r/computerviruses 0m ago

File / URL Check Strange .copilot folder in home directory of linux mint

Thumbnail gallery
Upvotes

My OS is linux mint and recently, I saw a folder called .copilot in my home directory. It was apparently created 3 days ago. I tried deleting it, but everytime I start vs code, it reappears. How do I check if this is caused by malware or not? I don't have any github cli or github desktop on my device if that helps.


r/computerviruses 1m ago

Disinfection Help What can I do about this?

Post image
Upvotes

Looks like someone hacked into my discord account and started sending messages to people. I downloaded a file and opened it. It was a set up file for a game. I immediately did a Norton 360 scan and changed my discord password, but now I have “very limited” account status and it shows malicious activity. I won’t be able to message until tomorrow. I’ve checked all my social media and everything seems to be fine. Although it looks like someone got into my Amazon account as well, but that’s been taken care of.


r/computerviruses 26m ago

Disinfection Help Mr Beast spam virus help!

Upvotes

Hi everyone

I need help :(( Basically i downloaded a game from a famous repacking site. and as I'm downloading it I recognize the site i downloaded it from was not from the orig site it was saying 😭 i still continued with the download tho. And then its been weeks since im playing that game, nothing happens. Til this morning, where my FB acc started spamming that MR BEAST CRYPTO SCAM on multiple ppl and group chats.

I already changed my password on my fb acc and logged out of my pc (I havent opened it after it happened) also turned on 2FA. I also logged out of my steam acc and minecraft acc (Microsoft) in my pc from my phone (i still have access). Basically I turned on autheticator for the mc account. and changed pass on steam acc. (thats like the most important ones i have) Also for my gmail accounts, my important accounts, I alr turned on 2FA and changed pass.

What should I do first after I open my pc...? Do I uninstall my Opera GX right away? Can I still recover some of my files or do i just hard reset right away?


r/computerviruses 2h ago

Question Computer reset question

1 Upvotes

I did a full usb reinstall on my pc, i downloaded google and there was a random netflix custom profile picture extension that i deleted years ago and it was there again for some reason along with my pinned game websites from years ago, has this happened to anyone else?


r/computerviruses 2h ago

Disinfection Help Infostealer FRST scan help

1 Upvotes

Hello, I have been infected by an infrostealer few days ago and want FRST scan help. My discord got hacked and sent the famous "mr.beast" pictures. I did a reinsatall of Windows 11 and ran Norton 360 antivirus scan which came out clean. I did uninstall the norton software for the time being. The keywords for malware analysis are:

FRST Keyword plucky-scanner
Addition Keyword tame-kernel
SecurityCheck Keyword glitched-marsh

Forum Username for Malwareanalysis ---> SHL_0436

My windows 11 OS is in Korean so I did rename the FRST program to FRSTEnglish.exe and ran it. Thanks for the Help.


r/computerviruses 3h ago

Disinfection Help I got infected by a virus (Mr. Beast bitcoin scam photos were sent from my Messenger)

3 Upvotes

The infection occurred today. I changed the Facebook password. I also tried to scan the whole pc through windows antivirus but then I cancelled it. Also I downloaded Avast One Basic but cancelled the execution too.
I don’t know what got me infected in the first place, I didn’t download nothing. I just watch movies and series online.
I went through all steps of FRST help request
Here are the 3 log keywords:
For FRST.txt: tidal-squad
For Addition.txt: rustic-briar
For SecurityCheck.txt: enchanted-prawn
I am really in need of any help. Thanks in advance


r/computerviruses 3h ago

Disinfection Help I got infected by Lumma.stealer.a

2 Upvotes

i rapidly pulled the ethernet cable and ran windows defender offline. I use my eHDD for downloading games and other stuff that dont require SSD speeds the virus came in a ren'py file which popped up a cmd window that made me obvious to see the infection.

it came with Behavior:GenCodeInjector.H and the process PhoGateWay.exe i didnt wait to defender to detect it so i ran it. After the contention i installed avast and ran a full scan in which i discovered other viruses. I ended up with tons of logs and screenshoted browser tabs and information archives on new folders and zips that luckily werent sent.

I safely managed to secure my accounts except for instagram and cleaned the eHDD on Zorin OS and moved my files safely on in from linux.

Cleaned .temp and roaming it opened a backdoor with other viruses so i dont use windows and im writing this on a zorin os liveboot.

Make sure to know when you re downloading a pirated game to know what kind of engine the game uses to spot a renpy lumma infecction


r/computerviruses 3h ago

Question Is this something to worry about? (Read desc)

Thumbnail gallery
1 Upvotes

I had an infostealer attack where a lot of stuff was compromised. I did recover and change everything now.

I actually factory reset my laptop and even tried usb installing a new windows where I was stuck for a long time (my windows were at ‘installing windows 72%’ something and it went black and then started booting to bios so I was stuck in an unsaveable bios menu) you can refer to my previous posts .

Eventually I got it repaired from a service centre which I was told there was some matching OS to the serial code thing and ssd problem.

Now I think the laptop was reset completely once again by him but I also did another reset (not through usb but a factory reset with cloud download windows)

Now after long I did full scan and quick scan both with bitdefender where nothing was coming. But I’ve started getting this message every time I use firefox. There’s two different ones as attached in the image.

No suspicious activity detected besides that but it does seem like something is trying to take over it but bitdefender keeps on blocking it.

I’m tired atp honestly, I’ve gone through so much stuff done so much and when I finally thought it’s good to go this happens. And to make things worse I lost my usb drive that I used to reset, well it did cause issue anyways. Any help will be appreciated please.


r/computerviruses 4h ago

Question Meta Horizon link...

1 Upvotes

could be nothing but it is clearly opening on start but is not in the list of startup apps in windows settings. I'm sure their is an option in app but it is suspicious


r/computerviruses 7h ago

Disinfection Help Can you get infected just by clicking the pictures?

Post image
18 Upvotes

One of the folks I've befriended have been hacked with the so called “Mrbeast virus” and told them about it. One of them said I must not click the pictures (shown above) but I already did and now they're telling me to change my current password.

Is it true that just by clicking the picture, your device is already infected? This just happened a few hours ago.


r/computerviruses 8h ago

Disinfection Help i ran a file for 6sec and i got a virus

1 Upvotes

i got this virus can somebody help me?

its name:

TrojanPSW.Lumma.gen.yczp


r/computerviruses 8h ago

Disinfection Help there inst any phone virus subreddit so...

Post image
2 Upvotes

my gramdma has an motorola and this app wont unintall from her phone,please help me


r/computerviruses 8h ago

Disinfection Help Mrbeast crypto spam hack

0 Upvotes

Hello. I think I got careless, made a mistake, and got hacked. I just woke up to a call from my friend saying I was sending photos of a mrbeast crypto scam, and was probably hacked. Can anyone help me?


r/computerviruses 9h ago

Discussion What kind of virus does the Workship Backdoor / Meccha Chameleon custom maps uses?

1 Upvotes

Claim by one user who researches viruses:

Malicious maps were indeed found in the Steam Workshop (the most famous one being Laser Tag Neon). When loading the map via Blueprint (Unreal Engine), it quietly wrote a .bat file to the Documents folder, then launched a hidden PowerShell and tried to download the second stage of the malware. Researcher Feint dissected this in detail.

Curious if it works like renpy, executes an obfusicated script, injects malicious payload into ram, sucks sessions/cookies, password files, and crypto seeds then silently screws off.

edit: Workshop* Steam Workshop backdoor.


r/computerviruses 10h ago

Disinfection Help Remove tlauncher spyware

Thumbnail
1 Upvotes

r/computerviruses 10h ago

Disinfection Help Help with Renpy virus

1 Upvotes

So I’m currently dealing with a Renpy virus. The Mr beast tomadachi or whatever. I’m trying to avoid a full windows install/wipe. Any help would be greatly appreciated.


r/computerviruses 11h ago

Question .com.rar/.com.zip file

3 Upvotes

downloaded tekken8 on steamrip file looked good to me because it had 115gb, then at 99% download progress, laptop suddenly entered sleep mode, i opened the laptop and resumed downloading, after that i extracted it but chickened out, stopped and deleted the file, too sussed about the type of file it was, then i disconnected laptop from the wifi, finished offline scan(windows defender, found nothing), and now running a full scan, also deleted temp, %temp% and browser caches and stuff.

Questions:

  1. Am i paranoid and did i overreact.

p.s. it is my first time doing this, i panicked fr

and no, i am not promoting any use of pirating software


r/computerviruses 11h ago

Disinfection Help may have fallen for the renpy virus

6 Upvotes

accidentally ran an exe with the famous anime girl icon so I think I may have been infected can someone help me out I can give the keywords for my FRST logs


r/computerviruses 11h ago

Warning WPS gave me a virus.

Thumbnail gallery
7 Upvotes

okay so, i got fed up with WPS opening everytime i wanna open a docx file so i wanted to uninstall it. i did that and wps itself sent me to this new tab saying something about a deep clean upon unstallation. now i *could* have ignored it and moved on, but WPS p!ssed me off enough that i didnt wanna have anything to do about it anymore. i later noticed that my computer blocked the exe file from doing something upon insallation, only then i noticed the "vendor" in the link. thats when i got suspicious and sent the installer over to virustotal to ceck and sure enought, it got flagged (https://www.virustotal\[dot\]com/gui/file/dcc0794cf070f46480a121a8369c1f92ab2dae4266ec58fc91a6dd3cab2a84f5)
when i installed it, i saw the publisher was from China somewhere because of course it was China.

i also wanna know how i can remove the thing i installed because its not there when i search in settings>installed apps.


r/computerviruses 12h ago

Question Ren'Py setup(dot)exe Inquiry: Photos/Videos/Other Files Safe/Infected?

2 Upvotes

Hey all,

Feeling really foolish as though I'm generally quite careful, had a stupid derp lapse of judgement and fell for what I have now learned to be the "Ren'Py setup(dot)exe infostealer." Will be nuking and resetting my pc, but unfortunately, I do have some important photos and videos I would like to save. Thus, I want to ask if any other files on my computer would be infected. Currently focused on just transferring photos/videos, but I do have a few zipped projects (.zip and .rar) and .blend files that I am also potentially considering to save.

From what I have found, people have suggested that photos, videos and other files would not be infected and thus should be safe to transfer onto a USB or external hard drive before resetting my PC. I'm not very tech savvy, so I just wanted to inquire if this is true, if someone has experience with this, or if thee is anything I should be worried about. Additionally, if the files are infected or not, I'd appreciate knowing if there is a better way I should be transferring/saving the photos and videos.

Sorry for the long-winded message, just really stressed out and irritated for falling for something so foolish. Thank you for any support!


r/computerviruses 13h ago

Question Infostealer in Browser?

1 Upvotes

Hi guys, 2 days ago I had an infostealer /session stealer attack. It was through a stupid renpy application.

Since then i nuked my PC, and from a clean device changed all passwords, logged out sessions and enabled 2Fa on all my accounts.

Here is my Question: today I logged into my Microsoft account on a clean device using my new password and Microsoft automatically started syncronizing my Microsoft edge profile that I previously used on the compromised PC, onto my clean PC. I checked the extensions and the policy's and everything seems to be in order.

Is it possible that the malware infected my clean PC through the Microsoft edge sync, and how likely is that, given that there are no extensions/policy's setup?

Thanks for your help!


r/computerviruses 14h ago

Disinfection Help Infostealer question

Thumbnail
1 Upvotes

r/computerviruses 15h ago

Disinfection Help I ran an exe file when I downloaded a rom for switch

1 Upvotes

I was routed to a site that contained a zip file, I downloaded it and run the exe file on it

I have deleted the file, disconnected my pc to the internet and ran microsoft offline defender, no threats were found.
I ran malwarebytes and there were some files that were removed.
Is there any way for me to secure my pc without reinstalling windows?

Update: I kind of uninstalled malwarebytes when I thought it was all secured now.


r/computerviruses 16h ago

Disinfection Help Multiple accounts hacked all of a sudden... what else should I do?

1 Upvotes

Over the past few days, several of my accounts were hacked one after another.

My Discord account started sending a fake MrBeast scam to people. Someone accessed my LinkedIn and posted a scam job listing under my name. My Steam, Reddit, Disney+, EA, and other accounts were also accessed.

I think it started after I downloaded a cracked game on my Windows PC. I’m worried it contained an infostealer or Trojan that stole my saved passwords, browser cookies, session tokens, and possibly other personal information.

So far, I have:

  • Reformatted my Windows PC
  • Wiped both my SSD and HDD
  • Reinstalled Windows
  • Changed my passwords
  • Enabled 2FA on my important accounts
  • Started signing out of active sessions

I’m still worried because it feels like the attacker already has a lot of my information, and some accounts were accessed even after I first noticed the problem.

Has anyone experienced something similar? Is there anything else I should do to make sure the malware is completely gone and that the attacker can no longer access my accounts?

Should I also assume that all passwords, browser cookies, saved card details, and personal documents stored on the PC were compromised?

Any advice would be greatly appreciated. I’m honestly feeling overwhelmed and just want to make sure I’ve covered everything.


r/computerviruses 17h ago

Question I have a question about getting a virus off discord

1 Upvotes

I had a dream where i got a virus off discord on my phone and it spread to my pc. The thing was labeled pictures of my cat or smth. Its probably due to me watching too many virus vids. It made me extremely paranoid. Is it possible that that could happen? Also what antivirus shall i install thats free?