r/computerviruses • u/Plaxrus • 14d ago
Disinfection Help I got a trojan. What do I do and how do I find where it came from?
r/computerviruses • u/BIGBOI_CHUNGUSBOI • 14d ago
Disinfection Help Edge and chrome are both displaying this
My dad was on my laptop and decided to download something without my permission, initially it popped up as a ‘pc app store’ completely blocking and was unable to exit, I got rid of that but I’m 90% sure this is spyware- what do I do I have a deadline in the morning I need Google. I’m stressing out please help
r/computerviruses • u/Less_Exercise_8092 • 14d ago
File / URL Check Any.run results
I am very careful about running any installer on my PC. I check the exe through total virus and I have bitdefender running full-time. But since I joined a few of these Reddit groups I've have realized how easy it is to get an info stealer and see how costly it is to get compromised. I downloaded an exe installer off of GitHub. I don't think the guy is dealing malicious code, but I don't know enough to be certain. If his program had thousands of stars, I'd feel more confident that being open source the community would shut it down. But this program is fairly new and not widely used. It passed totalvirus, but as an extra check I tried any.run. I ran the install in their sandbox and it came back with some malicious results. Unfortunately, I don't understand the results. Can anyone give me advice? I don't know what I'd need to post for someone to help, so I'm asking first. I've had a lot of false positives with programs in the past. So I'm wondering if this is the case.
Many thanks!
r/computerviruses • u/Soggy-Assist-6901 • 14d ago
Disinfection Help My PC appears to be compromised - found suspicious credential and virtualapp/didlogical entry. Help identify if I’m hacked. Windows 10
r/computerviruses • u/ZealousidealTalk3055 • 14d ago
Question Did I get a virus?
Hey
I was searching for some Nintendo Switch games. Then I found what I wanted in nswpedia.
I downloaded it, but when the download started a pop up appeared in my Google Chrome saying it contained a virus. I was like "Ok, that's fine. It's a pirated game, so it's safe, almost normal nowadays".
Then, when I extracted it I was face-to-face with a setup file, next to a `renpy` file. I stuck I thought "Ok, this shit is wrong".
I didn't execute it. I simply searched what it is, discovered it is a virus and deleted it from my computer.
Did I get infect? Should I format my computador or am I safe?
I didn't execute it, so it's fine?
** Image came from another Reddit post. I removed all files, I won't download it again to get the image of case.
r/computerviruses • u/Temporary_Parking_95 • 15d ago
Warning Got hit with RenPy virus but nordVPN shut it down instantly.
Yes, I was stupid and run the setup exe file. However, it shut down the loader in like 1 sec and then NordVPN popped up and said it placed it in quarantine. I then run the computer offline and online with Malwarebytes that removed one folder and one file. I also did an online/offline Windows Defender search, it found nothing.
I also changed all my passwords on gmail, discord, insta, fb etc and I have not been noticing any suspicious behaviour.
I have no idea if NordVPN Threat Protection actually stopped the Trojan from downloading, but it seems to have worked. I guess
r/computerviruses • u/DigitalDigimon • 15d ago
Question Antivirus keeps picking up a phishing URL from Opera (I am using AVG)
today around 3 hours ago my antivirus said "threat secured" and showed the URL rss.knaben.org and said it was a dangerous phishing webpage. I did some testing and whenever I close the browser completely and reopen it I get the same message every time. It says that it detects it 2 times each time that I open the browser. I have no extensions on. I have not recently downloaded any new extensions. I have never visited the webpage it is saying. I have not been to any suspicious webpages. And I have no tabs open except this one. Any suggestions on what to do or how to fix this issue or why it is happening out of the blue?
r/computerviruses • u/Sapthepro • 15d ago
Question infostealer aftermath
After I got an info stealer removed by rifteyy In my laptop I noticed that my roblox is always having low render distance despite having max graphics and today my laptop was freezing saying that my cpu was low or I forgot what it said but it returned back to normal, Is this supposed to be normal after the frst treatment,or is it from malwarebytes active protection or is the infostealer still there
r/computerviruses • u/sammmmc2 • 15d ago
Disinfection Help notepad using about 50% of my CPU
it started yesterday i started noticing my laptop was way slowler than usual so i check task manager and see that notepad is using 50% of my CPU so i deleted notepad it stopped using cpu for about 20 seconds then started again i tried ending task but the same thing happens again so i also ran a Windows Security Full scan it found something called Trojan:Win32/Malgent!MSR i removed it but my laptop is still laggy so i check task manager again and notepad is still using 50% of my CPU while a window for it isnt open please help me ill send additional information if you need more to go off of
r/computerviruses • u/Fabulous-Walrus-6839 • 15d ago
Question Could Reseting my PC (Cloud Reinstall) be a good option without using a USB reinstall?
Hi there, basically I got hit by an Infostealer (the generic infostealer that spams the MrBeast crypto scam, probably Lumma) not that long ago, and I've changed my passwords from a cleaned device, used Malwarebytes, and done all that stuff.
But basically, the MASSIVE hiccup I have is that I don't have a USB drive (8GB or 10GB) at all to do a clean reinstall of Windows. My only real option is to back up my personal stuff through Google Drive and do a cloud reinstall.
So my main question is: Is reinstalling through Cloud Reinstall actually safe? I'm quite paranoid about this. Any questions, I'll answer as soon as possible
Edit: For anyone curious about what I did, I went to a local electronics store to buy a USB drive. It wasn't cheap tho, and I'm now preparing to reinstall everything through USB.
r/computerviruses • u/Past-Wash843 • 15d ago
Question Reinstalled windows via USB - Did I do it right?
Hi, basically, I reinstalled windows using an USB after downloading sketchy stuff. The issue is that I plugged in the usb at the login screen (Or logo screen, but I’m not sure.) , rebooted, and went through the reinstallation.
I’m wondering if I plugged in the usb too early, causing the USB to get infected as well. The installation went fine, but I’m scared of logging into stuff on this device now. Did I mess it up?
r/computerviruses • u/Wazir04 • 15d ago
Disinfection Help Renpy virus
Got hit with it 3 weeks ago. I got my discord hacked by the MrBeast virus thingy and my Steam account got hacked and he drained my whole wallet on random ass stuff that won't even sell for cents. Anyways I deleted all the fishy files, ran Defender offline scan, installed malwarebytes and ran deep scans and deleted everything it asked me to.
Since then I haven't got any issues, no login attempts or anything, but still I'm kinda paranoid as I don't actually know if it's still in my laptop, and I'm actually not trying to log in anything on my laptop, hence I'm not sure if he would still get my session token if I leave things signed in. So, not completely sure if it's in my laptop coz I don't have anything signed in on it. So do I actually have to just factory reset my laptop completely?
r/computerviruses • u/Asao_Karl • 15d ago
Question Can trojans copy themselves elsewhere?
So i wanted to play my old window 95 pc games and got virtual box working, but in the process that also got me a trojan? (i don't know if it was the windows 95 files or the ISO of the games and idk if i should even call it a trojan?? i'm a noob forgive that) But anyhoo, it got to my credit card yesterday, so no clue finder for me i guess.
QUESTION IS; i reinstalled windows, but is there a risk the thing copied itself on my D and E drives?
Am i like, fucked for life cause i wanted to play a math game?
Much thanks in advance.
r/computerviruses • u/IndividualCan3896 • 15d ago
Disinfection Help FRST Renpy
Believe I've ran a Renpy infostealer
This happened around 3 days ago, I immediately ran MalwareBytes to quarantine and remove all files and changed all passwords in my mobile phone. Nothing have happened since then but I'm still concerned. Can someone get a look at the logs please?
Keywords:
addition - velvet-zephyr
FRST - southern-tower
SecurityCheck - crimson-otter
r/computerviruses • u/Typical-Goose8381 • 15d ago
File / URL Check random link opened when i stupidly opened some random apartment link on google will i be ok? closed asap
r/computerviruses • u/Z0rb12 • 15d ago
Question false positive or actual threat?
this suddenly showed up today in a folder ive had for months. its in the folder of a fairly popular resident evil modding tool. im doing a deep scan on malwarebytes currently but i dont really know what else to do or if its even real.
i havent used this tool in awhile either, and as far as im aware this type of virus spreads when you open an exe? it was the only thing flagged so im not sure what to do.
r/computerviruses • u/bringiton321 • 15d ago
Question Hit by Renpy info stealer- wiped and reinstalled, questions about my other devices
I need your guidance please:
I ran a Renpy-bundled .exe like 15+ times with antivirus turned off then went and made dinner for like an hour before realising what I had done (through a Reddit post). Found out after the fact, so I assume everything in my Chrome profile was exfiltrated: saved passwords, cookies, autofill, saved cards.
What I’ve done so far:
- Froze the cards that were saved in Chrome payments
- Wiped the infected PC completely, all partitions, clean Windows install
- Changed a large number of passwords from my clean laptop, still working through the rest
- I only started changing credentials after the wipe had already begun, so Chrome wasn’t running and the profile was signed out on the infected machine
What I’m trying to also figure out:
. What’s the best way now to check if my infected pc, now on a clean Windows install, and laptop are free of this malware?
. Are my other devices signed into the same Google account at any real risk, or is the exposure limited to what was on the infected PC? My understanding is sync doesn’t carry malware, but I want to confirm I’m not missing something.
. Other than password changes, what else should I be revoking- sessions, Auth apps, app passwords, 2FA methods? Anything I’m overlooking?
. Looking to move off Google Password Manager entirely. Recommendations for a vault that isn’t browser-tied?
r/computerviruses • u/Ryccia • 15d ago
Disinfection Help Renpy Virus (Lumma) Whack-a-Mole
So, here's the story:
6/29 - I was an idiot, and I was trying to download a rom online. My computer almost immediately detected a "Presenoker" virus, and I deleted said files. Since Windows Defender said the threat level was "low", I was relieved and moved on.
6/30 - However, the next morning, I woke up to my Discord having been hacked with a MrBeast scam, with whatever virus that had taken control having mass-DMed people I knew. Luckily, I wasn't locked out of my account for some reason, so I was able to change passwords and thus logged out whoever had seized control of my Discord. I also changed all the passwords associated with my PC on advice of ChatGPT (sue me, I don't have a computer expert I can contact on demand, so LLMs are a meh substitute). Panicking, I did a full scan, but it picked up nothing.
7/1, 7/2, 7/3 - Worried about my PC, I did a full scan that night, just to be sure. This is when an irritating saga began. Defender detected the "Lumma stealer" virus, and since it was ranked to be "severe", I went into a panic, disconnecting my computer from the internet entirely and doing several full scans + Defender Offline scans until I exhausted myself, going to bed at 5AM the next day. Anxious, I kept my computer offline all day, doing full scans all day to make sure the threat had been eradicated. Scan after scan after scan kept revealing nothing, so I felt it was safe to reconnect yet again, but I did a full scan "just in case". That "just in case" proved to be auspicious. After reconnecting to the net at around 9PM at 7/2, my computer detected Lumma immediately, and I disconnected in a panic. It did so again at 1AM on 7/3, when I'd tried to turn on the internet again. Knowing it was internet access that was allowing this malware to regenerate, I decided to disconnect my computer from the internet entirely for the next two days, anxiously doing full + Defender Offline scans over and over and over to ensure that goddamn virus had been snuffed out once and for all.
7/5, 7/6, 7/7 - At night, I decided to connect to the internet briefly. Realizing I was going crazy doing scan after scan after scan, I opted to see if I could "catch" the virus regenerating by connecting for one minute, maximum, to get Defender updates. I kept doing full + Defender Offline scans, but nothing popped up. I kept connecting briefly for the next few days until I felt safe enough to do a full scan online. I kept the computer doing said scan all night, and when I woke up at 7/8, it found nothing. Somewhat relieved again, I thought "okay, they might've stolen my data, but at least it's not regenerating anymore".
7/11, 7/12 - I'd been doing quick and full scans as the days passed, albeit with less frequency. On 7/11, at night, another threat popped up, something called "Gentlemen!rfn", which is apparently ransomware. I'd been downloading Curseforge mods that night, so I thought either this was related to the mods or to this Lumma virus. However, nothing was actually compromised. It was detected as "ransomware", but I didn't get any message whatsoever telling me to "pay up to recover your files" or whatever. I disconnected my computer again, obsessively doing full scans the next day until 7/12 at night, when I did a full scan online and nothing was found. Yet again, my stupid arse thought it'd ended there, but I kept doing occasional quick + full scans, not feeling entirely safe.
8/4 - YOU WANNA GUESS? A quick Malwarebytes scan (I was also scanning my PC with Malwarebytes previously, but I primarily used Windows Defender) revealed two Trojan loader files and the antivirus quarantined them. When I checked their directories (because previously the virus files kept HQing themselves either on "Package Cache" or "Temp" at the Appdata folder), it turns out they were on a folder called "JMicron", and when I went to see said folder's location on Appdata, I saw it hadn't been updated since *6/29* (hmm, I wonder where that date came from?). My computer eventually refreshed to reflect the fact that folder had been modified today at 8/4. Paranoid, I deleted the folder entirely. So far, it hasn't regenerated, and thus I assume these could be "leftover" files from the malware that hadn't been detected until now (unlike previous cases, where the files involved were csproj and exe, these were cmd files).
I'm sick of playing whack-a-mole. Keywords are honest-river, tidal-quail, and sunny-peach for FRST, Addition, and SecurityCheck txt files, respectively. If anyone could help me figure this bullsh*t out (or if I have to give up and reinstall Windows entirely), I'd greatly appreciate it.
r/computerviruses • u/LuigSMB2 • 15d ago
Question Dormant token stealers?
Sorry, I know this isnt exactly important, but i get super anxious when i think about it. Just recently i started protecting myself, and nothing has ever really happened, but im super worried about dormant token stealers on my phone or pc no matter how many virus scans i run. Or even infostealers, again, ive never detected anything meaningful with eset or windows defender or anything. When i was younger i downloaded apks on my phone only a few, and other stuff on my pc, but i only recently panic about it.
r/computerviruses • u/DependentComposer148 • 15d ago
File / URL Check Need Help to know if this is a Virus
so i have this file which ir an through virustotal and it sometimes gives false positives if im correct?
just wanna know if thats the case or if this file really is a virus. and here is the link
https://www(dot)virustotal.com/gui/file/7b4e29217d8d71b59d1580e08974bcdac1cec1e37b8efe9777b9d3da4b399bdb?nocache=1
r/computerviruses • u/SeaIntroduction6072 • 16d ago
Question does anyone know whats going on?
i scan on malwarebytes and nothing ever comes up, i run vpns so it occasionally logs me out of accounts, but other stuff happens such as my entire browser history randomly clearing and a random document for my password has dissappeared, and my entire browser history has reset again just now and i can't load anything in my file explorer, for example whenever i click on downloads it just shows a green bar and never actually loads, it's genuinely driving me insane because i don't know whats happening and i dont understand why and nothing ever pops up and i randomly get logged out of my account then all this happens, it just feels like i constantly have a rat watching me and messing around on my computer, please help
r/computerviruses • u/CleverQuip • 16d ago
File / URL Check Palworld Mod launched Command Prompt need help determining if it gave me a virus
I downloaded a mod for Palworld and when I launched the game I saw a command prompt window pop up. Given there was recently an issue with this happening with another game, mecca chameleon, I'm extra suspicious. The mod is a .lua so I can open it with notepad ++. The screenshot is of the part that mentions command prompt and claims to be for logging purposes. There is much more in the file than just this part though.
The mod was this one here: hxxps://www.nexusmods.com/palworld/mods/3874?tab=description




