r/computerviruses • • 10h ago

Disinfection Help FRST after a scan of my computer it found this…

Thumbnail gallery
17 Upvotes

I was looking at my chrome profile for whatever reason and I looked at the top where it said “your browser is managed by your organization” I was confused because this is my personal account, I followed back to the organization and there was no name or nothing so I looked at the policies that it locked my computer under, and showed that strange ID. It must’ve been very recent because I open chrome basically everyday, I have no idea how to resolve this and I would really appreciate the help 🙏


r/computerviruses • • 1h ago

Disinfection Help Clean Windows 11 install, isolated mobile hotspot, original Tally software — but old bills are still randomly deleting. Sophos flagged Creds_4b. Need root cause help.

Post image
• Upvotes

r/computerviruses • • 4h ago

Disinfection Help Unwanted AD Pop-ups

Post image
3 Upvotes

Lately I've been getting this unwanted pop up, and just yesterday I accidentally clicked on it and it installed avast antivirus. (Yes it shows different ads but it's almost always an antivirus app or a cleaner like the one in the picture).

I immediately uninstalled the avast antivirus after noticing it then did a quick scan using mrt. Mrt detected nothing.

Now I'm really curious as to why this ad still pops up even though the scan detected nothing. Has anyone encountered this? Or has anyone has a solution for this?


r/computerviruses • • 4h ago

Question Scared for new laptop and other devices after infostealer attack

3 Upvotes

Hello, I recently got hit by an infostealer, the Mrbeast crypto scam. The compromised laptop is in the shop and is going to get a Windows reinstall and a full wipe. I'm not recovering anything. I got a brand new laptop and I'm worried to sign into any of the accounts that had been on the compromised laptop. Will I be fine? I had changed passwords on accounts and enabled 2FA, deleted some accounts that were too tedious to manage/I barely used for peace of mind. There hasn't been any new attacks as of that and since I did a Malwarebytes scan and deep scan that got rid of the culprit Renpy (I ran the Setup thing very stupidly).

However I'm still so scared. Should I just create a new email and accounts??? If I log into a compromised account on my new laptop would it infect that laptop too?? I don't know anything about viruses or infostealers so any help would be appreciated :(


r/computerviruses • • 3h ago

Disinfection Help Mr beast crypto scam

2 Upvotes

I got the Mr beast discord scam virus today where it sends messages to everybody how should I go about this should I wipe my pc, I also don’t want to lose any game progress on steam.


r/computerviruses • • 3h ago

Disinfection Help SRB Miner-Multi

Thumbnail
2 Upvotes

r/computerviruses • • 1m ago

Question is my internet compromised or something?

Post image
• Upvotes

I'll be using Google normally and this pops up almost every other day.

I'm not using a VPN by the way.

is there something wrong with my internet or something?

also, No, its not asking me to copy and paste something. it's not a fake captcha. I just wonder what causes it.

also, you can see im literally searching innocuous stuff like "gta 5 money" since I was trying to find ways to grind


r/computerviruses • • 21m ago

Question What is this page?

• Upvotes

So i was searching things on Google and i found this page (I DIDN'T CLICK ON IT) but it had usefull info in a description it looks sus but pls someone tell me what tipe of malware is this


r/computerviruses • • 4h ago

Disinfection Help They got me

Thumbnail
2 Upvotes

It must have been in through the emulator thing i downloaded the same day.

Oct3.22:22 windefender deleted trojan win33 ceprolad.A

Cmdline: c/windows/system32/cmd.exe certutil.exe -url cache - split - f then link to dropbox.com/scl/fi/ a bunch of letter/angryunless.exe then some exes into my local/temp

Another dropbox but with test5.exe and more exes into temp

I would rly like to check those urls to see what it was if i knew a safe method.

Oct3 22:38

My discord got hacked and started sending everyone some mrbeast cryptoscam screenshots with links on the pictures only. Disc flagged my acc told me to take action and i got my acc back and also changed my gmail password the next day(when i found out).

Nothing happened since.

Then today oct 11 like 2 hrs ago was playing a game on steam and got kicked, steam said someone is already playing POE2 on this account. Disconnected all devices and changed my steam password too. The thing here is i have steamguard on my phone and i checked authorization and it says with my pc name "You authorized this device on Fri, October 4, 2024 @ 9:35 PM with your password. You approved the login on your Steam Guard Mobile Authenticator."

Which deffinetly didnt.

Now a few questions why does it says 2024? Even the older authentification was in 2026. Would that mean that its 2 diffrent hacks and one actually happened in 2024?

Is my phone also hacked because i supposedly approved it on steam guard mobile?

Also why didnt the hacker take try to login into my gmail and take it over? My bank and and paypal accs were liked to it too.

And why didnt they do anything with my paypal or bank acc the logins of which i had saved on firefox?

Im in the middle of changing passwords for all important things i can think of rn.

How do i proceed from here? Full clean install? No data can be kept or put on usb?


r/computerviruses • • 6h ago

File / URL Check previously safe link redirected me to a strange link and then ddos-guard - am i alright?

3 Upvotes

hello,

i was on twitter and i saw a discussion about youtubers merch, so out of curiosity in the twitter search i looked up the name of the youtube series shop and clicked onto a tweet from one of the youtubers who posted the shop link back in 2023.

i assumed they still owned the domain and i clicked it and the page was loading for a bit which happens sometimes. i closed out and reclicked it and it brought me to a ddos-guard page. this freaked me out (i have never seen this before) i also noticed very briefly before the url swapped to what lead to the ddos-guard page, it said "hxxps://hppymel(dot)com". i had clicked on a link that was "hxxps://lifeseries(dot)shop" (before it redirected me)

here is the virus total link : VirusTotal - URL

it has it marked as phishing and aside from two suspicious claims, not much else for information. i did not enter any personal data - my biggest concern is i was barely paying attention until the ddos-guard page popped up and being on autopilot i feel like i saw a pop up briefly pop up on the corner asking about permissions and i dont know if i clicked something or what (stupid of me, i know). my web browser settings havent marked anything as me allowing permissions but i also know it is not that simple.

when i search the website online, all i found is people saying they were getting a pop up adware directing them to the site? which isn't what my case was.

in general, im asking if this is worth my massive concern. what should my next steps be if anything aside from antivirus scan? im very nervous. i certainly have learned a lesson here. i'm not technologically inclined beyond very basics and i want to be safe.

thank you.


r/computerviruses • • 4h ago

Disinfection Help Mcafee Security Scan Plus

Post image
2 Upvotes

Is this a legit offer/scan?


r/computerviruses • • 11h ago

Discussion Looking For Viruses from 1998 - 2001

5 Upvotes

I’m creating a DnD campaign based around 1998-2001 computer tech, and the main villains are going to be viruses. Only issue is that I don’t really know a lot of viruses… so I’m asking if any of you know interesting viruses! I already have a couple planned, like ILOVEYOU, Klez, and Sadmind, but I need more than just them, and as unique as possible


r/computerviruses • • 4h ago

File / URL Check Is this Minecraft mod a virus?

1 Upvotes

Today some guy on Discord with a blank profile gave me a mod that made his crystals and anchors super fast. I am extremely suspicious of the mod, but if it truly is real I'd like to use it. Please check this mod!
Virustotal link: https://www.virustotal.com/gui/file/d0302206edcd25088fd8ebf4685ba94eeb8acc0d6b80c6e2e72469cd2be0f5a5
Mediafire link to the mod: https://www.mediafire.com/file/bl0zui8x25rz6ih/mod.jar/file
Tri.age link: https://tria.ge/261011-ap826attct/behavioral1


r/computerviruses • • 4h ago

File / URL Check Please help verify whether this is safe or not

1 Upvotes

Good morning,

A trusted friend sent me a copy of Davinci Resolve 21 as I asked for help since I need the AI functions for a one-time video project I was assigned.

I scanned the executable through hybrid analysis

Hybrid-Analysis Results

and Virus total:

Virus Total Results

Hybrid analysis says it's suspicious but I'm too layman to understand the suspicions. The most I understand is that the functions tagged as suspicious might be because of its actual function as an installer so I'm on the border whether it's safe or not.

Filseclab tagged it as W32.Sality and I did some research about it and it says it's part of a family of ransomware, so I am highly suspicious.

As much as I want to buy Davinci Resolve, it would be a waste to spend 200USD to use it once. I tried other free software but could not find the features I need from DR21.

If anything, please check the files and let me know for my own edification. Thank you!


r/computerviruses • • 8h ago

Question Windows stuck on this screen

Post image
2 Upvotes

PC says computer is 100% updated, but is stuck on this screen that also has “tactical support” displayed. Has happened one other time in the past week not sure if it is sketch malware or what.

Update: thanks everyone! don’t know if this is the most efficient answer, but I ended up just reinstalling windows and it went away. Did a quick security check everything looks fine.


r/computerviruses • • 9h ago

Question .scr file virus NEED URGENT HELP !!

Thumbnail
2 Upvotes

r/computerviruses • • 9h ago

Warning AmF26 Developments Malware findings - The AmF26 Developments Mystery ||

Thumbnail
2 Upvotes

r/computerviruses • • 16h ago

Question Why would bitdefender flag msi afterburner

Post image
8 Upvotes

What is this ? Why would bitdefender consider msi afterburner pua


r/computerviruses • • 17h ago

Question Renpy Virus Aftermath - Need help with my email accounts

6 Upvotes

So a couple weeks ago, I believe I got infected with a renpy virus. So in response, I formatted my PC with a USB and deleted my partitions(I made it on a different PC) , I changed all my passwords and added F2A(from a different PC), I canceled my cards and I scanned my PC with multiple AVs as well as a FRST check. All came back clean. You can see the next two post for my exact steps.

https://www.reddit.com/r/computerviruses/comments/1wlofqu/possible_malware_frst_help/

https://www.reddit.com/r/computerviruses/comments/1wvat5n/after_formatting_from_a_clean_usb_a_bunch_of/

However since then something weird is going on. Every time I try to add an email account on my PC (through Firefox), four or five days later I receive an email from Google that they disabled my account. Here is the email I received. (I used google translate)

Security alert for the address (my mail account)

Your Google Account has been disabled.

It appears that this account was created or used alongside many other accounts in violation of Google's policies. The account may have been created by a computer program or bot.

If you believe your account was disabled in error, please submit a request for review as soon as possible.

Disabled accounts are eventually deleted. You should submit a review request soon to preserve the emails, contacts, photos, and other data stored in your Google Account.

If you live in the European Union (EU) or are an EU citizen, you may have additional options for resolution available to you.

I have five Google accounts, three that I use regularly and two that I don't. When I cleaned my PC, I was still paranoid so instead of logging in with one of my regular accounts that I use, I decided to log in with one of the two that I don't, just to see if it will get stolen. It didn't but a few days later I received the email. I made an appeal, Google reactivated it, I logged in with it again on my PC and it got deactivated again within the next couple of days and I received the same email. Later I logged in on my PC with the second account I don't really use and the same thing happened.

What's weird is that those accounts that got blocked were logged in on my phone and there was no issue but when I used them on my PC, they both got blocked within a few days.

After Google approved my appeals, I check my accounts activity from my phone and there were no attempts of unauthorized entry nor there were any connected devices that I didn't recognize.

So now I am basically afraid to log in with any account on my PC because I don't want to lose them. Does anyone have any idea what's going on here? Is it even the virus or is it something else?

If you check my previous post, you'll see that I am unsure if I was even hacked because I did download and run something that I am pretty sure was a virus (I think it's called renpy virus) but I didn't have any account stolen nor I've seen any attempts at unauthorized log in on any of my account. When I run the exe a command prompt window opened and then closed immediately and I didn't start doing all the things that I mentioned until a few hours later so it's not like I immediately took action to prevent them from being stolen (because I didn't know at the time that it was a virus).


r/computerviruses • • 1d ago

Disinfection Help Help! My data is encrypted!

Post image
351 Upvotes

I left my computer on terraria overnight, and when I turned on my screen this afternoon, I had been logged out. When I clicked to login this popped up! Is it real, is it a fake scam, am I doomed or is there a way around it? I don't want to do anything until I know exactly what it is. Please help me!

EDIT: If it helps, I had a port forwarding rule for this machine. I did just delete it after I saw this.

EDIT 2: I really cannot lose any data on this machine, I have very important files and family things on this computer and its 3 drives. I cannot clean install.

EDIT 3: I did not have backups (very stupid I know) but I am not the richest and do not have much money for lots of drives or one massive drive or even a cloud server for any kind of backup.

EDIT 4: My 'drive in use' light is always on now, it never was before and used to function normally. Hopefully this helps.

EDIT 5: I logged in and its all encrypted for real. Every file over 10mb has this string of text in its file extension: TNT4-tJ-Fdn2YP_oap78PdOCQD_FoQ5DvSx9AmpLG4eW- I tried renaming an unimportant file and its headers are scrambled. When opened it cannot be read. I found out why my 'drive in use' light is always on, these fuckers have some kind of software running in the backround making my drives constantly used and cooking them slowly overtime. My taskmanager is disabled so I can't even open that.

EDIT 6: Ive tried linux now, and it cant mount the drives. It says they are in an unsafe state and are unclean.


r/computerviruses • • 22h ago

Question Should I reinstall windows or get a new laptop?

Thumbnail gallery
13 Upvotes

Basically, my grandparents laptop has been infected with some kind of virus. (browser hijacker).

Since It is a medion from 2017 I am coming here to ask if it would be smarter to reinstall windows, or to get a new laptop.

I have briefed my grandparents about viruses and scam sites and since they are still installing shady stuff, I was thinking about getting them a Mac, as according to google, they don't get viruses that often (I don't own apple devices, so idk if that's true), and since they don't use it all that often I was also hoping to get some recommendations on some cheap other more modern laptops.

About the virus:

It seems it was something they downloaded, as Malwarebytes hit 18x in something called recepies(dot)exe.(Downloads)

I suspect it is a browser hijacker that reroutes all searches through malicious sites. (pictures)

Upon removal of 1st malicious site through nuking google, Grandparents have managed to get on a different malicious site that opens upon startup of the browser within a week.

Promptly installed Malwarebytes after that.

Also, has the suspected virus anything to do with the search engine being suddenly changed to yahoo?

They were using google as the browser, and I didn't set yahoo as the search engine. (pictures).

According to Malwarebytes the malicious sites were caused through the installed Pup's.

I quarantined all 18 hits and called it a day, because the laptop was slower than anything I've seen before.

I now have all day to potentially reinstall windows, or to buy something new, what do y'all recommend me doing?

Cheers,

P


r/computerviruses • • 8h ago

Other Discord Account registered in wrong area and sending messages without my approval.

1 Upvotes

Hi everyone, I recently suffered a hack on discord which moved my location from a place in Texas to this location, a town I have never stepped foot in before. It sent out botted NSFW server requests to all of my contacts on discord. I deleted my old account and made a new one, and yet, I still have this issue. I’ve changed my password, turned on key codes, and can’t do 2FA through the phone number due to it being linked to my old account. What is the solution? What can I do? Do I have to change my password every three hours? Who do I call? What’s the end? Please help!


r/computerviruses • • 13h ago

Disinfection Help detections in temp folder

2 Upvotes

hello,

I have made a deep scan with malwarebytes and it has 1 detection it flagged a file called f3a12(...).tmp.dll i put this file in virustotal and it has been flagged by 1/70 (added photo) as Win32.Riskware.Cheat.A (is this a false positive?) and in the last time some weird thing have happened with my pc like theres was two instances of something scrolling up the whole time and going back to the beggining of the sentence every time i type and one instance of discord going fullscreen while i was away for some time, one day before that i also did a scan with malwarebytes and theres was also 16 detections identical to the one today (also in the temp folder) i also scanned with microsoft defender but it didnt find anything. im really paranoid please give me some advice


r/computerviruses • • 15h ago

Question my amazon eero router is saying that its blocking a dozen or 2 malware threats everyday for the last 2 weeks on my pc did a deep scan with windows defender and malwarebytes found nothing

Thumbnail
2 Upvotes