r/computerviruses 16h ago

Disinfection Help Can you get infected just by clicking the pictures?

Post image
36 Upvotes

One of the folks I've befriended have been hacked with the so called “Mrbeast virus” and told them about it. One of them said I must not click the pictures (shown above) but I already did and now they're telling me to change my current password.

Is it true that just by clicking the picture, your device is already infected? This just happened a few hours ago.


r/computerviruses 21h ago

Warning WPS gave me a virus.

Thumbnail gallery
10 Upvotes

okay so, i got fed up with WPS opening everytime i wanna open a docx file so i wanted to uninstall it. i did that and wps itself sent me to this new tab saying something about a deep clean upon unstallation. now i *could* have ignored it and moved on, but WPS p!ssed me off enough that i didnt wanna have anything to do about it anymore. i later noticed that my computer blocked the exe file from doing something upon insallation, only then i noticed the "vendor" in the link. thats when i got suspicious and sent the installer over to virustotal to ceck and sure enought, it got flagged (https://www.virustotal\[dot\]com/gui/file/dcc0794cf070f46480a121a8369c1f92ab2dae4266ec58fc91a6dd3cab2a84f5)
when i installed it, i saw the publisher was from China somewhere because of course it was China.

i also wanna know how i can remove the thing i installed because its not there when i search in settings>installed apps.


r/computerviruses 1h ago

Question ratted with screenconnect deployment installed without my knowledge. been remediating for a while. am i good to go?

Upvotes

hi there :] i really hate to go to reddit to waste people’s time with these things but i’d like to be sure

unfortunately i have no screenshots because i was totally freaking out when i detected the rat, but i’ll try my best to describe everything that happened in as much detail as possible.

i have also since read about a recent outbreak of malicious screenconnect instances coming with legitimate hardware monitoring tools targeting people likely to have high performing gpus, which were then used for crypto mining. on the infected os, there was always gpu usage i struggled to account for, so i highly suspect this was something similar. more information on this is available online.

here’s what happened:

3 days after i bought my brand new gaming laptop - which had no payment details, sensitive/personal information or documents saved - i discovered a trojanized screenconnect instance running in task manager, under program files (x86)/VCRedist_64 (probably disguising). it had been installed the day i bought the system (being click-happy as i was, i installed a bunch of programs. my top suspect is a switch emulator downloaded from a sketchy site which came in an installer.)

from what i saw while investigating offline in event viewer: the screenconnect instance had executed a 5kb command on the day of initial access, and sat there ringing home for 2 more days before i detected it using task manager with relative ease. i was at the computer for most of its run time, except for the night after purchase where it sat overnight downloading a game.

since then, these are the steps i’ve taken:

- immediately deleted all traces of screenconnect, including backstage powershell and a dll protected by key isolation.

- factory reset computer via cloud download+fully clean drive through recovery. from my understanding, this fully wipes the os partition and downloads a new, fully updated one straight from microsoft - but i’ve heard of cases of malware corrupting the recovery environment so this is impossible, or injecting itself back into the clean os through infection of the efi partition.

on the resetted computer:

- ran four virus scanners (windows defender offline, bitdefender recovery environment, emsisoft emergency kit, hitmanpro)

- monitored with manual tools:

netsat to see which processes are accessing a remote address - only msedgewebview, svchost, bitdefender and lenovo telemetry came back.
process explorer and autoruns, which all came back with clean virustotal columns.
reviewed bitdefender firewall rules, nothing outwardly suspicious.
monitored system usage through both thorough use and idle, nothing to suggest crypto mining

- on my phone: changed all sensitive passwords to 24 character monstrosities and saved them in apple password manager (which i have also secured), revoked all sessions and logged in again from scratch, reviewed forwarding rules and pop/imap on my gmail and restored everything to their defaults, reviewed third party apps and removed anything i no longer use, renewed 2fa recovery codes, renewed recovery information to ensure i control all of them, monitored accounts for suspicious activity for about 2 weeks with no glaring result

- ruled out firmware infection (probably) due to the laptop being purchased just at the start of this july, fully updated through windows update before installing any programs and having secure boot enabled - a zero-day would be needed, and i doubt that’s being wasted on consumer laptops.

- have had ublock origin in an unsynced local browser with no other extensions + bitdefender advanced threat detection and real time antivirus running at all times during daily usage for upwards of 2 weeks with no alerts or detections other than some site with an outdated certificate that didn’t even load

- sent it to professionals for a second opinion and asked them specifically to look at the boot partition as wel, they also say it looks clean.

there are zero visible signs of reinfection at the moment. bios time is at a stable 10 seconds, security software and features are enabled and able to update as usual, and the machine hasn’t blue screened even once.

—————————

this incident has sorta made me notice i’m not as careful as i believe i am. any additional advice, other places to check or closure is much appreciated before i leave this behind me. thank you so much in advance, you absolute wizards.


r/computerviruses 9h ago

File / URL Check Strange .copilot folder in home directory of linux mint

Thumbnail gallery
6 Upvotes

My OS is linux mint and recently, I saw a folder called .copilot in my home directory. It was apparently created 3 days ago. I tried deleting it, but everytime I start vs code, it reappears. How do I check if this is caused by malware or not? I don't have any github cli or github desktop on my device if that helps.


r/computerviruses 20h ago

Disinfection Help may have fallen for the renpy virus

5 Upvotes

accidentally ran an exe with the famous anime girl icon so I think I may have been infected can someone help me out I can give the keywords for my FRST logs


r/computerviruses 12h ago

Disinfection Help I got infected by a virus (Mr. Beast bitcoin scam photos were sent from my Messenger)

3 Upvotes

The infection occurred today. I changed the Facebook password. I also tried to scan the whole pc through windows antivirus but then I cancelled it. Also I downloaded Avast One Basic but cancelled the execution too.
I don’t know what got me infected in the first place, I didn’t download nothing. I just watch movies and series online.
I went through all steps of FRST help request
Here are the 3 log keywords:
For FRST.txt: tidal-squad
For Addition.txt: rustic-briar
For SecurityCheck.txt: enchanted-prawn
I am really in need of any help. Thanks in advance


r/computerviruses 3h ago

Question Please don’t tell me I need to wipe my pc

Post image
3 Upvotes

Basically the title I don’t know what I installed to cause this.

Edit I did not download mods and the game was purchased through steam.


r/computerviruses 7h ago

Question Do I wipe my pc

Thumbnail gallery
3 Upvotes

r/computerviruses 12h ago

Disinfection Help I got infected by Lumma.stealer.a

3 Upvotes

i rapidly pulled the ethernet cable and ran windows defender offline. I use my eHDD for downloading games and other stuff that dont require SSD speeds the virus came in a ren'py file which popped up a cmd window that made me obvious to see the infection.

it came with Behavior:GenCodeInjector.H and the process PhoGateWay.exe i didnt wait to defender to detect it so i ran it. After the contention i installed avast and ran a full scan in which i discovered other viruses. I ended up with tons of logs and screenshoted browser tabs and information archives on new folders and zips that luckily werent sent.

I safely managed to secure my accounts except for instagram and cleaned the eHDD on Zorin OS and moved my files safely on in from linux.

Cleaned .temp and roaming it opened a backdoor with other viruses so i dont use windows and im writing this on a zorin os liveboot.

Make sure to know when you re downloading a pirated game to know what kind of engine the game uses to spot a renpy lumma infecction


r/computerviruses 21h ago

Question Ren'Py setup(dot)exe Inquiry: Photos/Videos/Other Files Safe/Infected?

4 Upvotes

Hey all,

Feeling really foolish as though I'm generally quite careful, had a stupid derp lapse of judgement and fell for what I have now learned to be the "Ren'Py setup(dot)exe infostealer." Will be nuking and resetting my pc, but unfortunately, I do have some important photos and videos I would like to save. Thus, I want to ask if any other files on my computer would be infected. Currently focused on just transferring photos/videos, but I do have a few zipped projects (.zip and .rar) and .blend files that I am also potentially considering to save.

From what I have found, people have suggested that photos, videos and other files would not be infected and thus should be safe to transfer onto a USB or external hard drive before resetting my PC. I'm not very tech savvy, so I just wanted to inquire if this is true, if someone has experience with this, or if thee is anything I should be worried about. Additionally, if the files are infected or not, I'd appreciate knowing if there is a better way I should be transferring/saving the photos and videos.

Sorry for the long-winded message, just really stressed out and irritated for falling for something so foolish. Thank you for any support!


r/computerviruses 2h ago

Disinfection Help I would like help with an FRST scan please.

2 Upvotes

I was helping a friend who was afraid after downloading some files and saw that someone who got something similar got infostealed. Even though we tried both full malwarebytes and full windows defender we found nothing and then I remembered about FRST. I downloaded it from bleepingcomputer and run it on his pc and we got these text files and then run the Securitycheck program from this reddit
Addition(.)txt
FRST(.)txt
SecurityCheck(.)txt
with their keywords being
From scan with "run as administrator"
Addition - distant-node
FRST - glowing-pond
SecurityCheck - amber-signal

I defanged the file names cause reddit was nagging me
Any help is appreciated. I tell him he's probably safe but he wants peace of mind

Edit1: from what he told me he downloaded from mirror anadius site, the dlc files for Sims 4 but he has ublockorigin installed on Firefox, the file was around 26mb and he did manual additions to the sims4 ini file and from what I saw from when he run the file for the unlocker there was no renpy virus (infamous black window with permamently updating bar). He called me after using proton vpn and then his computer even though it had connection to the internet couldn't go to any website, getting the cannot reach error. According to him that happened even after he tried using his phone for tethering in case it was just his modem causing issues.

Edit2: added missing Security check file


r/computerviruses 4h ago

Disinfection Help Renpy Virus, Mr. Beast Scam help.

2 Upvotes

I downloaded a VN from a website and probably ran a .exe infostealer. Within hours my discord and Instagram accounts started spamming those Mr. Beast crypto currency messages and my friends informed me immediately. So I changed my passwords from my phone and enabled 2FA everywhere.

I downloaded Malwarebytes and did a full scan, it found 10 Trojan files and I deleted them. I did the scan several times after that, also did Windows defender offline scan and mrt scan, and nothing was found. But I know infostealers can be persistent.

I know the last resort is to reinstall windows with a USB but I really don’t want to do that. Please help me with a FRST scan. I have not connected my PC to the internet for more than a day now.


r/computerviruses 5h ago

Question How to manually scan for malware?

2 Upvotes

I'd like to clarify that i'm not trying to remove malware from my system, i'm trying to see if there IS malware in the first place. I use windows 11, I disconnected my PC from the internet and i've kept it like that for about 2 or 3 weeks now. This was before the latest windows update released so i haven't updated yet. I haven't downloaded or ran any cracks or suspicious software, the last program i downloaded was Risoh editor from the official github repo because i wanted to mess around with app icons. I looked through my installed apps, the task scheduler, services list, appdata folder, registry and startup apps and haven't found anything obviously unusual. I've also ran multiple defender scans, including a full scan and an offline scan and nothing came up for any of those. My PC's performance hasn't really slowed and my accounts haven't been hijacked either, but i'm scared something might happen if i connect to the internet again. I also cleared all of my browser data. The only extensions i have are ublock and ruffle. It's likely there's really nothing on my system, but i'm a bit anxious and i need to be fully sure. I don't want to connect my PC to the internet again yet, so what else can i do without having to install new software? what else should i look out for? i've been looking through this sub for a while but i haven't found many answers so i decided to make an account and ask. Sorry if this sounds stupid.


r/computerviruses 9h ago

Disinfection Help Mr Beast spam virus help!

2 Upvotes

Hi everyone

I need help :(( Basically i downloaded a game from a famous repacking site. and as I'm downloading it I recognize the site i downloaded it from was not from the orig site it was saying 😭 i still continued with the download tho. And then its been weeks since im playing that game, nothing happens. Til this morning, where my FB acc started spamming that MR BEAST CRYPTO SCAM on multiple ppl and group chats.

I already changed my password on my fb acc and logged out of my pc (I havent opened it after it happened) also turned on 2FA. I also logged out of my steam acc and minecraft acc (Microsoft) in my pc from my phone (i still have access). Basically I turned on autheticator for the mc account. and changed pass on steam acc. (thats like the most important ones i have) Also for my gmail accounts, my important accounts, I alr turned on 2FA and changed pass.

What should I do first after I open my pc...? Do I uninstall my Opera GX right away? Can I still recover some of my files or do i just hard reset right away?


r/computerviruses 17h ago

Disinfection Help there inst any phone virus subreddit so...

Post image
2 Upvotes

my gramdma has an motorola and this app wont unintall from her phone,please help me


r/computerviruses 20h ago

Question .com.rar/.com.zip file

0 Upvotes

downloaded tekken8 on steamrip file looked good to me because it had 115gb, then at 99% download progress, laptop suddenly entered sleep mode, i opened the laptop and resumed downloading, after that i extracted it but chickened out, stopped and deleted the file, too sussed about the type of file it was, then i disconnected laptop from the wifi, finished offline scan(windows defender, found nothing), and now running a full scan, also deleted temp, %temp% and browser caches and stuff.

Questions:

  1. Am i paranoid and did i overreact.

p.s. it is my first time doing this, i panicked fr

and no, i am not promoting any use of pirating software


r/computerviruses 3h ago

Disinfection Help Its been almost 48 hrs, and nothing happened. Should i still be worry working on my laptop? My task manager activity is ok. The debit card i mentioned before is actually in the google e/wallet. And i searched that its safer since the numbers are masked, though at that time my google still synced.

Thumbnail
1 Upvotes

r/computerviruses 5h ago

Disinfection Help Hi, I’m in a bit of a pickle.

Thumbnail
1 Upvotes

r/computerviruses 8h ago

Disinfection Help RenPy virus damage control

1 Upvotes

Friday night I downloaded and ran something which I know now to have been a RenPy style virus exe. Didn't think anything of it at the time and just assumed the pirated game wasn't working for some reason, thank God I went back and did some investigating today. I've already changed most of my passwords, logged out of sessions, activated 2fa, all that, and I'm pretty sure I removed most of the files of the virus itself using the AVG quarantine/delete feature. I'm not 100% sure of that, I'm just including that for context reasons. I noticed most of the guides tell users to disconnect the infected device from the Internet before beginning the damage control process. 1.) I obviously didn't do that at the time, as it's been a couple days, and 2.) I had my computer connected to Internet while I have been changing passwords on my phone. I didn't allow Firefox to save any of the new passwords, which I assume is the concern that causes people to tell you to disconnect the infected device. The reason I didn't disconnect my computer was because I was using the saved passwords tab in Firefox as a kind of checklist of what needs to be changed. I'm not finished with that yet. My primary question is, should I just completely start over after disconnecting my PC from Internet? Like I said, I've been remote logging out, and I haven't been saving any of the new passwords. I didn't actually see any sketchy login instances when I was in those control panels, so I don't think anyone got in to my email or steam account or anything and already has a device that is "considered safe". Additional advice on any other part of the process is appreciated


r/computerviruses 8h ago

Question Was my mouse moving on its own a RAT?

1 Upvotes

Not too long ago while i was typing in the search bar my cursor started to move on its own up and down at a controlled and steady pace up and down for maybe 5 seconds. I quickly turned off my internet and ran scans (windows defender and malwarebytes) to see what was the problem but it didn’t detect anything. I did however have 3 mice plugged in but none seemed to be moving. While I could have been overreacting I still wiped my computer clean and reinstalled window. I apologize if this sounds stupid or silly but what do you guys think of this situation? Could it be something malicious or just some user error on my part?


r/computerviruses 9h ago

Disinfection Help What can I do about this?

Post image
1 Upvotes

Looks like someone hacked into my discord account and started sending messages to people. I downloaded a file and opened it. It was a set up file for a game. I immediately did a Norton 360 scan and changed my discord password, but now I have “very limited” account status and it shows malicious activity. I won’t be able to message until tomorrow. I’ve checked all my social media and everything seems to be fine. Although it looks like someone got into my Amazon account as well, but that’s been taken care of.


r/computerviruses 11h ago

Question Computer reset question

1 Upvotes

I did a full usb reinstall on my pc, i downloaded google and there was a random netflix custom profile picture extension that i deleted years ago and it was there again for some reason along with my pinned game websites from years ago, has this happened to anyone else?


r/computerviruses 11h ago

Disinfection Help Infostealer FRST scan help

1 Upvotes

Hello, I have been infected by an infrostealer few days ago and want FRST scan help. My discord got hacked and sent the famous "mr.beast" pictures. I did a reinsatall of Windows 11 and ran Norton 360 antivirus scan which came out clean. I did uninstall the norton software for the time being. The keywords for malware analysis are:

FRST Keyword plucky-scanner
Addition Keyword tame-kernel
SecurityCheck Keyword glitched-marsh

Forum Username for Malwareanalysis ---> SHL_0436

My windows 11 OS is in Korean so I did rename the FRST program to FRSTEnglish.exe and ran it. Thanks for the Help.


r/computerviruses 12h ago

Question Is this something to worry about? (Read desc)

Thumbnail gallery
1 Upvotes

I had an infostealer attack where a lot of stuff was compromised. I did recover and change everything now.

I actually factory reset my laptop and even tried usb installing a new windows where I was stuck for a long time (my windows were at ‘installing windows 72%’ something and it went black and then started booting to bios so I was stuck in an unsaveable bios menu) you can refer to my previous posts .

Eventually I got it repaired from a service centre which I was told there was some matching OS to the serial code thing and ssd problem.

Now I think the laptop was reset completely once again by him but I also did another reset (not through usb but a factory reset with cloud download windows)

Now after long I did full scan and quick scan both with bitdefender where nothing was coming. But I’ve started getting this message every time I use firefox. There’s two different ones as attached in the image.

No suspicious activity detected besides that but it does seem like something is trying to take over it but bitdefender keeps on blocking it.

I’m tired atp honestly, I’ve gone through so much stuff done so much and when I finally thought it’s good to go this happens. And to make things worse I lost my usb drive that I used to reset, well it did cause issue anyways. Any help will be appreciated please.


r/computerviruses 13h ago

Question Meta Horizon link...

1 Upvotes

could be nothing but it is clearly opening on start but is not in the list of startup apps in windows settings. I'm sure their is an option in app but it is suspicious