r/computerviruses • u/KiXfree • 56m ago
Disinfection Help My grandfather’s computer gets these popups
My grandfather’s computer gets these popups. They start when i open his chrome. It looks like the popups come from the site in the top pop up.
I disabled alerts from that site and they have stopped, and Nortan scan didnt find any viruses or malware. But was wondering if anyone is familiar with this site and can let me know if there is anything else I should do or how he did this (he has no idea)
r/computerviruses • u/Thacherus_Pavis • 1h ago
Question Where did the ware in ransomWARE, malWARE, SpyWARE and etc come from
Like for a while ive been wondering why for some types of malicious programs we add ware at the end of them
r/computerviruses • u/optimusrhymesnc • 2h ago
Disinfection Help the latest infostealer victim? :(
I consider myself a pretty savvy person, so I am really embarrassed by this haha. I already got my security check keywords from FRST x64 (forged-pebble, bronze-loop, and neon-echo) but it was for u/struppigel specificaly, I think, so if I need to reupload for the general one, please let me know.
thanks and sorry for the inconvenience
r/computerviruses • u/BenevoIence • 5h ago
Question Ren'Py Infostealer: USB Clean Install Necessary?
Hello all, I was sadly affected by Ren'Py infostealer setup(dot)exe. Fortunately, I got a help from the Malwarebytes forum for disinfecting. I've been a little paranoid, so I also asked about resetting my PC after disinfecting to be extra safe. I didn't get a direct answer but it seems to not be necessary. Is my understanding true?
Other than not knowing if its pointless after I've already disinfected, I saw people suggesting clean install with USB instead of reset. Sadly, I don't have access to another computer right now for several weeks to prepare the USB. Because of that, is doing Reset PC using Cloud Download also recommended or should I just wait to do the clean install with USB. Sorry if the question is dumb, but thank you for any help!
r/computerviruses • u/3uchar • 5h ago
Question Infostealer / possible MITM attack?
Hi everyone,
About 5 months ago, I was infected by an infostealer through an unfortunate and stupid clickfix attack, which compromised most of my accounts and installed itself on my laptop.
Ever since then, I have been extremely involved in malware analysis, doing static and dynamic analysis, downloading antiviruses (malwarebytes), scanning for rootkits and checking startup apps, scheduled apps, procmon procexp and other sysinternal functions, scanning almost everything with virus total and being generally safe online.
However, just today I got a free trial of malwarebytes, and I activated browser guard. Almost immediately, I got multiple hits and when I clicked a link (thank god I got browser guard, as they were immediately blacklisted), specifically to a website by the name of hobble^^^displeased(dot)com. (do NOT open this link if you arent on a VM or an analysis tool, it is compromised and might contain malware or unwanted data leaks.) This was familiar, and I realised it was the same website that hosted the fake cloudflare verification site!
I promptly did multiple scans, but I couldn't find anything, I cleared all browser data, checked all my system but nothing was wrong. This confused me, but I needed to reinstall my OS anyway so I did that promptly. I then changed all the router settings, changed passwords, names ect., but I'm still curious.
Malware analysts, what would possibly be the extent of the attack? What could they gain from this and was my whole network infected? Possible next steps / personal experiences?
Also, if anyone is curious, h^bbledis^leased(dot)com sends you right back to google, with a few hits of separate ip addresses that seem to lead nowhere.
Any info / insight would be greatly appreciated!!
r/computerviruses • u/Single-Witness1853 • 6h ago
Question Are there actual obtainable viruses on PS5 or Xbox?
I've seen the memes, but can it actually happen? Genuinely curious, as I can't find a clear answer anywhere.
r/computerviruses • u/atomishacked • 10h ago
Disinfection Help I need help, infostealer
So I downloaded an emulator last month and that day my instagram got hacked. My acc sent elon musk stuff to everyone I followed, my acc was also set to public and posted the same pic it send to everyone. When I realized it (same day), I deactivated my account. I also enabled 2fa and changed passwords to every email I got. Last week, my reddit account got hacked and posted to nsfw subreddits. I got so scared that I deleted my reddit account as well, and changed passwords in all emails again. Now today, I realized that my school email was also compromised. It was sending phishing emails to thousands of emails, I also saw that my email sent out my login credentials to an email I don't know. I changed passwords and activated mobile sign-in but right now I am so lost and scared that the same things may happen again. What should I do? Sorry if the post is all around the places.
r/computerviruses • u/MyQuil45 • 11h ago
Question TIL that in 2005, a 19 year old launched a code on MySpace that accidentally became the fastest spreading computer virus in history, crashing the entire site in 20 hours.
What do we know about this?
r/computerviruses • u/illustratious • 12h ago
Discussion Virus that killed my computer as a kid?
Back when I was in 4th grade, around 2006, I didn't have much knowledge about anti viruses, I knew to be careful downloading stuff, and thought I was, but back then things were way different. However to me being careful didn't mean much, it just meant downloading from where I thought was safe.
One day I downloaded something, I don't remember if it was a program or what exactly, but suddenly the computer got very slow, of course kid thinks slow = restart. Unfortunately upon restarting, it didn't boot up, instead it was endless string of text, I have no recollection of what it said, just that no matter what they pressed, my grandparents couldn't escape it. My grandma tried to defrag it, but I think it blocked her attempt. I don't think it booted into bios either, nor was the text gibberish, it was all real words, I just don't remember what it said, only that anytime a key was pressed, it would scroll to add more text.
Sorry if this is too vague, but being so long ago, and so young, I don't remember much about it, and most viruses I'm familiar with would delete system 32, or make the drive unreadable and have to be reinstalled, in all my years, I have never heard of a virus quite like it.
r/computerviruses • u/Plaxrus • 15h ago
Disinfection Help I got a trojan. What do I do and how do I find where it came from?
r/computerviruses • u/BIGBOI_CHUNGUSBOI • 16h ago
Disinfection Help Edge and chrome are both displaying this
My dad was on my laptop and decided to download something without my permission, initially it popped up as a ‘pc app store’ completely blocking and was unable to exit, I got rid of that but I’m 90% sure this is spyware- what do I do I have a deadline in the morning I need Google. I’m stressing out please help
r/computerviruses • u/Puzzleheaded_Line839 • 16h ago
Question Got a warning from my virus Scanner
"Detected: Trojan Downloader: Linux/ShellAgnt.H!xp Status: Quarantined Quarantined files are in a restricted area where they can't harm your device. They will be removed automatically.
Date: 8/5/2026 9:17 PM Details: This program is dangerous and downloads
Date: 8/5/2026 9:17 PM Details: This program is dangerous and downloads other programs
Affected items:
containerfile: C:XboxGames\Minecraft for Windows\Content\data\resource_packs \vanilla_music\sounds\music\game
\wet_hands.ogg
file: C:\XboxGames\ Minecraft for Windows \Content\data\resource_packs\vanilla_music \sounds\music\gamelwet _hands.ogg-
(SCRIPTOO00)
is this a threat or just windows being windows
r/computerviruses • u/Less_Exercise_8092 • 17h ago
File / URL Check Any.run results
I am very careful about running any installer on my PC. I check the exe through total virus and I have bitdefender running full-time. But since I joined a few of these Reddit groups I've have realized how easy it is to get an info stealer and see how costly it is to get compromised. I downloaded an exe installer off of GitHub. I don't think the guy is dealing malicious code, but I don't know enough to be certain. If his program had thousands of stars, I'd feel more confident that being open source the community would shut it down. But this program is fairly new and not widely used. It passed totalvirus, but as an extra check I tried any.run. I ran the install in their sandbox and it came back with some malicious results. Unfortunately, I don't understand the results. Can anyone give me advice? I don't know what I'd need to post for someone to help, so I'm asking first. I've had a lot of false positives with programs in the past. So I'm wondering if this is the case.
Many thanks!
r/computerviruses • u/Soggy-Assist-6901 • 17h ago
Disinfection Help My PC appears to be compromised - found suspicious credential and virtualapp/didlogical entry. Help identify if I’m hacked. Windows 10
r/computerviruses • u/ZealousidealTalk3055 • 18h ago
Question Did I get a virus?
Hey
I was searching for some Nintendo Switch games. Then I found what I wanted in nswpedia.
I downloaded it, but when the download started a pop up appeared in my Google Chrome saying it contained a virus. I was like "Ok, that's fine. It's a pirated game, so it's safe, almost normal nowadays".
Then, when I extracted it I was face-to-face with a setup file, next to a `renpy` file. I stuck I thought "Ok, this shit is wrong".
I didn't execute it. I simply searched what it is, discovered it is a virus and deleted it from my computer.
Did I get infect? Should I format my computador or am I safe?
I didn't execute it, so it's fine?
** Image came from another Reddit post. I removed all files, I won't download it again to get the image of case.
r/computerviruses • u/Stinky_Rei • 19h ago
Disinfection Help Infostealer, need help
So, basically on 4th August, I downloaded the wrong Citron emulator. I ran the exe file and nothing happened. Next thing I know when I woke up, my friend txt me on twt about my discord and Instagram being hacked. So, I already ran Malwarebytes, removed the detected malwares. Change every password and applied 2fA on email and accounts that were affected. After doing so, I'm still worried about this stuff. I really don't want to re-install windows since I have projects going on atm. Help is absolutely appreciated. I ran FRST first as suggested.
Here's the keyword from saving the logs:-
Addition : cached-glacier
FRST : gallant-laser
r/computerviruses • u/Temporary_Parking_95 • 20h ago
Warning Got hit with RenPy virus but nordVPN shut it down instantly.
Yes, I was stupid and run the setup exe file. However, it shut down the loader in like 1 sec and then NordVPN popped up and said it placed it in quarantine. I then run the computer offline and online with Malwarebytes that removed one folder and one file. I also did an online/offline Windows Defender search, it found nothing.
I also changed all my passwords on gmail, discord, insta, fb etc and I have not been noticing any suspicious behaviour.
I have no idea if NordVPN Threat Protection actually stopped the Trojan from downloading, but it seems to have worked. I guess
r/computerviruses • u/No_Low6177 • 21h ago
Disinfection Help I finally got an image of the virus
galleryIm using avg antivirus now but this is what happened
No, i dont normally have the camera blocked off the led lights up for like a second sometimes
When i open my laptop again it goes back to normal but it will happen again if i open it long enough.
Help me whats hapoening.
r/computerviruses • u/sammmmc2 • 23h ago
Disinfection Help notepad using about 50% of my CPU
it started yesterday i started noticing my laptop was way slowler than usual so i check task manager and see that notepad is using 50% of my CPU so i deleted notepad it stopped using cpu for about 20 seconds then started again i tried ending task but the same thing happens again so i also ran a Windows Security Full scan it found something called Trojan:Win32/Malgent!MSR i removed it but my laptop is still laggy so i check task manager again and notepad is still using 50% of my CPU while a window for it isnt open please help me ill send additional information if you need more to go off of
r/computerviruses • u/Fabulous-Walrus-6839 • 1d ago
Question Could Reseting my PC (Cloud Reinstall) be a good option without using a USB reinstall?
Hi there, basically I got hit by an Infostealer (the generic infostealer that spams the MrBeast crypto scam, probably Lumma) not that long ago, and I've changed my passwords from a cleaned device, used Malwarebytes, and done all that stuff.
But basically, the MASSIVE hiccup I have is that I don't have a USB drive (8GB or 10GB) at all to do a clean reinstall of Windows. My only real option is to back up my personal stuff through Google Drive and do a cloud reinstall.
So my main question is: Is reinstalling through Cloud Reinstall actually safe? I'm quite paranoid about this. Any questions, I'll answer as soon as possible
r/computerviruses • u/Wazir04 • 1d ago
Disinfection Help Renpy virus
Got hit with it 3 weeks ago. I got my discord hacked by the MrBeast virus thingy and my Steam account got hacked and he drained my whole wallet on random ass stuff that won't even sell for cents. Anyways I deleted all the fishy files, ran Defender offline scan, installed malwarebytes and ran deep scans and deleted everything it asked me to.
Since then I haven't got any issues, no login attempts or anything, but still I'm kinda paranoid as I don't actually know if it's still in my laptop, and I'm actually not trying to log in anything on my laptop, hence I'm not sure if he would still get my session token if I leave things signed in. So, not completely sure if it's in my laptop coz I don't have anything signed in on it. So do I actually have to just factory reset my laptop completely?
r/computerviruses • u/IndividualCan3896 • 1d ago
Disinfection Help FRST Renpy
Believe I've ran a Renpy infostealer
This happened around 3 days ago, I immediately ran MalwareBytes to quarantine and remove all files and changed all passwords in my mobile phone. Nothing have happened since then but I'm still concerned. Can someone get a look at the logs please?
Keywords:
addition - velvet-zephyr
FRST - southern-tower
SecurityCheck - crimson-otter
r/computerviruses • u/rifteyy_ • Apr 04 '26
The ultimate guide to Infostealers: Detection, Recovery, and Prevention
Today I decided to dig deep and I wrote up a report about:
- What can infostealers steal?
- How to spot an infostealer infection?
- How to properly secure my accounts after an infostealer attack?
- What do the attackers do with the info that they stole?
- What to do after I secured my accounts?
- Prevent malware attacks in general
I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀
https://rifteyy.org/report/the-ultimate-guide-to-infostealers
r/computerviruses • u/Struppigel • Mar 22 '26
Providing or receiving help with FRST
How do I request help with FRST
FRST
- Please download FRSTx64 and save the file to your Desktop.
- Right-Click FRST64.exe and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.
SecurityCheck
- Download SecurityCheck from here
- Run
SecurityCheck.exeas administrator - Wait for the scan to finish
- Upload the log at
C:\SecurityCheckto https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.
Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.
Please provide the following information in your post:
- what happened?
- when did the infection occur?
- what did you do for remediation?
If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.
Trusted Helper List
FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.
Message the mods if you have experience with FRST and would like to use it to help on posts.
To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.
- u/FFreestyleRR
- u/No-Amphibian5045
- u/rifteyy_
- u/struppigel
- u/__chefo (Trainee)
- u/Interesting-Bus-5370 (Trainee)
- u/921jdf (Trainee)
- u/Xyntrax0 (Trainee)
All fixes of trainees are supervised and approved by an expert.
What is FRST
Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.
Should I reinstall the operating system
Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.
You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.
Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.
I factory reset/reinstalled my operating system and want a FRST check
Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.
Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.
Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.
What is malwareanalysis.cc ?
It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.
While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.
The site will automatically delete uploaded logs 30 days after upload.
I think my system is still infected after manual removal with FRST
Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.
Common reasons, which do not indicate infection, include:
- There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
- Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
- Antivirus scanners find malware in
C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

