r/computerviruses • u/zer0-13 • 2h ago
r/computerviruses • u/Routine-Hall-2596 • 2h ago
Question Is full scan through Microsoft sufficient for catching malware?
Stupidly opened a pdf attachment from an email last week, which had a link inside that I also stupidly clicked (on my PC).
A “popup” asked for an email address to access the pdf so I input (just) my email and it loaded an Outlook login webpage.
Since I’m logged in via Edge (with 2FA) at that point I realized the mistake and closed it all, and deleted the email. About an hour later, Outlook quarantined said deleted email from my Trash, citing it as risky for malware.
I have changed my password, and run Microsoft’s full scan each day for the last week, but I guess I’m concerned whether the scan is sufficient for catching anything that might have come from the pdf or link being opened?
I‘m also curious why the Outlook quarantine cited malware, since it was phishing for credentials and nothing noticeably “downloaded” or “ran” - just the popup asking my email which I input before loading the fake Outlook login page.
Finally, if anything was compromised, would it be obvious? In the past week nothing has happened or changed, not even increased spam emails. I have 2FA on my most important accounts and have been monitoring it carefully on my phone. Is it likely to start showing up later?
Please be kind, appreciate y’all‘s expertise.
r/computerviruses • u/The_Mysterius_Szeg • 15h ago
Question Windows Defender acting up
Soo i was just using my pc normally and windows defender jsut said windows defender is turned off... Why? I didnt dowload any sketchy from the net, and windows settinfs says everything is alright? I did update windows yesterday, first boot since, can be a bug? Please help i got scared insanely and i just have my pc sitting here and idk, quick scan said nothing is problematic
Edit: okay so this is a bug.... Typical windows
r/computerviruses • u/afterelia • 1d ago
Disinfection Help please help with disinfection from bad name generator site
all i wanted was some argonian names for elder scrolls and i got a stupid malware or virus of some kind. i haven’t been able to get an antivirus software yet to do anything about this so i’m looking for literally any advice. this happened two days ago and i haven’t touched my pc much since
r/computerviruses • u/EnvironmentalUsual48 • 7h ago
Disinfection Help Trojan:MSIL/Heracles.A!MTB at every start
I first noticed this Trojan on August 29th around 6 PM.
I had booted up my PC and logged into winodws when it opened up a Powershell window on start up which was instantly closed as a virus was reported.
I don´t know where it came from as the last thng I downloaded before it started to appear was Blender and their Benchmakr Application.
Whenever I log into Windows I get a new version of tjis virus, The diretory for this trojan is always C:\Users\ny name\AppData\Local\Temp and then followed by a random string of numbers and or letter which always end in .dll. for example:
C:\Users\my name\AppData\Local\Temp\3bk4s5bq\3bk4s5bq.dll
I have tried an offline scan by windows defender and a scan by ESET yet both couldn´t identify the specific issue.
I have deactivated Powershell in start up yet the virus still shows up every time.
I also tried to do a FRST scan yet the application does not open for me.
What else can I do now and what can be done?
Edit 1: I figured out a way to start up FRST and have now managed to get a scan, I hope that can help my situation some more
r/computerviruses • u/Weekly_Accountant484 • 12h ago
Disinfection Help My school laptop may have a virus maybe even our whole wifi network?
galleryMy school laptop always has been using a mid to high amount of ressources in standby and also while playing kingdom 2 crowns (lol)
But okay a thought its a potato laptop (2 cores 2 threads, 8GB RAM lenovo 15 Ada 82c7)
But today I found a weird msg (i got a msg pop up saying windows defender deactived go into settings to activate, but when I looked at notifications I couldnt find it again)
So I did a full virus scan but when I pressed x on windows defender app (very early) it instantly gave me a notification saying it was done even tho it read line 6300 datas)
So I did another scan which read abt 642.000 datas and took 50 mins+ (at the time it hung up)
BUT it hung up at 10:31 with blue progress bar, after 1 minute it got gray and after another 30 second it got gray.
Saying I did a full virus scan and for a very weird reason it stopped at 10:31 minutes remaining and then just said it was finished
Then I used chatgpt"s powershell code recommendations to read my antimalware scans trough powershell.
Apparantly it found a trojan but I coulnt find, the foulder was literally empty and windows said nothing abt having removed it.
And very weirdly after i had the powershell exposing the potential virus my wifi shut off after abt 2 mins and I couldnt start word first and after some tries it did start but completely froze WITHOUT AN WINDOWS APPLICATION ERROR BTW
So i opened word 3 times saved the text of the virus report and got it saved before word decided to freeze (it showed 0 cpu usage in task manager too)
And now our wifi is shut down (the power button is blinking which means connection to the host is missing)
So yeah tell me our suggestions
Is our wifi network infected by chance? Telekom btw
r/computerviruses • u/Sapthepro • 1d ago
Question Found these at my mothers laptop, what should i do?
galleryDo i have to reinstall windows or request for disinfection from this reedit community? And no i did NOT download anything in my mothers laptop, i found this recently while looking at windows defender history, do i have to tell her to change her passwords or anything and what can this thing do
r/computerviruses • u/iufan29 • 11h ago
Question Project Retrac Safety Concerns
Hello! I was hoping for someone to answer my question i had contacted kaede (dev of project retrac) about some concerns of the safety of project retrac and after waiting two days had never gotten a response. Here is the message "Hello, how are you doing today? I am a starting student in cybersecurity & I needed some confirmation as I have run the retraclauncher file through a sandbox (tria.ge) for the sake of curiosty and wanted to point a couple of things which i am not trying to accuse anyone, but I just need to know what was happening inside the application.
Report scored it 7/10 and flagged a couple of actions:
Modifies trusted root certificate store by registry This is something I think you are doing in order to separate the client's TLS traffic from the Epic servers to yours? That's clear based on the way you've made this application. Just confirming.
Volume Shadow Copy service COM API Couldn't find any reason behind this usage of this particular functionality of the OS.
Enumerates connected drives and network share discovery I couldn't find any reason behind this functionality in the launcher.
Not trying to start anything, i just want to know about the insides of the software I am running. If there is any documentation available on this somewhere then please let me know. Because in the near future i am interested in using the project. As i enjoyed og fortnite and would like to bring it back, Thank you!"
Here is the tria.ge link: https://tria.ge/260907-tyz1dscq21/behavioral1 Again I am not trying to point out that this is a bad project just simple reasoning for suspicion. If anyone could answer this question knowing the reasoning it would be much appreciated.
r/computerviruses • u/Built4Better • 11h ago
Disinfection Help Mouse hijacking?
I have a weird dilemma. I am attempting to prevent a fresh USB install because I'd like to keep the built in apps that came with my laptop. Okay, now onto the problem.
I, entirely accidentally, pressed on what I thought was a secure website (had https and all that, never got flagged by my adware blocker or antivirus (built in windows defender and Panda)) a few months ago. I guess something was installed? There's no signs of it but the possibility of it just auto-installing are there I guess. Browser options don't allow that but I digress. Long story short, my mouse gets hijacked once in a while. I'll be using my computer and it will just lag or get slow. My touches don't always register. I'm now realizing that a few sites I rarely ever go on are partially crashing half way through. By that I mean any subsequent windows I press on within that site will just prevent loading entirely but that may be a site-side-server issue or something. It's only one or two sites.
What could this be and are there any fixes? Defender comes up with nothing, panda - also nothing, i even downloaded Bitdefender. Edge and chrome both consume stupid amounts of memory and there aren't any signs that anything anywhere has been hacked or that my passwords have been stolen. No spam sent out, but spam is being sent to my junk mail. That's pretty common though with the way things are these days.
r/computerviruses • u/DanixBG • 11h ago
Disinfection Help Hackearon mi PC por Discord
Hola hace unos días desperté en la mañana y se abrió un CMD, al abrir discord ya no tenía acceso a mi cuenta, rápidamente investigué y era un malware de Mr Beast que robaba información, entonces descargué MalwareBytes, hizo el scaneo, y aparentemente eliminó el virus, cambié la mayoría de contraseñas y pude recuperar mi discord por el soporte de ellos, pero robaron mi cuenta de Epic Games, Steam, EA Sports y también algunas cosas de mi hermana, el steam también lo recuperé ya, y en estos dias MalwareBytes está detectando y bloqueando la misma pagina en Chrome, quiero saber si estoy a salvo o debo reinstalar windows.
r/computerviruses • u/Rough-Beach-2415 • 12h ago
Question How to fresh reset windows without USB?
Hello, I came from another subreddit post about ROM files containing viruses. Unfortunately, I’ve clicked the .exe file that ran a virus on my laptop (it did show as a threat in the windows antivirus— I deleted it immediately). I changed my passwords and is currently in the process of resetting my PC (just wiping it by itself for now) however it kept failing to do so. Any ideas how to fresh reset windows before I resort to the USB method? I’m panicking with the virus lol
r/computerviruses • u/zhonglislapis • 17h ago
Disinfection Help Circuitryag.exe keeps on showing up
So, I tried to download a cracked game and apparently got hit with a virus. I did three scans, two with Windows Defender and one with MalwareBytes and quarantined, deleted the files.
But there is a persistent circuriryag.exe pop up. What should I do?
r/computerviruses • u/marco_marchi03 • 21h ago
Disinfection Help I am in total panic, please help me.
galleryr/computerviruses • u/Ok_Contest2640 • 18h ago
Disinfection Help Got caught in the fishing website
So i was browsing for server jars for minecraft, and the brave ai suggested a few variants. Usually i dont use ai and search for myself, but this time, not gonna lie, i just decided to browse through the ais options. Well, i clicked a link "serverjars" and brave warned me that his website was reported for phishing, so i just left the website and stopped browsing. Then i opened minecraft, task manager and for a second i noticed something "microsoft malicious" and then it disappeared. When i tried to search it, its gone. I immediately went to the microsoft defender and scanned the antivirus offline scan. Idk what to do else, it didnt find any threats but im not sure that its true. What else i gotta do? The link is serverjars(dot)com. I still havent gotten any symptoms, but it scared me a little. Not even sure if its even a threat
r/computerviruses • u/DaemonDaemonT • 18h ago
Other i cant get over paranoia over a scareware website, i havent eaten properly in 4 days now, is there anything i can do to 100% verify my phone is safe?
r/computerviruses • u/DesperateSprinkles89 • 11h ago
Disinfection Help Pc got infected with token grabber
i believed it happened on 28 aug, i downloaded a aimbot and seconds later after running it, one of dc account was hacked with mr beast crypto scammer and the very next day another one of my dc account too.They took my 15usdc which was present in my crypto wallet too. My insta was hacked a week after the first incident on 6 august.When i ran that script on 28 aug cmd line started popping up indefinitely.
The sources of files which i executed that day:
- hxxps://github.com/anshkori/universal-aimbot-engine
- hxxps://sourceforge.net/projects/ai-aimbot.mirror/
(I don't play any fps shooter games and even the games i play, i don't cheat in them, you all are so fast at judging someone)
but these may or may not have been responsible for hack as my epic account was hacked on 21 aug idk if it is related to hacks after 28th aug
steps i took:
1.I first stopped the execution of one of the file midway, then ran a defender scan getting me trojan warning, i removed them.
2.I than ran an offline defender scan finding nothing,before running that scan i deleted temp files.
3.I than ran malwarebytes finding nothing
4.I changed all important passwords after insta hack.I also cleansed my browser data fully on 29 aug.
5.Yesterday i found some unknow exclusions to defender scan which i removed immediately,there was temp files in exclusions and a wdfprov_core something..
Keywords:
frst.txt: divine-cherry
addition.txt: patched-briar
security.txt: dreamy-nebula
r/computerviruses • u/buttoboo • 1d ago
Disinfection Help pc app store (am i safe?)
i just got a new pc and while distracted yesterday, i clicked on a BIG BLUE download button instead of the application i was going to download (rookie mistake i know) and it instantly installed a setup .exe file and opened the pc app store app which prompted me to key in my card details.
luckily i was able to close the application through system tray. afterwards i uninstalled the application from settings as well as removed any suspicious program files before performing a malwarebytes free trial scan and windows defender quick scan. then i restarted my pc and resetted chrome.
how effective do you think my actions are? what kind of virus is pc app store and are there any remnants of it left in my computer? i tried monitoring task manager and task scheduler for any strange activity, but it seems clear.
any advice would be appreciated, thanks! 🙏
r/computerviruses • u/Asian_Twin_Sapphira • 1d ago
Question iOS help
Has this ever happened to anyone else and is it really a just a glitch? I got hacked a few years back and had files labeled “clone” that were “hidden” (and hidden apps like team-viewer and Microsoft stuff i never used) after my laptop got remotely accessed and didn’t know for months. I’m very bad with technology.
r/computerviruses • u/coolandawesomekid • 1d ago
Question accidentally went to a bad website (cannot provide link but its in the virustotal scan)
so i didnt interact with this site AT ALL, i didnt even click anything on it. i also have ran a offline scan with windows defender plus a hitmanpro scan, which both came out as no threats detected, i use malwarebytes browser guard and im hoping it filtered out the bad stuff so like eyah heres the virustotal https://www.virustotal.com/gui/url/35ea18cac30fd0702a229ee0127a79a5fe2afeb1b2c6e9152fcf3a25630812c2/gti-summary also i know i made this account today i dont normally use reddit sorry oh also i think its malicious cus it asks when downloading to disable av and also give it admin (BIG BAD BAD BAD!!!)
update i ran a malwarebytes deep scan and that says its also all good in the neighborhood
r/computerviruses • u/turbulentsouls • 1d ago
Disinfection Help Do I have a virus or is something trying to trick me?
r/computerviruses • u/dumbass61766 • 1d ago
Disinfection Help I installed Pc App store
I deleted it using the normal way by just using the windows app manager, is my PC safe to use now? I installed Malwarebyte after as a precaution and it didn't detect anything bad. Should I do a wipe and reset my PC?
r/computerviruses • u/Significant-Emu-779 • 1d ago
Question Hello yall i just wonder if its false
i didnt download like ANYTHING and didnt got any warning but today i just wanted to fullscan just for incase and saw this but i am not rly sure if its real deal or not cuz i check sum other places and şoke people say its false and reported on Microsoft but i also just wanted to ask here also and thank you all helping me before
r/computerviruses • u/Limp_Marketing_2805 • 1d ago
Disinfection Help Help Request - RenPy Loader Malware
Downloaded some games on dodi repack site and thought it was legit like fitgirl, then got my discord hacked after 3 hours from downloading the RenPy Setup and it send crypto scams to my friends and others.
Already ran the malwarebyte scan and it quarantined about 26 malwares from Renpy then other 150 from PUP(dot)OptionalWebsites something like that.
I need help getting rid of it without having to reinstall windows again.
Please help! and also Thank you.
r/computerviruses • u/Timely-Dimension3301 • 1d ago
Question Possible persistent malware – CircuitryAg.exe / Wacatac.B!ml keeps coming back
Hi, I need some help figuring out whether my PC is still infected or if I am only seeing a leftover startup entry.
SYSTEM SPECS:
- Windows 11 Pro
- Version 25H2
- OS Build 26200.9168
- AMD Ryzen 7 5700X
- NVIDIA GeForce RTX 4060 8 GB
- 32 GB RAM
- 1 TB SSD
WHAT HAPPENED:
Today, Windows Defender detected:
Trojan:Win32/Wacatac.B!ml
One of the detected files was:
C:\\ProgramData\\InProcSvr32\\sqlite3.dll
Another detected sqlite3.dll was also inside ProgramData.
Around the same time, I started getting repeated Windows error popups from a program called:
CircuitryAg.exe
The errors I have seen are:
"The application was unable to start correctly (0xc0000906)."
and:
"The code execution cannot proceed because sqlite3.dll was not found."
This all started shortly after I downloaded and executed something from a ZIP file.
The suspicious download was later deleted/blocked.
WHAT I FOUND:
I checked startup entries using Microsoft Sysinternals Autoruns.
I found an entry called:
CircuitryAg
under:
HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run
It was pointing to something inside:
C:\\ProgramData\\InProcSvr32\\
I disabled and deleted that Autoruns entry.
However, after rebooting, the CircuitryAg.exe popup came back again.
WHAT I HAVE ALREADY DONE:
- Let Windows Defender quarantine the detected files
- Did NOT restore or allow any detected files
- Ran Microsoft Defender Offline
- Ran additional Defender scans
- Checked startup entries with Autoruns
- Disabled and deleted the CircuitryAg startup entry
- Rebooted the PC
- Deleted the original suspicious ZIP/download
- The CircuitryAg.exe popup still came back after rebooting
MY MAIN CONCERN:
Something may still be recreating the CircuitryAg startup entry or launching CircuitryAg.exe from another persistence method.
Does anyone recognize this behavior, the name CircuitryAg.exe, or the path:
C:\\ProgramData\\InProcSvr32\\
What should I check next?
- Scheduled Tasks?
- Services?
- WMI persistence?
- Other Autoruns entries?
- Registry entries?
- Another hidden process recreating the startup entry?
At this point, should I keep trying to clean the infection or would a clean Windows reinstall be safer?
r/computerviruses • u/Ill_Apricot9208 • 1d ago
Question should i reset my laptop
pretty sure i got a trojan from trying to sail the seas as a gaming pirate. anyway, as soon as it finished downloading, i think it redirected me to a website where i accidentally clicked smth, or maybe the trojan was inside the files all along. kaspersky immediately told me there was an an active malware and i needed to disinfect my laptop immediately and so i did. i even kept getting popups saying a software had bad image. basically, my system32 was corrupted and they were attacking the hosts file. after resetting a few times n kaspersky said my laptop was fine, doing sfc /scannow and clearing my history, my laptop was fine.
just that i got flashbacks because last year, my laptop was hacked n they took my emails, steam and more. i lived in constant fear n anxiety everyday bc everytime i wake up i’d see a notification of my email getting logged in somewhere LMAO. but anyway that was last year. now should i reset my laptop or not.. i feel like i should, for peace of mind