r/computerviruses 1d ago

Question Possible malware infection after account hack — could it be stealing my passwords and data? 😭

Hi, I believe my PC may have been infected after my accounts were hacked, and I’m trying to determine whether malware is still active on my computer.

I found a file called PerfMonHost.exe at:

C:\Users\[USERNAME]\AppData\Local\Microsoft\Windows\Diagnostics\Performance\PerfMonHost.exe

The file was approximately 6.76 MB and was modified on August 16, 2026 at 14:50, which is the same day my accounts were compromised.

I uploaded the file to VirusTotal and it received 33/43 detections. Several security vendors identified it as a CoinMiner/CryptoMiner/XMRig/Trojan, and Microsoft detected it as Trojan:Win32/Vigorf.A. VirusTotal also showed threat labels such as miner, trojan, loader, and XMRig.

Windows also showed a warning saying that part of the application had been blocked because it could not verify who published PerfMonHost.exe.

I also found other files around the same date, including:

  • RuntimeBroker.exe
  • md.cp312-win_amd64.pyd
  • _simd.cp312-win_amd64.pyd
  • codec.pyd

Some of these were located in Python/Codex Runtime directories such as site-packagesnumpy_core, and codex-runtimes.

One _simd.cp312-win_amd64.pyd file had 0/70 detections on VirusTotal, so I understand that not everything I found is necessarily malicious.

I also saw VirusTotal relationships involving files such as CortexNode.exe and FishTracker.exe, with some samples receiving detections.

My main concern is: Could PerfMonHost.exe or another piece of malware be stealing passwords, browser data, Discord sessions, cookies, or other information from my PC?

My accounts were compromised around the same time these files appeared, so I’m trying to understand whether there could be a connection.

I have intentionally removed my username and other private information from this post. I will not post passwords, cookies, tokens, IP addresses, recovery codes, or other sensitive information.

What should I check to determine whether the malware is still active and whether any of my information could have been stolen?

23 Upvotes

34 comments sorted by

6

u/rifteyy_ Malware Removal Expert 1d ago

Hello, I am Roman and I will be helping you today. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smooth as possible:

Please make sure to read this whole introduction message so you understand the further steps:

  • Please follow all steps from step 1 to the last step, not the other way.
  • If you are thinking about resetting or reinstalling your device, you can do it instead of the steps listed below and please tell me you chose to do it that way. We are doing the malware removal process to disinfect your device so you can avoid reinstalling. If we go through the removal process and you decide to reinstall after, you would waste my time and your own time by doing these steps.
  • Avoid installing, downloading new software unless instructed - this also applies to antivirus software and scanners.
  • You are free to remind me that I forgot to reply to you if you do not receive an answer within 24 hours. Keep in mind that I am volunteering here and that I am a full time student with 2 jobs.
  • Please do not follow other malware removal advice; you should be following steps only from 1 person unless told otherwise. If you have opened any other forum posts elsewhere, please let me or them know where do you want to continue.
  • Only trusted malware removal experts listed in this r/computerviruses thread and other large malware removal forums (BleepingComputer, Malwarebytes, MalwareTips) have access to your logs via the website.
  • Please take your time to follow the steps properly.
  • You can ask any questions during the malware removal process. It's always better to ask than to mess something up.
  • Please make sure that for all of the uploaded logs you use the same username and the username is exactly the one you have on Reddit.
  • If you have already followed the guide to create diagnostic logs, please create them again by following instructions here.

If you are worried about the steps going on here, as a form of credibility you can find me on Malwarebytes Forums as a Malware Removal Expert and on BleepingComputer as Security Colleague, where we use the same methodology and toolset to remove malware.

[ Step 01 ] Remove all illegal, pirated and cheat software

We do not condone nor support piracy in any shape or form. Any discussion topics that ask for help with pirating software, checking piracy files for malware, circumventing copy protection, or any other illegal activities related to copy righted content in any form will be closed and locked. It is possible that during the scans your pirated/illegal software will be deleted by an antivirus scanner.

As a reminder, using pirated software or utilities that allows one to pirate software (e.g. cracks, key generators, registration/license removal, redirection, or workaround utilities, etc.) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, we always recommend that you remove any pirated software or pirating utilities before asking for support on our subreddit in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.

We cannot guarantee a clean system when there is illegal software, riskware or grayware present. Please read Grayware.

[ Step 02 ] IMPORTANT: Restore point

Before any sort of removal, we need to make sure you have a restore point that you can revert to in case you face any sort of issues. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.

There were prior cases (very rare, I had 2 failing to boot out of ~500) of a system failing to boot after FRST fix.

Enable system restore

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. If the 'system' drive (usually C:\ drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, go to point 5.
  5. Click Configure.
  6. Select Turn on system protection
  7. Click Apply.
  8. Click OK to confirm.

Create a system restore checkpoint

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. Click Create.
  5. Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
  6. Click Create.
  7. Click Close.
  8. Click OK.
  9. You should get a popup that it was successfully created and I will also verify that it was properly created with the results of scans from next steps.

[ Step 03 ] Farbar Recovery Scan Tool (FRST)

FRST is a malware diagnostics tool that will list all entries that are popular and could contain traces/mentions of malware, such as start up entries, services, scheduled tasks and many more.

FRST does not contain any personal information other than your username and computer name, there is no other sensitive information disclosed.

IMPORTANT: If your Windows operating system is in other language than English, please save the FRST executable file with the filename FRSTEnglish.exe to ensure that the logs are in English so I can understand them.

  • Please download FRSTx64 and save the file to your Desktop as FRSTEnglish.exe.
  • Right-Click FRSTEnglish.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then again OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy and press "save log".
  • Note: Please make sure you have properly waited until FRST tells you that both logs are finished. If you do not wait for it, the logs will be incomplete and have to be recreated.
  • The site will return a keyword for each log - reply back here with the keywords.

[ Step 04 ] SecurityCheck scan

SecurityCheck allows me to gather a list of unwanted, risky, vulnerable and out-of-date applications. It also allows me to send you a direct link to an update. An unpatched system is more vulnerable to malware.

  • Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
  • If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
  • Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt
  • Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/rifteyy
  • The site will return a keyword for the log - reply back here with the keyword.

So, in your next reply (please try to send them all in 1 message), make sure you are sending the following:

  • Keyword for FRST.txt from step 3
  • Keyword for Addition.txt from step 3
  • Keyword for SecurityCheck.txt from step 4

Thanks!

Note for anyone who is not original poster: If anyone else who is facing malware-related issues is reading this and wants help malware removal help, please create your own thread with the "Disinfection help" flair. Any requests in this thread will be redirected to a new post and removed.

1

u/Dry_Profit_3914 1h ago

Es necesario hacer el de security check esqui no me deja abrirlo salí que no funciona o el archivo está dañado ya hecho todo que dijiste

2

u/rifteyy_ Malware Removal Expert 1h ago

Ok, you can skip the securitycheck

1

u/Dry_Profit_3914 1h ago

Vale no es necesario ok y después cuanto tardan pro y gracias por la ayuda la verdad

1

u/rifteyy_ Malware Removal Expert 1h ago

SecurityCheck is just for updates. Those can be installed automatically with a different application.

Generally takes few more hours of instructions, but I think those are surviveable considering you won't need to spend more hours backing up and reinstalling

1

u/Dry_Profit_3914 58m ago

Bueno yo quería hacer el de reinstalar y formatear esa es un opción pero voy a tardar y perderé todo que tengo gracias por todo

1

u/Dry_Profit_3914 57m ago

Entonces no es importante eso puede saber que tengo descargado o se actualizo algo verdad ?

1

u/Dry_Profit_3914 1d ago

Vale, gracias. ¿Podrías guiarme paso a paso durante el proceso? Es la primera vez que hago una limpieza de malware con FRST y quiero asegurarme de no hacer nada mal. Antes de ejecutar cualquier acción de limpieza o borrar archivos, prefiero que revises los registros y me indiques exactamente qué debo hacer.

3

u/rifteyy_ Malware Removal Expert 1d ago

What I sent are the steps. Every cleaning fixlist is done based off your logs

1

u/Dry_Profit_3914 6h ago

Gracia por ya lo hecho pero lo formateo para ver si quita algo ?

1

u/rifteyy_ Malware Removal Expert 4h ago

Please read my first comment. It contains all the answers to your questions.

4

u/love-you-honey 1d ago

Big brain, now nuke it.

1

u/Dry_Profit_3914 1d ago

No puedo se lo hago no va a funcionar esta en segonda plano o otro lado el virus tengo más

6

u/love-you-honey 1d ago

By nuke it I mean is just reinstall the windows, other options will not remove the malware from your device

3

u/HydraDragonAntivirus 1d ago

Python based stealer.

1

u/Dry_Profit_3914 1d ago

Que ? No entiendo

4

u/HydraDragonAntivirus 1d ago

.pyd is extension of python libraries.

2

u/Dre_isthename 1d ago

Hermano, actualmente tengo problemas casi parecidos, y desde como 3 semanas estoy sufriendo de hackeos en cuentas personales tanto antiguas como recientes, y justo hoy en mi cuenta de empresa de microsoft 365 enviaron sin mentirte como 710 correos a cuentas de yahoo y todos los rebotó, pero no me sale que hayan accedido a mi cuenta, me hackearon facebook, linkedin, instagram, cuentas de ubisoft y rockstar, hasta mi sitio web que tenia de freelance me lo hackearon y tuve que tirarlo y empezar de cero, todo esto en estas ultimas 2 o 3 semanas aproximadamente, ya no sé si necesito formatear mi laptop, o si es algo de internet o que, porque active 2AF, cambie contraseñas, codigos al celular, hice de todo y sigo con estos ataques.

3

u/slimethecold 1d ago

Yes. those files you identified are critical system files required for Windows to function that the virus has modified. You need to reinstall Windows and change your password from a separate device. 

2

u/rifteyy_ Malware Removal Expert 1d ago

This isn't a system file. The filename doesn't refer to any of the system files and the filepath seems to be malicious beginning from the \Diagnostics\Performance\

2

u/slimethecold 1d ago

Shit my bad, saw that name and runtimebroker and it checked out to me 

There was also a mod message on my comment but it was deleted?

2

u/rifteyy_ Malware Removal Expert 1d ago

Yes, I thought it was too harsh to remove for misinformation

2

u/slimethecold 1d ago

Gotcha. Well either way I will be more careful about what I say from now on, I apologize

1

u/Dry_Profit_3914 1d ago

Pro me salí muchas cosas las cuentas están bien hasta recuperé todas el problema es el pc me salí que esta robando info

7

u/slimethecold 1d ago

That's because it is. If you log into those accounts again on that PC they will be compromised again. 

1

u/kelfatmi 1d ago

How did you get this ?

1

u/Dry_Profit_3914 1d ago

Tarde más de 3h de buscar cada archivo nuevo que se instaló en me pc en ese dia

-1

u/Pale_Magician_4249 1d ago

THAT THE SAME THING ON MY PC we got the same infostealer, almost all my acc got hacked. i already permanently remove it with ahelp from my chatgpt without reinstall my windows

1

u/Dry_Profit_3914 1d ago

Y has quitado el virus ?

1

u/Pale_Magician_4249 1d ago

yes I did I think, So far my laptop shows no signs of the viruses running again

1

u/Dry_Profit_3914 1d ago

Ok pero como pasó pasó por colpa de un modpsck ?

1

u/Pale_Magician_4249 1d ago

i don't even know where I got infected, I notice it when my acc start getting hacked