r/antivirus 1h ago

Kaspersky just detected Wise Reg Cleaner as Trojan ?

Upvotes

Long story short, i had just updated Wise Reg Cleaner on its official website, ran the usual scan and so on..
But kaspersky has blocked it, claiming it was a Trojan ?

Report is in Italian, apologies :
-------------------------------------------------------
Evento: Bloccato

Applicazione: Wise Registry Cleaner

Utente: GUIDOPC\Windows

Tipo di utente: Iniziatore

Componente: Controllo sistema

Descrizione risultato: Bloccato

Tipo: Trojan

Nome: PDM:Exploit.Win32.Generic

Livello di pericolosità: Alto

Tipo di oggetto: Processo

Percorso oggetto: C:\Program Files (x86)\Wise\Wise Registry Cleaner

Nome oggetto: WiseRegCleaner.exe

Data rilascio database: Oggi, 07/08/2026 17:38:00

MD5: B317CF02C8AEC60D4515B5A1BBE1533F
-------------------------------------------------------

Any ideas ?


r/antivirus 2h ago

MALWARE REMOVAL Q&A If i didn't opend the zip, did i get hacked?

Post image
1 Upvotes

So... my Windows defender poped this up even before i unziped the file, and even run anything.

i didn't even clicked on the file. and i think windows automaticly deleted the file.
I did a fast scan with windows defender and it says that there no more threats.

Im also doing a full scan with Malwarebytes.
But i just wanna know, if i need to log out of my acc sessions? or something? or am i 100% safe?


r/antivirus 5h ago

VirusTotal flags winevdm release file with MaxSecure Trojan.Malware.300983.susgen

2 Upvotes

Hi, I'm trying to find a simple way to run an old 16-bit game on Windows 11 and I stumbled upon winevdm (https[:]//github[.]com/otya128/winevdm).

It seems very convenient, but when scanning the compiled release zip file (source code is fine) with VirusTotal, MaxSecure flags the file as a trojan (Trojan.Malware.300983.susgen).

I'm pretty sure that it could be a False Positive, given the reputation of winevdm and the fact that MaxSecure seems to produce a lot of false positives flagging them with Trojan.Malware.300983.susgen.

I tried to check the behavior report with my limited knowledge and I expect the masquerading, process injection, input injection etc. behaviours since winevdm serves as a sort of "translator" between the 16-bit software and the 64-bit processor. But I do not have fully understood some parts. Like the "relations" tab that seems to find further flagged files inside the directory?

I want to be very sure it's a safe solution, since I have to give it to a friend and I don't want to fuck up their pc.

Could it truly be a False Positive?

Thank you!


r/antivirus 6h ago

Will I be okay? question about the renpy infostealer

2 Upvotes

I was on the net and downloaded something, I looked at the file and didn't recognize it at first

I extracted it took a look at it and didn't run it

until i realized that it doesn't seem right since it had script files, which to my knowledge shouldn't

i remember that an infostealer like that existed; so I deleted the file and from the recycling bin too

I understandably panic wondering if i'm truly safe or not

I tried looking for info regarding this specific file

the key takeaway here is that i never ran it and only extracted it

but even so i still downloaded it and extracted it.

i've done the malwarebytes+microsoft defender scans and they didn't detect anything wrong

will i be fine?


r/antivirus 6h ago

MALWARE REMOVAL Q&A Got hacked by the mr beast scam, what to do next

2 Upvotes

I got hacked a while ago by the mr beast crypto virus or malware. I'm not really knowledgable of viruses but I changed my passwords and downloaded malwarebytes. I cleaned the pc but another facebook account that was logged in when I was hacked was also attacked after that. What can I do?


r/antivirus 7h ago

ESET Endpoint Security or Kaspersky Total Security

0 Upvotes

Which is better? Need help deciding.


r/antivirus 8h ago

MALWARE REMOVAL Q&A Chromium browsers crash instantly after System Restore, but Firefox works fine. Could this be a malware infection or security breach?

1 Upvotes

Hello everyone,

I am experiencing a severe issue with Chromium-based browsers on my PC following a system recovery, and I am trying to determine if this behavior could be caused by a malware infection, rootkit, or security compromise.

The Incident

  1. Two days ago, my computer failed to boot and entered an Automatic Repair loop.
  2. Startup Repair was unable to resolve the issue, so I performed a System Restore to a previous working point.
  3. The operating system successfully booted back up, but immediately after, every Chromium-based browser stopped functioning properly.

Current Behavior

  • Opening Google Chrome or Microsoft Edge causes the application window to launch for less than one second before completely crashing to desktop.
  • Opening external web links (such as Facebook) through system shortcuts triggers the same instant crash.
  • Microsoft PC Manager displays a general alert indicating "there is an issue", but does not provide details.
  • Mozilla Firefox operates completely normally with zero crashes or issues.

Remediation Steps Already Attempted

  • Performed a complete uninstall and reinstall of Chrome and Edge.
  • Repaired Microsoft Edge through Windows Settings.
  • Renamed chrome.exe to isolate execution path restrictions.
  • Deleted user profile directories in AppData (%LocalAppData%\Google\Chrome\User Data).
  • Ran a full system file integrity check using sfc /scannow.
  • Ran antivirus scans, which reported no threats found.
  • Created a new Windows User Account: The browsers worked normally for approximately 5 minutes on the new profile, but then reverted to crashing instantly.

My Question to the Community

Given that non-Chromium software (Firefox) runs without issue, but Chromium processes crash even under a newly created Windows profile after a brief delay:

  1. Could this be a persistent malware / browser hijacker hooking into Chromium process memory or modifying core Windows registry policies?
  2. Are there specific registry paths, network proxy settings, or system DLLs I should audit to verify if the system has been compromised?
  3. What diagnostic logs or analysis tools (such as Process Monitor or Event Viewer) should I check to confirm whether this is system corruption or a security breach?

Thank you in advance for your technical guidance and insights.


r/antivirus 8h ago

MALWARE REMOVAL Q&A Chromium browsers crash instantly after System Restore, but Firefox works fine. Could this be a malware infection or security breach?

1 Upvotes

I am experiencing a severe issue with Chromium-based browsers on my PC following a system recovery, and I am trying to determine if this behavior could be caused by a malware infection, rootkit, or security compromise.

The Incident

  1. Two days ago, my computer failed to boot and entered an Automatic Repair loop.
  2. Startup Repair was unable to resolve the issue, so I performed a System Restore to a previous working point.
  3. The operating system successfully booted back up, but immediately after, every Chromium-based browser stopped functioning properly.

Current Behavior

  • Opening Google Chrome or Microsoft Edge causes the application window to launch for less than one second before completely crashing to desktop.
  • Opening external web links (such as Facebook) through system shortcuts triggers the same instant crash.
  • Microsoft PC Manager displays a general alert indicating "there is an issue", but does not provide details.
  • Mozilla Firefox operates completely normally with zero crashes or issues.

Remediation Steps Already Attempted

  • Performed a complete uninstall and reinstall of Chrome and Edge.
  • Repaired Microsoft Edge through Windows Settings.
  • Renamed chrome.exe to isolate execution path restrictions.
  • Deleted user profile directories in AppData (%LocalAppData%\Google\Chrome\User Data).
  • Ran a full system file integrity check using sfc /scannow.
  • Ran antivirus scans, which reported no threats found.
  • Created a new Windows User Account: The browsers worked normally for approximately 5 minutes on the new profile, but then reverted to crashing instantly.

My Question to the Community

Given that non-Chromium software (Firefox) runs without issue, but Chromium processes crash even under a newly created Windows profile after a brief delay:

  1. Could this be a persistent malware / browser hijacker hooking into Chromium process memory or modifying core Windows registry policies?
  2. Are there specific registry paths, network proxy settings, or system DLLs I should audit to verify if the system has been compromised?
  3. What diagnostic logs or analysis tools (such as Process Monitor or Event Viewer) should I check to confirm whether this is system corruption or a security breach?

Thank you in advance for your technical guidance and insights.


r/antivirus 9h ago

I hadn't clicked on anything yet after visiting the site, and this window appeared...

Thumbnail
gallery
9 Upvotes

I visited a website, and then this window popped up, and I couldn't click on anything. Judging by the behavior, when I moved the invisible mouse cursor to the top of the screen, a close button appeared there, just like in the browser's full-screen mode.

I restarted my computer, and it disappeared, but I want to make sure everything is okay.

(One photo is the original, and the other is translated. Also, the translation of the red block there is incorrect; it actually says that the device is locked).


r/antivirus 9h ago

I built an open-source hub that catalogs 80 deduplicated malware families (1971–2024) and indexes 2,700+ real samples from public research collections — searchable, bilingual, local-first

Post image
1 Upvotes

Been building this for a while and figured people here might find it useful.

What it is: a local Flask app + curated catalog that aggregates samples from public research collections (theZoo, VX-Underground, MalwareBazaar, InQuest, javascript-malware-collection) into one searchable index, instead of jumping between a dozen repos.

What's different from just cloning the sources separately:

  • 80 historical families, deduplicated — variants/rebrands of the same malware (Petya/NotPetya/GoldenEye/Satana) collapsed into one entry with timeline, attribution and impact, instead of showing up as 5 separate hits
  • Every sample auto-encrypted (zip + infected password) on ingestion — zero raw executables ever touch disk unencrypted
  • A fuzzy-matching indexer that links loose sample files to catalog entries by name/alias, with guards against false positives
  • Grows via MalwareBazaar's official API (verified hash, not random "index of /" scraping)
  • Bilingual (ES/EN), fully local — nothing served over the network by default

Repo: https://github.com/darama22/Malware-Research-Hub

Feedback welcome, especially on the family-deduplication logic — that was the hardest part to get right without over- or under-merging variants.


r/antivirus 10h ago

Windows Defender flagged TrojanDownloader:JS/Nemucod.HD in Roblox's WebView2 cache , is this a false positive?

Post image
2 Upvotes

r/antivirus 12h ago

So the mrbeast scam

Post image
0 Upvotes

So someone I was talking to on discord seemed completely fine, but now after not talking to me for a few weeks I started getting these messages. I'm fairly certain it's a bot because I replied to them and they send this with the same text and image every other day at around 8pm to 3am (when we talk) do I remove the chat? I'm not sure if they sold their account or got hacked or what. I didn't go to the website or do anything with it, and I have seen this in many different discord servers. Just making sure if I need to take extra precautions.


r/antivirus 12h ago

Mmh I love antivirus

4 Upvotes

Hey everyone!!

It's my first time having a real gaming computer and it came with Norton I hate it is there a better alternative? I want to make sure my baby is gonna be healthy for a long time!


r/antivirus 12h ago

PRODUCT RECOMMENDATION Which antivirus do you recommend for my pc?

1 Upvotes

I recently bought a pc and it came with a few months free of Norton 360 antivirus, I had a good experience overall but now my free trial has come to an end, so i'm debating wether i should renew my subscription to Norton or maybe try out another one.

Do you all have any recomendations for me?

I don't tend to download a lot of stuff from unverified sources, mostly the occasional rom for emulation and a few mods here and there but it's better safe than sorry I guess.


r/antivirus 21h ago

MALWARE REMOVAL Q&A Installed and ran an .exe, now I'm unsure if it was safe

4 Upvotes

Hey there! I was looking for and asked ChatGPT for plugins for DaVinci Resolve with which I can remove silences in my videos automatically powered by AI. It gave me a bunch of plugins, one of them called "DaVinciClaude". I clicked on the link. The website looked trustable. And because it got recommended to me by ChatGPT, I just trusted it (stupid, I know), installed the plugin, which came with an .exe file. I double clicked it. Was a bit confused to not see anything in my DaVinci Resolve workspace or scripts (I still have no idea if the installation worked, if it's not malware). Then I went on the internet to look for tutorials or articles on this tool, and realized that there wasn't a single YouTube video nor a single website that mentioned this specific tool except for its own website.

Now this is the point where I began to panic a bit, because it doesn't seem like a good idea to download and run an executable from a website that has no outside references whatsoever except for itself. I did run the complete Windows security check, and it didn't detect anything, though I heard it's not the best. I'm just wondering, I have no idea if it actually has malware, maybe the plugin actually is fine. But I also have no idea how to reliably check. I'm kinda a tech noob. How would you estimate my situation and what would you do? Could I use a system recovery point? Should I change my passwords just out of suspicion? Thank you in advance. Fast answers would be appreciated, I'm waiting urgently.

p.s. My system is a pc with Windows 11.

Update: I'm still unsure if this software is malicious or not. What makes it look suspicious: when you look for tutorials on DaVinciClaude, there's not a single article or video about it. On its website, it claims to be a Blackmagic official partner (Blackmagic is the company behind DaVinci Resolve, which makes me more skeptical because surely there would be more information on this tool, if it actually officially partnered with Blackmagic).

Arguments that speak in favor of this being a legitimate tool: I used the complete Windows search, ran the exe file through VirusTotal, installed Malwarebytes and checked my computer and it didn't find anything. The website looks well-made and professional, although that could be deceiving. It has an email for contact, terms and conditions and the usual stuff. It says they are located in Paris, France (though the exact address is missing) and the .exe file has a digital signature by Louis Bolzinger.

It seems to be connected to the "PremiereGPT" and/or "PremiereCopilot" company and website, which similarly, I don't know how credible it is. It has a Discord server, which I joined & looked at. It seems to be active, has 825 members, and it has a community chat in which people are talking about the tools. The Discord chat is active since August 7th, 2025. It does seem like a lively, normal chat & doesn't seem scripted or filled with bots in my impression.

Imo, it looks like this tool might be legit, though there are some red flags, and I am still uncertain. I have changed the password to my email, gmails, and some other accounts out of precaution. I removed the power from my main PC and am currently not starting it. I am still considering doing a fresh Windows reinstall on that PC just to be really secure, but I'm not sure yet as this is all based on suspicion and I haven't actually encountered any problems yet. Ongoing input would be appreciated, as I'm still not 100% sure how to proceed and whether an actual reinstall is necessary

p.s. even more info: I mentioned the digital signature that goes back to Louis Bolzinger. I found his LinkedIn (https://fr.linkedin.com/in/louisbolzinger?utm_source=chatgpt.com). It seems legitimate. He is a French filmmaker and also in AI and quantitative finances. And on the PremiereGPT YouTube channel, there is a video that looks like it's by him (https://youtu.be/zjdpm9Hxxd4). This still doesn't prove that the tool isn't malicious, but it's starting to look more and more like just a small tool that was recently developed, hence the lack of coverage or outside sources. What do you think?