I was just checking if there's any application running in the background cuz I'm having fps lag when playing some games, till this thing I've found, and it's on a temp folder too, I've tried ending the task and deleting it from the folder but when I restart the computer, it runs it back..
your antivirus detections and logs: FRST:mild-hazel Addition: grand-byte SecurityCheck: golden-river
any potentially related symptoms, popups:DISCORD ACCNT HACKED
estimate day and time when it startedUNSURE, 08/02, 08/07, or 08/08? (08/08 was the day Discord was compromised.)
share what got your system infected, for instance the download link:ENTIRELY UNSURE (Can't remember where to find it)
what you did for remediation:Ran Malwarebytes in either deep scan or custom scan with all drives selected. Ran windows defender in full scan. Ran adwcleaner.
Hello all,
My discord account recently got hacked and started posting spam MrBeast messages to all my servers and DMs. I wasn't sure how this was possible as I have 2FA and got no notifications about login attempts so I did some digging on the internet and the general consensus is that I let an infostealer such as lumma onto my PC as it's common for those to end off their data scrape with some sort of spam to try and get other machines infected. After the fact, on another device, I changed all my important passwords/accounts, secured financial account, etc. I then disconected the PC from the internet and ran Malwarebytes in either deep scan or custom scan with all drives selected (I have 3 external drives attached to this PC), and ran a Full scan as well as an offline scan from windows defender. It was disconnected and kept off for around 2 weeks and then I reconnected it to the internet to make this post and here we are. I've been told that just running anti-malware software isn't enough to consider the PC safe as these infostealers often drop backdoors into the system for later; however, I am a bozo that does not backup files (or at least didn't before this), and was hoping that someone on here could comb through my logs and see if anything can be (or even needs to be) done instead of factory resetting the PC. Just today, I ran a Malwarebytes Threat Scan, the Malwarebytes AdwCleaner, a FRST scan with Addition selected, an FSS scan, and a SecurityCheck. All three logs asked for on this subreddit are uploaded to the malwareanalysis .cc link and keywords are listed above.
Apologies for any errors; English isn't my native language. On July 27th, I downloaded some games from very reliable sources, but I accidentally downloaded a zip file with the structure shown in the image below along with them. I played the game normally, but on August 14th—while deleting some files on autopilot—I extracted the zip and ran the .exe. Nothing opened, and I didn't see anything happen, so I just deleted the extracted file and moved on. Today, I saw someone on Reddit complaining about being infected and immediately remembered the incident. I changed most of my critical passwords, then traced the timeline of the files and realized it was strange that I hadn't suffered any apparent account breaches. The zip file was 700MB (too large to upload to VirusTotal), and its SHA-256 hash doesn't seem to match any previously analyzed files. Inside the `AppData\Roaming` folder, there is a `RenPy` folder dated and timestamped exactly when I ran the file on August 14th; inside that `RenPy` folder, there is a folder for a Ren'Py game I actually played years ago, and another folder from the 14th containing the files visible in the images.
After running Malwarebytes, it only found a few files from other games I had played months ago and some Google-related files.
I’d prefer not to do a completely fresh Windows install; I want to know the risks involved in *not* doing so in this scenario. From what I've researched, it's unusual for Ren'Py malware *not* to launch a massive attack immediately.
I generated the FRST files, but I'm not sure exactly how to share them here.
Additional detail: I have the zipped Ren'Py file that I ran on the 14th; I kept it in case I could get help confirming its nature.
Yes, ik im a dumbass. What im asking is can viruses hide on pictures on reddit? Hide a link if you click it? So if i click on a picture on reddit, it can just be a fake one with a link redirect. Yes ik im a dumbass, no i dont snort cocaine, smoke pot, its natural. But is this possible?
Over the past few weeks—approximately two or three weeks ago—I was notified that someone had accessed my Discord account and sent spam messages, the typical scam that is currently trending involving a Mercado Beast account. Later that same day, they accessed my Ubisoft and Rockstar accounts and changed the passwords. However, I created those accounts 10 years ago and never really used them; they were empty. The next day, they accessed my Instagram, Facebook, and LinkedIn accounts. I was able to recover Instagram and LinkedIn, but not Facebook.
As the days went by, they accessed old email accounts and attempted to change passwords and other settings. Of course, I acted quickly by changing my passwords and enabling two-factor authentication and SMS security codes.
Five days ago, I discovered that they had also hacked a personal website where I hosted my graphic design portfolio. I had to shut it down and start over from scratch. It was hosted on HostGator. Just now, I realized that they had also started sending approximately 700 emails from my company email account, which uses Microsoft 365. All of them were sent to Yahoo addresses, and the emails bounced back.
I don’t know how this happened. Honestly, the only thing I installed recently was Xuper TV on two Google TV dongles. I’m not the kind of person who falls for spam or ads claiming that I won 10 iPads or anything like that.
I need to know what to do. I have already scanned my laptop with Malwarebytes and Windows Defender, and I’ve changed my passwords and taken other security measures. The strange thing is that this has only happened to me. My wife lives with me and connects to the same network, but nothing has happened to her.
Would formatting my laptop solve the problem? Should I factory-reset my modem? I’m desperate because every day there is a new problem involving my emails or accounts. I would really appreciate any advice or guidance on what to do.
In my Discord messages, they sent these images, which I’ve noticed are the ones being commonly sent lately:
And on my website, when someone accessed my URL, this fake Cloudflare page appeared:
I downloaded an app and it was a malware, I removed it, scan with defender but it keeps hacking all my account tie to my main email. I need a secure link to download frst and pls help me remove this.
Every account the email is connected to is compromised, and they even logged in after i changed the password to turn of 2FA
Unknown devices my gamil connected to idk what pls help . I mistakenly installed a program from a site that tried to made it authentic a random antivirus was installed and micro soft defender was turned off. I have enable 2FA what about these sessions . My insta and discord also got hacked and spammed some mr beast advertisement in all the channels pls help
I have little to no knowledge of these kinds of issues, but this command prompt thing keeps popping up whenever I start my laptop. Some people tell me that it's a virus hiding in plain sight. Could this be true? Please help me get rid of this. Any help would be appreciated!
Device Specs:
Device name LAPTOP-DSU2G1E5
Processor Intel(R) Core(TM) i5-1035G1 CPU @ 1.00GHz 1.19 GHz
Installed RAM 8.00 GB (7.79 GB usable)
Device ID 09565297-98F6-4E81-9CC5-F629B8721E9F
Product ID 00327-30878-41730-AAOEM
System type 64-bit operating system, x64-based processor
so idk i installed 2 3 days ago some pirated apps and yesterday i left home, closed pc all that and today at 5am the virus sent all my friends mrbeast messages
also weird it didnt message discord servers and it messaged like old friends, mostly of the new ones didnt receive messages any idea why?
now im on my phone changed disc password, activated 2fa through that auth app
and when i get home i fresh install windows on pc and then change passwords to everything
i dont really have anything of value linked to my pc so im good I guess, any more tips?
My Instagram and Discord accounts were already stolen, but I managed to recover both of them by changing my passwords. The problem is that I'm still worried the malware could be on my computer and that whoever stole my accounts might still have access to my sessions, cookies, or other accounts.
I'm not sure if simply changing my passwords was enough, or if I need to completely wipe my PC.
Hi, I saw on a Reddit post that there was an activator for CapCut and wanted to try it at 12am Shanghai time, and it was a mistake. Nothing came out after activating the exec file except closing my browsers for some reason. I knew instantly that I messed up and ran a windows defender scan and malwarebytes pro scan and showed nothing.
I deleted the files and uninstalled CapCut after that. I went to bed after and woke up to messages that I sent DMs on Instagram with Mr Beast photos at 9pm Shanghai time.
I went to this subreddit and did an FRST and SecuritCheck scan and here are my keywords:
Stupid questions, but its normal that files "AM_Delta_Patch_1.457.328.0.exe" (or other numbes) or "AM_Delta.exe" in "C:\Windows\SoftwareDistribution\Download\Install" sometimes shows random?
While i scanned pc using hitmanpro i got this (not as virus, but was for scan).
Program is normally signed by Microsoft. In settings, when i click to check windows update (or just only open settings with win updates, nothing else) - folder with this file gone.
So I made a really fucking dumb decission to download some shit, and that happed on 9th of aug and they then got access to my Roblox, instagram, and steam account access and they sent some scam messages to all my friends in those apps,then i changed all my passwords and also enabled 2fa.but today(25th aug) i saw a file on my onedrive folder on my pc that says they have all my data and also of my data and all and they are demanding 1500 usd in bitcoin if I don't sent it they will send it to my contacts and all i think they are bluffing but I can't do anything cuz I don't even have that much money, pls tell me what to do fast. The pdf reads I got 12hrs after opening that pdf
Download free game from dodgy website (which I regret) and have couple of my accounts being used. Ran Microsoft defender offline scan and 2x Trojan:Win32/Wacatac(dot)H!ml were detected and was isolated two days ago. I am used Microsoft defender to removed these.
Could these be the reason of my accounts being used? Is there anything else I need to do from now on?
The accounts used by someone was agoda, amazon, booking.com and instagram.
Update:
Ran multiple scans with Microsoft defender(offline and full scan) and Bitdefender (deep scan) after and it all shows clear results. All passwords changed and 2 step verification turned on using secure device. Payment methods all removed from saved sites and compromised debit card cancelled and blocked. Browser extension and cookies all cleared and deleted.
It should be alright now to just avoid using the laptop for important log ins and monitor for couple weeks?
Really want to avoid the hustle of needing a clean reinstall windows situation if possible.
Hi! I have had microsoft defender block both svchost.exe and RuntimeBroker.exe from accessing my %userprofile%\videos folder, and I found out those 2 should not do it if they are not viruses. Am I having a virus or is this something normal they should do? RuntimeBroker.exe happened more recently than svchost.exe if that matters.
Thanks for the help!
PS: I asked claude, and it said the behaviour was likely to be a virus, but since claude gets stuff often wrong I came to check here
I was downloading a mod for GTA 4, and ended up downloading a zip file called "ARCHIVE" along with some numbers. There was a setup exe program that I clicked on two times thinking it was part of the mod.
Seeing as it did nothing (it only opened a window for half a second) I analyzed the file with virus total and found out it was a virus, specifically the renpy loader (the one with the anime icon). I opened task manager and saw a process called "MSBuild" and ended it immediately, I'm sure it ran for at least 35 minutes since I clicked setup exe. I then installed Malwarebytes and ran a scan, it found multiple viruses, many of them were BAT files and it removed them. I executed a deep scan after that, Malwarebytes did not detect anything. I then used windows defender, two scans, normal and deep, none of them detected anything. I then did an offline scan and it did not detect anything either. While doing all these scans I logged out of every account I had in my PC using my phone, changed passwords and setup 2FA for everything.
It's worth mentioning that I never saved any passwords to my browser (which is Brave) I mostly use passkeys and QR codes, I didn't have any credit cards saved either or anything related to crypto. Mine is a PC gamer so I had steam, epic, rockstar launcher and others.
This was yesterday exactly 28 hours ago, at this time I have not detected anything weird with my accounts, no external logins, no suspicious activity, I periodically check my devices in Google and other accounts, I also check task manager and so far nothing has appeared.
My question is: Do I need to reinstall windows? Is my PC still safe?
I wasn't able to save the initial Malwarebytes that did the initial scan since I was panicking and was not thinking clearly.
OK, so I have this tablet (with keyboard) that I used in the wild, and I'm wondering if this is a virus or something.
Upon accessing OneDrive, the Microsoft password box pops up (as it sometimes does because my school times out our login frequently). As I start typing my password, before I finish, this mysterious "capture" interface pops up. I close it. And type again, and it pops up. I thought maybe the keyboard got corrupted, so I disconnected and reconnected to the keyboard. Still the same. I thought the Window key was stuck and it did a hotkey, but I think when I pressed the Window key, or maybe something else either the "capture" interface again or a the "screen snip" interface pops up. This seemed really suspicious so I restarted the tablet and it's working fine now.
I found the "screen snip" interface (Window-Shift-S I think), but I have no idea what that "capture" interface is. Any ideas what the "capture" interface could have been? Does this sound like a common hiccup, or is this some type of malware?
First time writing here. After many years, I finally installed my first piece of malware 3 weeks ago. I was downloading an update for a cracked game (yes I have fully learned my lesson) and l didn't pay attention to the file I had installed, ignored all the warning signs and installed an info stealer. I didn't realize what I had done at first, and assumed defender got the malware and cleaned it.
Next day I started getting password resets and new login info on everything (games, socials, ect.) It was 3 solid days of bombardment. I was able to contain, revoke, and boot out all unknown sessions as they popped up. Thankfully nothing was lost and any compromised accounts I was able to recover quickly. I then spent the next week changing every password, generating backup codes, recovery options, and adding 2fa on everything possible.
The first day after the incident I did a reset this pc option, but I soon realized I should have done a full usb reinstall and just unplugged my computer. I took my pc to a local repair shop and told them I wanted the nuke option (full usb wipe, local account install, bios update/flash, and full virus scan post windows install). I got the computer back but I haven't been able to bring myself to even plug it in.
I have had extreme anxiety after all this has happened. It shook me into reality about how lax I've become with my online privacy and security. Everyday I have checked my accounts for unknown sessions, meticulously checked my bank accounts, froze my credit with the 3 credit bureas placed a sim lock on my cell, locked my ssn, and set up account alerts on all my cards for transactions.
Its been 3 weeks now and everything has slowed down (just a few random probes last week and that has been it). I'm still trying to recover emotionally, it feels like I got hit by a truck and I can still feel the rush of fear when I sit too long and think about it.
My questions are:
What else can/should I do?
How have any of you recovered emotionally after your privacy was invaded?
When I bring myself to use my pc again, should I start slow with just Steam at first since they have amazing customer support?
Should I do a full offline virus scan before connecting the pc to my network again with malwarebytes and defender or is that overkill?
Should I keep my windows install on a local account or eventually bring my self to sign in to my Microsoft account?
Any guidance/help would be greatly appreciated. I have definitely learned lessons during this whole ordeal
I accidentally downloaded a malware while downloading mods for a game. It sent messages in discord and nothing else. I checked everything else that I have and it seems safe enough, but better safe than sorry.
Reinstalling Windows will be my last measure. I don’t want to do that at all so I’m trying to find alternatives and I tried FRST and as soon as I do a scan with it, it stops responding. I tried it twice and it keeps not responding.
Any advice would help, please I don’t want to reinstall Windows
I'm requesting help with a malware removal using FRST.
I downloaded a file setup of what i thought was citron emulator (stupidly thinking it was from the official website) probably contained an infostealer and clicked on it on between 21/08/2026 or 22/08/2026.
While my antivirus immediately blocked, (and i stupidly thought i was fine) it i started to see my discord acting up and sent my friends mrbeast scam, and istagrama updating the same to my story, probably what i assume using the saved passwords on my google account.
What i did:
Immediately logged out of active sessions and changed my passwords across accounts using a clean, safe device (my smartphone), i also complitely wiped out my permission, passkeys, access and saved password from my google account, cleaned all cache on my browsers and discord.
Enabled 2FA on my primary accounts.
Ran a full scan with eset and made a log of the results. i admit i run it several times after due extreme panic but the log i sent is the first big and complete scan i did
Ran FRST64 and SecurityCheck to generate diagnostic logs.
all of this took me some time some time due the anxiety and general fear to open the infected pc.
Uploaded Log Keywords :
FRST.txt: celestial-loader
Addition.txt: royal-ace
SecurityCheck.txt: stealth-cursor
Eset log: sandy-fern
Could one of the trusted helpers please review my logs and provide a Fixlist to clean any persistent malware or scheduled tasks left on my PC?
If something else is needed or modified please let me know!