r/antivirus Feb 22 '24

MOD POST [MOD POST] LIST OF TOP MESSAGES, NEWS + IMPORTANT INFO

17 Upvotes

Hello,

Welcome to r/antivirus's new top-level Announcements post. Since Reddit has a limit of two (2) stickied announcements per subreddit, this will be a way to provide links to important information like announcements about new rules and moderators, activities in the subreddit, and so forth. If you are new to r/antivirus, please take a quick look at them. You can even take a look if you are not new here.

DISCUSSION DATE POSTED DATE LAST REVISED
[MOD POST] New rules, staying safe, and an update from your Mod Team 2025-JUN-03 -
[MOD POST] We're back in business! and an update on automod rules 2024-MAR-11 -
News & Updates from your r/Antivirus Mod Team, Q1 2024 Edition 2024-MAR-04 -
Updates & News from the r/Antivirus Mod Team, Autumn 2023 Edition 2023-OCT-04 -
Notes from your Moderators (Summer Edition) 2022-JUL-08 -
Quick Note from the mod team about spam 2021-JUN-01 -
To the people asking for opinions on a specific file 2020-JUL-05 2020-JUL-05

Additionally, the r/antivirus subreddit operates a bit differently than other subreddits you might be familiar with and normally use. Here are some tips and tools to help you use it.

  • The subreddit has a wiki that is regularly updated with answers to commonly-asked questions. Check it out. The answer to your question may already be in there.

  • Asking a question about a report on a file or website from a service like Hybrid Analysis, MetaDefender, Triage, or VirusTotal? You must include the actual link to it and not just a screenshot, or your post will be removed.

  • Be kind to each other and be professional in your conduct here. Personal attacks will not be tolerated and will be dealt with appropriately.

  • Do not ask for copies of hacking tools, malware, or suspicious files. If someone sends you a chat request or private message asking for a file or offering assistance based on what you posted here, report them to Reddit and notify the mods.

  • Do not post direct links to malicious, suspect, or potentially unsafe files or web sites.

  • Follow Reddiquette. This means correctly upvoting and downvoting posts, and reporting posts with dangerous or unsafe advice to the mods.

  • If you work for a vendor of security products, services, or in a related field, you must identify yourself as such, either in the post or with flair. Also, you may not steer conversations to your products or services, only respond to posts about them to clarify or defend.

  • No low-effort, off-topic, spam, or meme posts. This includes AI/ChatGPT/LLM-generated text, questions about password manager or VPNs, requests for assistance with non-security related software like autoclickers or MP3 downloaders, and so forth.

  • No requests for assistance with pirated software or media.

  • Posts may be removed and threads closed at any time based on the moderators' discretion

The complete list of rules for the subreddit can be found here. Read them before posting.

Questions, comments, feedback on this post? Just reply here. Thank you.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus Jun 04 '25

[MOD POST] New rules, staying safe, and an update from your Mod Team

6 Upvotes

[UPDATE #1 (20250604-0916 GMT): Made some small updates to grammar for readability. ^AG]

Hello,

It has been about a year since our last Mod Post, so we wanted to give you an update on things, plus provide a dedicated message thread for discussing the state of the r/antivirus subreddit and to answer any questions that you might have.

We will begin with the toughest subject first, that of politics in the subreddit:

A note about politics

r/antivirus is a technology-focused subreddit, with the interest being in helping people protect their computers from malicious software, securing them after a security incident, and so forth.

In June 2024, the US Government enacted a ban on Kaspersky Lab's software, taking effect in October of that year. This has generated a lot of discussion not just in this subreddit, but across Reddit and numerous social media platforms as well.

The moderation team has tried to keep the political discussions about this out of this subreddit and to remain neutral, allowing Kaspersky Lab's customers to ask and answer each other questions, provide assistance to each other, and generally have a way to share information, tips and tricks with each other.

However, we do have to draw a line when these turn into political discussions, though:

Requests for how to circumvent bans, petitions to governments, etc., are clearly outside the scope of what this subreddit is for and will be removed.

Moderating the subreddit is an all-volunteer job, and we sometimes miss things. If you come across any political messages we may have missed, use the subreddit's report function to notify us.

We are doing our best to keep this a place where people can get help with whatever security software they prefer, including Kaspersky Lab's software. However, we cannot allow discussions to devolve into arguments over politics, which are never going to provide any kind of satisfactory answer to the parties involved.

If the political discussions continue, the moderation team will have to look into ways to prevent them, even if it means doing things which we would prefer not to do.

Rules Updates

The rules of the r/antivirus subreddit have been updated:

Rule #7, which previously covered media download tools, has been updated to cover additional types of software.
To begin with, a more general prohibition to cover autoclickers (previously covered under Rule #8) and some other types of tools like aimbots and cheats. These types of tools often come from random sources and often require expert analysis to determine if they are safe. It can be difficult to determine if they are malicious figuring that out requires examining not just the tool, but whatever program it is attempting to modify, and what the intent is behind that modification.
Just because something was recommended in a Discord server with hundreds of members, a YouTube video with tens of thousands of views, or is seeded by several hundreds peers does not mean that it is safe to use: These are all inherently unsafe sources, and criminals will often exploit the belief that these are trusted sources to trick people into downloading and running malicious programs like information stealers and remote access trojans.

Rule #8 has been amended to remove autoclickers (etc.) since that is now covered under Rule #7.

Two new rules have been added:

Rule #9 covers bypassing core security features. Questions about how to disable security software, operating system updates, bypass security features and so forth are not allowed.

Rule #10 covers requesting assistance with obsolete software and hardware. This means discussions about how to secure computers running Windows XP, Windows 7, etc. are not allowed. There is no reason that devices running these obsolete operating systems should be connected to the internet and doing so exposes everyone to risk. Note that questions involving Windows 10 will continue to be allowed until at least October 2028, when paid-for Extended Security Updates for it end.

A bit more on the rules

The list of rules is not meant to be exhaustive in scope. It provides a general listing of common rules that are more specific to and more frequently required by the r/antivirus subreddit when needed beyond Reddit's general rules and guidelines.

Moderators can and will remove posts and ban redditors, either temporarily or permanently, who are disruptive to the subreddit entirely at their discretion and are not subject to any discussion. If a moderator chooses to discuss a rule violation with you, it is entirely as a courtesy on their part.

If you have had a post removed or been banned from the subreddit and do not receive a response in reply to any questions as to why, ask yourself if your behavior could be interpreted as brigading, spamming, trolling, using disrespectful or offensive language, or consistently providing incorrect, low-quality, poor, or even damaging information.

As always, the latest version of the rules can be found at https://old.reddit.com/r/antivirus/about/rules/. If you have questions about them, ask below.

Getting help fast

The moderation team is seeing an increasing trend where people ask for help while providing no information about what they need help with. This includes titles with 1-3 words like "Urgent! Help needed!", posts where the author shares a screenshot of *something* with no information about the operating system or antivirus involved, or is so small/blurry as to be unreadable, etc.

Everybody who participates regularly in this subreddit volunteers their time for free to do so. Provide them with enough information in your first post so they can start helping you right away without having to ask a lot of questions. This means your first post should contain things like:

  • title with enough information to attract an expert to read it
  • operating system and version
  • brand/name of antivirus software
  • name of URL, or file and its location
  • name of malware that was detected
  • what happened, exactly
  • steps you have taken to troubleshoot/diagnose so far, if any
  • relevant log file entries, if any

The more information you provide, the quicker you will get your problem solved.

As a reminder, starting multiple posts on the same topic will not get you a faster answer, and may result in in a ban.

The wiki + other Reddit resources

There is a lot of great information in the wiki about all the tools you can use, tips for using them, lists of antivirus vendors and how to contact them, and even a section on how to secure your computer.

We frequently update the wiki in response to questions being regularly asked in the subreddit, so you might want to check there first before posting.

Some of the questions we regularly see in the subreddit have nothing to do with computer viruses or malicious software at all, but instead are about scams, privacy-related questions, and so forth. Here are some subreddits that specialize in answering those types of questions:

New moderators?!

As the subreddit grows (we just passed 100K users), so does the need for additional moderators.

The moderation team has been looking at the folks who have been regularly posting here and consistently given good advice to build a list of candidates, and will be reaching out over the next few weeks to see if any are willing to volunteer their time and expertise in the subreddit. There will be more coming on that, but I did want to let everyone know that the process is already underway.


That pretty much covers everything we wanted to discuss, so we'll now await your questions, below.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus 1h ago

Grandparents Laptop

Thumbnail
gallery
Upvotes

Is this legit? I think this an attempt to hack/download more viruses. This is my grandparents laptop and they asked for help. They said that my father did put McAfee onto the compute. I’m not a tech savvy person, so i have no clue what I’m dealing with here.


r/antivirus 5h ago

Lumma Stealer in recycle bin

Post image
4 Upvotes

Hello, everyone. Windows Defender found Lumma stealer on my computer as seen in the picture. I changed all my passwords logged out everywhere and I am planning to reinstall. But I have some questions. Last time I downloaded something from the internet was on July 7th and it were mods for Minecraft from modrinth[.]com and forgecdn[.]net. I downloaded forge, collective, full brightness toggle, fusion connected glass, new glowing ores, 'connected glases.mcpack' (which is my biggest suspicion, but I never ran it, I deleted it) (all from forge) and vanilla-connected-glass from modrinth. All files were jars. On july 22nd defender detected Lumma. Why now?

Could this be a false positive?

If Lumma was really on my computer, what info does it steal and does it steal only if you are logged in or even if the account is added and you are logged out of it?


r/antivirus 1h ago

Help!!! I've really screwed up. Please read me.

Upvotes

It turns out that a while ago I downloaded some programs that unintentionally made some changes to my computer, which I ignored until now.

I ran a scan with Malwarebytes, which quarantined a bunch of files. I deleted them all (there were a lot) and continued. Then I ran a full in-depth scan with Kaspersky Virus Removal Tool, which found three malware items (a Trojan, an injector, and a cryptominer). I clicked "Neutralize everything" and continued, and it ran the blocking process, where I think Panda Dome neutralized or intercepted something. Then it restarted, ran again, and it seemed like nothing had changed.

I think the miner is still there. What can I do? Maybe the Trojan is gone, but this one is giving me trouble.


r/antivirus 1h ago

Edit me! Captcha Trojan but no special instructions?

Upvotes

So I somehow allowed a Trojan on my work computer, andI feel horrible about it. I was on Whitepages, clicked a captcha box, and my machine freaked out - beeping, a voice telling me my ip address was suspended, something about identity theft and fraud. Lots of scary popups. Hit escape, closed browser, called IT. But my question is, well…wtf? Everything I’ve seen says that the suspicious captchas will ask you to do stuff. This was just a checkbox. Any thoughts?


r/antivirus 23h ago

I woke up to my Discord hacked

Post image
57 Upvotes

So, this morning i woke up to multiple text from friends saying my discord account was hacked, i am currently on vacation and cannot access my computer, as far as i know it had been off for over a week. Same thing happed to my uncle, he got hacked too, i also found out my gmail that was linked to my discord was also on his computer, so i contacted my sister to reset my pc. Then she told me that it wouldn’t let her reset it at all, like it would pause mid reset and not happen, so i reset all my gmail passwords, i also activated 2FA on my gmails and reset passwords to most of the apps i use, i still have access to my discord, roblox steam, ect. I was never logged out of my discord or anything so i reset those passwords and switched to a gmail i knew was safe, can someone please help me with the resetting thing?? When i get back home what do i do? Do i try to reset it another way and re download windows? This has never happened and im pretty scared i dont want to fall victim to extortion


r/antivirus 2h ago

is this secure?

1 Upvotes

According to virustotal, it may be a pup, but im not sure what that means? Please help

https://www.virustotal.com/gui/file/41a41d903eb5a817599da2f39ad121957b0b7e6f44b710d929fc8876a5771141?nocache=1


r/antivirus 8h ago

help me potential malware not detected by antivirus ig

1 Upvotes

so i run full checks probably every a couple of days and my antivirus doesnt detect anything but theres cmd opening when i turn on the laptop and now after my subscribtion to the antivirus has ran out i get constant lag spikes everywhere

so is there a way to find it and delete it if thats something i have to be concerned about


r/antivirus 10h ago

Windows Defender finds Trojan in recycle bin

Post image
1 Upvotes

Hello everyone, tonight at 2am (as seen in the screenshot) windows defender detected a trojan on my computer. Recently I haven't downloaded anything except a replay file from my cs2 game personal data (.dem.bz2 zipped). I unzipped it got .dem file in csgo folder and then put the zipped file and an empty folder associated to that replay in the recycle bin which apparently made defender detect the virus 2 minutes after. I do not know how did that even happen and if this is defender giving a false positive but this type of detection is almost never a false positive. I had a false positive due to some rootcerts and Microsoft's error but this one doesn't look like it. What should I do (I changed all my credentials to important apps and services)?


r/antivirus 10h ago

How do i remove this without factory resetting

Thumbnail
gallery
1 Upvotes

I am scared i might mess in the process


r/antivirus 20h ago

MalwareBytes scan found a renpy trojan on my Logitech files. Is this a false positive?

4 Upvotes

Is there a legitimate GEP.exe on the Lgitech folder or is it a renpy virus?

Trojan.RenpyLoader, C:\USERS\ADMIN\APPDATA\LOCAL\LOGITECH\LOGITECH GAMING SOFTWARE\DISKCACHE\GEP.EXE, No Action By User, 22143, 1397879, 1.0.112382, , ame, , E961458D3D879AD7F1F19C99962045A7, B35F09B876EDB18695347860F79ACDDC68993F711274556156769476CD05AE8A


r/antivirus 13h ago

Dr.Web detects "Malicious container" in cc30wk.exe – false positive or real threat?

0 Upvotes

Hi everyone, I need a second opinion on a detection I got from Dr.Web.
Object: cc30wk.exe Threat: Malicious container Action: Cure, move to quarantine if incurable Path: C:\Program Files\WindowsApps\CLEVOCO.FnhotkeysandOSD_7.88.1.0_x64__6h6z29zh29qx0\FnKey\cc30wk.exe

I'm afraid that if I click Cure System, something might happen. My laptop has 16 GB of RAM, but for some reason I sometimes can't allocate 7 GB to a game. Although it might be because of Chrome, which might be open in the background at that moment, I don't really believe that Chrome can take up 9-10 GB of RAM.
I hope you can help me with this. Thanks in advance!


r/antivirus 1d ago

Got a virus from downloading a mod pack for minecraft

6 Upvotes

I secured my accounts as far as I know and haven't done anything with the computer since. It is Windows 10.

So I downloaded the mod pack from the guy on discord which was stupid, I know. I told him to give me the mod list and I'll download the mods but I did it anyway. So I've ran a deep scan with windows and malwarebytes and they both turn up nothing. Im now waiting as Microsoft safety scanner is going and has found 37 files.

I don't have another PC to make a boot drive from so I'm not sure if just factory reset is going to work. When I open most, but not all, normal exe files they run command prompt. When I open file location the file location opens to cmd in the system32 files.

Any help appreciated but also just wanted people to know.

Update: I've spent all day and to find what I believe is the culprit I had to disconnect from the internet and launch one of my shortcuts on my desktop so it runs the cmd, it stayed open and I could see the path it lead to where I found a folder that had replaced Discord

Essentially, inside was a couple files and a folder with more files, 2 .exe files were labelled "Discord" and "Update." Since deleting them the icon for the discord shortcut on my desktop broke. I assume I have removed the folder that it was trying to open things at but still unsure if there's anything like keyloggers but so far all my scans come back clean.


r/antivirus 14h ago

This keeps popping up on my screen and I’m afraid it’s a virus

Post image
0 Upvotes

It keeps coming back even after I click no, does anyone knows how to get rid of it? Also I can’t find it anywhere in the file explorer.


r/antivirus 16h ago

I put Logi Device Assistant exe in virustotal and got this

1 Upvotes

This exe just showed up on my computer yesterday unprompted, I disabled it on startup then today I put it in virustotal and well... is trapmine a good antivirus is this even true?

https://www.virustotal.com/gui/file/34570a4c5850ac7418288d0c645a823d2e6eb865356501a5c8069439fb0a4cfe/detection


r/antivirus 1d ago

My housemate sent this link, is it dodgy?

Post image
8 Upvotes

Is my housemate trying to ruin my day or is this legit?


r/antivirus 22h ago

is tree it safe?

Thumbnail virustotal.com
2 Upvotes

I was looking for software for tree generation/building and found tree it, I see a lot of people recommending it and nobody saying that it has any viruses included in it, but when I had checked virustotal it was flagged for having a threat?

(Sorry if this isn't the correct subreddit to ask for this stuff, I didn't see anywhere else for this type of stuff though)


r/antivirus 18h ago

I just checking my process explorer and it flagged itself as a trojan.

1 Upvotes

So I was just run my process explorer as administrator when process explorer itself was flagged as a trojan. I just wanted to know if this is a false positive or not since the search says that its a virus that pretends to be a legitimate software and I downloaded the process explorer in the real microsoft site.

This is where I downloaded my process explorer

https[:]//learn[.]microsoft[.]com/en-us/sysinternals/downloads/process-explorer

This is the virus total result:
https://www.virustotal.com/gui/file/8404b6cfad9d998b10d2df6073e1275b7744c0416982bdc5cb7ef5b74348333d/detection


r/antivirus 1d ago

Help. Someone accessed My Google acount from Vietnam.

5 Upvotes

On July 19th, Google alerted me that someone had logged out of my secondary Gmail account from Windows at 7 AM in Vietnam. Later, at 2 PM, someone logged out of my primary account. I have a desktop PC at home that my father and I use, and he had the same problem. We installed antivirus software on the computer and changed our Google passwords. Is there anything else I should do?


r/antivirus 20h ago

best general anti virus? for windows 10, 11 and linux

1 Upvotes

Just looking for a recommended general anti virus for a windows 10 computer my current workhorse. At some point im planning on getting two other laptops one for general fun and the other just for business like payments and stuff. Any recommendation for windows 10 right now is highly appreciated. Thanks yall


r/antivirus 1d ago

Need help completely removing Vipre Antivirus from a Personal Windows PC

2 Upvotes

Hello all!

This is my first post here and hoping one of you can help me.

A week or so ago we had a Windows PC in our house start producing BSODs. Something like System Service exception and a few others. All of them were referencing FLTMGR.SYS and it is my understanding that this file heavily interacts with third party anti virus.

We currently only have one antivirus on the system which is Vipre. Despite it having a lifetime license I have a hunch it is our culprit.

Is there a tool I should use to completely remove Vipre, it's registry entries, and it's drivers?


r/antivirus 1d ago

Could this be caused by a virus?

Post image
7 Upvotes

A few days ago I used my phone as a hotspot for a pc. Supposedly, this pc is infected by a virus. Yesterday I got a notif saying that my sd card is corrupted and now I can't open the apps I moved on it anymore. The logo disappeared, and if I try to click on them it says "app not installed". Half of my apps don't work anymore. Some of them even seem to have lost their names (ex. org.cocos2dx something is the name for some app).

Could this be caused by a malware? What can/should I do, and what are the risks?


r/antivirus 1d ago

Accidentally downloaded a trojan and got rid of it am i fine?

6 Upvotes

Hi i was trying to download a visual novel off a sketchy site (first time ever doing this idk why i did so this time but whatever) and got a trojan it was in my laptop for about 10 ish minutes before i was able to get rid of it. its not in my lapptop anymore and windows defender offline scan came in clean, im doing a full scan now if this comes back clean am i in the clear? if so what precautions should i take to keep all my stuff safe and if im not in the clear what should i do?


r/antivirus 1d ago

pop ups persisted until i logged out of microsoft edge on my windows 11

1 Upvotes

ok so my laptop caught a virus so i did whatever i could to “delete” the virus using built in window tools like the safe mode and mrt. i ran a scan it said there was no malicious software detected but when i got out of safe mode the weird popups started again but it stopped after i signed out of microsoft edge so my question is is there really no malicious software??? do i have to change all my passwords etc???