is Healthy.exe a virus and did I delete it properly?

About a week ago, I accidentally installed a disk image file from a website that turned out to be malicious. I immediately noticed a new app called "Healthy.exe," and when I looked it up I got a bunch of results calling it malware. I deleted the healthy.exe file, but I was still experiencing performance issues days after. With windows defender, quick scans, full scans, and offline scans all returned with no issues. As far as I could tell, nothing was taking up an abnormal amount of memory in task manager, although it seemed that my ram and cpu/gpu usage would randomly spike. A few hours ago, I encountered this odd issue where clicking and even just moving the mouse would not actually click and instead would just cause a beep to be played through the speaker, as if there was some sort of dialogue that I couldn't see. This problem resolved itself when I reset my PC. Eventually, I search for "healthy" in my file explorer and found a folder in "C:>Users>[my account]>AppData>Local>Healthy." Just now, I deleted this folder. However, it still appears among the list of programs under "startup" in task manager. Also, I'm not sure if the disc partition "D:" that initially got created when I installed the disk image file is still causing issues or not. (There was some sort of suspicious hidden folder called "app" that wouldn't let me click on it because it was "located on a D: drive that had been ejected" or something like that.) Also, I noticed that the "Game DVR and Broadcast" service would sometimes spike to 100% gpu usage at random moments when I'm not even using it. When I opened the file location, it gave me a svchost file inside of the system 32 folder. I'm not sure whether or not that's suspicious. I'd appreciate if anyone could explain these things to me.

Hello Jack,
I am Jaspreet Singh.
Try running a scan from free version of malwarebytes. Some of the malware that are not detected by defender will show up on a scan by this scanner.

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

It didn't detect anything. Hopefully that means I'm probably fine. Thank you for the response

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Yes that would mean the system is not infected. Have a great day ahead Jack.

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Yes hello since this is new and might be abit too late I know what website you using steam unlocked and no the website is safe but hackers put there own viruses in the iso file the “install.exe” is safe but do NOT click on the healthy.exe it’s a bit coin miner pretty smart it mines bitcoin for the hacker in your pc so he does not have to pay servers. Smart kid.

Delete everything thst looks **** or you don’t remember getting, or go to windows safe mode so third party apps can’t run in background so you don’t crash bc of the gps usage.

I’m right now downloading some games to see if all the iso files when burned have the virus, but what I can say it isn’t like in videos where it hacks your pc and it’s gone just a background miner. So don’t lose hope on downloading games for free paying 60£ for a **** game is mad but there’s always a downside to it, they have to earn money themselves the people who get it for free. Could be worse like the old website they used.

1 person found this reply helpful

·

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

While removing it, every program that detected it referred to it as adware and or a browser hijacker. Same site, same file name, but nothing mentioned it being a miner. Do you have anymore information about it to share. I think I've killed it thoroughly now, but I'm not sure how concerned to be. In fact, while cleaning up, I found it had a user data folder referencing browser autofill and cache logs.

1 person found this reply helpful

·

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

I've opened a case with the Malwarebytes team about healthy. I'll let you know If i get it resolved or learn anything.

6 people found this reply helpful

·

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

I know I’m a bit late but I have some more info on healthy.exe. This information isn’t game breaking but it’s information nonetheless. I’m pretty sure I got healthy.exe from a chrome extension or a Minecraft pack download. I think it was matched with a chrome extension because my chrome was wonky for a bit but the only reason I found healthy on my pc was because of chrome saying I had a sus (cringe word I know) program on my pc. There is another app with the same logo like a green thing by tan background. They worked together and were mining on my pc because I found the them secretly working on task manager. That one was called strength.exe. I’m pretty sure I fully removed both because they haven’t been on task manager at all and I did a full scan. I’m pretty sure it’s not a virus but just a glitch, my windows scanner doesn’t appear and says to talk to the help desk. So I used the Microsoft emergency scanner. But that’s all I know right now so I hope that other people can add more information.

1 person found this reply helpful

·

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

 
 

Question Info


Last updated May 21, 2023 Views 3,162 Applies to: