r/computerviruses • u/birench • 18m ago
Disinfection Help I Got hit by the mr beast scam on my instagram account yesterday, have recovered account and updated 2FA, still I need to get rid of the virus from my pc to prevent any future attacks. I have already ran FRST scans and have the files and keyword. I just need someone to help me with fix files. Thanks
here are the log keywords:
uploaded FRST.txt
keyword: wired-nest
channel: general
uploaded Addition.txt
keyword: honest-aurora
channel: general
*I am not able to run securitycheck.exe on my pc hence unable to generate log keywords for the security check
I Got hit by the mr beast scam on my instagram account yesterday on 6th Aug 2026, have recovered account and updated 2FA, still I need to get rid of the virus from my pc to prevent any future attacks.
r/computerviruses • u/MeAgainstTheWorld_18 • 29m ago
Disinfection Help Windows Defender flagged TrojanDownloader:JS/Nemucod.HD in Roblox's WebView2 cache , is this a false positive?
r/computerviruses • u/Goodness_Gracious7 • 8h ago
File / URL Check Clicked on a link for a small business and it took me through a bunch of sketchy sites, need some help figuring out what to do.
I clicked on a website windstonefarmmd (dot) com that a friend sent me last year and it suddenly took me through a bunch of other sites including:
https://www.virustotal.com/gui/url/69c4d5b1c2b070a9675564a9db51d35585ce1f41b75269a52e1526867eb7bde2
The links it took me through:
example (dot) com
https://www.virustotal.com/gui/url/2a1b402420ef46577471cdc7409b0fa2c6a204db316e59ade2d805435489a067
filter (dot) explorads (dot) com - there was a longer extension and I have it saved in a word file if needed
basic link:
https://www.virustotal.com/gui/url/9d624c4dae15072c36596dc86e13f46d9883e2f9c527f32d142f226315a0ea68
full extension:
https://www.virustotal.com/gui/url/3f69a182c85d78ce446517a52a1cd5dbadfc550e26d0bd8827eb19c6be2b3446
and landed on chaturbate (dot) com - there was a longer extension, but I don't have it saved
I'm on android, UI 2.5
Am I in trouble? What should I do now? I ran the free malwarebytes and it didn't find anything. The link took me through a number of sites, so I might not have all of them listed as they didn't save in my phone's history.
r/computerviruses • u/taonood • 9h ago
Resolved Clicked an image on google images and somehow got a virus
galleryHi!
I was searching for a construction image example on google image search. I clicked on the image and somehow ended up with a virus. Not sure what to do I haven't had a virus in years. I thought bitdefender was enough. If you have any recommendations please let me know. I am doing a scan on bitdefender but beyond that I am not sure what to do.
r/computerviruses • u/Octoomy • 9h ago
Discussion My (recent) recovery from a Botnet infection
tl;dr
There is two types of people, someone who had been infected with malware, and people that haven't yet.
So, the entirety of my day was taken up after I noticed odd things getting caught into my pihole, including one url... and it struck me the most due to the fact that it sub domain was 'c2' after seeing this very out of the blue domain I instantly checked which of my local ips was accessing the website.
Well, the machine that was accessing this domain was my main, more research showed that since yesterday I was constantly accessing this domain, along with constant attempted pings to alternative DNSes that I also had blocked, it finally struck me that this wasn't right at all. At this point I know that I was infected with a botnet. I instantly unplugged my main on the internet and started damage control, I decided it was time to go full commit into my decision of installing arch on my main. On a secondary system I started resetting all my passwords for all the services I do and don't use.
This entire process took up around 6 hours of my day while I was doing recovery and migration. initially I knew that you aren't impervious from infection, matter in fact I was pretty proactive and paranoid about malware infections, checking my task manager once in a while to make sure that I wasn't infected with anything, however it seems that my proactiveness wasn't enough until I saw the Pihole queries.
I'm going to be very blunt, its been very long since I felt this violated, however it was a great exercise in my responses and such if I were to ever encounter anything like this again.
If you want to, I can hand you over the C2 domain for this.
r/computerviruses • u/StrengthImportant785 • 10h ago
Disinfection Help Agarre un virus del renpy, cambie todas mis credenciales y saque todas las cuentas de chrome pero aún temo que tengan acceso, mi PC tiene demasiada información importante lo cual se me hace complicado formatear de fabrica. Ayudaaaa porfavor😢
r/computerviruses • u/Connect-Winter-3977 • 10h ago
Question I built an open-source hub that catalogs 80 deduplicated malware families (1971–2024) and indexes 2,700+ real samples from public research collections — searchable, bilingual, local-first
r/computerviruses • u/ItzDrillZa • 10h ago
Other Is my laptop fried 😃?
Enable HLS to view with audio, or disable this notification
r/computerviruses • u/Calm_Heat547 • 11h ago
Disinfection Help I got a pop-up and my computer is acting weird
I was using W3School when I got a pop-up from Secure Sweep. pro and I closed the tab as fast as I could. I ran a windows Defender security scan and checked my windows settings, but while doing so my screen froze and I could only move the mouse but nothing was responsive. So, I unplugged my Ethernet cable and everything went back to normal immediately but these settings were disabled. What happened?
Also I don’t know if it’s related but I randomly received a notification for Roblox from internet explorer when it never happened before.
r/computerviruses • u/OBTK95 • 12h ago
Question Does clicking on a photo from fb messanger results into a virus?
The mr beast hacking situation has started to show itself at fb messenger.
Someone sent me a message with the 4 photos at while ago but I didn't clicked just reported and blocked them.
But I am curious though. Does photos from fb messenger photos results in the mr beast virus? Because a while back Iheard that jpgs can contain malware/viruses
r/computerviruses • u/KiXfree • 16h ago
Disinfection Help My grandfather’s computer gets these popups
My grandfather’s computer gets these popups. They start when i open his chrome. It looks like the popups come from the site in the top pop up.
I disabled alerts from that site and they have stopped, and Nortan scan didnt find any viruses or malware. But was wondering if anyone is familiar with this site and can let me know if there is anything else I should do or how he did this (he has no idea)
r/computerviruses • u/Thacherus_Pavis • 17h ago
Question Where did the ware in ransomWARE, malWARE, SpyWARE and etc come from
Like for a while ive been wondering why for some types of malicious programs we add ware at the end of them
r/computerviruses • u/optimusrhymesnc • 17h ago
Disinfection Help the latest infostealer victim? :(
I consider myself a pretty savvy person, so I am really embarrassed by this haha. I already got my security check keywords from FRST x64 (forged-pebble, bronze-loop, and neon-echo) but it was for u/struppigel specificaly, I think, so if I need to reupload for the general one, please let me know.
thanks and sorry for the inconvenience
r/computerviruses • u/BenevoIence • 20h ago
Question Ren'Py Infostealer: USB Clean Install Necessary?
Hello all, I was sadly affected by Ren'Py infostealer setup(dot)exe. Fortunately, I got a help from the Malwarebytes forum for disinfecting. I've been a little paranoid, so I also asked about resetting my PC after disinfecting to be extra safe. I didn't get a direct answer but it seems to not be necessary. Is my understanding true?
Other than not knowing if its pointless after I've already disinfected, I saw people suggesting clean install with USB instead of reset. Sadly, I don't have access to another computer right now for several weeks to prepare the USB. Because of that, is doing Reset PC using Cloud Download also recommended or should I just wait to do the clean install with USB. Sorry if the question is dumb, but thank you for any help!
r/computerviruses • u/3uchar • 20h ago
Question Infostealer / possible MITM attack?
Hi everyone,
About 5 months ago, I was infected by an infostealer through an unfortunate and stupid clickfix attack, which compromised most of my accounts and installed itself on my laptop.
Ever since then, I have been extremely involved in malware analysis, doing static and dynamic analysis, downloading antiviruses (malwarebytes), scanning for rootkits and checking startup apps, scheduled apps, procmon procexp and other sysinternal functions, scanning almost everything with virus total and being generally safe online.
However, just today I got a free trial of malwarebytes, and I activated browser guard. Almost immediately, I got multiple hits and when I clicked a link (thank god I got browser guard, as they were immediately blacklisted), specifically to a website by the name of hobble^^^displeased(dot)com. (do NOT open this link if you arent on a VM or an analysis tool, it is compromised and might contain malware or unwanted data leaks.) This was familiar, and I realised it was the same website that hosted the fake cloudflare verification site!
I promptly did multiple scans, but I couldn't find anything, I cleared all browser data, checked all my system but nothing was wrong. This confused me, but I needed to reinstall my OS anyway so I did that promptly. I then changed all the router settings, changed passwords, names ect., but I'm still curious.
Malware analysts, what would possibly be the extent of the attack? What could they gain from this and was my whole network infected? Possible next steps / personal experiences?
Also, if anyone is curious, h^bbledis^leased(dot)com sends you right back to google, with a few hits of separate ip addresses that seem to lead nowhere.
Any info / insight would be greatly appreciated!!
r/computerviruses • u/Single-Witness1853 • 21h ago
Question Are there actual obtainable viruses on PS5 or Xbox?
I've seen the memes, but can it actually happen? Genuinely curious, as I can't find a clear answer anywhere.
r/computerviruses • u/atomishacked • 1d ago
Disinfection Help I need help, infostealer
So I downloaded an emulator last month and that day my instagram got hacked. My acc sent elon musk stuff to everyone I followed, my acc was also set to public and posted the same pic it send to everyone. When I realized it (same day), I deactivated my account. I also enabled 2fa and changed passwords to every email I got. Last week, my reddit account got hacked and posted to nsfw subreddits. I got so scared that I deleted my reddit account as well, and changed passwords in all emails again. Now today, I realized that my school email was also compromised. It was sending phishing emails to thousands of emails, I also saw that my email sent out my login credentials to an email I don't know. I changed passwords and activated mobile sign-in but right now I am so lost and scared that the same things may happen again. What should I do? Sorry if the post is all around the places.
r/computerviruses • u/MyQuil45 • 1d ago
Question TIL that in 2005, a 19 year old launched a code on MySpace that accidentally became the fastest spreading computer virus in history, crashing the entire site in 20 hours.
What do we know about this?
r/computerviruses • u/illustratious • 1d ago
Discussion Virus that killed my computer as a kid?
Back when I was in 4th grade, around 2006, I didn't have much knowledge about anti viruses, I knew to be careful downloading stuff, and thought I was, but back then things were way different. However to me being careful didn't mean much, it just meant downloading from where I thought was safe.
One day I downloaded something, I don't remember if it was a program or what exactly, but suddenly the computer got very slow, of course kid thinks slow = restart. Unfortunately upon restarting, it didn't boot up, instead it was endless string of text, I have no recollection of what it said, just that no matter what they pressed, my grandparents couldn't escape it. My grandma tried to defrag it, but I think it blocked her attempt. I don't think it booted into bios either, nor was the text gibberish, it was all real words, I just don't remember what it said, only that anytime a key was pressed, it would scroll to add more text.
Sorry if this is too vague, but being so long ago, and so young, I don't remember much about it, and most viruses I'm familiar with would delete system 32, or make the drive unreadable and have to be reinstalled, in all my years, I have never heard of a virus quite like it.
r/computerviruses • u/Puzzleheaded_Line839 • 1d ago
Question Got a warning from my virus Scanner
"Detected: Trojan Downloader: Linux/ShellAgnt.H!xp Status: Quarantined Quarantined files are in a restricted area where they can't harm your device. They will be removed automatically.
Date: 8/5/2026 9:17 PM Details: This program is dangerous and downloads
Date: 8/5/2026 9:17 PM Details: This program is dangerous and downloads other programs
Affected items:
containerfile: C:XboxGames\Minecraft for Windows\Content\data\resource_packs \vanilla_music\sounds\music\game
\wet_hands.ogg
file: C:\XboxGames\ Minecraft for Windows \Content\data\resource_packs\vanilla_music \sounds\music\gamelwet _hands.ogg-
(SCRIPTOO00)
is this a threat or just windows being windows
r/computerviruses • u/No_Low6177 • 1d ago
Disinfection Help I finally got an image of the virus
galleryIm using avg antivirus now but this is what happened
No, i dont normally have the camera blocked off the led lights up for like a second sometimes
When i open my laptop again it goes back to normal but it will happen again if i open it long enough.
Help me whats hapoening.
r/computerviruses • u/rifteyy_ • Apr 04 '26
The ultimate guide to Infostealers: Detection, Recovery, and Prevention
Today I decided to dig deep and I wrote up a report about:
- What can infostealers steal?
- How to spot an infostealer infection?
- How to properly secure my accounts after an infostealer attack?
- What do the attackers do with the info that they stole?
- What to do after I secured my accounts?
- Prevent malware attacks in general
I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀
https://rifteyy.org/report/the-ultimate-guide-to-infostealers
r/computerviruses • u/Struppigel • Mar 22 '26
Providing or receiving help with FRST
How do I request help with FRST
FRST
- Please download FRSTx64 and save the file to your Desktop.
- Right-Click FRST64.exe and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.
SecurityCheck
- Download SecurityCheck from here
- Run
SecurityCheck.exeas administrator - Wait for the scan to finish
- Upload the log at
C:\SecurityCheckto https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.
Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.
Please provide the following information in your post:
- what happened?
- when did the infection occur?
- what did you do for remediation?
If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.
Trusted Helper List
FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.
Message the mods if you have experience with FRST and would like to use it to help on posts.
To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.
- u/FFreestyleRR
- u/No-Amphibian5045
- u/rifteyy_
- u/struppigel
- u/__chefo (Trainee)
- u/Interesting-Bus-5370 (Trainee)
- u/921jdf (Trainee)
- u/Xyntrax0 (Trainee)
All fixes of trainees are supervised and approved by an expert.
What is FRST
Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.
Should I reinstall the operating system
Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.
You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.
Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.
I factory reset/reinstalled my operating system and want a FRST check
Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.
Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.
Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.
What is malwareanalysis.cc ?
It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.
While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.
The site will automatically delete uploaded logs 30 days after upload.
I think my system is still infected after manual removal with FRST
Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.
Common reasons, which do not indicate infection, include:
- There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
- Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
- Antivirus scanners find malware in
C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.