i have some malware that is stealing all my accounts on my pc!

Anonymous
2025-01-31T12:53:08+00:00

just to clearify, i believe i have something like Ravadon.E or something that keeps stealing my accounts and replaces their emails to some @rambler.ru emails, i get like 4 emails per day about password reset or email replacement in my old account which i lost access yesterday, not just microsoft, its even google and all my games and apps accounts are getting replaced by some @rambler.ru emails, if you ask me, my friends emails was on my pc and got replaced by those emails also, same as my other accs which never got anything till when i used them on my pc, and i used those to try to detect anything :- trying many anti-virus softwares including windows security : didn't detect anything, they just deleted my GPU's software and all my games and apps, tagged everything as a malware even discord, microsoft bing, google chrome and brave browser. (so basically all detections were false positive)

  • trying any online tutorials to detect Ravadon.E or any similar things : couldnt detect any.
  • i made sure all my accounts have 2FA enabled and yet i change their passwords very often.- i removed all my accounts on pc and deleted browsing cookies so the malware cant get access to them anymore
    oh and also the malware keeps spamming sussy links in my discord like $50 steam gift links, and it logs me out of discord and starts spamming till i get my account back. pls if anyone know how to fix this thing pls help, my pc is my life.
Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
{count} vote

18 answers

Sort by: Most helpful
  1. Anonymous
    2025-02-01T06:26:39+00:00

    Hello,Best of bestst of the best

    Welcome to posting in the Microsoft Community.

    I understand very well the dilemma you are currently facing and knowing that malware is threatening to steal your account and you are losing control over your personal information and account, it certainly brings a great deal of psychological stress. Based on what you have described, such as accounts being replaced and the frequent password reset emails you are receiving, it may indicate that the problem is not just due to malware infection, but information leakage is playing a key role here as well. This means that even if the malware can be removed by formatting the system and reinstalling the operating system, the attacks may continue to occur if the information leak is still present.

    You have tried several methods to solve the problem, including using antivirus software and online tutorials, but none of them have yielded the desired results. In particular, you mentioned antivirus anomalous behavior; many tools fail to identify these threats and incorrectly mark some normal programs as malware, making it difficult to determine the root cause of the problem. These situations you have experienced are indeed clear symptoms of an attack on your computer, but the exact method of attack is still unknown. In order to better assist you in resolving the problem, I recommend that you take the following steps:

    1. Change your Microsoft account alias: This can be done by changing your Microsoft account alias on a secure device and deleting the previous account name, which will help reduce the chances of a hacker gaining access to your new account information. When performing this step, please make sure that you do this after you have finished formatting and reinstalling your system in case malware is still present on your system. You may refer to the following link for more information on how to do this:

    Add or remove an email alias in Outlook.com - Microsoft Support

    1. Format the disk and reinstall the system: Consider formatting the hard disk and reinstalling the operating system after backing up important data. This is an effective way to remove all potential malware and make your device more secure. For the steps to reinstall the system, please refer to the following link:

    Reinstall Windows with the installation media - Microsoft Support

    Disclaimer: At this point, we have exhausted all troubleshooting and I recommend that we try to perform a clean install to get your computer back into a working condition. Please ensure that you backup any important data, including Documents, Pictures, Videos, and more.  

    1. Proceed with caution: Before changing your account alias, it is recommended that you always format and reinstall your system to ensure that any important account operations are carried out in a clean environment and to avoid the effects of previous malware on your new account.

    Please be sure to keep in touch with me in a timely manner, I am very concerned about your situation and any updates from you will help us narrow down the problem more accurately. Please be confident that you are not alone and let me know if you have any questions and I will answer you further. Thank you for your understanding and cooperation!

    Best Regards,

    Rota|Microsoft Community Support Specialist

    0 comments No comments
  2. Anonymous
    2025-02-01T10:44:12+00:00

    so basically, the only way is to install a new windows?

    0 comments No comments
  3. _AW_ 65,616 Reputation points Volunteer Moderator
    2025-02-01T14:18:25+00:00

    To thoroughly check for malware, please run a scan with Farbar Recovery Scan Tool (FRST) and share your logs.

    https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

    Note: If you are using Edge, SmartScreen may initially block the download.

    Click on the three dots next to the warning and select Keep => Show more => Keep anyway.

    • If your computer's language is not English, rename FRST64.exe to FRST64English.exe
    • Run the tool, leave the default settings, and press Scan.
    • Zip the logs, FRST.txt and Addition.txt, then upload to a cloud storage service like OneDrive, Google Drive or gofile.io
    • Post the share link.

    Share OneDrive files and folders - Microsoft Support

    0 comments No comments
  4. Anonymous
    2025-02-02T14:51:50+00:00
    0 comments No comments
  5. _AW_ 65,616 Reputation points Volunteer Moderator
    2025-02-02T22:31:16+00:00

    Please change the share permissions to "Anyone with the link" as the logs are inaccessible.

    0 comments No comments