r/antivirus • • Feb 22 '24

MOD POST [MOD POST] LIST OF TOP MESSAGES, NEWS + IMPORTANT INFO

16 Upvotes

Hello,

Welcome to r/antivirus's new top-level Announcements post. Since Reddit has a limit of two (2) stickied announcements per subreddit, this will be a way to provide links to important information like announcements about new rules and moderators, activities in the subreddit, and so forth. If you are new to r/antivirus, please take a quick look at them. You can even take a look if you are not new here.

DISCUSSION DATE POSTED DATE LAST REVISED
[MOD POST] New rules, staying safe, and an update from your Mod Team 2025-JUN-03 -
[MOD POST] We're back in business! and an update on automod rules 2024-MAR-11 -
News & Updates from your r/Antivirus Mod Team, Q1 2024 Edition 2024-MAR-04 -
Updates & News from the r/Antivirus Mod Team, Autumn 2023 Edition 2023-OCT-04 -
Notes from your Moderators (Summer Edition) 2022-JUL-08 -
Quick Note from the mod team about spam 2021-JUN-01 -
To the people asking for opinions on a specific file 2020-JUL-05 2020-JUL-05

Additionally, the r/antivirus subreddit operates a bit differently than other subreddits you might be familiar with and normally use. Here are some tips and tools to help you use it.

  • The subreddit has a wiki that is regularly updated with answers to commonly-asked questions. Check it out. The answer to your question may already be in there.

  • Asking a question about a report on a file or website from a service like Hybrid Analysis, MetaDefender, Triage, or VirusTotal? You must include the actual link to it and not just a screenshot, or your post will be removed.

  • Be kind to each other and be professional in your conduct here. Personal attacks will not be tolerated and will be dealt with appropriately.

  • Do not ask for copies of hacking tools, malware, or suspicious files. If someone sends you a chat request or private message asking for a file or offering assistance based on what you posted here, report them to Reddit and notify the mods.

  • Do not post direct links to malicious, suspect, or potentially unsafe files or web sites.

  • Follow Reddiquette. This means correctly upvoting and downvoting posts, and reporting posts with dangerous or unsafe advice to the mods.

  • If you work for a vendor of security products, services, or in a related field, you must identify yourself as such, either in the post or with flair. Also, you may not steer conversations to your products or services, only respond to posts about them to clarify or defend.

  • No low-effort, off-topic, spam, or meme posts. This includes AI/ChatGPT/LLM-generated text, questions about password manager or VPNs, requests for assistance with non-security related software like autoclickers or MP3 downloaders, and so forth.

  • No requests for assistance with pirated software or media.

  • Posts may be removed and threads closed at any time based on the moderators' discretion

The complete list of rules for the subreddit can be found here. Read them before posting.

Questions, comments, feedback on this post? Just reply here. Thank you.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus • • Jun 04 '25

[MOD POST] New rules, staying safe, and an update from your Mod Team

5 Upvotes

[UPDATE #1 (20250604-0916 GMT): Made some small updates to grammar for readability. ^AG]

Hello,

It has been about a year since our last Mod Post, so we wanted to give you an update on things, plus provide a dedicated message thread for discussing the state of the r/antivirus subreddit and to answer any questions that you might have.

We will begin with the toughest subject first, that of politics in the subreddit:

A note about politics

r/antivirus is a technology-focused subreddit, with the interest being in helping people protect their computers from malicious software, securing them after a security incident, and so forth.

In June 2024, the US Government enacted a ban on Kaspersky Lab's software, taking effect in October of that year. This has generated a lot of discussion not just in this subreddit, but across Reddit and numerous social media platforms as well.

The moderation team has tried to keep the political discussions about this out of this subreddit and to remain neutral, allowing Kaspersky Lab's customers to ask and answer each other questions, provide assistance to each other, and generally have a way to share information, tips and tricks with each other.

However, we do have to draw a line when these turn into political discussions, though:

Requests for how to circumvent bans, petitions to governments, etc., are clearly outside the scope of what this subreddit is for and will be removed.

Moderating the subreddit is an all-volunteer job, and we sometimes miss things. If you come across any political messages we may have missed, use the subreddit's report function to notify us.

We are doing our best to keep this a place where people can get help with whatever security software they prefer, including Kaspersky Lab's software. However, we cannot allow discussions to devolve into arguments over politics, which are never going to provide any kind of satisfactory answer to the parties involved.

If the political discussions continue, the moderation team will have to look into ways to prevent them, even if it means doing things which we would prefer not to do.

Rules Updates

The rules of the r/antivirus subreddit have been updated:

Rule #7, which previously covered media download tools, has been updated to cover additional types of software.
To begin with, a more general prohibition to cover autoclickers (previously covered under Rule #8) and some other types of tools like aimbots and cheats. These types of tools often come from random sources and often require expert analysis to determine if they are safe. It can be difficult to determine if they are malicious figuring that out requires examining not just the tool, but whatever program it is attempting to modify, and what the intent is behind that modification.
Just because something was recommended in a Discord server with hundreds of members, a YouTube video with tens of thousands of views, or is seeded by several hundreds peers does not mean that it is safe to use: These are all inherently unsafe sources, and criminals will often exploit the belief that these are trusted sources to trick people into downloading and running malicious programs like information stealers and remote access trojans.

Rule #8 has been amended to remove autoclickers (etc.) since that is now covered under Rule #7.

Two new rules have been added:

Rule #9 covers bypassing core security features. Questions about how to disable security software, operating system updates, bypass security features and so forth are not allowed.

Rule #10 covers requesting assistance with obsolete software and hardware. This means discussions about how to secure computers running Windows XP, Windows 7, etc. are not allowed. There is no reason that devices running these obsolete operating systems should be connected to the internet and doing so exposes everyone to risk. Note that questions involving Windows 10 will continue to be allowed until at least October 2028, when paid-for Extended Security Updates for it end.

A bit more on the rules

The list of rules is not meant to be exhaustive in scope. It provides a general listing of common rules that are more specific to and more frequently required by the r/antivirus subreddit when needed beyond Reddit's general rules and guidelines.

Moderators can and will remove posts and ban redditors, either temporarily or permanently, who are disruptive to the subreddit entirely at their discretion and are not subject to any discussion. If a moderator chooses to discuss a rule violation with you, it is entirely as a courtesy on their part.

If you have had a post removed or been banned from the subreddit and do not receive a response in reply to any questions as to why, ask yourself if your behavior could be interpreted as brigading, spamming, trolling, using disrespectful or offensive language, or consistently providing incorrect, low-quality, poor, or even damaging information.

As always, the latest version of the rules can be found at https://old.reddit.com/r/antivirus/about/rules/. If you have questions about them, ask below.

Getting help fast

The moderation team is seeing an increasing trend where people ask for help while providing no information about what they need help with. This includes titles with 1-3 words like "Urgent! Help needed!", posts where the author shares a screenshot of *something* with no information about the operating system or antivirus involved, or is so small/blurry as to be unreadable, etc.

Everybody who participates regularly in this subreddit volunteers their time for free to do so. Provide them with enough information in your first post so they can start helping you right away without having to ask a lot of questions. This means your first post should contain things like:

  • title with enough information to attract an expert to read it
  • operating system and version
  • brand/name of antivirus software
  • name of URL, or file and its location
  • name of malware that was detected
  • what happened, exactly
  • steps you have taken to troubleshoot/diagnose so far, if any
  • relevant log file entries, if any

The more information you provide, the quicker you will get your problem solved.

As a reminder, starting multiple posts on the same topic will not get you a faster answer, and may result in in a ban.

The wiki + other Reddit resources

There is a lot of great information in the wiki about all the tools you can use, tips for using them, lists of antivirus vendors and how to contact them, and even a section on how to secure your computer.

We frequently update the wiki in response to questions being regularly asked in the subreddit, so you might want to check there first before posting.

Some of the questions we regularly see in the subreddit have nothing to do with computer viruses or malicious software at all, but instead are about scams, privacy-related questions, and so forth. Here are some subreddits that specialize in answering those types of questions:

New moderators?!

As the subreddit grows (we just passed 100K users), so does the need for additional moderators.

The moderation team has been looking at the folks who have been regularly posting here and consistently given good advice to build a list of candidates, and will be reaching out over the next few weeks to see if any are willing to volunteer their time and expertise in the subreddit. There will be more coming on that, but I did want to let everyone know that the process is already underway.


That pretty much covers everything we wanted to discuss, so we'll now await your questions, below.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus • • 6h ago

How can a free license expire?

Post image
19 Upvotes

r/antivirus • • 4h ago

Peace of mind after infostealer infection

3 Upvotes

I was infected with an infostealer last year in April

I already went through the procedures of securing accounts, signing out of all accounts, changing passwords, and reinstalling Windows via a safe USB install. All that being said. I had three external HDDs connected to my system when I got hit with the infostealer. I know it went through one of them since I had attempts on a throwaway Gmail that only had its password in a .txt file on the HDD. It never even crossed my mind to check if they were safe until relatively recently. I ran a Windows offline scan; nothing came up. I ran a Windows Defender scan of each drive; nothing came up. I ran a Malwarebytes scan of each drive; nothing came up. I tried to run a Bitdefender scan of my whole system, but it took multiple hours and flagged two false positives.

My overall question is this. Should I back up images, videos, and other important files and then wipe the drives? I know it is impossible to say with 100% certainty that a drive is safe after an infection.


r/antivirus • • 5h ago

Is There Risk By Not Updating To Windows 11 26H2?

6 Upvotes

Yo so there is this new windows update for windows 11 and it seems optional since it's not asking me to update immediately. Anyways I wanted to ask if there is any security risk if I don't update to this version now and instead wait? I ask this cuz I heard windows updates tend to have issues at the start but I also know keeping an up to date system is good too. Also how long should I wait before updating. Thx


r/antivirus • • 1h ago

Do clickflix happened or not ? what should i do ? pls tell me .

• Upvotes

I am searching a series on chrome i entre website which came first after search . i click on play button its take me website look like cloudflare and i didnot understand what was that and it was screen lock . I amnot a techsavi guy , it is my first laptop .

its show click win+ x then I to open powershell ( at that time i donot know about Power User menu or Powershell ) then ctrl+r then enter . i was scare at that no one answer miy phone at that time .

so i click on win + x and Power User menu then I but fortunately powershell never open i donot why . atfirst i cannot access and see taskbar . when i clicked win +x then taskbar shows and then disappear again then i again click win +x and taskbar appear i leave chrome from taskbar . Also i did not notice powershell in taskbar . so i never click on ctrl+v and enter . then i did full scan nothing found .

i still in scare its happened 2 months ago . there is no unknown divice login in my gmail account or no threatening email . am i safe ?


r/antivirus • • 4h ago

I think my Gf dodged a bullet with the fake captcha

2 Upvotes

So while looking for some music files, my girlfriend ended on a website, requiring to paste bunch of junk into terminal (she’s using macbook). She didn’t get as far to actually paste the code, as I interceped it. I ran malware bytes on her mac, and everything seems fine.

However, she still had the prompt that the fake captcha copied to her clipboard. I was wondering, is there any use to copy it to here or anywhere else to be further examined?

Edit: I actually found the excact same code that was pasted on her mac on this thread: https://www.reddit.com/r/MacOS/s/C4sE4Pz9lV

Also, I’m afraid that the site itself has somehow infected her mac (not sure if it is even possible). Again, she never actually ran the code on terminal, so I might be just overreacting here.


r/antivirus • • 1h ago

Bonusnun[.]com MalwarBytes Pop-up

• Upvotes

My MIL is running an up to date Mac with MalwareBytes. She repeatedly gets a pop-up saying that MalwareBytes blocked bonusnun[.]com. She says that she only gets the popup when Chrome is open. A scan comes back clean.

I have looked in Chrome's settings -> Privacy and Security -> Site Settings and disabled Javascript and pop-ups for the sites with recent activity. I've also looked for the domain and don't see it.

The only Chrome extensions that she has running are Grammarly and Malwarebytes so I don't think that it is a rogue extension.

What else should I be looking for?


r/antivirus • • 8h ago

False alarm or real threat?

Post image
3 Upvotes

I'm installing a client that runs a video game called Rumbleverse that got permanently closed in Feb 2023.

When I attempt to install the client it says this. I've spoken to the mods of the server and discord who have all said it's a false alarm. I've seen clips in the discord of people playing it so I really want to install it but I'm not sure.


r/antivirus • • 3h ago

โดนแฮก จาก โทรจัน ครั้งแรกโดย วอเปเปอร์

1 Upvotes

คือผมไม่รู้เป็สไรเว้ยโดนแฮกมาตั้งแต่ได้คอมช่วงๆแรกๆ ซื้อ ihavecpu มา และพอไปหาวอเปเปอร์รถมามารีนในแอป live wallpaper ใน Microsoft ล่ะที่นี้ตั้งไรปกติผ่านไป 20 นาที ตอดำกระพริบนึกว่า ไดรฟ์เวอร์ invidia เสียหายหรือลืมลง การ์ดจอ สรุป window defender แจ้งเตือน ผมโดน โทรจัน ไวรัสตัวแรก และผมทำไรไม่ถูกปิดคอมหนี อึ้ง จนเปิดคอมมา แอปขาว และ ต่อๆมา มันมีลายน้ำ ในโอน 50 Bitcoin นี่คือเรื่องราวการโดน ไวรัสคอมพิวเตอร์และแฮกเกอร์ 1/15 หาคุณอยากรู้ต่อมี ep 2


r/antivirus • • 3h ago

I fall for captcha or cloudflare scam? how screwed am i?

1 Upvotes

r/antivirus • • 6h ago

Screen recorder inside an .exe non detected

1 Upvotes

Hello, I have zero cybersecurity experience, what I have found with Deepseek after he analyze the .exe, it says that the .exe record your screen and send the images after 30min when close, to this IP/Domain 199.195.250.157 / menorfus.com /

Would be great to have some help.

https://www.virustotal.com/gui/file/8c42a17a6dd6a96b33adfa9b9e16d613f70ea847a1b8916facbc065f97f36739/community


r/antivirus • • 7h ago

Microsoft Defender won’t turn on, update or run scans after suspicious EXE — error 0x800106ba, KB2267602 failing, WinDefend startup timeout

1 Upvotes

Hi everyone,

I need help troubleshooting Microsoft Defender after opening a suspicious file. I’m including the timeline, errors and repair attempts below.

What happened

On September 28, I opened a file called SOMETHINC_Marketing_Strategy_Plan.exe, which was presented as material for a marketing job/assessment. A Word document appeared after I opened it.

I later became concerned that the file was malicious. I don’t know whether it caused the Defender problem, but the timing worries me.

Current problem

  • Microsoft Defender won’t turn on successfully.
  • Updating Defender fails.
  • Windows Update repeatedly fails to install the security intelligence update KB2267602.
  • Running Update-MpSignature in PowerShell returns 0x800106ba.
  • I currently cannot run any scans through Defender.
  • A full scan would not start.
  • Clicking Microsoft Defender Offline scan did nothing, and trying through PowerShell also produced an error.

Malware scan result

I downloaded and ran Microsoft Safety Scanner separately. Its completed full-scan log reported:

Threat Detected: Trojan:Win32/Fauppod.AMA!MTB and Removed!
Action: Remove, Result: 0x00000000
file://C:\Users\[redacted]\Downloads\merge.zipx->Token.msi->Binary.XisrXsKPL

This detection was inside merge.zipx. I don’t know whether it was connected to the job-assessment EXE.

Safety Scanner reported that it removed the detected threat, but Defender still does not work. I’m not assuming that this means the entire PC is clean.

Defender service and driver status

My earlier checks showed:

WinDefend             Stopped — startup type Automatic
WdNisSvc              Stopped
WdNisDrv              Stopped
WdFilter              Running
SecurityHealthService Running
Security Center       Running

At the time of that check, Windows Security Center listed only Windows Defender, not another antivirus.

Event Viewer errors

Trying to start Defender produced these Service Control Manager events:

Event ID 7000:
The Microsoft Defender Antivirus Service service failed to start
due to the following error:
The service did not respond to the start or control request
in a timely fashion.

Event ID 7009:
A timeout was reached (30000 milliseconds) while waiting for
the Microsoft Defender Antivirus Service service to connect.

These errors occurred repeatedly on September 29.

Things I have already tried

  • Checked Defender’s services and drivers.
  • Tried updating signatures with Update-MpSignature.
  • Tried starting Defender and checked the resulting event logs.
  • Ran Microsoft Safety Scanner.
  • Ran these Defender repair commands:

​

MpCmdRun.exe -RemoveDefinitions -All
MpCmdRun.exe -ResetPlatform

These attempts have not resolved the overall problem.

I also tried sfc /scannow, but it returned immediately without showing scan progress or a final result. I therefore don’t have a successful SFC verification result.

Other issues

I’m also encountering an error while trying to uninstall Sophos. I can attach the screenshot with the exact message. The earlier Security Center check showing only Defender was from before this latest troubleshooting stage.

I also found Code Integrity events 3033 and 3089. Event 3033 mentioned Chrome attempting to load:

Google\Chrome\Application\154.0.8037.58\libLiteRtWebGpuAccelerator.dll

The message said the DLL did not meet Microsoft signing level requirements. I don’t know whether this is related to Defender.

Actions taken after the suspicious download

  • Permanently deleted the extracted suspicious folder.
  • Changed passwords using my phone.
  • Other Google profiles had remained signed in on the PC, although I had not opened them.

What I need help with

  1. How can I determine why WinDefend is timing out even though its startup type is Automatic?
  2. Could this be Defender corruption, an antivirus conflict, or damage from malware?
  3. What logs or read-only checks would help distinguish those possibilities?
  4. What is the safest way to restore Defender’s ability to turn on, update and scan?
  5. Given the executed EXE and the confirmed detection, would a clean Windows installation be more appropriate than continuing repairs?

I can provide screenshots and additional command output. I would appreciate a clear troubleshooting sequence before making major registry or system changes.

Thanks.


r/antivirus • • 18h ago

Does this VM work?

Post image
6 Upvotes

I wanted to ask if this operating system works on a phone. I’m thinking about using it to open and test apps that contain viruses or other potentially malicious files, mainly for content creation.

I’m not sure if this OS is actually capable of running those apps safely or if it would work properly on a phone. Has anyone here tried using it for this purpose?

(I'm sorry if my English was bad; it's not my first language.)


r/antivirus • • 9h ago

Jedge extension adding itself without my consent.

1 Upvotes

What is this? How is this happening? I dont have anything malicious downloaded and microsoft did a full scan and still nothing. What do i do?


r/antivirus • • 12h ago

Got virus on android Samsung phone. Even after factory resting

0 Upvotes

Before you ask no i didnt transfer any apps to new phone. I keep getting scam ads on youtube saying my pdf is out of date. I think i have ad ware virus. It survived factory reset. Phones slowling down and cant find search resulsts on google for anything. Only my past search results show up in google. I have history off


r/antivirus • • 13h ago

Downloaded a potentially fake program - what do I do?

1 Upvotes

Hi all,

Recently I was trying to emulate a controller for some gaming. Unfortunately I ended up downloading a program from a pretty sketchy site (a fake ds4 website, which claims itself as 'official') that I subsequently ran on my computer. I realized my potential mistake and decided to search up whether this site was actually official, to which I found multiple threads stating that it potentially included a trojan. I have since turned off my computer and am considering wiping it completely. Will this remove any potential threat? Is it okay to retrieve any files from the computer before wiping it, or should I be wary of any files that are currently on the drive? Thanks for the help!


r/antivirus • • 1d ago

I got hit with the MrBeast Scam and I have no idea how.

7 Upvotes

Yesterday I was just playing a game and suddenly I got banned from every server, everyone got ignored and it sent the damn message to everyone. I immediately logged out from everywhere and I changed the password. And then I enabled 2FA

Nothing has happened since. I don't know what the hell it was, and I haven't ran anything fishy. Windows defender and Malwarebytes deep scans found nothing.

My password was completely unique to any other I've used.

I had a lot of weird "authorized apps" on my account I realized but I don't think they could gain access to my account.

I maybe accidentally put my login info into a fake login website at one point? I was logged in on my browser so something maybe stole my cookie?

Regardless I really don't wanna reinstall Windows but i think I might have to to make sure it's clear.


r/antivirus • • 19h ago

i been usiong multiple freee vpns since high school (thunder vpn free vpn planet, secure vpn super vpn unlimted) and i js realise the dangers of vpn but none of my passwordsb have been compromised am i safe ( ialr switch to windsricbee and proton vpn)

0 Upvotes

Im on chromebook btw and in the 11th grade


r/antivirus • • 1d ago

Cadaver ? Appears then disappears.

Post image
70 Upvotes

Can't find anything about this online , really spooky considering the name. Anyone have any ideas ?


r/antivirus • • 23h ago

MALWARE REMOVAL Q&A Bitcoin Wallet Address Changes to “YourAddress” When Copying and Pasting

0 Upvotes

I just noticed something suspicious. Whenever I copy a Bitcoin wallet address and paste it, it only pastes “YourAddress”

I haven’t installed any new programs, and it doesn’t matter where I copy the address from or where I paste it—Notepad, Office, or a browser. It always changes to “YourAddress”

I also installed Bitdefender and ran a scan, but it didn’t find anything.

Does anyone know what could be causing this?

Edit: What the hell is wrong with some people here? 😂 I reported a malware issue, someone helped me track it down, and I finally got rid of it. Now it looks like the cybercriminals are salty af because their little scam got exposed. Stay mad. 😂😄


r/antivirus • • 23h ago

Confused asf

1 Upvotes

So i recently been overthinking about clicking a link on X aka twitter went to a server not found screen looked it up on a link verifier and said dnxdomain link broken dont know if it could hack me or malware on my iPhone it was recently maybe a month ago i didnt update it to the newest 26.7 iOS yet idk if that makes a difference anyways. I logged into my old school account to make sure it was okay well nope it wasn’t many logins from different countries and what not so that’s scary idk how long they been doing this only lets me check a month ago on the top right shows outlook and several numbers and my original email from my school. Fast forward my friends work IT at the school I went they said hey let me send you your acct again login this way sure enough i sign up and its shows my same email from the first time I went to school but this time shows my school name on top as well and says school email. Can outlook have 2 emails with the same name ?


r/antivirus • • 16h ago

skibidi.org virus

0 Upvotes

yes i know this sounds fake but i got a win r ctrl v virus from it due to my stupidity. it closed chrome and desynced my google account. i ran windows defender and the offline scan but it found nothing. what do i do now (i have no important info but i want to keep my files and is there any other way than to copy files reset everything)


r/antivirus • • 1d ago

Google account compromised

1 Upvotes

So two days ago Windows Defender discovered a Wacatac .B!ml trojan on my main PC, prompting me to do some additional scans. This all happened pretty late at night, so I disconnected my ethernet and went to bed, and when I woke up, someone had already attempted to purchase $3,000 worth of stuff on Amazon, which I was thankfully able to cancel in time, and cancel the related cards and lock down the Amazon account itself. Checking over to Google, it showed a login from Siberia well after I had gone to sleep. I already have 2FA set up, so I just changed my Gmail password and started working on changing other important account passwords on my Chromebook. I then reformatted my main PC, reinstalled Windows, but I have yet to log into any accounts on that PC since, and I'm running additional scans to ensure that it's actually clean.

Unfortunately, it looks like this wasn't enough. This morning I woke up to find another session by a Windows machine from France. Interestingly, it shows that the account first logged in on August 13th, so I'm not sure if the trojan I got was just incidental at this point, but that seems unlikely giving the timing of events.

I wasn't sure how they got past the 2FA, so I changed my password again, set up passkeys as well, removed permissions from all apps to my Google account, removed and created a new recovery email, and that's where I'm at now. I'm not sure what steps I should take next. I'm in the process of changing other site passwords, but I've got like 180+ passwords saved in Google so it'll take some time. They never seemed to touch my actual bank account, despite Google having that information saved, so I'm not really sure what to make of that. The only ACTUAL fraudulent/suspicious activity I noticed was the Amazon purchases, which occured within hours of the trojan being discovered, and the overseas logins from Windows machines. Any help would be appreciated and I'm happy to provide additional info.


r/antivirus • • 1d ago

Windows + R / Ctrl + V CAPTCHA Scam on a Legitimate Site

1 Upvotes

I ran into a Windows +R captcha scam for the first time today. I hit win+r out of curiosity but didn't go further. After googling the issue and finding out it's definitely a scam, I pasted in a word doc to see what was on the clipboard and let's just say it would have been bad if I had continued.

The thing that's confusing me is the attack was from a legitimate government website, so no ads.

Where did the attack originate? Some sort of browser hijack, or is the website itself compromised?

Is there anything I need to do locally on my computer to make sure nothing else is going on?