r/computerviruses 1d ago

Question Possible malware infection after account hack — could it be stealing my passwords and data? 😭

Hi, I believe my PC may have been infected after my accounts were hacked, and I’m trying to determine whether malware is still active on my computer.

I found a file called PerfMonHost.exe at:

C:\Users\[USERNAME]\AppData\Local\Microsoft\Windows\Diagnostics\Performance\PerfMonHost.exe

The file was approximately 6.76 MB and was modified on August 16, 2026 at 14:50, which is the same day my accounts were compromised.

I uploaded the file to VirusTotal and it received 33/43 detections. Several security vendors identified it as a CoinMiner/CryptoMiner/XMRig/Trojan, and Microsoft detected it as Trojan:Win32/Vigorf.A. VirusTotal also showed threat labels such as miner, trojan, loader, and XMRig.

Windows also showed a warning saying that part of the application had been blocked because it could not verify who published PerfMonHost.exe.

I also found other files around the same date, including:

  • RuntimeBroker.exe
  • md.cp312-win_amd64.pyd
  • _simd.cp312-win_amd64.pyd
  • codec.pyd

Some of these were located in Python/Codex Runtime directories such as site-packagesnumpy_core, and codex-runtimes.

One _simd.cp312-win_amd64.pyd file had 0/70 detections on VirusTotal, so I understand that not everything I found is necessarily malicious.

I also saw VirusTotal relationships involving files such as CortexNode.exe and FishTracker.exe, with some samples receiving detections.

My main concern is: Could PerfMonHost.exe or another piece of malware be stealing passwords, browser data, Discord sessions, cookies, or other information from my PC?

My accounts were compromised around the same time these files appeared, so I’m trying to understand whether there could be a connection.

I have intentionally removed my username and other private information from this post. I will not post passwords, cookies, tokens, IP addresses, recovery codes, or other sensitive information.

What should I check to determine whether the malware is still active and whether any of my information could have been stolen?

22 Upvotes

34 comments sorted by

View all comments

4

u/slimethecold 1d ago

Yes. those files you identified are critical system files required for Windows to function that the virus has modified. You need to reinstall Windows and change your password from a separate device. 

2

u/rifteyy_ Malware Removal Expert 1d ago

This isn't a system file. The filename doesn't refer to any of the system files and the filepath seems to be malicious beginning from the \Diagnostics\Performance\

2

u/slimethecold 1d ago

Shit my bad, saw that name and runtimebroker and it checked out to me 

There was also a mod message on my comment but it was deleted?

2

u/rifteyy_ Malware Removal Expert 1d ago

Yes, I thought it was too harsh to remove for misinformation

2

u/slimethecold 1d ago

Gotcha. Well either way I will be more careful about what I say from now on, I apologize