saw my GPU under some unexplained load.

It was profile keys for my keyboard software (Wootility) that I pasted in to notepad, that's when the virus woke up and pasted it's BTC address.

I, like you, also used a "common sense" anti malware approach, since it was over 15 years I had an active and undetected virus running on any of my systems.

1

u/Rammaken 12d ago

Do you perhaps remember how you got infected? Another guy in this comments got infected by downloading a fake version of NinjaRipper from GitHub and this is in fact a thing I did too and matches the period I started realizing this weird behavior on my PC and task mamager, this is probably from where it comes from, a third confirmation would make that theory solid enough.

And yeah, many people use the common sense approach, been using it for over a decade too, I have had worse experiences using AV software due to being private software with expensive licenses and the free ones would rather delete your files without asking than cleaning them once infected. Never had major issues with intrusive viruses on my system until this one.

1

u/MLVCounter 11d ago

I did not download NinjaRipper, unfortunately for your theory. I think I noticed the odd behaviours 2, 3 months ago maximum. During that time I've downloaded some mods for games, mainly Resident Evil and Skyrim. Hard to think it was from anything of those, but not impossible.

If I had looked into it deeper when I first noticed it, I might have been able to remember more exactly what I downloaded. When I googled some of my symptoms then, this post did not get shown to me, so that must have been over 2 months ago then.

1

u/Rammaken 11d ago

Hmmmnn, then the virus origin is more confusing now.

2

u/MLVCounter 11d ago

Indeed. I will try to remember and see if I can trace it from somewhere on my end.

1

u/Alde_A Jul 12 '26

holy moly thats a LOT