/r/antivirus

Photograph via snooOG

For all of your Antivirus needs.

Welcome to r/Antivirus

Everyone:
1. Please take a moment to familiarize yourself with our [rules].
2. Check our regularly-updated [wiki] before posting. Last major update: 2024-OCT-25

The top rules are as follows:

  • 🆕This is a subreddit where people come for help with computer viruses and malicious software. Memes, jokes, and discussions involving politics are strongly discouraged.

  • Asking a question about a VirusTotal or Hybrid Analysis report? Include a link to it, not just a screenshot, or your post may be removed.

  • Do not post links to websites offering commissions, affiliate links, or sponsored installs.

  • Do not intentionally link to malicious sites (links to VirusTotal and Hybrid Analysis are fine). If you must post a link, please 'de-fang' it by breaking the URL up with brackets like so: https[:]//www[.]example[.]com

  • Failure to respect the rules and each other may result in a permanent ban.

  • If you see any spam or abusive messages, please use the report function to report it to the mods.

The complete list of rules can be found [here].

(Yes, that is a clickable link.)


Regular Users:
Welcome! You can get all of the help you need here, along with advice on removing any kind of malicious or unwanted software and choosing the right antivirus/internet security/endpoint protection for you!


Security Vendors:
You are more than welcome here, as long as you respect Reddit's Self Promotion rules, and are not pushing your product unduly. Do not abuse your welcome. Posting about Sales, Beta's, that sort of thing is allowed, but don't spam it. You are expected to participate in discussions where you can lend your expertise. Click here send a message to the r/antivirus mods so we can set you up with your company flair.


👉We Have a Wiki! (Click Here)

Our regularly-updated wiki contains all sorts of useful information, including links to reputable developers of antivirus/antimalware/internet security/endpoint protection/endpoint detection and response/{insert marketing-term-du-jour here} programs, information about specialized scanning and cleaning tools, information about security tests and testers, practical information on securing your devices and a glossary.

PLEASE CHECK THE WIKI FOR BASIC HELP + TROUBLESHOOTING INFO BEFORE POSTING.

/r/antivirus

86,923 Subscribers

1

Are these infected archives or just damaged?

https://preview.redd.it/4qizjv9wpzzd1.png?width=1546&format=png&auto=webp&s=138a8796582e73897b5cb8db79b5abadd864911e

https://preview.redd.it/b8eswx9wpzzd1.png?width=1538&format=png&auto=webp&s=d003ac8638b619d1f72457e71cd33463745dcdd5

I ran a Kaspersky scan after a while (not from the USA) and it came up with these 4, labeled as "events" instead of "objects".

Two says theyre from Edge update and 2 are from Kaspersky itself. Would that mean these are files that got damaged or are these infected?

0 Comments
2024/11/10
03:08 UTC

3

Windows Defender Keeps Detecting 'Predator ab!mtb' Virus, Then Immediately Clears Itself—Is This a Real Threat or a False Alarm?

Recently, Windows Defender started spamming me with alerts about a virus called "Predator ab!mtb." Each alert would pop up, but then disappear just a second later. Worried that it might be hiding itself, I decided to run a full system scan with Kaspersky Standard. Surprisingly, Kaspersky found nothing related to Predator. Was this just a false alarm from Defender, or could the virus still be lurking in some way? Has anyone else experienced something similar or knows what's going on?

3 Comments
2024/11/10
00:21 UTC

2

My phone randonly opened facebook

So i was scrolling through Reddit and i saw i got the sharing badge progress twice. I went to close the app in the overview that lets you switch between apps (i have an android, so its three stripes) and suddenly facebook was open. What do i do?

0 Comments
2024/11/09
23:01 UTC

2

I might have f'd up. help?

I got a pop up website which i should have known better than to double check but it made me copy and paste something into the windows run panel. i feel really stupid for not checking but I'm wondering what i should do now. I could copy what was ran into the post but im not sure if im allowed as it might count towards linking to something malicious. id be forever grateful if someone could help me out here!!!!

4 Comments
2024/11/09
22:54 UTC

2

Kaspersky flags Insta360 Studio legit .exe as TrojanWin32Gen: anyone else experience this?

Hi, today I downloaded the Insta360 Studio software directly from the official Insta360 website.

The software itself works fine, and my PC is running smoothly. However, after about 10-15 minutes of use, Kaspersky flagged the insta360-thumbnail-service[.]exe file as exhibiting "suspicious activity" and identified it as a potential Trojan (Generic).

Here the report from Kaspersky: https://opentip.kaspersky.com/2d13d0d0c513061bf8a769fe404f1b4cd9f3b3f928fda21aebf5670bc3b57cf5/results

I completely forgot to run it through VirusTotal, but I believe this is likely more a "false positive" than a "generic one". As a precaution (since the software wasn’t essential for my needs), I decided to uninstall it and run Kaspersky’s "Disinfect and Restart" procedure. Afterward, my PC returned to normal (as it has always been), and a subsequent scan showed no issues.

I tried searching for similar cases, but I didn't find anything.
I just wanted to check if anyone else has experienced this and get your thoughts on the situation. Thank you!

2 Comments
2024/11/09
22:11 UTC

2

Eset brave

I have brave since a long time and just now While i Was playing eset marked it as malware (Win64/Agent_AGen.CLQ Trojan) Anyone knows why?

4 Comments
2024/11/09
20:46 UTC

2

I got infected and am asking for guidance.

So I most likely downloaded something which turned out to be a piece of Malware. I think it’s pretty new because neither Defender nor Malware Bytes can detect it. After some basic investigation with sysinternals and browsing through my drive. I believe it is this:

https://any.run/report/cacc573a567a5b3dd379e8d9cbac8e5b4f325f77d8c2814bc3b678bb084d71dc/7b90dd8a-e27a-4a32-a73d-bc6579b83228

They’ve already stolen session tokens for my steam and discord and proceeded to sell my items as well as message a scam link to all my friends. I’ve changed passwords everywhere I can think of but my questions are as follows:

Is there a way for me to identify if this is a worm or if it is capable of spreading to let’s say a usb drive? I plan on recovering a few important files before a full format but I’m scared it will spread to the usb.

Does someone have any tips on tracking down the root of this malware? I’m a newbie but this is very interesting and before formatting my drive I’d like to investigate this malware a bit. I’ve already disconnected my Ethernet cable so that there is no network connection.

Thanks!

3 Comments
2024/11/09
19:46 UTC

16

Kaspersky is Flagging Cheat Engine and Chrome Cache Files, Is This Normal?

23 Comments
2024/11/09
19:23 UTC

0

is twitter malicious?

4 Comments
2024/11/09
16:59 UTC

2

Can someone help me analyzing this file

This file is supposably intended to create a ruler in your screen and keep it there. Can someone in the community help me checking if it has anything malicious (I know there are tons of alerts but I just wanted to make sure they are not false alerts) - https://www.virustotal.com/gui/file/5f8d717b6cb76356855b85a36e9f97db238db1d85802244c28d90674636b72bd/behavior

2 Comments
2024/11/09
16:53 UTC

0

Is this Bitdefender Total Security deal legitimate?

I’m considering buying Bitdefender Total Security for 1 device with a 3-year subscription. I found it on Amazon for ₹599 (approximately $7). This price seems unusually low, especially compared to the official Bitdefender India website, where it's much higher. Is this product legitimate, and has anyone else had experience with deals like this? Product Link: https://amzn.in/d/cLLKYFH

17 Comments
2024/11/09
14:45 UTC

2

is this file scanned in virustotal a false positive?https://www.virustotal.com/gui/file/4ba7d2f6ff6e53d15536fe92abc5858e59eecb45a160949cbe6b485e36b65fd3/detection

Hello, I was scanning a file to be able to play batman arkham origins online, managing your own host, everything comes out clean except this file, could it be dangerous or is it just a false positive?

1 Comment
2024/11/09
13:16 UTC

2

Kasperski (United Kingdom)

My 24month sub is up next month (was renewed from 3 years before).

I have it installed across 5 devices with kid supervision, password db etc.

I don't specifically want to change to another provider mainly the hassle that comes with it migrating all apps, settings etc!

I've read Kasperski are agnostic, but being Russian also the flip side and red flags.

Any reason why as a UK user I should not renew?

Thanks!

10 Comments
2024/11/09
11:56 UTC

3

Microsoft Safety Scanner Weird Behaviour

So I scanned my pc with it and internet was disconnected during the scan. At about 90% of scan progess, it was showing 6 infected files. Then the scan got stuck on some .dat file for about 10 minutes. Then the scan finished abruptly and it showed that there were no virus, spyware ,etc. My question is what about the 6 infected files it showed earlier during the scan. There was no option of checking a report of the scan so I can't even find which were those 6 files? Is this normal or should I be worried?

Btw I had already scanned the system with Malwarebytes, HitmanPro and even used rkill and I have Kaspersky premium on top of everything. And none of these showed anything.

6 Comments
2024/11/09
09:13 UTC

10

found this app on my apps list but when I search it on my phone it doesn't show up, I don't even remember downloading it but from what I've seen there are no dictionary apps like this. I even ran malwarebytes but it says Im good. Is this malware?

18 Comments
2024/11/09
08:55 UTC

4

Android 9 McAfee pop up, scan needed

I got this on my screen, there is no way I'm interacting with it but how did it get there in the first place? Looking in Google play store and nothing relevant seems to be installed.

May or may not be relevant but I reset the device a few weeks ago so I could pass to my son.

https://preview.redd.it/2zm4bxxb4uzd1.jpg?width=720&format=pjpg&auto=webp&s=19a48883291cf6ce8c115ec2e2e7ac79d7b199b5

3 Comments
2024/11/09
08:17 UTC

33

Why is my registry connected to this computer?

Installed AMD chipset drivers and now this has appeared as a connection on my Registry

22 Comments
2024/11/09
07:29 UTC

1

Format related question

Can Sality virus (yep the old school one) survive a format ?
like my external drive was infected so i formatted it . is it safe to use now ?

1 Comment
2024/11/09
06:08 UTC

6

is norton good enough for basic PC use?

Hi all, as per title, want to know if norton is good enough for basic use. aware that there may be better antivirus but i am able to get up 70-90% cashback with norton so it would quite definitely be the cheapest option.
Would also like to know more about the add ons and if they are any good to be getting, if its worth getting.

17 Comments
2024/11/09
04:10 UTC

6

I do hitmanpro scans regularly and they never found anything, but recently I deleted one small file, ran a scan shortly after and saw this. False positive or I'm cooked?

I didn't download anything or visit any suspicious site between my previous scan, which didn't find anything, and this one. Only deleted one file which wasn't named like this and wasn't even an .exe file

9 Comments
2024/11/09
03:00 UTC

3

If I Install a RAT on my virtual phone will it infect my windows 10 laptop?

5 Comments
2024/11/09
02:23 UTC

1

Trying to identify what nllVmm.sys is - causing BSOD's

Hey all. I *think* this is something to do with Norton, but does anyone know for sure? It was the cause of a recent BSOD and the Minidump report shows this as so, but I can't pinpoint it. The report says 'Product Name: Antivirus' and when I search through Task Manager, 'nll' comes up as Norton, but there doesn't appear to be any actual process called nllVmm.sys.

Any help is appreciated!

0 Comments
2024/11/09
00:48 UTC

10

is this something to be worried about?

12 Comments
2024/11/08
23:54 UTC

1

Need help about multiple accounts on PC

Hello!

As following the guidelines for a "safer computing", I, after a bit of time, have finally set up a secondary account on my Windows computer for day-to-day use, without the admin privileges.

Now, for some questions:

• I have created this secondary account as "local" and have not yet connected it to a Microsoft account, but the admin profile is connected to one. So, if I connect this new user to the same MS account, does it create any interference? And let's say a malicious program or code can get through the defenses, and into the computer - Even if this new local acc does not have admin privileges, if it's connected to the same MS acc as the admin, can this malware mess with the other user?

1 Comment
2024/11/08
23:33 UTC

1

Have the green check marks disappeared from chrome for any other norton users?

Usually they come back after a few days but its been a while now. Will they eventually come back by themselves? They were very handy - i could see the health of any website before i clicked on the link.

0 Comments
2024/11/08
23:12 UTC

1

I got 2 trojan labels from Jiangmin and VBA32. Are these false positives or true?

6 Comments
2024/11/08
22:48 UTC

3

Is it normal for the free version of bitdefender antivirus to open a command prompt window while installing?

Was just wondering since I am new to instlling antiviruses on my own

3 Comments
2024/11/08
22:02 UTC

12

Is this a trojan/virus? I heard theres a trojan that pretends to be explorer.exe

11 Comments
2024/11/08
21:38 UTC

0

Que tal a todos, estaba a punto de descargar este driver para una impresora térmica pero escaneando en VIRUSTOTAL me aparece que tiene un virus

https : //drive . usercont ent . google .com/download?id=1Z2qZRpr5nKbAVvlqr94uOrve9U5ZIfoJ&export =download&authuser=0 este es driver

https://preview.redd.it/qy0m6bdegqzd1.png?width=1892&format=png&auto=webp&s=39265422440b70651b6c35704350467596e7c619

y aquí el analisís https://www.virustotal.com/gui/file/6d7844eecbddcc15b5f6b0e8ca7ff07f8873f1467d768477230158f2f2e515ed

2 Comments
2024/11/08
19:55 UTC

6

I've recently been compromised, and I can't root it out

I have everything 2FA app secured and always had, I'm moderately tech savvy. Yet recently my Steam, Instagram and Facebook account all got infected by bot activity. When I'd check login locations, Facebook and Instagram are completely clean, yet when I login and deauthorize all devices and change password, it stopped. Instagram just started following hundreds of accounts, and I just deleted it.

My suspicions were my email, or remote access to my PC or Phone. I've checked all of them and contacted support. Email is clean, I've tried 5 different Anti-virus software recommended often on this subreddit, on both my PC and my Phone including rootkit scans, and apart from some Potentially Unwanted Programs on PC that I've removed, nothing out of the ordinary. And today, it happened again on my Facebook, a bot sent mass messaging to Market sellers to scam them.

Any recommendations before I nuke everything and factory reset both my PC and my phone?

5 Comments
2024/11/08
19:41 UTC

Back To Top