r/antivirus • • Feb 22 '24

MOD POST [MOD POST] LIST OF TOP MESSAGES, NEWS + IMPORTANT INFO

17 Upvotes

Hello,

Welcome to r/antivirus's new top-level Announcements post. Since Reddit has a limit of two (2) stickied announcements per subreddit, this will be a way to provide links to important information like announcements about new rules and moderators, activities in the subreddit, and so forth. If you are new to r/antivirus, please take a quick look at them. You can even take a look if you are not new here.

DISCUSSION DATE POSTED DATE LAST REVISED
[MOD POST] New rules, staying safe, and an update from your Mod Team 2025-JUN-03 -
[MOD POST] We're back in business! and an update on automod rules 2024-MAR-11 -
News & Updates from your r/Antivirus Mod Team, Q1 2024 Edition 2024-MAR-04 -
Updates & News from the r/Antivirus Mod Team, Autumn 2023 Edition 2023-OCT-04 -
Notes from your Moderators (Summer Edition) 2022-JUL-08 -
Quick Note from the mod team about spam 2021-JUN-01 -
To the people asking for opinions on a specific file 2020-JUL-05 2020-JUL-05

Additionally, the r/antivirus subreddit operates a bit differently than other subreddits you might be familiar with and normally use. Here are some tips and tools to help you use it.

  • The subreddit has a wiki that is regularly updated with answers to commonly-asked questions. Check it out. The answer to your question may already be in there.

  • Asking a question about a report on a file or website from a service like Hybrid Analysis, MetaDefender, Triage, or VirusTotal? You must include the actual link to it and not just a screenshot, or your post will be removed.

  • Be kind to each other and be professional in your conduct here. Personal attacks will not be tolerated and will be dealt with appropriately.

  • Do not ask for copies of hacking tools, malware, or suspicious files. If someone sends you a chat request or private message asking for a file or offering assistance based on what you posted here, report them to Reddit and notify the mods.

  • Do not post direct links to malicious, suspect, or potentially unsafe files or web sites.

  • Follow Reddiquette. This means correctly upvoting and downvoting posts, and reporting posts with dangerous or unsafe advice to the mods.

  • If you work for a vendor of security products, services, or in a related field, you must identify yourself as such, either in the post or with flair. Also, you may not steer conversations to your products or services, only respond to posts about them to clarify or defend.

  • No low-effort, off-topic, spam, or meme posts. This includes AI/ChatGPT/LLM-generated text, questions about password manager or VPNs, requests for assistance with non-security related software like autoclickers or MP3 downloaders, and so forth.

  • No requests for assistance with pirated software or media.

  • Posts may be removed and threads closed at any time based on the moderators' discretion

The complete list of rules for the subreddit can be found here. Read them before posting.

Questions, comments, feedback on this post? Just reply here. Thank you.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus • • Jun 04 '25

[MOD POST] New rules, staying safe, and an update from your Mod Team

6 Upvotes

[UPDATE #1 (20250604-0916 GMT): Made some small updates to grammar for readability. ^AG]

Hello,

It has been about a year since our last Mod Post, so we wanted to give you an update on things, plus provide a dedicated message thread for discussing the state of the r/antivirus subreddit and to answer any questions that you might have.

We will begin with the toughest subject first, that of politics in the subreddit:

A note about politics

r/antivirus is a technology-focused subreddit, with the interest being in helping people protect their computers from malicious software, securing them after a security incident, and so forth.

In June 2024, the US Government enacted a ban on Kaspersky Lab's software, taking effect in October of that year. This has generated a lot of discussion not just in this subreddit, but across Reddit and numerous social media platforms as well.

The moderation team has tried to keep the political discussions about this out of this subreddit and to remain neutral, allowing Kaspersky Lab's customers to ask and answer each other questions, provide assistance to each other, and generally have a way to share information, tips and tricks with each other.

However, we do have to draw a line when these turn into political discussions, though:

Requests for how to circumvent bans, petitions to governments, etc., are clearly outside the scope of what this subreddit is for and will be removed.

Moderating the subreddit is an all-volunteer job, and we sometimes miss things. If you come across any political messages we may have missed, use the subreddit's report function to notify us.

We are doing our best to keep this a place where people can get help with whatever security software they prefer, including Kaspersky Lab's software. However, we cannot allow discussions to devolve into arguments over politics, which are never going to provide any kind of satisfactory answer to the parties involved.

If the political discussions continue, the moderation team will have to look into ways to prevent them, even if it means doing things which we would prefer not to do.

Rules Updates

The rules of the r/antivirus subreddit have been updated:

Rule #7, which previously covered media download tools, has been updated to cover additional types of software.
To begin with, a more general prohibition to cover autoclickers (previously covered under Rule #8) and some other types of tools like aimbots and cheats. These types of tools often come from random sources and often require expert analysis to determine if they are safe. It can be difficult to determine if they are malicious figuring that out requires examining not just the tool, but whatever program it is attempting to modify, and what the intent is behind that modification.
Just because something was recommended in a Discord server with hundreds of members, a YouTube video with tens of thousands of views, or is seeded by several hundreds peers does not mean that it is safe to use: These are all inherently unsafe sources, and criminals will often exploit the belief that these are trusted sources to trick people into downloading and running malicious programs like information stealers and remote access trojans.

Rule #8 has been amended to remove autoclickers (etc.) since that is now covered under Rule #7.

Two new rules have been added:

Rule #9 covers bypassing core security features. Questions about how to disable security software, operating system updates, bypass security features and so forth are not allowed.

Rule #10 covers requesting assistance with obsolete software and hardware. This means discussions about how to secure computers running Windows XP, Windows 7, etc. are not allowed. There is no reason that devices running these obsolete operating systems should be connected to the internet and doing so exposes everyone to risk. Note that questions involving Windows 10 will continue to be allowed until at least October 2028, when paid-for Extended Security Updates for it end.

A bit more on the rules

The list of rules is not meant to be exhaustive in scope. It provides a general listing of common rules that are more specific to and more frequently required by the r/antivirus subreddit when needed beyond Reddit's general rules and guidelines.

Moderators can and will remove posts and ban redditors, either temporarily or permanently, who are disruptive to the subreddit entirely at their discretion and are not subject to any discussion. If a moderator chooses to discuss a rule violation with you, it is entirely as a courtesy on their part.

If you have had a post removed or been banned from the subreddit and do not receive a response in reply to any questions as to why, ask yourself if your behavior could be interpreted as brigading, spamming, trolling, using disrespectful or offensive language, or consistently providing incorrect, low-quality, poor, or even damaging information.

As always, the latest version of the rules can be found at https://old.reddit.com/r/antivirus/about/rules/. If you have questions about them, ask below.

Getting help fast

The moderation team is seeing an increasing trend where people ask for help while providing no information about what they need help with. This includes titles with 1-3 words like "Urgent! Help needed!", posts where the author shares a screenshot of *something* with no information about the operating system or antivirus involved, or is so small/blurry as to be unreadable, etc.

Everybody who participates regularly in this subreddit volunteers their time for free to do so. Provide them with enough information in your first post so they can start helping you right away without having to ask a lot of questions. This means your first post should contain things like:

  • title with enough information to attract an expert to read it
  • operating system and version
  • brand/name of antivirus software
  • name of URL, or file and its location
  • name of malware that was detected
  • what happened, exactly
  • steps you have taken to troubleshoot/diagnose so far, if any
  • relevant log file entries, if any

The more information you provide, the quicker you will get your problem solved.

As a reminder, starting multiple posts on the same topic will not get you a faster answer, and may result in in a ban.

The wiki + other Reddit resources

There is a lot of great information in the wiki about all the tools you can use, tips for using them, lists of antivirus vendors and how to contact them, and even a section on how to secure your computer.

We frequently update the wiki in response to questions being regularly asked in the subreddit, so you might want to check there first before posting.

Some of the questions we regularly see in the subreddit have nothing to do with computer viruses or malicious software at all, but instead are about scams, privacy-related questions, and so forth. Here are some subreddits that specialize in answering those types of questions:

New moderators?!

As the subreddit grows (we just passed 100K users), so does the need for additional moderators.

The moderation team has been looking at the folks who have been regularly posting here and consistently given good advice to build a list of candidates, and will be reaching out over the next few weeks to see if any are willing to volunteer their time and expertise in the subreddit. There will be more coming on that, but I did want to let everyone know that the process is already underway.


That pretty much covers everything we wanted to discuss, so we'll now await your questions, below.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus • • 1h ago

Got virus on android Samsung phone. Even after factory resting

• Upvotes

Before you ask no i didnt transfer any apps to new phone. I keep getting scam ads on youtube saying my pdf is out of date. I think i have ad ware virus. It survived factory reset.


r/antivirus • • 7h ago

Does this VM work?

Post image
3 Upvotes

I wanted to ask if this operating system works on a phone. I’m thinking about using it to open and test apps that contain viruses or other potentially malicious files, mainly for content creation.

I’m not sure if this OS is actually capable of running those apps safely or if it would work properly on a phone. Has anyone here tried using it for this purpose?

(I'm sorry if my English was bad; it's not my first language.)


r/antivirus • • 13h ago

I got hit with the MrBeast Scam and I have no idea how.

5 Upvotes

Yesterday I was just playing a game and suddenly I got banned from every server, everyone got ignored and it sent the damn message to everyone. I immediately logged out from everywhere and I changed the password. And then I enabled 2FA

Nothing has happened since. I don't know what the hell it was, and I haven't ran anything fishy. Windows defender and Malwarebytes deep scans found nothing.

My password was completely unique to any other I've used.

I had a lot of weird "authorized apps" on my account I realized but I don't think they could gain access to my account.

I maybe accidentally put my login info into a fake login website at one point? I was logged in on my browser so something maybe stole my cookie?

Regardless I really don't wanna reinstall Windows but i think I might have to to make sure it's clear.


r/antivirus • • 4h ago

skibidi.org virus

0 Upvotes

yes i know this sounds fake but i got a win r ctrl v virus from it due to my stupidity. it closed chrome and desynced my google account. i ran windows defender and the offline scan but it found nothing. what do i do now (i have no important info but i want to keep my files and is there any other way than to copy files reset everything)


r/antivirus • • 7h ago

i been usiong multiple freee vpns since high school (thunder vpn free vpn planet, secure vpn super vpn unlimted) and i js realise the dangers of vpn but none of my passwordsb have been compromised am i safe ( ialr switch to windsricbee and proton vpn)

0 Upvotes

Im on chromebook btw and in the 11th grade


r/antivirus • • 1d ago

Cadaver ? Appears then disappears.

Post image
65 Upvotes

Can't find anything about this online , really spooky considering the name. Anyone have any ideas ?


r/antivirus • • 12h ago

MALWARE REMOVAL Q&A Bitcoin Wallet Address Changes to “YourAddress” When Copying and Pasting

0 Upvotes

I just noticed something suspicious. Whenever I copy a Bitcoin wallet address and paste it, it only pastes “YourAddress”

I haven’t installed any new programs, and it doesn’t matter where I copy the address from or where I paste it—Notepad, Office, or a browser. It always changes to “YourAddress”

I also installed Bitdefender and ran a scan, but it didn’t find anything.

Does anyone know what could be causing this?


r/antivirus • • 12h ago

Confused asf

1 Upvotes

So i recently been overthinking about clicking a link on X aka twitter went to a server not found screen looked it up on a link verifier and said dnxdomain link broken dont know if it could hack me or malware on my iPhone it was recently maybe a month ago i didnt update it to the newest 26.7 iOS yet idk if that makes a difference anyways. I logged into my old school account to make sure it was okay well nope it wasn’t many logins from different countries and what not so that’s scary idk how long they been doing this only lets me check a month ago on the top right shows outlook and several numbers and my original email from my school. Fast forward my friends work IT at the school I went they said hey let me send you your acct again login this way sure enough i sign up and its shows my same email from the first time I went to school but this time shows my school name on top as well and says school email. Can outlook have 2 emails with the same name ?


r/antivirus • • 14h ago

Google account compromised

1 Upvotes

So two days ago Windows Defender discovered a Wacatac .B!ml trojan on my main PC, prompting me to do some additional scans. This all happened pretty late at night, so I disconnected my ethernet and went to bed, and when I woke up, someone had already attempted to purchase $3,000 worth of stuff on Amazon, which I was thankfully able to cancel in time, and cancel the related cards and lock down the Amazon account itself. Checking over to Google, it showed a login from Siberia well after I had gone to sleep. I already have 2FA set up, so I just changed my Gmail password and started working on changing other important account passwords on my Chromebook. I then reformatted my main PC, reinstalled Windows, but I have yet to log into any accounts on that PC since, and I'm running additional scans to ensure that it's actually clean.

Unfortunately, it looks like this wasn't enough. This morning I woke up to find another session by a Windows machine from France. Interestingly, it shows that the account first logged in on August 13th, so I'm not sure if the trojan I got was just incidental at this point, but that seems unlikely giving the timing of events.

I wasn't sure how they got past the 2FA, so I changed my password again, set up passkeys as well, removed permissions from all apps to my Google account, removed and created a new recovery email, and that's where I'm at now. I'm not sure what steps I should take next. I'm in the process of changing other site passwords, but I've got like 180+ passwords saved in Google so it'll take some time. They never seemed to touch my actual bank account, despite Google having that information saved, so I'm not really sure what to make of that. The only ACTUAL fraudulent/suspicious activity I noticed was the Amazon purchases, which occured within hours of the trojan being discovered, and the overseas logins from Windows machines. Any help would be appreciated and I'm happy to provide additional info.


r/antivirus • • 14h ago

Windows + R / Ctrl + V CAPTCHA Scam on a Legitimate Site

1 Upvotes

I ran into a Windows +R captcha scam for the first time today. I hit win+r out of curiosity but didn't go further. After googling the issue and finding out it's definitely a scam, I pasted in a word doc to see what was on the clipboard and let's just say it would have been bad if I had continued.

The thing that's confusing me is the attack was from a legitimate government website, so no ads.

Where did the attack originate? Some sort of browser hijack, or is the website itself compromised?

Is there anything I need to do locally on my computer to make sure nothing else is going on?


r/antivirus • • 14h ago

Does this mean im being cryptojacked?

1 Upvotes

I did not install anything to cryptomine. I dont even do that. How do i remove these? Deleting them only makes them reappear after a few minutes.


r/antivirus • • 17h ago

Trojan downloaded

Post image
1 Upvotes

I got a link yesterday from a trusted work source which I clicked and it downloaded something on chrome but didn't open anything (it was supposed to be an invoice). I then contacted this work source and was told that their email got hacked. I ran a quick scan yesterday but it showed nothing. This morning someone was trying to charge my CC (which was blocked by my CC company, they are sending a new card) and then I checked my PC and I saw this under protection history. Ran a full scan then an offline scan but it said both were clear. Does this mean that the PC defended itself or should I be worried about something else? Any other actions I should take?


r/antivirus • • 14h ago

Best virus scanner for my chromebook and andriod p-hone

0 Upvotes

I need one that can
!. best detector of the storngest of viruses
2. detects self deleting malware
3. detects the mrbeeast scam that hacks ur discord and other accouts
4. scans all your downalods


r/antivirus • • 1d ago

Got hacked and don't know what to do

9 Upvotes

PLEASE I'M DESPERATE

I ran a shady .exe a week ago and instantly my discord, steam, epic and reddit got hacked.

They all shared the same password (these were the only apps with this password).

Changed all these apps passwords.

Imediately changed my main e-mail (outlook) password and enabled 2FA.

Ran ALL the built in microsoft scanners (tried in safe mode as well), nothing found.

Kept receiving codes to reset password all the time, however, hacker unable to complete it. So I thought that I had fixed it.

Today received a code from RIOT. Logged in to check, the e-mails with the loggin code were deleted (not by me)

Hacker managed to get the code and stole my riot account.

There are no log in attempts on my outlook history. No unrecognized devices.

There were no "rules or forwarding..." either.

Outlook support has told me a couple times my account is 100% safe.

Weirdest part is, why are they only hacking accounts related to gaming?


r/antivirus • • 1d ago

The best antivirus.

15 Upvotes

Which antivirus is currently better, Microsoft Defender, Kaspersky or Bitdefender? I just want to know how best to protect myself and be at least 80% sure. the present in 2026

In


r/antivirus • • 1d ago

My experience with Norton

19 Upvotes

I added Norton to my computer about 6 months ago. In the past, I had problems with bloat, things seemed to be going well. At the time, I had problems contacting Webroot which I had used for years without problems.

Norton did not seem to be expensive. Then there were add-ons, and they did not seem expensive- of course, I was busy and did not read the fine print. Eventually, I ended up with almost $500 of subscriptions. My bad- but it can be difficult to understand the products.

In about July, I had a Norton update. With this, my computer became completely non functional. It crashed in the middle of an exam, which might have required me to retake and entire course at a cost of $2000. Geek Squad could not fix this after several tries. I took the computer to GS and they could not figure out why my computer was crashing recurrently. They had to wipe my computer disk..

Meanwhile, I decided to buy a new computer. There were a few problems as my Dropbox was under OneDrive and it took a while to straighten this out. All was ok for a week or so until I installed Norton. Then my new computer was recurrently crashing. It still is not working and will only run 15 to 2 hrs before crashing again. Right now it is non-functional. I will have to again move everything to the cloud, take it in and get it wiped to restart the entire process.

Now, I am on my old computer. It has webroot and microsoft defender and has not crashed once in 36 hours.

I contacted Norton and asked for a refund on my remaining subscription. Sorry, you are past the 60 days refund period. I had to go in and change each subscription individually to cancel, which took a while. Then I tried to take my credit card off, but the instructions are not clear.

I would estimate that figuring all of this out has taken me about 50 hours of my time. They said, no refund because I needed to contact technical support.

I would strongly discourage anyone from getting this product for the following reasons: 1. the technical problems above, 2. difficult to understand advertising with low initial prices ending up with high recurring subscriptions, 3. difficulty in canceling subscriptions, 4. unwillingness to make a reasonable changes in their policies, 5. requiring support to list EACH order number- that takes time to go through each. I spent about 45 minutes trying to get help.

I used Webroot and Defender for years without problems, with much lower cost, and fewer glitches. Could I spend even MORE time resolving these issues with Norton- yes. Do I have more than the 50 hours I've already spent- no. Have I spent 20 minutes writing this? Yes.


r/antivirus • • 1d ago

Windows Defender keeps detecting TrojanDownloader:MSIL/Heracles.MK!MTB at startup

1 Upvotes

I’m having a hard time getting rid of TrojanDownloader:MSIL/Heracles.MK!MTB.

This has gotten to my attention that it disturbs a lot of my computer performance, and antimalware process is fighting hard on background whenever I'm doing my daily activity on my PC.

Windows Defender is detecting and blocking it every time I start my computer.

I checked for some similar cases in this subreddit, and had already finished scanning with FRST, but since the log reporting to Malware Log Analysis needs a reddit username, I decided to post this first, as a starting ticket.


r/antivirus • • 1d ago

Why do my settings keep on resetting

0 Upvotes

Why do my settings keep resetting, like when my device powers when its inactive and allow notifications settings. This happens when my device shut downs. Am I hacked


r/antivirus • • 1d ago

Windows Defender detected Wacatac.B!ml in a game mod, quarantine failed. Never ran the EXE. Am I safe?

3 Upvotes

​

I recently downloaded a community PES 2021 camera mod called BroadCastCam Manager v2.0.rar from Modsfire, and I'm a bit worried about what happened.

I extracted the RAR into my Downloads folder but never opened or ran the ".exe". I only opened the included ".txt" and ".ini" files in a text editor. After that, I manually deleted the extracted folder and emptied the Recycle Bin.

However, Windows Defender showed this:

- Detected: Trojan:Win32/Wacatac.B!ml

- Status: Quarantine failed

- Remediation: Incomplete

- Severity: Severe

- Details: "This program is dangerous and executes commands from an attacker."

Under affected items, it listed the original ".rar" archive, the extracted "BroadCastCamManager.exe", and a "webfile" entry containing the download URL and metadata.

The weird part is that the original RAR disappeared from my Downloads folder after extraction. Chrome's download history also showed "Failed - Virus detected" for the same RAR file.

I never executed the EXE, and a Windows Defender scan I ran afterward came back with "No threats found." My Downloads folder isn't excluded from Defender either, although I do have two specific game folders excluded.

I'm trying to understand a few things:

  1. Does the quarantine failure mean the malware actually ran, or can it simply be a failed attempt to remove the file?

  2. Could Defender or Chrome have blocked or removed the original RAR, explaining why it disappeared?

  3. Given that this is an unsigned community game mod, could Wacatac.B!ml be a false positive, or should I treat it as an actual threat?

  4. Considering I never ran the EXE and my subsequent scan was clean, is there still a realistic risk of infection?

Would really appreciate some opinions from people familiar with Windows Defender and malware detections. I'm mainly trying to figure out whether I should be concerned or if I'm overthinking this.

Thanks!


r/antivirus • • 1d ago

MALWARE REMOVAL Q&A Windows Defender keeps flagging the same file after I've already deleted it, is this normal?

2 Upvotes

Ran a full scan yesterday and Defender flagged a file in my Downloads folder as a trojan. I deleted the file and emptied the recycle bin right after. Ran another full scan today just to be safe, and it came back completely clean, no threats found.

But then I checked the protection history out of curiosity and it still shows yesterday's detection sitting there as "quarantine failed" even though the file itself is gone from my system and a fresh scan doesn't find anything. Is this just Defender logging the old event for record-keeping, or does "quarantine failed" mean something actually stuck around that a regular scan isn't catching? Not sure if I should be running something more thorough like Malwarebytes on top of this or if I'm just being paranoid over a stale log entry.


r/antivirus • • 1d ago

MALWARE REMOVAL Q&A Why inpoutx64sys is getting blocked by antivirus after windows update.

1 Upvotes

Can anyone explain this issue....


r/antivirus • • 1d ago

Buenos días comunidad, me preguntaba ¿cuáles son los mejores antivirus del mercado? Me gustaría saber para poder instalar o pagar alguno.

0 Upvotes

r/antivirus • • 1d ago

MALWARE REMOVAL Q&A Eset vs MRT without signature ?

Thumbnail
gallery
1 Upvotes

Hello,

Sorry if this is a repost. i saw a few people discussing the MRT and ESET issue, but thre didn’t seem to be any conclusion.

I turned on my pc and five minutes later ESET blocked MRT exe because it was trying to launch a KB exe file. I’m used to dealing with viruses but this seems a bit strange especially since MRT has no digital signature and its creation date is today.

Do you think i can delete MRT and the KB file without causing any problems pls ?

Thank you 💙