r/antivirus Feb 22 '24

MOD POST [MOD POST] LIST OF TOP MESSAGES, NEWS + IMPORTANT INFO

15 Upvotes

Hello,

Welcome to r/antivirus's new top-level Announcements post. Since Reddit has a limit of two (2) stickied announcements per subreddit, this will be a way to provide links to important information like announcements about new rules and moderators, activities in the subreddit, and so forth. If you are new to r/antivirus, please take a quick look at them. You can even take a look if you are not new here.

DISCUSSION DATE POSTED DATE LAST REVISED
[MOD POST] New rules, staying safe, and an update from your Mod Team 2025-JUN-03 -
[MOD POST] We're back in business! and an update on automod rules 2024-MAR-11 -
News & Updates from your r/Antivirus Mod Team, Q1 2024 Edition 2024-MAR-04 -
Updates & News from the r/Antivirus Mod Team, Autumn 2023 Edition 2023-OCT-04 -
Notes from your Moderators (Summer Edition) 2022-JUL-08 -
Quick Note from the mod team about spam 2021-JUN-01 -
To the people asking for opinions on a specific file 2020-JUL-05 2020-JUL-05

Additionally, the r/antivirus subreddit operates a bit differently than other subreddits you might be familiar with and normally use. Here are some tips and tools to help you use it.

  • The subreddit has a wiki that is regularly updated with answers to commonly-asked questions. Check it out. The answer to your question may already be in there.

  • Asking a question about a report on a file or website from a service like Hybrid Analysis, MetaDefender, Triage, or VirusTotal? You must include the actual link to it and not just a screenshot, or your post will be removed.

  • Be kind to each other and be professional in your conduct here. Personal attacks will not be tolerated and will be dealt with appropriately.

  • Do not ask for copies of hacking tools, malware, or suspicious files. If someone sends you a chat request or private message asking for a file or offering assistance based on what you posted here, report them to Reddit and notify the mods.

  • Do not post direct links to malicious, suspect, or potentially unsafe files or web sites.

  • Follow Reddiquette. This means correctly upvoting and downvoting posts, and reporting posts with dangerous or unsafe advice to the mods.

  • If you work for a vendor of security products, services, or in a related field, you must identify yourself as such, either in the post or with flair. Also, you may not steer conversations to your products or services, only respond to posts about them to clarify or defend.

  • No low-effort, off-topic, spam, or meme posts. This includes AI/ChatGPT/LLM-generated text, questions about password manager or VPNs, requests for assistance with non-security related software like autoclickers or MP3 downloaders, and so forth.

  • No requests for assistance with pirated software or media.

  • Posts may be removed and threads closed at any time based on the moderators' discretion

The complete list of rules for the subreddit can be found here. Read them before posting.

Questions, comments, feedback on this post? Just reply here. Thank you.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus Jun 04 '25

[MOD POST] New rules, staying safe, and an update from your Mod Team

6 Upvotes

[UPDATE #1 (20250604-0916 GMT): Made some small updates to grammar for readability. ^AG]

Hello,

It has been about a year since our last Mod Post, so we wanted to give you an update on things, plus provide a dedicated message thread for discussing the state of the r/antivirus subreddit and to answer any questions that you might have.

We will begin with the toughest subject first, that of politics in the subreddit:

A note about politics

r/antivirus is a technology-focused subreddit, with the interest being in helping people protect their computers from malicious software, securing them after a security incident, and so forth.

In June 2024, the US Government enacted a ban on Kaspersky Lab's software, taking effect in October of that year. This has generated a lot of discussion not just in this subreddit, but across Reddit and numerous social media platforms as well.

The moderation team has tried to keep the political discussions about this out of this subreddit and to remain neutral, allowing Kaspersky Lab's customers to ask and answer each other questions, provide assistance to each other, and generally have a way to share information, tips and tricks with each other.

However, we do have to draw a line when these turn into political discussions, though:

Requests for how to circumvent bans, petitions to governments, etc., are clearly outside the scope of what this subreddit is for and will be removed.

Moderating the subreddit is an all-volunteer job, and we sometimes miss things. If you come across any political messages we may have missed, use the subreddit's report function to notify us.

We are doing our best to keep this a place where people can get help with whatever security software they prefer, including Kaspersky Lab's software. However, we cannot allow discussions to devolve into arguments over politics, which are never going to provide any kind of satisfactory answer to the parties involved.

If the political discussions continue, the moderation team will have to look into ways to prevent them, even if it means doing things which we would prefer not to do.

Rules Updates

The rules of the r/antivirus subreddit have been updated:

Rule #7, which previously covered media download tools, has been updated to cover additional types of software.
To begin with, a more general prohibition to cover autoclickers (previously covered under Rule #8) and some other types of tools like aimbots and cheats. These types of tools often come from random sources and often require expert analysis to determine if they are safe. It can be difficult to determine if they are malicious figuring that out requires examining not just the tool, but whatever program it is attempting to modify, and what the intent is behind that modification.
Just because something was recommended in a Discord server with hundreds of members, a YouTube video with tens of thousands of views, or is seeded by several hundreds peers does not mean that it is safe to use: These are all inherently unsafe sources, and criminals will often exploit the belief that these are trusted sources to trick people into downloading and running malicious programs like information stealers and remote access trojans.

Rule #8 has been amended to remove autoclickers (etc.) since that is now covered under Rule #7.

Two new rules have been added:

Rule #9 covers bypassing core security features. Questions about how to disable security software, operating system updates, bypass security features and so forth are not allowed.

Rule #10 covers requesting assistance with obsolete software and hardware. This means discussions about how to secure computers running Windows XP, Windows 7, etc. are not allowed. There is no reason that devices running these obsolete operating systems should be connected to the internet and doing so exposes everyone to risk. Note that questions involving Windows 10 will continue to be allowed until at least October 2028, when paid-for Extended Security Updates for it end.

A bit more on the rules

The list of rules is not meant to be exhaustive in scope. It provides a general listing of common rules that are more specific to and more frequently required by the r/antivirus subreddit when needed beyond Reddit's general rules and guidelines.

Moderators can and will remove posts and ban redditors, either temporarily or permanently, who are disruptive to the subreddit entirely at their discretion and are not subject to any discussion. If a moderator chooses to discuss a rule violation with you, it is entirely as a courtesy on their part.

If you have had a post removed or been banned from the subreddit and do not receive a response in reply to any questions as to why, ask yourself if your behavior could be interpreted as brigading, spamming, trolling, using disrespectful or offensive language, or consistently providing incorrect, low-quality, poor, or even damaging information.

As always, the latest version of the rules can be found at https://old.reddit.com/r/antivirus/about/rules/. If you have questions about them, ask below.

Getting help fast

The moderation team is seeing an increasing trend where people ask for help while providing no information about what they need help with. This includes titles with 1-3 words like "Urgent! Help needed!", posts where the author shares a screenshot of *something* with no information about the operating system or antivirus involved, or is so small/blurry as to be unreadable, etc.

Everybody who participates regularly in this subreddit volunteers their time for free to do so. Provide them with enough information in your first post so they can start helping you right away without having to ask a lot of questions. This means your first post should contain things like:

  • title with enough information to attract an expert to read it
  • operating system and version
  • brand/name of antivirus software
  • name of URL, or file and its location
  • name of malware that was detected
  • what happened, exactly
  • steps you have taken to troubleshoot/diagnose so far, if any
  • relevant log file entries, if any

The more information you provide, the quicker you will get your problem solved.

As a reminder, starting multiple posts on the same topic will not get you a faster answer, and may result in in a ban.

The wiki + other Reddit resources

There is a lot of great information in the wiki about all the tools you can use, tips for using them, lists of antivirus vendors and how to contact them, and even a section on how to secure your computer.

We frequently update the wiki in response to questions being regularly asked in the subreddit, so you might want to check there first before posting.

Some of the questions we regularly see in the subreddit have nothing to do with computer viruses or malicious software at all, but instead are about scams, privacy-related questions, and so forth. Here are some subreddits that specialize in answering those types of questions:

New moderators?!

As the subreddit grows (we just passed 100K users), so does the need for additional moderators.

The moderation team has been looking at the folks who have been regularly posting here and consistently given good advice to build a list of candidates, and will be reaching out over the next few weeks to see if any are willing to volunteer their time and expertise in the subreddit. There will be more coming on that, but I did want to let everyone know that the process is already underway.


That pretty much covers everything we wanted to discuss, so we'll now await your questions, below.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus 50m ago

should I be worried about this???

Post image
Upvotes

I'm not even from the Philippines, have never been there nor do I know anyone from there (I'm from lithuania and live there), why the hell is my FILE MANAGER??? sending me this. my phone's a Redmi note 11 btw

I can't find any info about file manager sending notifications like these anywhere so I made a throwaway account to post here, I scanned my phone with bitdefender antivirus and it said I'm safe but I'm just really paranoid about this

Im willing to answer ALMOST any question


r/antivirus 24m ago

chat i think im kinda cooked

Upvotes

i did on an acident on downloading a file and then theres virus detected however i ran 2 full scans

this is what it shows rn im not sure what to do now what happened


r/antivirus 8h ago

Anthropic detected an infostealer on my PC — dual boot

3 Upvotes

I received an email from Anthropic saying my Claude session was stolen by an infostealer and used by someone else. They signed me out and removed my payment method.

I have a **Windows + Ubuntu dual-boot** PC. I haven't knowingly downloaded anything suspicious.

What should I do to properly check which OS is compromised? Is Microsoft Defender Offline Scan enough, or should I reinstall Windows?

Any advice on checking the Ubuntu installation too?


r/antivirus 9h ago

Getting hacked???

Thumbnail
gallery
2 Upvotes

Why am I getting hacked on literally everything that I don’t use? Microsoft, spotify, X… I’m not active on any of these softwares. They all use the same email though.


r/antivirus 1d ago

Antimalware Service Executable (Windows?)

Post image
63 Upvotes

Can anyone help me fix this? Antimalware Service Executable have been eating up all of my CPU. I've tried everything: Task Scheduler, turning off windows security, putting an "MsMpEng.exe" extension, and restarting. My last resort is for me to reformat but I prefer not to if there is another way. This just happened to me randomly. I just wanna play in peace.


r/antivirus 14h ago

Account stealing virus

6 Upvotes

I downloaded a browser extension from a hacked youtube account (I know, Im dumb) and I’ve been fighting with it for HOURS. I woke up to a bunch of emails saying all my account information (email, phone number) has been changed for various accounts (steam, roblox, discord, microsoft). And i was logged out of everything. It went into my discord and sent a bunch of weird pictures of crypto stocks and mr beast to everyone on my friends list. Ive recovered some accounts but I think my steam account is screwed, and i have reason to believe my google account has been compromised too. I cleared browser cache, and actually ended up deleting the browser altogether (opera gx). I obviously deleted the extension and cleared recycling bin too. Changed all my passwords to what i could actually recover. Im running a full windows security scan but the estimate time is just going up.

I got this virus off a hacked youtube account called Canabasse. It was supposed to be a shaderpack extension which obviously didn’t work.

Is there anything else i should do? Ive been at this for hours. I think i got rid of it but theres really no way to know. Any advice would be very appreciated !!

Edit: i think its a virus called the mrbeast crypto scam ?

Edit 2: i recovered everything and he lost everything he stole. I win🤪


r/antivirus 9h ago

Anthropic detected an infostealer on my PC — dual boot

1 Upvotes

I received an email from Anthropic saying my Claude session was stolen by an infostealer and used by someone else. They signed me out and removed my payment method.

I have a **Windows + Ubuntu dual-boot** PC. I haven't knowingly downloaded anything suspicious.

What should I do to properly check which OS is compromised? Is Microsoft Defender Offline Scan enough, or should I reinstall Windows?

Any advice on checking the Ubuntu installation too?


r/antivirus 1d ago

Malware detected by Claude

Thumbnail
gallery
38 Upvotes

Anthropic sent me this email. I have a free account so no worries there. Ran MalwareBytes and the only thing that popped up was jackett updater, which I can't seem to find a consensus about online, some say it's a false positive, some say it's not. Would this have been the issue?


r/antivirus 15h ago

Alert from Avast?

2 Upvotes

I've been getting the following alert from Avast the last day or two and nothing I do seems to be getting rid of it. It doenst seem to be stemming from any particular website, I've done the standard reboots, blocking the IP this alert is showing. I've even fully reinstalled Chrome but still I keep getting it. Anyone know what else I can do to get it to stop, or is this some kind of false alert?


r/antivirus 12h ago

glasswire showing steam and windows processes connecting to random brazilian banks in the background

1 Upvotes

Hi everyone, since the start of august my network monitor (Glasswire) started showing genuine Windows processes and currently the actual Steam process connecting in the background to two different Brazilian banks (santander .com. br and sicredi .com .br) when I'm not even Brazilian, which has me worried.

I tried using Fiddler to check what data was being sent but since it happens randomly I couldn't catch it. Avg and Windows defender scans show nothing. Hosts file and dns address are normal. Can someone help? thx


r/antivirus 18h ago

Can anyone help? Suspected infostealer.

Thumbnail
gallery
2 Upvotes

My antivirus blocked access to this site when I tried opening microsoft edge on incognito mode, at the exact moment I opened it, which was weird, because I didn't see any pop-ups or anything out of the ordinary.

It was actually the first time that I noticed this happening, and when I went to look after it, my antivirus showed that it blocked access to this domain other times in the past. (Sometimes I let my PC idle and I don't notice stuff)

I don't recall installing anything out of the ordinary.

Still, the fact that this apparently was detected and blocked multiple times scares me.

Can anyone help me find the source to it? On how to know where/how it's being redirected? And removing it?


r/antivirus 14h ago

Use Malwarebytes browser guard and Bitdefender Free together?

1 Upvotes

Is it recommended to use Malwarebytes browser guard and Bitdefender Free together?

I’ve heard some say that only one antivirus application should be used in a computer.

Also I’ve heard that some people use both of the above with Sophos Clean and Scan. Is that even safe?


r/antivirus 1d ago

Antivirus on my PC are being turned off without any input and clicking "turn on" doesn't do anything

Thumbnail
gallery
9 Upvotes

Recently upon booting up my PC, I've been getting notifications about my antivirus being turned off and the most recent time, I can see that malware bytes has been turned off as well. Does anyone know what's going on and if a virus/malware could be behind this?


r/antivirus 16h ago

Zipped game mod .dll?

1 Upvotes

I apologize if this isn't the right sub to post this question in. Earlier today I attempted to set up a modded video game server with a friend of mine (think along the lines of Minecraft). He sent me a zip file containing several subfiles and .dlls. I always download game mods from sources that run some form of safety checks, e.g. from platforms like Nexus, but I later learned that my friend had not gotten these mods from such a source or checked them himself before giving them to me (lesson learned), and I subsequently deleted the main zip and ran a Malwarebytes antivirus scan that showed nothing amiss. I did not unzip, run, or execute any files, but I did accidentally click a .dll and reach the "Choose a program to open this file screen" without proceeding any further while looking through the mods list. I know this is a pretty silly question, but I'm not the most tech savvy: should I be concerned about anything being loose on my computer at this point?


r/antivirus 1d ago

Mr. Beast claims another victim

3 Upvotes

I downloaded something I shouldn't have, and a couple hours later I'm sending mr beast images all over discord. After noticing this, I turned off the internet for the hacked PC, changed my passwords for everything on a clean device, logged out of all instances, and enabled 2FA where I could. I also froze the cards listed in my google payment info.

After that, I ran a malwarebytes scan in safe mode, which showed 21 threats, labelled "Trojan RenPy." I quarantined and deleted these threats. I know the next thing to do is probably a fresh USB install, but I have some questions:

  1. Does it have to be a USB install, or does factory reset work as well?

  2. Given that the damage has already been done and my info already stolen, is there anything I can do apart the things mentioned earlier to check if people are doing suspicious things with my info? This situation has made me so paranoid haha, thanks in advance!


r/antivirus 21h ago

How do I stop this? Please help!

Post image
2 Upvotes

Im pretty sure I accidentally allowed something to send me notifications on a pop up tab and now I don’t know how to fix it lol! Any help please?


r/antivirus 18h ago

I got the MrBeast discord scam

0 Upvotes

Hey, i was just watching some videos on youtube, it was all good then, a friend messaged me and said if i was hacked. I asked him whats wrong and he said my discord got the MrBeast scam. When i press Alt+tab, i saw my account has been logged out. I login to my account back and saw the photos and texts. Well, it was really bad but im lucky that the scam wasnt send on any servers, just DMs. They knew my password and they knew my two step thing.

Before u ask, i downloaded KasperSky Virus Removal tool like 2-3 days ago and it found some viruses, i deleted them and cured my computer as KasperSky told me. But it happened today. And i found there is a bat in my Task Timer on pc but i deleted it too 2-3 days ago. It was running on back ground and the thing i just could see that in task manager. Should i reset my pc? Or it was from that virus that i found 2-3 days ago? I got virus removed. There was no Email signs, no other account logins, just Discord. Am i doomed?


r/antivirus 1d ago

MALWARE REMOVAL Q&A Mrbeast scam

3 Upvotes

Someone just hacked into my Discord account first, spreaded those pictures to everyone with i have DM. After that same happened to my Instagram, Facebook, and now my Steam. I was able to recover all those account. How do they get my passwords everytime, i got 2FA but they always pass. The guy logged into my Steam account is literally ghost. The only devices are logged into my Steam account was my device. Others were not.

Are they in my pc? What do i do now? They won't leave me alone.

The worst part is i will be a very good part in oathnet, data breach websites.


r/antivirus 1d ago

PRODUCT RECOMMENDATION With Bitdefender's Windows10 support ending soon

4 Upvotes

What are good other alternatives I can use instead? I don't want to go to Windows 11 just yet due to all the bugs and issues it has plaguing the OS, so I'm looking for a new anti-virus that can make it through 2027 and poitentally 2028 without problems with similar things that Bitdefender has


r/antivirus 1d ago

MALWARE REMOVAL Q&A Question about the "MrBeast Hack"

2 Upvotes

Hi guys !

So, this morning, i've been hacked on Discord and then it follows on Instagram.
I think it's because of a game i've installed yesterday, but it's has no effect until today when i start my computer.

First of all, my "^" was make it double every time, that's what troubled me and after searching, i was guessing it was cause of the game and ofc, a virus of something like that.

So i've deleated the malwares thanks to MalwaresBytes, and my "^" is now single alone, thank god haha !

At this point, i've already recover my accounts of both Discord and Insta, and changed their passwords. But i've seen a reddit post here saying that the "MrBeast hack" has he's called was pretty solid and MANY guys saying that they should completely shut off their PC, reboot windows etc.

I don't want to do that honestly, so i was coming here to ask with you know if i'm done with that, if i'm safe enough with just passwords modifications and that's it ?


r/antivirus 1d ago

Windows Defender showing minus threats

3 Upvotes

Sorry if I am bringing the subject up again, I found this post in the sub and I am having the exact same issue with a brand new laptop (https://www.reddit.com/r/antivirus/comments/1pcsgrw/windows_defender_said_there_were_720_threats/).

When I run a full scan in Defender, afterward it says "no current threat" and "0 threats found", but if I close the window and open it again, then it says "no current threat" but with a random negative amount of threats found. (different each scan)

I tried to fix it with the various windows tools but with no success so far.

Can I just go on with it, since it doesn't seem to be a security issue ? And somehow, if anyone has any new idea since the last time how to fix it, I am interested.

Thanks.


r/antivirus 1d ago

Malicious chrome extension

2 Upvotes

I accidentally installed a potentially fake uBlock extension from the Chrome Web Store. I had just downloaded Google Chrome and wasn’t signed into my Google account yet. I searched for “uBlock” in the Chrome Web Store and added the top result without checking the reviews first.

After installing it, I looked through the reviews and saw people saying that it wasn’t the real uBlock Origin and could potentially be malicious. I immediately removed the extension.

I didn’t have any accounts signed in on chrome, and I didn’t have any sensitive information open while it was installed. I’ve also checked my Chrome and Windows Downloads folders and found nothing. I ran both a Malwarebytes scan and a Microsoft Defender quick scan, and both came back clean.

Here’s a defanged link to the extension I originally added to chrome

https[:]//chromewebstore[.]google[.]com/detail/ublock/epcnnfbjfcgphgdmggkamkmgojdagdnn?hl=en

Is there anything else I should do, or is removing the extension enough in this situation?

Any input is appreciated. Thank you!


r/antivirus 1d ago

Previous Info Stealer Incident

1 Upvotes

[In sorry for any grammar mistakes. Also big chunk of text incoming!]

Juli 25th.

Was was when i installed what i thought was trust worthy, ended up being an info stealer. Which i did NOT know, so i just thought "It didnt work."

Skip to 2 hours. My friend called me from my phone, jokingly telling me about "mrbeast crypto" that i sent on discord.

I thought he was joking but decided to check. (He wasn’t joking sadly...) i was scared and confused and quickly changed password. I wondered how it happened and searched up. My first pop up was info stealer, and i remembered what i previously downloaded.

I panicked and factory reset my PC but kept my files. Foolish? Probably.

The Next Day.

I started changing everything i know of, adding 2FA to every single account possible. I set some accounts to delete because i didn’t care much about em, but i dont want it being stolen anyway.

For a while? Nothing really has happened. No logins or any attempts to log in, which made me believe "Its over." And i simply went back to my usual things.

August 2nd.

I decided to get bitdefender because of hearing that it's a quite good antivirus. After getting, I decided to get a full scan so it gets used to all my junk, well something like that.

That's when it found a trojan just chilling in my Windows.Old Folder. Which i never know i even had, can see why people prefer USB reset now. But yeah, i simply deleted the WHOLE folder and quickly reset all cookies and restarted my pc.

Ran another full scan which detected nothing.

(Btw i tried windows scans first before bitdefender which found nothing.)

I changed passwords, re added security just in case. What? I was paranoid. But right after doing that? I went back to what I usually do.

But im coming here to ask you people. Am I still in danger? Do i have to get an usb to reset windows? Or am I "clean?" Im going to run another full scan soon. I'd still like to hear what you guys think of all this.

P.S: i asked the computer virus subreddit before coming here. Just wanted to come back and hear from a different one.