/r/antivirus

Photograph via snooOG

For all of your Antivirus needs.

Welcome to r/Antivirus

Everyone:
1. Please take a moment to familiarize yourself with our [rules].
2. Check our regularly-updated [wiki] before posting. Last major update:

2025-JAN-28


The top rules are as follows:

  • 🆕This is a subreddit where people come for help with computer viruses and malicious software. Memes, jokes, and discussions involving politics are strongly discouraged.

  • Asking a question about a VirusTotal or Hybrid Analysis report? Include a link to it, not just a screenshot, or your post may be removed.

  • Do not post links to websites offering commissions, affiliate links, or sponsored installs.

  • Do not intentionally link to malicious sites (links to VirusTotal and Hybrid Analysis are fine). If you must post a link, please 'de-fang' it by breaking the URL up with brackets like so: https[:]//www[.]example[.]com

  • Failure to respect the rules and each other may result in a permanent ban.

  • If you see any spam or abusive messages, please use the report function to report it to the mods.

The complete list of rules can be found [here].

(Yes, that is a clickable link.)


Regular Users:
Welcome! You can get all of the help you need here, along with advice on removing any kind of malicious or unwanted software and choosing the right antivirus/internet security/endpoint protection for you!


Security Vendors:
You are more than welcome here, as long as you respect Reddit's Self Promotion rules, and are not pushing your product unduly. Do not abuse your welcome. Posting about Sales, Beta's, that sort of thing is allowed, but don't spam it. You are expected to participate in discussions where you can lend your expertise. Click here send a message to the r/antivirus mods so we can set you up with your company flair.


👉We Have a Wiki! (Click Here)

Our regularly-updated wiki contains all sorts of useful information, including links to reputable developers of antivirus/antimalware/internet security/endpoint protection/endpoint detection and response/{insert marketing-term-du-jour here} programs, information about specialized scanning and cleaning tools, information about security tests and testers, practical information on securing your devices and a glossary.

PLEASE CHECK THE WIKI FOR BASIC HELP + TROUBLESHOOTING INFO BEFORE POSTING.

/r/antivirus

95,762 Subscribers

1

Help I need to know if this is safe

1 Comment
2025/02/01
05:23 UTC

1

Bitdefender - Free? W/ Firewall? Or Free with 3rd Party Firewall???

So I'm looking at Bitdefender as my AV of choice.

I do game and I install mods and such from time to time and do some 3D modeling (but my models come from big stores typically). I'm saying that to say that I'd like a decent AV and a firewall.

I've been scrolling through the "search" results from this reddit looking at firewalls and I have some options:

Bitdefender Free + Simplewall

Bitdefender AV Plus + Simplewall

Bitdefender AV Plus + the Bitdefender Firewall

Some other combination I am not yet aware of???

Thanks for any input!

3 Comments
2025/02/01
03:18 UTC

1

Chrome Help

Apologies if this is the wrong way to go about things. I was just on Chrome, playing typeracer. I didn't click on anything but a new tab opened to an evident virus site, and the site gave me the Chrome notification "scan in progress". (One of the pop up ones that flash at the top of the website, if that makes sense.) I didn't click on anything on the site, immediately closed it, checked for any browser extensions (there were none), did a Microsoft Defender scan which had no new threats, and am now doing a full scan.

Is there anything else I should do? Should I be worried? Thank you in advance to anybody who reads or comments, you're a lifesaver!!

2 Comments
2025/02/01
01:06 UTC

2

What should I do next? I deleted the file from the system and looked at the location but the affected item no longer exists?

I ran a full scan today and this file was found by Windows Security what should I do next? I am not sure how long it could have been on my computer.

6 Comments
2025/02/01
00:36 UTC

1

I just got infected with a rootkit.

Hello guys, i just got infected with a rootkit and a btc miner. i used hitman to delete some malicious files, resetted and reinstalled windows and flashed my bios. is there ANY chance it might still be on my pc? I heard they could still be on my RAM or my GPU.

9 Comments
2025/01/31
23:33 UTC

1

Looking for feedback on our open-source YARA-X malware scanner

Hey antivirus community,

For the past couple of years, I’ve been working on an open-source malware scanner that integrates with YARA-X (the new system from VirusTotal). It started as a personal project, but now we’ve grown into a small team, and we’d love to get feedback from people who are into security and malware analysis.

The scanner is completely free, open-source, and cross-platform, with a focus on being lightweight and using minimal system resources. We have a stable release, but we're always looking for ways to improve—so if you have any feature ideas, suggestions, or just general thoughts, we’d really appreciate it!

You can check it out here: https://github.com/Raspirus/raspirus

Looking forward to hearing what you think!

0 Comments
2025/01/31
20:10 UTC

1

Installed an app which turned out to have adware on my BLU G33 and now the adware reappears after a factory reset and I'm getting strange notifications.

My BLU G33 has been infected by adware and still is ever since I installed an app that has turned out to be infected with a variant of Youmi adware. I did a factory reset 3 times and it's still appearing also I'm getting strange notifications. Whenever I click the settings on the notification I get "This app wasn't found in the list of installed apps".

1 Comment
2025/01/31
20:01 UTC

1

How do I add exclusion file without the manage settings option?

I need to make a file exclusion for the antivirus but all the tutorials I seen online show that you have to click on the manage settings option then add an exclusion but for me there is no manage settings option and I really need to add the exclusion

0 Comments
2025/01/31
19:31 UTC

3

What is this? I downloaded nothing.

2 Comments
2025/01/31
19:12 UTC

1

HitmanPro lists Steam as a Trojan

Here is the info, there are some weird things like it mentions listening for inbound network connections which I thought Steam itself wouldn't do, and the fact that this exe was modified about 3 days ago but there has been no Steam update?

Name steam.exe

Location C:\Program Files (x86)\Steam

Size 4.2 MB

Time 3.7 days ago (2025-01-28 00:56:46)

Authenticode Valid

Entropy 6.9

Product Steam

Publisher Valve Corporation

Description Steam

Version 09.48.97.91

Copyright Copyright (C) 2021 Valve Corporation

RSA Key Size 3072

Parent Name C:\Windows\explorer.exe

LanguageID 1033

SHA-256 BE92837C03BCFE27E7B455EA3CE172B41115BD4A1B40A6C150EABD22B6904156

Detection Names

HitmanPro Win32/Backdoor.Behavior

Scoring (119.0)

--Red Text--

One or more antivirus vendors have indicated that the file is malicious.

This file's reboot survivability is vigorously protected. This is typical to malware.

--Grey Text--

This program is actively listening for inbound network connections.

Uses the Windows Registry to run each time the user logs on.

Program starts automatically without user intervention.

Time indicates that the file appeared recently on this computer.

The file is in use by one or more active processes.

--Green Text--

Program is code signed with a valid Authenticode certificate.

The file appears to be part of an installation package or setup program. This is typical for most programs.

Startup

HKU\S-1-5-21-REDACTED-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Steam

5 Comments
2025/01/31
19:06 UTC

2

Is Upscaly Safe? VirusTotal Detected a Suspicious File—Need Confirmation

I downloaded Upscaly, an image enhancement software, from their official website. However, when I uploaded the .exe file to VirusTotal for a security check, one antivirus detected something suspicious.

Can someone confirm whether it's truly safe to install, or if there's anything I should be concerned about?

Download Website:
https://upscayl.org/download

GitHub Repository:
https://github.com/upscayl/upscayl

VirusTotal Scan Result: https://www.virustotal.com/gui/file/5dd7f58abafae2907fede489324a074cb6959a93c5714f3d0609650ab942ff3c

1 Comment
2025/01/31
17:23 UTC

0

Which one to choose ? Bitdefender or Kaspersky ?

Yesterday I have tried Bitdefender total security and today Kaspersky Premium (both trial). I did download a malicious file in a zip. Bitdefender instantly caught it, even after whitelisting it I tried to run it, it still blocked the EXE and showed me a roadmap what are things it has gone through until it was blocked.
now today same file with Kaspersky, after extracting it no warnings, even I ran it.
I have gone through a lot of posts here, almost everyone recommend Both. I'm not from US, so not worried about the ban going on.
Kaspersky found 7z.exe vulnerability. which was a good thing to know.
let me know if I'm missing something.

12 Comments
2025/01/31
16:24 UTC

0

I'm looking at paying for an anti virus for my pc and was wondering which is better between Mcafee and AVG

23 Comments
2025/01/31
15:20 UTC

1

Downloaded a suspicious zip file from a fake anydesk website

I downloaded a zip file from a suspicisious website. I didn't open or extract it, I had no interaction with the file at all. I only ran a microsoft defender check on the file which told me that there are no threats. Then I just deleted the file and emptied the bin. My question is, am I safe? Are there any more steps I have to take to ensure my laptop's safety?

1 Comment
2025/01/31
13:42 UTC

1

My PC keeps downloading xlsx files without any input on my part

Hello.
This morning my PC started downloading xlsx files. They are of various kind: "Employee Salary List", something related to a Purdue University (I never attended to it, I am from Italy), etc...I tried to scan my pc with Windows Defender (I have Windows 10) and Malwarebytes but nothing strange came up. I also tried to scan the singles files but they seem ok. I also tried to disable automatic download from my browser, but to no avail, another file was downloaded.

I a bit worried and I am going to carry my PC to a local shop for assistance and support.

5 Comments
2025/01/31
12:24 UTC

1

yall is this a false positive? i really want to play this game from my childhood but im not sure if its safe. i got the link and i downloaded the file from mediafire.

hey so i wanted to know if this is actually a virus or a false positive. beacuse i scanned it in virustotal and MaxSecure flagged it as Trojan Malware 300983 susgen. all the others didnt flag it as anything and it went through. i didnt execute it yet but i just want to check if this is safe. heres the virustotal analysis link: https://www.virustotal.com/gui/file/e6357b29c8d3c068541b94c42f2ead3ce78952522ffafa47aea961b47c4c35b0 thanks.

5 Comments
2025/01/31
11:47 UTC

2

Downloaded old game. Flagged by a single vendor when ran through VirusTotal. False positive?

I downloaded an old discontinued game (it has ads) from a now defunct company and ran it through VirusTotal (link: https://www.virustotal.com/gui/file/139161e6f70b353c91884561f842e95c156d5c4cff388c9acf3fc438b8bc76c7/summary). I only got a single hit from Kingsoft of 'Win32.Troj.CharBoost.a', but not from any of the other security vendors. Is this a false positive?

3 Comments
2025/01/31
11:11 UTC

2

What’s the best antivirus/edr for an university?

Hey guys, we are currently thinking about purchasing either Defender for Endpoint or BitDefender GravityZone Enterprise, but we really need to get an opinion on what might be the best/good on budget antivirus/edr.

5 Comments
2025/01/31
07:06 UTC

1

Question about Roblox

My pc says “This app has been blocked by your administrator” when I try to open Roblox and Microsoft defender keeps on blocking it and Roblox wants access to my files account/usser files. I allowed access to it and it keeps popping up and I fixed it by running Roblox as administrator but is this some type of virus???

0 Comments
2025/01/31
04:39 UTC

0

can’t download dr web, any help?

3 Comments
2025/01/31
03:54 UTC

1

Is this a false positive or am I cooked?

Some NVidia file was quarantined as a "Poly.Worm.Kido". Its only being flagged by "MaxSecure" and it's within the NVidia app files. From what I've read "MaxSecure" is "Permanently Closed" but they still have an active website. Should I be scorching earth right now or am right in suspecting this as a false positive?

https://www.virustotal.com/gui/file/241a1992b956f13aeb2869214b4766216e9f70466bf2efab794ce7089349140a/detection

3 Comments
2025/01/31
03:08 UTC

3

I am looking for an Antivirus that also has vpn for both Windows and Android. Any suggestions?

4 Comments
2025/01/31
01:48 UTC

10

Does anyone knows what this is?

Got this bowsing websites like letterboxd , my Guess is something caused by the ads or a browser hijack i have no clue, did a antivirus search but didint find anyting.

3 Comments
2025/01/31
00:16 UTC

1

I need help with choosing an anti-virus

Windows security updates stop on October 2025 and im looking for an anti-virus for my pc. I heard Kaspersky has a good plan with a vpn(vpn is not necessary), but I also heard they had some controversy in the past. Can somebody advise me which one should i consider buying.

16 Comments
2025/01/31
00:08 UTC

1

Expiro help

So I have an external hard drive that I recently found at it has expiro[.]npd and expiro[.]cu infecting all my .exe and .dll archives I scanned it with Nod32 (the antivirus I use) and it putted all the infected files on quarantine. Is there any way I can desinfect the affected files and wipe out the virus saving as much info as possible (formating the would be the last and more deperate option). I already checked the rest of storages drives and are clean. Pd: Sorry for bad english

3 Comments
2025/01/30
23:48 UTC

1

Malwarebytes Add Blank Allow List Domain?

Hello I have a domain I need to hope up but Malwarebytes (MB) is not allowing me to go through when allow list is okay. I'm trying to put a blanking allow list under the domain such as HTTP://*.1234.com but it doesn't seem to be working, does anybody know the correct setup?

0 Comments
2025/01/30
22:37 UTC

2

Escort scam - how to check iPad for malware?

Hi, long story short, I browsed a few escort websites yesterday and messaged a few escorts. Received threatening texts and phone calls today saying they know my name and family. I used a google voice number, but I’m wondering if i clicked on some malware? I think there was a recaptcha on one of the sites and I read on this sub here that there’s a recaptcha phishing thing out there. So maybe my iPad is compromised? How can i verify that it’s clean? I’m so nervous. I don’t know much about tech. Also, they texted a video but I’m afraid to click on it but i need to know that it doesnt contain anything private about me. How can i view it without compromising my device and/or email (i deleted the google voice text, but GV forward the texts to my email so i can still view it there)?

3 Comments
2025/01/30
21:36 UTC

1

Is this a false positive? [Virus Total]

So i wanted to download the free ver of Malware bytes & decided to just check some of the stuff inside it on virus total. I got a 'Trojan.Shlem.ui' from Jiangmin and wanted to know if its a false positive or if i should just not run this.
link: https://www.virustotal.com/gui/file/81a28988d59a8e75b771456f61aa3029f334f2a492da70f53bd93403122e2951

2 Comments
2025/01/30
21:18 UTC

Back To Top