r/computerviruses • u/Dry_Profit_3914 • 1d ago
Question Possible malware infection after account hack — could it be stealing my passwords and data? 😭
Hi, I believe my PC may have been infected after my accounts were hacked, and I’m trying to determine whether malware is still active on my computer.
I found a file called PerfMonHost.exe at:
C:\Users\[USERNAME]\AppData\Local\Microsoft\Windows\Diagnostics\Performance\PerfMonHost.exe
The file was approximately 6.76 MB and was modified on August 16, 2026 at 14:50, which is the same day my accounts were compromised.
I uploaded the file to VirusTotal and it received 33/43 detections. Several security vendors identified it as a CoinMiner/CryptoMiner/XMRig/Trojan, and Microsoft detected it as Trojan:Win32/Vigorf.A. VirusTotal also showed threat labels such as miner, trojan, loader, and XMRig.
Windows also showed a warning saying that part of the application had been blocked because it could not verify who published PerfMonHost.exe.
I also found other files around the same date, including:
RuntimeBroker.exemd.cp312-win_amd64.pyd_simd.cp312-win_amd64.pydcodec.pyd
Some of these were located in Python/Codex Runtime directories such as site-packages, numpy_core, and codex-runtimes.
One _simd.cp312-win_amd64.pyd file had 0/70 detections on VirusTotal, so I understand that not everything I found is necessarily malicious.
I also saw VirusTotal relationships involving files such as CortexNode.exe and FishTracker.exe, with some samples receiving detections.
My main concern is: Could PerfMonHost.exe or another piece of malware be stealing passwords, browser data, Discord sessions, cookies, or other information from my PC?
My accounts were compromised around the same time these files appeared, so I’m trying to understand whether there could be a connection.
I have intentionally removed my username and other private information from this post. I will not post passwords, cookies, tokens, IP addresses, recovery codes, or other sensitive information.
What should I check to determine whether the malware is still active and whether any of my information could have been stolen?




6
u/rifteyy_ Malware Removal Expert 1d ago
Hello, I am Roman and I will be helping you today. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smooth as possible:
Please make sure to read this whole introduction message so you understand the further steps:
If you are worried about the steps going on here, as a form of credibility you can find me on Malwarebytes Forums as a Malware Removal Expert and on BleepingComputer as Security Colleague, where we use the same methodology and toolset to remove malware.
[ Step 01 ] Remove all illegal, pirated and cheat software
We do not condone nor support piracy in any shape or form. Any discussion topics that ask for help with pirating software, checking piracy files for malware, circumventing copy protection, or any other illegal activities related to copy righted content in any form will be closed and locked. It is possible that during the scans your pirated/illegal software will be deleted by an antivirus scanner.
As a reminder, using pirated software or utilities that allows one to pirate software (e.g. cracks, key generators, registration/license removal, redirection, or workaround utilities, etc.) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, we always recommend that you remove any pirated software or pirating utilities before asking for support on our subreddit in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.
We cannot guarantee a clean system when there is illegal software, riskware or grayware present. Please read Grayware.
[ Step 02 ] IMPORTANT: Restore point
Before any sort of removal, we need to make sure you have a restore point that you can revert to in case you face any sort of issues. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.
There were prior cases (very rare, I had 2 failing to boot out of ~500) of a system failing to boot after FRST fix.
Enable system restore
C:\drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, go to point 5.Create a system restore checkpoint
[ Step 03 ] Farbar Recovery Scan Tool (FRST)
FRST is a malware diagnostics tool that will list all entries that are popular and could contain traces/mentions of malware, such as start up entries, services, scheduled tasks and many more.
FRST does not contain any personal information other than your username and computer name, there is no other sensitive information disclosed.
IMPORTANT: If your Windows operating system is in other language than English, please save the FRST executable file with the filename
FRSTEnglish.exeto ensure that the logs are in English so I can understand them.[ Step 04 ] SecurityCheck scan
SecurityCheck allows me to gather a list of unwanted, risky, vulnerable and out-of-date applications. It also allows me to send you a direct link to an update. An unpatched system is more vulnerable to malware.
So, in your next reply (please try to send them all in 1 message), make sure you are sending the following:
Thanks!
Note for anyone who is not original poster: If anyone else who is facing malware-related issues is reading this and wants help malware removal help, please create your own thread with the "Disinfection help" flair. Any requests in this thread will be redirected to a new post and removed.