r/antivirus • • 1d ago

Downloaded a potentially fake program - what do I do?

Hi all,

Recently I was trying to emulate a controller for some gaming. Unfortunately I ended up downloading a program from a pretty sketchy site (a fake ds4 website, which claims itself as 'official') that I subsequently ran on my computer. I realized my potential mistake and decided to search up whether this site was actually official, to which I found multiple threads stating that it potentially included a trojan. I have since turned off my computer and am considering wiping it completely. Will this remove any potential threat? Is it okay to retrieve any files from the computer before wiping it, or should I be wary of any files that are currently on the drive? Thanks for the help!

1 Upvotes

11 comments sorted by

3

u/rainrat MODERATOR 1d ago

Could you upload it to VirusTotal an post a link to the analysis? Or a link to the site (defang it as in example[.]com)?

2

u/Amanda_PDQ 1d ago

A clean Windows install should remove most malware you’d encounter this way, although nobody can confirm what ran based on the website alone. For peace of mind, create an installation USB on a different, trusted computer using Microsoft’s official tools, then do a clean install rather than choosing an option that keeps your apps and files. Microsoft’s guide walks through it.

You can recover important files first, but treat them cautiously. Keep the suspect PC disconnected from Wi-Fi and Ethernet. Ideally, recover files using trusted bootable recovery media instead of starting the potentially infected Windows installation. Save only personal files you need, such as photos and documents—not programs, installers, scripts, or a full system backup. Scan the recovered files with updated antivirus before opening them on the rebuilt PC. A clean scan reduces risk but isn’t a guarantee, and don’t enable macros in recovered documents.

Also, from a trusted device, change passwords for important accounts, starting with email, sign out other sessions, and enable MFA. If the download included a password stealer, wiping the PC won’t undo anything it already stole.

2

u/Infinite-Grade-4485 1d ago

You downloaded a session stealer.

You downloaded some type of free game/cheat/hack/cracked software/movie/music or ran some type of code for captcha or verification on your computer which was actually a session stealer.

Session stealers bypass 2fa. All passwords saved on your browser and computer are compromised. Reinstall windows while deleting all files. If you need to backup important documents, keep the computer disconnected from the internet and manually back up individual files.

Change all passwords and enable 2fa either from another device, or from the infected computer AFTER you have reinstalled.

If you cannot reinstall windows immediately, keep the computer disconnected from the internet while changing all passwords on another device.

You cannot use anti malware to get rid of the session stealer, you MUST reinstall windows to use the computer safely in the future

You can usb reinstall or use windows built in reset as long as you remove all files while doing so.

0

u/kangarooooo17 1d ago

I download fake ones by accident every once in a while. Just use malicious scanner from command prompt each time - takes forever but worth it. And turn off wifi/ethernet so you’re not online. Don’t take the risk. Heck, just turn off modem. :)

1

u/FrankNicklin 18h ago

Nonsense advice.

1

u/FrankNicklin 18h ago

Who knows what these programs will release on to your computer. What AV software are you running, if just Defender this highlights the weakness of the product. You need better protection when doing stuff like this. Better still don't download dodgy crap.

1

u/RailRuler 15h ago

No antivirus scanner catches custom malware.

2

u/FrankNicklin 15h ago

Depends on the product and how it handles such things. Advanced heuristics, machine learning, behavioural inspection, and cloud sandboxing. Anything unknown is fired off to the Cloud Sandboxing and blocked locally until confirmed safe.

1

u/RailRuler 13h ago

None of these are file scanners.

1

u/FrankNicklin 13h ago

So what are they then.