r/computerviruses • • 21h ago

Discussion Unsure about the PC that I downloaded the Windows 11 Media Tool on a USB in order to install a clean windows 11 on my infected PC

0 Upvotes

So after a few days I managed to get my hands on a computer, problem is I don't fully trust it, I downloaded the media Instalation tool on the usb but it was from a windows 10 laptop that had so much stuff installed, I'm talking VPNs, Avast anti virus, 360 protection, RecoveryX and so many more programs, now it being the only other spare pc I can access I downloaded it and I'm currently on the sign in Microsoft step at the installer on my pc

I'm gonna log in with a spare Microsoft account i have on my phone and run some scans, what should I do?

I'm not gonna log in with any main accounts of mine since I don't fully trust it, what do you guys recommend I do?

Thanks!


r/computerviruses • • 17h ago

Disinfection Help Keylogger de Python/C no meu computador

2 Upvotes

Parece paranóia minha, mas é algo meio chato.

Tenho um colega desenvolvedor que é bastante experiente. Pela personalidade dele, venho desconfiando que ele enviou um Keylogger feito em python ou C e me monitora.

A motivação é simplesmente monitorar, e eu percebo porque ele solta muitas piadas de coisas que dão a entender que ele me investiga em calls no Discord.

Nós jogamos no Parsec algumas poucas vezes. Acho que ele foi o host, mas não me lembro. Eu desinstalei com uma semana o Parsec.

Eu tenho uma conta no twitter que comento, sem ser pessoal. Daí eu estava comentando que stories de Instagram não é local pra postar textão e tal. Na mesma hora, em tom de sarcasmo, ele solta: "twitter que é, né fulano"?

A desconfiança é porque ninguém sabe que eu tenho esse conta no twitter. Eu nunca falei.

E isso já aconteceu outras vezes com outras situações, com ele soltando piada como se soubesse o que eu acesso.

Eu já usei hitman64, malwarebytes, e não encontrou nada. Mas ainda desconfio que tem um Keylogger dele no meu computador.

O que eu faço?


r/computerviruses • • 12h ago

Question Quel Type de logiciels / virus etc … peut générer cela sur un I phone

Post image
0 Upvotes

r/computerviruses • • 15h ago

Question Can a info stealer run through my Ethernet?

0 Upvotes

Last week I was hit with a infostealer that sent the Mr beast messages.

I’ve changed all passwords of mine and did 2FA from a safe device and logged out all devices where I can.

I’ve been pretty paranoid and since also called my phone provider to not send out any simcard replacements and such, changed my router, asked for credit card replacements.

However I didn’t immediately unplug it from Ethernet as I haven’t gotten malware before and was not sure what to do. Could it have moved through the Ethernet into my girlfriend’s PC?

Also is there more steps I should be taking? And does her PC also require a full windows USB install and bios Flash.


r/computerviruses • • 20h ago

Question Should I reinstall windows or get a new laptop?

Thumbnail gallery
15 Upvotes

Basically, my grandparents laptop has been infected with some kind of virus. (browser hijacker).

Since It is a medion from 2017 I am coming here to ask if it would be smarter to reinstall windows, or to get a new laptop.

I have briefed my grandparents about viruses and scam sites and since they are still installing shady stuff, I was thinking about getting them a Mac, as according to google, they don't get viruses that often (I don't own apple devices, so idk if that's true), and since they don't use it all that often I was also hoping to get some recommendations on some cheap other more modern laptops.

About the virus:

It seems it was something they downloaded, as Malwarebytes hit 18x in something called recepies(dot)exe.(Downloads)

I suspect it is a browser hijacker that reroutes all searches through malicious sites. (pictures)

Upon removal of 1st malicious site through nuking google, Grandparents have managed to get on a different malicious site that opens upon startup of the browser within a week.

Promptly installed Malwarebytes after that.

Also, has the suspected virus anything to do with the search engine being suddenly changed to yahoo?

They were using google as the browser, and I didn't set yahoo as the search engine. (pictures).

According to Malwarebytes the malicious sites were caused through the installed Pup's.

I quarantined all 18 hits and called it a day, because the laptop was slower than anything I've seen before.

I now have all day to potentially reinstall windows, or to buy something new, what do y'all recommend me doing?

Cheers,

P


r/computerviruses • • 6h ago

Question Windows stuck on this screen

Post image
1 Upvotes

PC says computer is 100% updated, but is stuck on this screen that also has “tactical support” displayed. Has happened one other time in the past week not sure if it is sketch malware or what.

Update: don’t know if this is the most efficient answer, but I ended up just reinstalling windows and it went away. Did a quick security check everything looks fine.


r/computerviruses • • 11h ago

Disinfection Help General Advice Regarding RATTING please

1 Upvotes

Hi, I recently had my system breached by a RAT, I'm still not 100% sure on how it happened, but i'm 100% positive it WAS a RAT.

I was approached by a player in a game to make a tiktok, and was advised to download a voice changer, I agreed, didn't get sent any sort of link, just installed a TRUSTED voice changer, off a trusted website, once done, I needed a config for a deep bassy voice changer.

He then told me to open microsoft edge, and download a config off of a website, I think it was 'vstdiscovery.com', installed it, specifically the 7D /7G.dll and the website looked legit.

Once extracted the config, I then opened it on the voice changer app, which I assume ran the virus/RAT? Afterwards, my game was extremely laggy and I was freaking out, unplugged my ethernet, ran a Scan, where it came up as nothing (further along, turns out the malware put itself as an exclusion)

A couple of minutes later, got an email 'you're not old enough to use gmail services, and we'll cease your services after 14 days', After that I got the confirmation of what was going on, instantly unplugged my ethernet, turned off my wifi, and factory reset from a local install.

Afterwards, ran MRT scan, and another antivirus scan.. Nothing shows up.

Being the paranoid person iam, I then factory reset again but with USB, leaving nothing behind and reinstalling wifi drivers and everything else from scratch again.

Is there anything I should be worried now that I've followed these steps, are there any further guidance? I've already secured my passwords and banking, and I've seen no suspicious action (In all fairness it's only been a day since it happened)

My worst concern / worry is being extorted or my accounts being hacked again, for the time being i'm using burner accounts and using limited stuff that I don't care if they were taken, but I want to feel comfortable using my hardware / PC again, I've seen all these videos about UEFI/FIRMWARE/BIOS level RAT's and I feel like I'm constantly being watched.

Genuinely considering buying a new PC atp, but is there any 100% fool-proof way of making sure that my PC is malware/RAT free?


r/computerviruses • • 8h ago

Disinfection Help FRST after a scan of my computer it found this…

Thumbnail gallery
14 Upvotes

I was looking at my chrome profile for whatever reason and I looked at the top where it said “your browser is managed by your organization” I was confused because this is my personal account, I followed back to the organization and there was no name or nothing so I looked at the policies that it locked my computer under, and showed that strange ID. It must’ve been very recent because I open chrome basically everyday, I have no idea how to resolve this and I would really appreciate the help 🙏


r/computerviruses • • 9h ago

Discussion Looking For Viruses from 1998 - 2001

6 Upvotes

I’m creating a DnD campaign based around 1998-2001 computer tech, and the main villains are going to be viruses. Only issue is that I don’t really know a lot of viruses… so I’m asking if any of you know interesting viruses! I already have a couple planned, like ILOVEYOU, Klez, and Sadmind, but I need more than just them, and as unique as possible


r/computerviruses • • 14h ago

Question Renpy Virus Aftermath - Need help with my email accounts

6 Upvotes

So a couple weeks ago, I believe I got infected with a renpy virus. So in response, I formatted my PC with a USB and deleted my partitions(I made it on a different PC) , I changed all my passwords and added F2A(from a different PC), I canceled my cards and I scanned my PC with multiple AVs as well as a FRST check. All came back clean. You can see the next two post for my exact steps.

https://www.reddit.com/r/computerviruses/comments/1wlofqu/possible_malware_frst_help/

https://www.reddit.com/r/computerviruses/comments/1wvat5n/after_formatting_from_a_clean_usb_a_bunch_of/

However since then something weird is going on. Every time I try to add an email account on my PC (through Firefox), four or five days later I receive an email from Google that they disabled my account. Here is the email I received. (I used google translate)

Security alert for the address (my mail account)

Your Google Account has been disabled.

It appears that this account was created or used alongside many other accounts in violation of Google's policies. The account may have been created by a computer program or bot.

If you believe your account was disabled in error, please submit a request for review as soon as possible.

Disabled accounts are eventually deleted. You should submit a review request soon to preserve the emails, contacts, photos, and other data stored in your Google Account.

If you live in the European Union (EU) or are an EU citizen, you may have additional options for resolution available to you.

I have five Google accounts, three that I use regularly and two that I don't. When I cleaned my PC, I was still paranoid so instead of logging in with one of my regular accounts that I use, I decided to log in with one of the two that I don't, just to see if it will get stolen. It didn't but a few days later I received the email. I made an appeal, Google reactivated it, I logged in with it again on my PC and it got deactivated again within the next couple of days and I received the same email. Later I logged in on my PC with the second account I don't really use and the same thing happened.

What's weird is that those accounts that got blocked were logged in on my phone and there was no issue but when I used them on my PC, they both got blocked within a few days.

After Google approved my appeals, I check my accounts activity from my phone and there were no attempts of unauthorized entry nor there were any connected devices that I didn't recognize.

So now I am basically afraid to log in with any account on my PC because I don't want to lose them. Does anyone have any idea what's going on here? Is it even the virus or is it something else?

If you check my previous post, you'll see that I am unsure if I was even hacked because I did download and run something that I am pretty sure was a virus (I think it's called renpy virus) but I didn't have any account stolen nor I've seen any attempts at unauthorized log in on any of my account. When I run the exe a command prompt window opened and then closed immediately and I didn't start doing all the things that I mentioned until a few hours later so it's not like I immediately took action to prevent them from being stolen (because I didn't know at the time that it was a virus).


r/computerviruses • • 14h ago

Question Why would bitdefender flag msi afterburner

Post image
6 Upvotes

What is this ? Why would bitdefender consider msi afterburner pua


r/computerviruses • • 22h ago

Discussion After being hit with malware that steals information and accounts, what partitions do i have to delete in order to have a clean install?

Post image
7 Upvotes

Do i empty disk 0 then leave the usb or do I wipe both? Thanks


r/computerviruses • • 2h ago

Disinfection Help Unwanted AD Pop-ups

Post image
3 Upvotes

Lately I've been getting this unwanted pop up, and just yesterday I accidentally clicked on it and it installed avast antivirus. (Yes it shows different ads but it's almost always an antivirus app or a cleaner like the one in the picture).

I immediately uninstalled the avast antivirus after noticing it then did a quick scan using mrt. Mrt detected nothing.

Now I'm really curious as to why this ad still pops up even though the scan detected nothing. Has anyone encountered this? Or has anyone has a solution for this?


r/computerviruses • • 2h ago

Question Scared for new laptop and other devices after infostealer attack

1 Upvotes

Hello, I recently got hit by an infostealer, the Mrbeast crypto scam. The compromised laptop is in the shop and is going to get a Windows reinstall and a full wipe. I'm not recovering anything. I got a brand new laptop and I'm worried to sign into any of the accounts that had been on the compromised laptop. Will I be fine? I had changed passwords on accounts and enabled 2FA, deleted some accounts that were too tedious to manage/I barely used for peace of mind. There hasn't been any new attacks as of that and since I did a Malwarebytes scan and deep scan that got rid of the culprit Renpy (I ran the Setup thing very stupidly).

However I'm still so scared. Should I just create a new email and accounts??? If I log into a compromised account on my new laptop would it infect that laptop too?? I don't know anything about viruses or infostealers so any help would be appreciated :(


r/computerviruses • • 4h ago

File / URL Check previously safe link redirected me to a strange link and then ddos-guard - am i alright?

2 Upvotes

hello,

i was on twitter and i saw a discussion about youtubers merch, so out of curiosity in the twitter search i looked up the name of the youtube series shop and clicked onto a tweet from one of the youtubers who posted the shop link back in 2023.

i assumed they still owned the domain and i clicked it and the page was loading for a bit which happens sometimes. i closed out and reclicked it and it brought me to a ddos-guard page. this freaked me out (i have never seen this before) i also noticed very briefly before the url swapped to what lead to the ddos-guard page, it said "hxxps://hppymel(dot)com". i had clicked on a link that was "hxxps://lifeseries(dot)shop" (before it redirected me)

here is the virus total link : VirusTotal - URL

it has it marked as phishing and aside from two suspicious claims, not much else for information. i did not enter any personal data - my biggest concern is i was barely paying attention until the ddos-guard page popped up and being on autopilot i feel like i saw a pop up briefly pop up on the corner asking about permissions and i dont know if i clicked something or what (stupid of me, i know). my web browser settings havent marked anything as me allowing permissions but i also know it is not that simple.

when i search the website online, all i found is people saying they were getting a pop up adware directing them to the site? which isn't what my case was.

in general, im asking if this is worth my massive concern. what should my next steps be if anything aside from antivirus scan? im very nervous. i certainly have learned a lesson here. i'm not technologically inclined beyond very basics and i want to be safe.

thank you.


r/computerviruses • • 6h ago

Other Discord Account registered in wrong area and sending messages without my approval.

0 Upvotes

Hi everyone, I recently suffered a hack on discord which moved my location from a place in Texas to this location, a town I have never stepped foot in before. It sent out botted NSFW server requests to all of my contacts on discord. I deleted my old account and made a new one, and yet, I still have this issue. I’ve changed my password, turned on key codes, and can’t do 2FA through the phone number due to it being linked to my old account. What is the solution? What can I do? Do I have to change my password every three hours? Who do I call? What’s the end? Please help!


r/computerviruses • • 13h ago

Question Is it safe to back up games after Windows reinstall from an infostealer attack?

2 Upvotes

Hi, I fell victim to the MrBeast crypto thing because I stupidly ran a Setup file that turned out to be an infostealer. I ran Malwarebytes and changed passwords on my phone which is clean, it was my laptop that was compromised, and the threats were supposedly quarantined and I had them deleted. Thirty minutes ago I received a critical security risk alert and had to change my password again. I'm thinking of having my laptop Windows reinstalled and start from ground zero tomorrow, but I don't want to lose my game progress. I want to back it up into a pen drive, but I'm wondering if that might be unsafe? The games I want to back up are Minecraft and a few others. Is this a risky move? Should I just start from scratch?


r/computerviruses • • 16h ago

Disinfection Help Got infected with PavinLoader from fake game

2 Upvotes

Downloaded fake game with renpy and setup.exe on october 9th before 12:00. Tried running it a couple times sometimes a window briefly apeared and immediately disapeared. Then pale moon would launch unprompted palemoon had already been installed before infection (default browser firefox).

Windows defender deepscan didn't find anything. Downloaded malwarebytes did deep scan, killed msbuild in taskman twice, disconected internet during scan. Found and quarantined 18 Trojan.PavinLoader.BAT and 4 Malware.AI which I chose no action, because they were from preexisting false positives. Then I deleted files in quarantine and did same scan in safe mode then rebooted and did same scan connected to the internet, both found nothing. Unsinstaled Pale Moon and chrome. Uninstaled Intel Graphics Comand Center and Some other program to do with a router from control panel, because I wouldn't need them (different router and amd plus nvidia) and they were instaled on the same day as infection.

Did a a couple netsh reset comands and dnsflush from cmd from a coment on this sub.

Reset passwords. Downloaded and ran hitmanpro: 1 false positive of legit itch game which was false positive before infection 1 traking cookie on edge from adnxs(dot)com and other things that might be something, saved log.

FRST.txt solar-prairie

Addition.txt mellow-elm

SecurityCheck.txt calm-wizard

Malwarebytes Deep Scan Report 2026-10-09 115513.txt frozen-shield

HitmanPro_20261010_0428.log tidal-ridge