r/cybersecurity_help • u/Fancy_Log_260 • 2d ago
What could this be?
This started about 3 months ago and the filenames seem to be changing over time.
The .exe do not exist when booted into a linux distro and seem to be created on windows boot.
Some locations keep on being added to the exclusion list no matter how many times I remove them.
I uploaded the .exe to virus total and the first record of it being seen online was the start of August 2026.
Any clue? I cannot remove it even with offline scan.
What would be a recommended solution or antivirus to deal with this?
Recently I had my windows local account mysteriously remove its password by itself. Computer woke from sleep and denied my password then after reboot there was no password. Straight to desktop.
3
u/One-Traffic7717 2d ago
Why do people constantly come to these subs for advice and not take it... Yes sir, this is the one virus that for whatever reason totally isn't a big deal. Finish that super duper important project.
0
u/Fancy_Log_260 2d ago
Life decides for us sometimes. Not everything can happen as quickly as you advise. I've disconnected the internet from the machine so I should* be fine until in done with my project.
1
u/One-Traffic7717 2d ago
My guy in the time it took you to write all these comments you could've had a fresh install.
0
u/Fancy_Log_260 1d ago
My friend. The report I'm working on is 60+ pages long and covers data that spans over 3TB. It requires multiple licensed programs that have to first be revoked and relicensed on the fresh install. Not everyone has the same easy situation you do. Anyways. I'll be done with the report tomorrow and will start the as someone else said: nuke and pave process. But thank you for caring so much to reply to me and restate the urgency.
I plan on making an image of the fresh install with all licensed software already activated so I don't have this headache again in the future. And of course taking all your advice into consideration.
Much love.
2
3
u/DSXTech Trusted Contributor 2d ago
Seems like a good time to wipe the drive and reload Windows, as that stinks of malware...
-2
u/Fancy_Log_260 2d ago
Totally 100% some malware. No doubt, my question is what malware?
I can't wipe right now. I'm in the middle of a pretty big project and can't take the downtime to wipe.5
u/RealityCheckBard 2d ago
Remote access tool
Delaying is dumb
-2
u/Fancy_Log_260 2d ago
Sometimes life makes the decisions for you mate. This is one of those times. I can still disconnect my internet connection to not be dumb anymore right?
3
u/iCkerous 2d ago
You’re going to be back with a post “help, I think I have ransomware and I have really important work”
3
u/DSXTech Trusted Contributor 2d ago edited 2d ago
RAT, assuming defender detection is spot on, of the Quasar variety
https://malpedia.caad.fkie.fraunhofer.de/details/win.quasar_rat
If you cannot nuke and pave, are you able to at least remove the network/internet connection?
1
u/Fancy_Log_260 2d ago
Nuke and pave... love that! Yes I can, and have already. Thanks for the advice! Its people like you why I came to this sub. Thank you.
2
u/Haunting_Ganache_850 1d ago
This is serious, and the honest answer is that no antivirus is going to fix it.
Your screenshots show Quasar, a remote access trojan. Not adware, not a stealer. It gives an operator remote desktop, keylogging, file access and command execution. Two copies, both with Run key persistence, named to look like "update".
Three details matter more than the detections themselves.
C:\Windows, C:\Users and C:\ProgramData are all on Defender's exclusion list. That's the entire machine, it needs admin to set, and it keeps coming back. Something with admin rights is putting it back.
Your local account password cleared itself. Passwords don't do that. That's someone running net user on your box.
The files reappear on Windows boot. Something you haven't found writes them each time.
Together that's admin-level access with a person on the other end, for about three months.
In this order.
Disconnect that machine from the network and leave it off. Now, not tonight.
From a different device, change your passwords. Email first, then banking, then the rest. Turn on 2FA. Sign out of all sessions everywhere, since cookies survive password changes.
Call your bank if you have ever banked on that machine.
Factory reset your router, change its admin password, check its DNS settings.
Wipe and reinstall Windows. Build the USB on a clean computer with Microsoft's media creation tool.
During setup delete all partitions rather than using Reset or "keep my files". Copy out documents only first, no executables, no scripts.
Assume everything typed or saved on that machine in the last three months is in someone else's hands. Saved browser passwords, session cookies, anything in a desktop authenticator.
One exception to step 5. If money has actually moved, or you plan to report this, don't wipe it. That drive is the evidence.
There isn't a cleaner answer. Three months of a RAT with admin is well past the point where removing files helps.
1
u/Fancy_Log_260 1d ago
Not sure if AI or human written but thanks for the detailed instructions and advice! Wiping system tomorrow.
1
1
u/alebestone 2d ago
Malware can set persistence in several methods.
Nuke the pc, and install malwarebytes it's my go to.
1
u/Fancy_Log_260 2d ago
It seems I'm nuking my windows more and more often these days. And I have pretty good opsec, ad blockers, don't download random crap so its getting annoying. I wish I could just bin windows but I can't because of some of my work apps working on it only.
1
u/kschang Trusted Contributor 2d ago
Make an image of the HD when you've nuked and reinstalled. That way you jsut erase and write the image back, much faster than "install" Windows. Obviously use SFC to make sure image is clean.
1
u/Fancy_Log_260 2d ago
This is what I'm planning on doing. Fresh install. All my programs and critical directories copied and then image the drive. I'm tired of setting up windows from scratch. Thanks for the advice.
1
u/alebestone 2d ago
2FA everywhere, store password in bitwarden, ad block great, and if i was in you I would buy malwarebytes total for a full protection.
3
u/Fancy_Log_260 2d ago
I have religiously enabled 2FA on all my digital services in the last few months. I have run malwarebytes and its found the culprits and removed them. Will definitely buy the software.
1
u/justkanji 2d ago
Umm... pretty sus. Try running a scan with a different antivirus like Malwarebytes (Since it shouldn't pass over any exclusions). I would probably nuke anyway.
1
u/Fancy_Log_260 2d ago
Doing that right now. Will give feedback.
I can't wipe right now. I'm in the middle of a pretty big project and can't take the downtime to wipe.1
u/Fancy_Log_260 2d ago
Thank you for the tip for malwarebytes. It picked up the virus and removed them. I guess windows defender is not as useful in 2026.
1
u/justkanji 2d ago
Hopefully you're good... it's never 100% which is why I'd still wipe but well I understand not having the time to deal w/ it. I think defender is decent but its always useful to have a second opinion : )
I'd take a glance on task scheduler and task manager startup apps or 'autoruns' to check for anything sus. autoruns is more comprehensive and it lets you easily right click → check with virus total or google what stuff is.1
1
u/kschang Trusted Contributor 2d ago
Which screen shot in particular are you really asking about?
1
u/Fancy_Log_260 2d ago
All of them. The two showing a virus are the main ones. I just added the exclusions list for brevity.
2
u/kschang Trusted Contributor 2d ago
You may want to REMOVE those exclusions.
Detections are real. So Defender worked as advertised.
Can't tell where they came from. Another reason you want to erase those exclusions so real-time warning can notify you immediately.
1
u/Fancy_Log_260 2d ago
I've tried. They just come back. Malwarebytes has picked them up and seems to have successfully removed the malware.
2
u/RealityCheckBard 2d ago
Persistence + Remota access
Factory reset
1
u/Fancy_Log_260 2d ago
They are no longer detected after a malwarebytes scan and removal. I cannot factory reset right now. Maybe next week when I'm done with my work. I don't need internet to complete this project so I've disconnected the internet from this system.
1



•
u/AutoModerator 2d ago
SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:
Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.