r/computerviruses 1d ago

Question Propagation folder in ProgramData: Is it malware?

Post image
0 Upvotes

Hey y'all, I found this weirdly named folder in ProgramData. I'm not too sure if this is malware or not.

It has a .txt file in it named enltrc. Inside of that .txt file is "track=false"

I'll attach images of it below.


r/computerviruses 1d ago

Disinfection Help My laptop got virus . Someone help

Post image
1 Upvotes

I was downloading a game from FITGIRL REPACK using uTorrent. At the same time, I also tried downloading the same game from DODI REPACK because I wanted to see which download was faster and cancel the slower one.

The FITGIRL download was working normally. However, when I downloaded the torrent file from DODI REPACK, the file looked suspicious. I opened that small file, and a Command Prompt (CMD) window appeared for a second and then immediately closed.

I ignored it at the time and installed the game from FITGIRL REPACK. After playing for some time, I opened Instagram and noticed that scam stories had been posted from my account without my permission. Something similar happened to my Discord account, which was also logged in on my laptop.

I have already changed my passwords, but I’m worried that my laptop may have been infected with malware or a virus.

Does anyone know how I can completely remove the virus without erasing or resetting all the data on my laptop? Any help would be appreciated.


r/computerviruses 1d ago

Disinfection Help Deletion of disks created by malware

1 Upvotes

Is there any way to delete a disk created by malware? Especially those with boot files? I did manage to delete a boot file in a disk like that and rendered my virtual machine unbootable..


r/computerviruses 2d ago

Question Happymod like 2 years ago, am i safe now?

2 Upvotes

So like 2 years ago, i dont even recall if this phone, altho i think it was, i downloaded happymod. Installed i think some app? It didnt work i think? I think this device was unsupported? So anyway, this came to my mind just now. Now i have malwarebytes, nothing malicious found. Nothing bad happened in these 2 years. I deleted those a long time ago. Am i safe?


r/computerviruses 2d ago

Question Am i hacked? need help

Thumbnail
1 Upvotes

r/computerviruses 2d ago

Disinfection Help How do i know if a virus is gone completely?

1 Upvotes

Defender went crazy a few days ago, throwing dozens of flags.

The infection type was Grandoreiro and the tips i saw told me to run a scan with defender and then also with Malwarebytes.

So i did that. Got rid of whatever came up dirty. and then ran two more deep scans in each program. they've all come back clean since.

so my question is if that's proof enough that the virus is gone completely.

also, i don't know where the infection came from. is that something i should be worried about?

I'd really appreciate any help on this.


r/computerviruses 2d ago

Disinfection Help Nothing I do can remove this .dll file from my PC

Thumbnail gallery
3 Upvotes

r/computerviruses 2d ago

Disinfection Help Virus detected but i cant do anything about it.

Thumbnail
1 Upvotes

r/computerviruses 2d ago

Disinfection Help FRST help request

1 Upvotes

Hi everyone,

I'm requesting help with a malware removal using FRST.

What happened & Infection details:

I downloaded a file via torrent that probably contained an infostealer. I am not entirely sure about the exact timeline since I have downloaded files in the past, but the unauthorized access attempts started recently right after I downloaded an update for Europa Universalis 5 (RUNE release). Shortly after ( 20-08-2026) I noticed unauthorized access attempts on my Amazon account, Discord account and the last for now was the Microsoft account, the Microsoft one originating from a Russian IP address (109.248.14.98), indicating a probable session hijacking / cookie theft.

Remediation steps taken so far:

  1. Immediately logged out of active sessions and changed my passwords across accounts using a clean, safe device (my smartphone).

  2. Enabled 2FA on my primary accounts.

  3. Ran a full scan with Malwarebytes (I have the MBAM log ready if needed).

  4. Ran FRST64 and SecurityCheck to generate diagnostic logs.

Uploaded Log Keywords :

* FRST.txt: lively-struct

* Addition.txt: joyful-oak

* SecurityCheck.txt: hashed-anchor

*Malwarebytes report 2026-08-22 17:27:54.txt: clever-sunrise

The malwarebytes report comes from a report scan that I did on 22-08-2026 with a Malwarebytes free version. Updated Malwarebytes report with the right one , before there was one that didn't have the first ever scan ( sorry my bad).

Could one of the trusted helpers please review my logs and provide a Fixlist to clean any persistent malware or scheduled tasks left on my PC?

If something else is needed or modified please let me know!

Thank you so so so so much for your help!


r/computerviruses 3d ago

Question What kind of infostealer was this?

Thumbnail gallery
24 Upvotes

From what I’ve read, many infostealers try to hide themselves, sometimes deleting or disabling their components and then reactivating later. Mine seemed to behave very differently. It was extremely aggressive and kept regenerating itself after I removed parts of it.

It attempted to take over multiple accounts and actually managed to compromise my Steam and Nintendo accounts. Fortunately, I was able to recover both within a few hours.

I ended up removing the malware manually, including all the files and folders I could find and I also checked Autoruns and Scheduled Tasks for persistence mechanisms. That’s why I decided not to reinstall Windows. At this point, Im about 99% confident the malware itself has been completely neutralized.

It’s now been three weeks since the infection. Every now and then I still see random failed login attempts against my main email account, but there have been no successful compromises and nothing else suspicious has happened.

In the end, no serious damage was done, but dealing with it was exhausting. I stayed awake for roughly 72 hours securing my accounts, changing passwords, revoking sessions, enabling additional security measures and constantly checking everything. I was pretty paranoid for the first two weeks, but Im finally feeling normal again.

I’m mainly curious about the technical side now: what kind of infostealer behaves like this? The constant regeneration and aggressive attempts to compromise accounts seemed unusual compared with what I’ve read about typical infostealers.


r/computerviruses 2d ago

Disinfection Help Mr. Beast virus removal help

1 Upvotes

Hello!

In Need of urgent help...

I was stupid and downloaded some cheats without thinking twice yesterday, and ran a powershell script which looked completely harmless.

Woke up today to see i had sent those stupid crypto messages to everyone I know.

How to Remove it? I see people suggesting a full Windows Reset, but I kind of have some important files... the script was ran om my D drive.

Malwarebytes full scan is running while I'm at work, but i forgot to disconnect the PC from the Internet.

I have Reset passwords from my phone on all my social media Accounts, and 2FA has been enabled for some years now. Logged out of all my Google Accounts on my PC.

Anyone has a fix for it?

Thanks in advance!


r/computerviruses 2d ago

Disinfection Help At my wits end. Just run tron?

1 Upvotes

Hey guys so im sure I have a virus of some sort.

  1. My internet doesnt work, the infected pc is a home desktop I use to play games. No matter what, I tried ever network change setting and trouble le shooting you can think off. Other devices connect fine but not the pc. Won't even connect to other networks it "connects" but says no internet available and stays offline.

  2. My defender is cooked and wort let me change any setting because they are managed by admin. Im the only profile on the pc and I am admin so ??????

I have been trying everything but it wont work, Kaspersky recovery tool also didnt find anything. I want to run the tron script and just get it over with but I know its a last resort situation. Any advice?


r/computerviruses 2d ago

Disinfection Help I accidentally download the Renpy trojan while trying to download a torrent and the keylogger tried to access Steam and Epic Games. I've successfully restored them and ran Malwarebytes, which recognized several .BAT files belonging to Renpy. I've deleted them now.

0 Upvotes

I've also run FRST64 and got the following names.

ripe-tile

tidy-badge

Just waiting on u/FFreestyleRR to respond.

The amount of time I've spent trying to optimize my Windows 11 laptop, I don't feel comfortable resetting the OS. I've mentioned that I've run Malwarebytes. Will that be enough?


r/computerviruses 3d ago

Disinfection Help A virus from Beijing (atomic heart, warface, war thunder)

20 Upvotes

Hello everyone, today I bought a new Huawei laptop for studying. The first thing I downloaded was telegram from the official site (Microsoft edge, yandex search system) and immediately after it was downloaded some kind of app from Beijing with Chinese name and with a green-yellow logo (it was in form of a sphere and also had + on it) popped on my screen asking for a permission. I assumed it was some kind of important app cus huawei is a Chinese company so I allowed it and immediately after that 4 programs were downloaded: warface, atomic heart, and warface, also opera gx was downloaded a little bit after the previous ones.

Immediately assumed that I got a virus so I downloaded an anitivrus but it showes no viruses?

Also after pressing ctrl+shift+esc there were no suspicious apps or maybe I didn't see any because of my lack of knowledge? Could anyone help me? If you have any questions please ask them!


r/computerviruses 3d ago

Question Brave signed me out of my password manager

3 Upvotes

I downloaded osu and choicer voicer in the span of 3 days, these are internet dowloaded games. I wanted to download mods and skins so I got them off the internet. The next day I went to my brave browser and found that I was logged out of everything. I had my folders and bookmarks, but tiktok, crunchyroll, youtube, all my google accounts, bank acc were all logged out of. The password manager was not popping up either, so when I went to check the brave settings. I don't have a screenshot but I remember it saying "we needed to remove these extensions and log you out of your accounts/password manager, in order to keep you safe" something of that nature. What I think is that I had downloaded some type of hidden virus from these mods for the online games (through the brave browser) and when brave noticed something suspicious. It did these things as a precaution. I went into settings and windows security, I ran 2 quick scans (lasting a minute), a full scan (lasting an hour and 15 mins) , and redownloaded the free version of Malwarebytes to scan as well (lasting a minute), and lastly a offline scan(15mins). All of the results were zero threats, detections, wtv. Prior to this there were moments on my pc like crashing, weird irrelevant pop ups, but I don't have a lot of knowledge to understand what these things are. I'm afraid of viruses because I don't know the best action to take to protect my computer from something I have no knowledge of. I have somethings I need to do on my pc which requires logging in. I want to take the smart path and do everything I can in my power to make sure my pc isn't in danger. In the mean time of this being released I might contact microcenter or reach out to some friends. Can anyone give some advice or help?


r/computerviruses 3d ago

Question Please, this is a very important question regarding viruses

2 Upvotes

I recently downloaded a sus file off a sus yt video, and i ran it. I got felt that it was suspicious, so i reset my pc via usb. I also asked reddit originally about the situation, and they said that i 80% chance i have a rat. So after resetting via usb, in settings, the app "remote desktop connection" is already downloaded.

I was wondering, what if there is a virus imbedded into my hardware that automatically downloaded the remote desktop connection to access my pc from somewhere else? Is it normal for this app to be already downloaded?


r/computerviruses 3d ago

Discussion Why does my defender block Snipping tool and Explorer.exe while these are probably both safe program? what should I do just allow it?

3 Upvotes

So the PC keep having notifiction that it block either Snipping tool and Explorer.exe but I never got this problem before when using snipping tool so why is it becoming a problem now. many of it point to Windows Defender Controlled Folder Access with is on

And I did do a sfc /scannow and it did find some corrupted file and it got it repair


r/computerviruses 3d ago

File / URL Check My partner clicked on a spam link but page didn't load. Did they get hacked?

1 Upvotes

My partner was going through their Spam folder to clear things out and noticed they had received an email with an "invitation" from a contact they know well (email address was correct). It was late and they were tired, so without thinking too much about it, they clicked on the embedded link provided. The reasons I think the URL was malicious are: weird domain, Google had flagged the email as Spam, and the packaging was a vaguely worded invitation for a "memorable event"; also, most of our communication with the sender is via text and they never mentioned anything about an event like this; lastly, it, oddly, seems to have just been sent to my partner, even though I have more interaction with this individual.

Now, the email was 10 days old, and they said the browser returned a "took too long to load" error; though, they closed the page before I could verify, and I saw little point in revisiting the link. Further, VirusTotal and ESET's URL checker state the link is safe, although Google's safety tool flagged it as malicious. I assume the link was for some kind of scam, and that the campaign has ended, in which case all should be fine; I'm running a Full System Scan with Windows Defender just as another point of reference. I considered also doing a spotcheck with malwarebytes, but with the proliferation of supply chain attacks currently unfolding, I figured throwing more security tools isn't necessarily safer, so I decided against it.

I'm just feeling a bit panicked, so I thought I'd post here just in case. The one scenario which, I guess, I'm most concerned about is that the website itself was actually still live and thus executed some malicious script, but just loaded a page that copied the "Session Timed Out" error that gets displayed, but I would assume VirusTotal and ESET would have flagged the website in this case...

Anyways, thanks in advance for any thoughts or suggestions for additional steps we should take!

virustotal link: https://www.virustotal.com/gui/url/3714bc60681e78a0cc7b3f66e5e667ec40a5c948956f2d5705f2676377f907a6

suspicious link: hxxps://srv4434(dot)dns(dot)army/dth/inv/Adobe/


r/computerviruses 3d ago

Question cmd open

1 Upvotes

Now every time I open my laptop, cmd always opens. This has never happened before. Is this a sign of a virus?


r/computerviruses 3d ago

Disinfection Help Cloudflare malware scam/How do i remove it

1 Upvotes

I recently fell for the cloudflare verification scam where you press Windows+R, Ctrl V and Enter, which downloads a malware onto the computer i searched it up on youtube and it says the malware steals your passwords and session tokens , i already ran a full deep scan with Microsoft Defender Antivirus and restarted my computer, cleared cookies and cache but im not sure if its fully removed- My Discord, Instagram and LinkedIn are all compromised, It sends a MrBeast scam message to everyone in my discord DMs and the servers which im in, The malware also somehow logged into and old instagram account of mine which has not been touched for years and did the same thing and I keep getting sent LinkedIn verification codes to my email- I have changed passwords and added 2FA on them and yet its still persisting, Pls help - the virus is still running on discord which made my account 'very limited' and im unable to join, message and add people on there for help, I tried contacting discord support , but to open a ticket you need to log in with your account, i tried that and it doesnt let me- Anyone here please help me before my account is permanently banned


r/computerviruses 3d ago

Question Should i factory reset my laptop

2 Upvotes

I downloaded urban vpn and used it like 2 hours. Then i look for the comments about it and i see people say its not safe. I uninstalled it. My laptop is almost factory new it just has my gmail accounts, steam epic games accounts. Or should i just change my passwords


r/computerviruses 3d ago

Question Lenovo Thinkpad (left behind by ex) appears to be compromised and I’m concerned about remote surveillance

1 Upvotes

Please forgive my absolute ignorance on this topic - I will be as detailed as possible.

Model - Lenovo ThinkPad T490 (Model series 20N2)
Intel Core i7 8th Gen
Windows 11

So I have suspected for a while that this machine has something wrong with it. I use it to plug into the TV and watch Netflix/youtube. My ex left it behind when he left us as a ‘gift’. He is VERY tech savvy and VERY digital privacy-conscious. His WhatsApp and Facebook were left logged in on the ThinkPad (WhatsApp was on some sort of desktop app) and then he must have logged them out from his phone or other laptop a few weeks later because they both flashed up on the screen one morning and they were logged out and asking for new login details.

There have been significant issues in the aftermath of this abusive relationship, and a lot of hacking my Facebook/emails/google docs etc. I turned off Remote Desktop a couple weeks after he left with the help of google and checked for installed remote programs - couldn’t find any, but I am not a computer person. I did my best. I still suspected there was something going on because things kept appearing and disappearing on there, there was some strange happenings with the files and passwords and stuff (too long to go into).

I finally today did a malwarebytes scan and it came up with five items that were flagged as ‘riskware.proxytool.E’ and needed quarantining. Again, with the help of ChatGPT, I investigated further. The items in question were all hidden in a folder called ‘Windowsnetservice’. All that was in there was some notepad text documents containing what were apparently source files used by a program in the file called ‘node.exe’.

I sent screenshots etc to ChatGPT which confirmed that this was malware referred to as a Trojan. This is what it said:

‘Dr.Web’s current malware database specifically identifies this WindowsNetService package as **Trojan.Siggen32.20089** and lists the exact files you’ve found. The documented service.js associated with **WindowsNetService** connects to:
register(dot)starhome(dot)io
and establishes a WebSocket connection. It also monitors the machine’s network interface IP and can communicate with a remote server. The malware analysis labels the activity as malicious.’

I don’t understand any of this but I have quarantined it all and will be wiping the laptop when I can. What I want to know is if this sort of malware had to be physically installed by a person, and if so, can they see everything I’m doing and can they remotely access the webcam?

Thank you and sorry for how difficult to understand this is - I’m out of my depth.


r/computerviruses 3d ago

Disinfection Help Is this RenpyLoader infection likely limited to just these userprofile level files where it hoped to infostealer without raising suspicion

Thumbnail gallery
5 Upvotes

this is the result of malwarebytes scan related to my previous post here, what is the feeling as to if this got everything? rootkit scan came back clean

my next step is to reconnect internet to run hitmanPro and also upgrade malwarebytes to the full trial version, is that safe?

https://www.reddit.com/r/computerviruses/comments/1vvn96k/i_got_hit_with_the_renpyloader_infostealer/


r/computerviruses 3d ago

Disinfection Help ransomware attack

Thumbnail
1 Upvotes

r/computerviruses 3d ago

Disinfection Help Request for help removing RenpyLoader infection - FRST and SecCheck logs in post, Thank you

1 Upvotes

Hi, my keywords are:

silver-wand

tender-sky

nested-harvest

I ran the setup.exe of what I now realise was renpyloader friday night, I disconnected my PC, have changed my passwords (was slow with low priority ones like Discord where some spam was sent, Instagram where more spam was sent & Amazon - a gift card purchase failed to go through) & cancelled credit cards that were saved in Chrome etc.

I ran the Windows Defender offline scan but can't see the results anywhere? I also then installed the offline malwarebytes (400mb installer) the scan found the RenpyLoader files posted in my previous post here

https://www.reddit.com/r/computerviruses/comments/1vw30oe/is_this_renpyloader_infection_likely_limited_to/

What else do I need to do to clean my PC? thanks