HELP ME MY COMPUTER HAVE A VIRUS 🦠!!!

Idk lol 5 Reputation points
2026-03-18T19:30:50.7833333+00:00

I messed up big time,

I think I’m a victim of a coordinated Supply Chain Attack. Yesterday I downloaded a build of Xeno Executor, but as soon as I bypassed the SmartScreen prompt, my system started behaving like it’s being remotely controlled by a RAT (Remote Access Trojan).

Here is what I’ve observed in the last 4 hours:

Persistence & Registry Hijacking: My Windows Defender was killed via a Group Policy override. When I try to open ms-settings:windowsdefender, the window immediately crashes. I checked HKCU\Software\Microsoft\Windows\CurrentVersion\Run and found a suspicious entry pointing to a hidden .vbs script in my AppData\Roaming folder.

Credential Harvesting: My .ROBLOCOOKIE was exfiltrated within minutes, but now it’s worse. I’m seeing 'Unauthorized Login' alerts for my Gmail and Discord. It looks like it dumped my Local State file from Chrome to grab my encrypted Master Key.

Network Activity: I ran netstat -ano and I see an established connection to a Command & Control (C2) server on port 4444. There is massive outbound traffic on Port 80—I think it’s uploading my entire Documents folder.

Lateral Movement & Worm Behavior: My home NAS (Network Attached Storage) just alerted me to a 'High Volume of File Rename Operations.' I think the malware is acting as a Worm and trying to encrypt my network shares. It's already started dropping .crypt extensions on my secondary D: drive.

Rootkit Suspicions: I tried to boot into Safe Mode, but the system hangs on classpnp.sys. I’m terrified this is a Bootkit that has compromised the EFI partition.

Roblox account statues: I can't log into my Roblox account anymore it says *wrong password" even tho I write the correct password to my account

Is there any way to kill the callback beacon without a full DBAN wipe? I have sensitive info on this machine and I'm worried about an identity theft escalation

Windows for home | Windows 10 | Security and privacy

2 answers

Sort by: Most helpful
  1. Carl-L 19,955 Reputation points Microsoft External Staff Moderator
    2026-03-20T09:51:14.6033333+00:00

    Hello Idk lol,

    Welcome to Microsoft Q&A forum.

    Based on what you've described, it's without a doubt that your computer has been infected. The first thing we should do in this, like what the AI assistant has suggested, is to disconnect the computer from the internet completely. We are not sure on what have already been uploaded, but we shouldn't let it get any more data.

    Next, you should change the password of every Account that is on the computer (Not just Microsoft Account). Also, you should go to "Credentials manager" and remove all entries if possible.

    I understand that you'd like to avoid a clean wipe of your computer. However, based on the behavior that you observe (disable the Defender, established a connection on its own, disable the ability to go into safe mode...), the best way to go forward is still a clean install of the OS.

    You can still backup your data before a clean wipe. However, there is a few notes before proceeding.

    • You should only backup data-only files. (docx and xlsx files for example). They cannot store macro and are relatively safer than other files.
    • Make sure to scan every file before transferring.
    • I'd suggest doing this from a known clean computer that is not connect to internet so you can still use Windows Defender offline to scan the file.

    Next, here is a few note for you before reinstalling the OS:

    • You will need a clean computer and a clean USB thumb drive to process with this.
    • Download Windows 10 install only from Microsoft Official Site.
    • Remove all external drives and devices, only keep the keyboard, mouse and the installation drive to avoid cross infection.
    • After the installation is done, do not connect it to the internet yet. Please open Windows Defender and perform a boot-level offline scan to make sure the BIOS/UEFI is clean.

    If you need any assistance with this, please let me know.

    Was this answer helpful?

    10+ people found this answer helpful.

  2. AI answer

    2026-03-18T19:31:12.4133333+00:00

    Do the following immediately on the infected Windows 10 PC and any other device where that Roblox account or Microsoft account was used.

    1. Disconnect and scan for malware
    1. Disconnect from the internet (unplug Ethernet or turn off Wi‑Fi).
    2. In Windows 10, open Windows Security and run a Full scan with Microsoft Defender Antivirus. Make sure security intelligence is up to date.
    3. If you still suspect infection after the full scan, run Microsoft Defender Offline for a deeper scan. For stubborn or unwanted software, follow the steps in Protect your PC from unwanted software.
    1. Change all passwords from a clean device Only after scanning and cleaning:
    1. On a different, clean device (not the infected one), change the password for:
      • Roblox account
      • Email account(s) linked to Roblox
      • Microsoft account and any other accounts where the same or similar password was used
    2. Use strong, unique passwords for each account.

    If the stolen password was for a Microsoft account, follow the hacked‑account guidance:

    • First, clear malware as above.
    • Then change or reset your Microsoft account password using the official process.
    1. Secure the Microsoft account (if affected) If the attacker accessed a Microsoft account (Outlook, Xbox, etc.):
    1. After changing the password, review account security settings.
    2. Check for unusual sign‑ins, forwarding rules, or connected accounts and remove anything not recognized.
    1. Protect the PC going forward
    1. Keep Windows Update turned on and fully updated.
    2. Make sure Microsoft Defender Antivirus is active and set to update and scan automatically.
    3. In Microsoft Edge, keep SmartScreen turned on and pay attention to warnings about unsafe downloads.
    4. Avoid downloading “executors,” cheats, or cracks from untrusted sites; these are a common source of malware and credential theft.

    If problems persist (strange behavior, can’t remove software, or scans keep finding threats), back up important files and consider a Reset this PC with “Keep my files” to reinstall Windows.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    4 people found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.