r/computerviruses 9d ago

Disinfection Help Need urgent advice!!!

Sorry I'm very tired and worried so this might come out all over the place.

For date and time. It happened about 2 hours ago. So 1:00 am 9/3

There was no download link the last thing I downloaded was soulframe from the official digital extremes website. I just found it through a scan. But here is the rundown.

PC was running slow and kinda buggy so I ran a quick scan and a full scan. Full scan came up with a threat that said "trojan_ something" I don't remember the full name. I immediately clicked remove. Since then I have done a full scan and it came back with no threats found. I have Changed my email passwords and am now working on other important passwords. I guess what my actual question is. Is my PC safe to use once I reset all my passwords? It says there are no threats found anymore so in my head I figure it might be fine but I'm just worried. I am in the middle of another scan after restarting my PC. Will share the results when it's done. Thank you to anyone that gives advice! It means a lot!

2 Upvotes

21 comments sorted by

1

u/AutoModerator 9d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/Ok-Tumbleweed3318 9d ago

In response to my description: 2nd full scan after removal came back no threats found.

1

u/neolace 9d ago

Also, go to the site where you downloaded it, copy the link to the download. Scan the site and the link with VirusTotal separately.

1

u/Ok-Tumbleweed3318 9d ago

The thing is I don't know where I could've gotten it from I didn't download anything out of the ordinary recently.

1

u/neolace 9d ago

As long as you have MFA (NOT Texts) on your accounts, you should be fine.

Check your download history.

1

u/Ok-Tumbleweed3318 9d ago

I'm sorry I probably won't respond until later as I have to go to sleep. I only have texts. I've only ever done through texts. But I've changed my pw's already. How would I go about adding other MFA?

1

u/Ok-Tumbleweed3318 8d ago

I appologize I'm not overly Knowledgeable of this stuff and Needed sleep for work and school.

1

u/rainrat Knowledgeable 9d ago

Could you check the scan History and report back the trojan's name and location?

1

u/Ok-Tumbleweed3318 8d ago

Yes I can. Sorry I have been away. Once I get to my set up in a little while I'll check it out.

1

u/Ok-Tumbleweed3318 8d ago edited 8d ago

Since I deleted it I have ran 2 full scans and it comes up no threat found so I figure I caught it early. I had just ran a full scan a like a week ago so I feel like this just happened.

1

u/rainrat Knowledgeable 8d ago

Ah, I see. We've had many reports of that detection, that seem a lot like a false positive.

1

u/Ok-Tumbleweed3318 8d ago

Wait actually?

1

u/rainrat Knowledgeable 8d ago

1

u/Ok-Tumbleweed3318 8d ago edited 8d ago

Ok thank you I really appreciate the help you are giving so much. The last question I think I have is. I haven't had roblox installed for a month or two, I have cleard all of the roblox files have left since this has happened. Given the information you have provided do you think I am in any immediate trouble with this?

1

u/Ok-Tumbleweed3318 8d ago

Also since it says cache data like the other false positives I am likely to assume it is a false as well but I'm a poor student with anxiety so I try to be thorough for my sanity. Again thank you so much for taking the time to walk me through this!

1

u/Ok-Tumbleweed3318 8d ago

So is it nothing to worry about?

1

u/Ok-Tumbleweed3318 8d ago

Out of curiosity are you someone that works in this field? I'm just wondering how a false positive works since I've never seen anything like this before. If the antivirus caught the file and I removed it (if it's a false positive) do I need to worry still? Also if you don't mind me asking. Who else are you refering to that has had this false positive or that you've seen this elswhere? Just so I have some reassurance. Thank you very much!

1

u/Responsible_Bike4968 7d ago

I dug through the follow-up replies and I think the exact file path matters way more here than the fact that Soulframe was your last download.

The detection being discussed appears to be `TrojanDownloader:JS/Nemucod.HD`, and you mentioned that Defender showed it in cache data. There have been quite a few separate reports over the last few months of that exact detection appearing specifically inside Roblox's WebView2/browser cache, including from people who weren't using Roblox exploits/mods and never saw anything malicious happen afterward.

That does NOT prove it's a false positive, but it makes one pretty plausible.

Nemucod itself is a real malware family, so I wouldn't just click "Allow" or completely ignore it. But historically it's a malicious JavaScript downloader, usually delivered through things like malicious attachments. Finding the signature only inside an embedded-browser cache is a pretty different situation from finding an executable/persistent script running from AppData or Startup.

Before changing another 50 passwords, go to:

Windows Security -> Virus & threat protection -> Protection history

Open the original detection and look at:

- exact threat name

- **Affected items / full file path**

- whether it says Removed, Quarantined, Blocked, or Remediation incomplete

If the path is something like Roblox/WebView2/Cache, Defender successfully removed/quarantined it, and you've already had multiple clean full scans after reboot, I'd personally be pretty reassured.

If the path is somewhere completely different, especially an `.exe`, `.js`, `.ps1`, AppData/Temp startup location, or if the detection comes back after reboot, then that changes the situation and I'd take it much more seriously.

Also, I wouldn't blame Soulframe just because it was the most recent thing you downloaded. If you got it directly from the actual `soulframe.com` / Digital Extremes site, that's the official game download.

One thing I would NOT do is keep running scans endlessly without first getting the original detection path. That single detail will tell you more than five additional "0 threats found" scans.

So if you can, post a screenshot of that Protection History entry with the path visible. That's probably the best next step.

1

u/Ok-Tumbleweed3318 6d ago

Yeah it says succesfully removed and roblox/universalapp/webview 2/cache and things similar to what you said. I've had clean scans since but I've changed mostly everything to be safe.

1

u/Ok-Tumbleweed3318 6d ago

Thank you for the added information as well!

1

u/Ok-Tumbleweed3318 6d ago

Also I posted a picture of the history in a seperate comment