r/malwares
Windows trojan.
Hey guys. Recently I was attacked by some virus by installing an app from a random link. And that exe. File compromised my windows system. Luckily I changed my password and everything was good until about a week later just today when i turn on my laptop there were some PDFs saved on my screen. Saying my windows has been compromised all the passwords and with the guy who infected my windows. He demands for money he has sent a qr code. It also said he had access to my microphone, webcam meaning he stole my private life clips. He threatens me to pay him or else he's gonna leak all that.. he mentioned " do not try to reset the os" I'm worried sm rn. Idk what to do as I've never been through SMTH like this. Please if anyone can guide me about what should I do next to be free from this?
Virus concern or paranoia
3 months ago, i got a virus on my pc and lost multiple accounts. When i tried to find ways to solve it, i found out some virus can actually infect the router and other devices on the same network. Now even when i got kaspersky for my pc, i keep thinking other devices are infected and changing the router wont help because the infected devices will get the router again despite not seeing any clear symptoms. What can i do about this?? Is it just me being paranoid? Does factory reset on the phone remove all viruses? Do i need to replace my router? I forgot to mention this. I also downloaded a zip file for a pvz2 mod on my phone but resetted it. After that, i keep logging in to admin router on both my pc and my phone to check for weird settings and turn them off. Now im scared that i mightve created some hole for virus to get in. I even got a new router. Im too anxious now and would do anything for a peace of mind. I dont even know if replacing the router helps now as i find out that virus like switcher trojan or stuff like wannacry, vpnfilter can just infect the router when connected and others can just go straight to other devices without infecting the router.
Google Chrome detected a Chrome Extension called "Enhanced Image Viewer" as malware
Is this true? Is the flag a result of faulty AI moderation? Do I need to remove it or can I reenable it?
Sucuri vs. Wordfence
I recently noticed that Sucuri found a virus on a site that Wordfence was installed on. and did not detect. Is Sucuri a better solution overall or does someone recommend paying for both?
Accidentally opened a link that was trying to download a file named rto.apk
Yesterday, I have mistakenly clicked a link that tried to download rto.apk file and I use iPhone I checked thoroughly like checking downloads and battery usage and vpn settings as well and I also know that u can’t install apk in iOS but I am little bit paranoid because i am getting repeated messages from Tata 1mg saying otp for login even though I don’t have that app and also o have deleted my bank accounts from my phone
I am concerned does malwarebytes have false positives?
So I downloaded gamehub lite on my android device from the official source. When I scanned with malwarebytes it stated it was a virus. I of course deleted it re scanned and it stated it was good. What should I do now to protect my device? Thanks!
Is this something I should be concerned about?
This has been popping up over the last few weeks which came out of nowhere and I’ve been suspicious of it but I don’t know what to do, I usually just press the x and it redirects me to adobe website, up until now nothing strange has happened on my computer so I avoided it but right now I turned it back on from sleep mode and I saw Microsoft edge open (I never use Microsoft edge) and it had a search in it called Liah437 or something.
[URGENT] Self Healing WordPress Malware Keeps reinfecting across 30+ sites on same housting - Please help 😭
I'm dealing with a persistent, self-healing malware infection across ~30 WordPress sites on the same cPanel shared hosting account (A2 Hosting).
Symptoms:
· Files reappear seconds after deletion
· mu-plugins/nexus-router-run.php (empty 0-byte file) keeps coming back
· Advanced-cache.php, db.php, and .g_*.php files in wp-includes
· Shared memory segments (shmop) storing payloads
· Processes like .g_98130eea.php running even after file deletion
· .user.ini files with auto_prepend_file pointing to backdoors
What I've done:
· Replaced WordPress core with fresh files
· Replaced all plugins from official sources
· Replaced Astra theme from official source
· Cleaned database (removed sc_, wp_91_, transient_sc* options)
· Changed database name, username, and password
· Regenerated WordPress salts
· Killed all .g_ processes
· Cleared shared memory (ipcrm)
· Deleted all .user.ini files
· Deleted all mu-plugins
· Deleted advanced-cache.php and db.php
· Disabled all cron jobs
· Changed cPanel password
The problem:
Shared memory keeps coming back (new segments appear), and the .g_ process restarts. Something is recreating it. I suspect it's either:
· A system-level cron job outside my user
· A hidden backdoor in another infected site
· Something at the server level A2 Hosting needs to handle
Questions:
- Has anyone dealt with this specific "Crux Runner" or "SC_" malware family?
- How do I find what's re-creating the .g_ process?
- Is this a server-level infection that only A2 Hosting can fix?
I've spent days on this. Any help appreciated.
Recovering from an infostealer attack- how safe am I?
So about a week ago I was hit by a infostealer attack, and my instagram, facebook and discord were affected. At the time when I downloaded the virus, my internet was turned off by me. I didn’t do a USB reset, but instead used the built in factory reset. I chose to delete all files, and used a cloud download. I enabled 2FA on all my accounts and changed the password to a more secure password. How safe am I?
Roblox luna executor
Do not download luna executor It had virus when u deleted try full scan it's undetected I still didn't manage to get rid of it try to reset clean data app my laptop was reset then I open it up then it was still there the files I find the location its on in this pc go by name called .luna I cant get rid of its so tiredness I've search YouTube TikTok tried some thing tog et rid of it but it just doesn't when I click to deleted it says Oder to delete this file u need provide administrator permissions to deled this file but
Add on to my potential malware problem (Noteit)
So this is adding onto my other post about Noteit (ill link the other one in the comments). So basically I ended up deleting it, but as we speak, I am looking through appdata and found "Noteit". As any curious person would, I had a look through it. I ended up finding something that shocked me (picture below). I scanned the whole folder with malwarebytes and it hasn't found a problem (picture below). I'm really scared rn. Is it safe to open those files? What do I do???
Annoying antivirus
Idk how this got download or its just Mcafee rebranded but i cant ssem to delete this things and cant find in anywhere else, talking about my pc, i changes files and folders its so annoying how do i delete this i have tried to delete from app data it just switched files
I got Blockify (the Spotify Blocker Extension) removed from my pc today due to "malware". Did this happen for anyone else? And what data did it take??
reddit.comНе наебывай меня, тони
Хотел скачать prism launcher (с офф сайта), кинул ссылку на скачивание в вирустотал, прилетела угроза мол this domain is used by amadey.чзх, кто знает, безопасно или нет?
Suspicion de malware sur CODEX !!
Bonjour la communauté, je vous avoue que c'est la première fois que je passe parce que j'ai un réel gros gros doute. J'étais introduit d'utiliser Codex, puis, d'un coup, on ordi a dû s'éteindre avec une mise à jour de Windows, un écran vert qui a paru et là, quand j'essaie de rouvrir codex, je tombe sur cet écran hyper bizarre et inquiétant, je ne pense pas que OpenI forcerait, comme plaire dans la capture d'écran, à cliquer sur oui et même le bouton non quand je clique sur nom, il n'est pas utilisable.
Je sais pas du tout quoi faire, c'est la première fois que je vois ça, mais je tiens également informé toute la communauté qu'un malware codex est possible si vous savez comment m'aider, n'hésitez pas à me dire quoi faire svp
Virus in PC, Discord hacked. what to do?
Hi! So I downloaded the new version of mirror anadius (aaron/aaros) sims 4 updater. I used the older version for years and never had any issues with it. The newer version showed up as a virus. a lot of people said it was a false positive. It wasn’t. It found trojans and a bunch of other stuff. I activated Malwarebytes and it says my PC is clean now. I’m going to put in pictures of what the security says. It is in Dutch though. But, my discord was hacked and it sent a bunch of weird messages to my friends. I’ll also put pictures of that in. Someone also tried to get into my Microsoft account. I changed the password of that. And also of my Instagram, Tiktok, Snapchat and Discord and a lot of other things. My friend said that I need to reinstall windows 11 completely and that all of the passwords saved in my Google account need to be changed. (That’s more than a 100. But mostly stuff I don’t even use anymore). Do I actually need to do all of that even though my PC says it’s all clean and no actions are needed? Please help. I’ve been stressing about this all day. Also, I got the viruses last night and then the messages on Discord got sent this evening. So almost a day later. The log in on my Microsoft account was located in Germany. Could be false, but thought it was worth mentioning.