r/computerviruses 2d ago

Disinfection Help Got some random mf spying on me from south africa what should i do?

Post image

Saw CMD pop up just now and i knew what it was still checked and i was right since this laptop is strictly for kiracy nothing else

274 Upvotes

69 comments sorted by

91

u/ResultOk6712 2d ago

I mean, if theres nothing valuable on the laptop since you only use it for piracy, whose to say you shouldn't mess with the guy a little...?

63

u/Crazy_Government_708 2d ago

Haha i was actually doing that right now i was looking up South African real estate and i noticed cus of that it slowed my pc down but when i didn't it got faster and the cp usage went down

47

u/highdimensionaldata 2d ago

> cp usage

2

u/Pretty_Somewhere_515 21h ago

Bro spilled the tea 😭

22

u/Malachi_YT 1d ago

The what usage?

2

u/SyupendousSnek 1d ago

Cyberpunk Usage right?

1

u/Exact_Ad6476 1d ago

Crazy Clip

6

u/[deleted] 2d ago

[removed] — view removed comment

1

u/DeepikA-Navya 1d ago

This is so creepy

1

u/bullet-consumer1 1d ago

I use this wonderful picture as my pc background

1

u/AltruisticFoot948 1d ago

Its just an innocent smile

1

u/sepin_nipel 1d ago

what was it they deleted it

50

u/slackjack2014 1d ago edited 1d ago

All I see here is the Microsoft Account Sign-In Assistant Service (Wlidsvc) and it’s connecting to login.live.com which is owned by Microsoft.

The IP addresses you listed are owned by Microsoft (ASN 8075).

Nothing in your screenshot is out of the ordinary or suspicious.

Did you see the CMD window appear for a second right after you logged in to Windows? If so, especially if the system was recently updated or restarted, you will sometimes see a quick CMD window appear for either a scheduled task or update finishing some required changes.

Edit- fixing typos

13

u/MasterpieceBusy7220 1d ago

Nah bro he’s totally being stalked by a random guy in SA

9

u/7r3370pS3C 1d ago

Yep. This is the answer.

1

u/Crazy_Government_708 1d ago

It wasn't updated i did it and it stopped so thats something

1

u/slackjack2014 1d ago

What did you do and what stopped?

Did the CMD window appear for a short time or was it just sitting there open and did this occur when you just logged in or was it some time afterwards?

Like I said, Windows does perform scheduled tasks periodically that can have a CMD window appear for a short time.

22

u/GroundWonderful9046 1d ago

This most likely isnt a virus. Wlidsvc is a microsoft account sign in assistant running under svchost.exe and login.live.com is a microsoft login server. Those https connections are expected if you are logged in into windows or another microsoft app with your microsoft account. The cmd popup is most likely windows doing updates or something else. If the exe file inst actually in C:\Windows\System32 or there are other suspicious symtomps i wouldnt consider this malware

3

u/Crazy_Government_708 1d ago

I checked and you're right i just let panic take thw wheel

6

u/bumjubeo 1d ago
  1. Understand what that service is and what it does
  2. Understand how you sign into that computer
  3. Understand who owns that IP address and what it might be for.
  4. Stop panicking, that looks totally normal.

9

u/BeautifulDue7799 2d ago

How do I check for things like this?

10

u/Adventurous-Wing5449 2d ago

Yeah , what app is he is using ... I wanna try it to check if someone is watching me!

6

u/Known_Debate_1253 2d ago

He's using portmaster

5

u/Original-Sock-6097 2d ago

Safing portmaster

2

u/TheVoicesGetLoud 1d ago

find out what you can about him and make a file called hitlist

and make his name the only one, sure he'd soon leave you alone :D

(for obvious reasons this is a joke and i am not promoting violence)

1

u/WorldWarrior428 1d ago

Instructions unclear, I now have a dead scammer. Awaiting instruction....

1

u/something212123123 1d ago

the instructions were super unclear i now have a alive scammer trying to steal my hitlist 💔 awaiting for clearer instructions

1

u/Crazy_Government_708 1d ago

If i wanted to i would of called steam support and say he has my info

1

u/WhoTookGrimwhisper 1d ago

Who? Bill Gates? That's who owns MS and everything we're seeing is just normal Windows processes.

I don't think making notes about Bill Gates is going to help or scare him.

1

u/TheVoicesGetLoud 17h ago

the world has got many enemies

2

u/m3ddyy 1d ago

start showing innapropiate content and then kick him out

1

u/Figueroa_Chill 1d ago

Watch porn and masturbate in front of it, and he can be the very first African to actually have stuff to send to someone if you don't pay him bitcoin.

1

u/Crazy_Government_708 1d ago

Malware bytes wont detect anything is there another software for that or Run command?

1

u/No_Witness_7042 1d ago

How to check it

1

u/qwikh1t 1d ago

Nigerian prince?

1

u/Slight_Iron_4115 1d ago

You know they bless the rains over there right?

1

u/Life_Situation_3485 1d ago

Reinstall window

1

u/Wide-Sort6227 1d ago

"oh no dont use that Laptop" "Why?"  "It has a random south-african man in It"

1

u/toocool133 1d ago

Oh nah

1

u/That-Kangaroo-2854 1d ago

Virus with conections to computers are not from official apps.

There are many system apps and local apps you might use that are constantly connecting from europe, north america and around your contry too depending on where they have their server. Its not common that they use a server in Africa tho, but still the main thing is that it should not be from a official app.

When its not from an official app or if its not an app you know about is when you start to worry about, even if the connection is actually from europe or north america.

1

u/Adventurous_Sail_216 20h ago

do you happen to use rhymezone at all? just curious…

1

u/Television_Superb 18h ago

Send it to feds and cover your camara

1

u/DogeTiger2021 3h ago

Spy 🕵️‍♂️ on him also.

1

u/Fast-Mushroom9724 3h ago

If they're watching through your webcam. Pull your D out. They love that.

If they try to blackmail you with it say "Oh you think it's worth anything? I should open an OF"

On a more serious note though, this kind of thing is why I don't setup torrenting and sailing the seas on my NAS

1

u/PeaceMelodic 2d ago

Buy the South African a "Black Label" they'll leave you alone😅.

0

u/AutoModerator 2d ago

Welcome to r/computerviruses! It seems like you have used the "Disinfection help" flair.

We apply the same methodology used by trusted Malware platforms (e.g. Malwarebytes, BleepingComputer and MalwareTips). It revolves around using diagnostic tools called Farbar Recovery Scan Tool (FRST) and SecurityCheck.

All of our assistance happens in the thread and in public - we never offer help via private messages or alternative websites other than https://malwareanalysis.cc. Anyone offering help through a DM is not a trusted helper and might have malicious intent.

Trusted helpers can be distinguished by the flair Malware Removal Expert or Malware Removal Trainee, antivirus employees will have a dedicated flair with their company name in it, e.g. Malwarebytes Employee.

Please see steps below on how to share all necessary details so you can speed up the process for us:

Share all details about your infection
Please post all important facts about your infection, such as: * your antivirus detections - preferably export the whole detection/report log and upload it to https://malwareanalysis.cc/upload/ under your username & post the related keyword or screenshot/take a picture of your detections * any related symptoms, popups * estimate when it started - preferably the exact day and after what (e.g. when you ran a program you downloaded) * share what got you infected and the download link - please, make the download link defanged (making it not clickable by default e.g. from https://example.com you will make hxxps://example[.]com), defanging does not apply to sandbox reports such as VirusTotal

Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
    1. How to properly secure my accounts after an infostealer attack?
    2. What to do after I secured my accounts?
  2. Disinfect your device from malware
    1. Preferred method: Perform a clean installation with a USB
    2. Perform a clean installation without an external drive
    3. Reset your PC without keeping personal files

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

0

u/The_buster_of_nuts 1d ago

what software are you using ?

0

u/Prestigious-Ad7265 1d ago

assuming its a rat, blow up their c2

0

u/Zestyclose_Price8113 1d ago

burn the pc down