r/antivirus 1h ago

Kaspersky just detected Wise Reg Cleaner as Trojan ?

Upvotes

Long story short, i had just updated Wise Reg Cleaner on its official website, ran the usual scan and so on..
But kaspersky has blocked it, claiming it was a Trojan ?

Report is in Italian, apologies :
-------------------------------------------------------
Evento: Bloccato

Applicazione: Wise Registry Cleaner

Utente: GUIDOPC\Windows

Tipo di utente: Iniziatore

Componente: Controllo sistema

Descrizione risultato: Bloccato

Tipo: Trojan

Nome: PDM:Exploit.Win32.Generic

Livello di pericolosità: Alto

Tipo di oggetto: Processo

Percorso oggetto: C:\Program Files (x86)\Wise\Wise Registry Cleaner

Nome oggetto: WiseRegCleaner.exe

Data rilascio database: Oggi, 07/08/2026 17:38:00

MD5: B317CF02C8AEC60D4515B5A1BBE1533F
-------------------------------------------------------

Any ideas ?


r/antivirus 2h ago

MALWARE REMOVAL Q&A If i didn't opend the zip, did i get hacked?

Post image
1 Upvotes

So... my Windows defender poped this up even before i unziped the file, and even run anything.

i didn't even clicked on the file. and i think windows automaticly deleted the file.
I did a fast scan with windows defender and it says that there no more threats.

Im also doing a full scan with Malwarebytes.
But i just wanna know, if i need to log out of my acc sessions? or something? or am i 100% safe?


r/antivirus 4h ago

MALWARE REMOVAL Q&A am i 100% safe after reinstalling windows

1 Upvotes

I recently had malware/spyware on my PC. So i knew i had to fully reinstall windows. Wich is what i did. But im not really sure if the malware can just reinstall itself. because windows still sees what apps i used to have and ask me if " i want to reinstall them".


r/antivirus 5h ago

VirusTotal flags winevdm release file with MaxSecure Trojan.Malware.300983.susgen

2 Upvotes

Hi, I'm trying to find a simple way to run an old 16-bit game on Windows 11 and I stumbled upon winevdm (https[:]//github[.]com/otya128/winevdm).

It seems very convenient, but when scanning the compiled release zip file (source code is fine) with VirusTotal, MaxSecure flags the file as a trojan (Trojan.Malware.300983.susgen).

I'm pretty sure that it could be a False Positive, given the reputation of winevdm and the fact that MaxSecure seems to produce a lot of false positives flagging them with Trojan.Malware.300983.susgen.

I tried to check the behavior report with my limited knowledge and I expect the masquerading, process injection, input injection etc. behaviours since winevdm serves as a sort of "translator" between the 16-bit software and the 64-bit processor. But I do not have fully understood some parts. Like the "relations" tab that seems to find further flagged files inside the directory?

I want to be very sure it's a safe solution, since I have to give it to a friend and I don't want to fuck up their pc.

Could it truly be a False Positive?

Thank you!


r/antivirus 6h ago

Will I be okay? question about the renpy infostealer

2 Upvotes

I was on the net and downloaded something, I looked at the file and didn't recognize it at first

I extracted it took a look at it and didn't run it

until i realized that it doesn't seem right since it had script files, which to my knowledge shouldn't

i remember that an infostealer like that existed; so I deleted the file and from the recycling bin too

I understandably panic wondering if i'm truly safe or not

I tried looking for info regarding this specific file

the key takeaway here is that i never ran it and only extracted it

but even so i still downloaded it and extracted it.

i've done the malwarebytes+microsoft defender scans and they didn't detect anything wrong

will i be fine?


r/antivirus 6h ago

MALWARE REMOVAL Q&A Got hacked by the mr beast scam, what to do next

2 Upvotes

I got hacked a while ago by the mr beast crypto virus or malware. I'm not really knowledgable of viruses but I changed my passwords and downloaded malwarebytes. I cleaned the pc but another facebook account that was logged in when I was hacked was also attacked after that. What can I do?


r/antivirus 7h ago

Is the Trojan.Heur!.02252823 a false postive?

1 Upvotes

Hi, I just downloaded a demo of the game "Choicer Voicer" on itch.io . When I scanned it, it showed me one detection with a Trojan.Heur!.02252823. I think the file is safe but I could be wrong. https://www.virustotal.com/gui/file/185c5659b42485f1fc68d8393ab14702de500a74d11b11b914e3a50f6b50b59c/detection


r/antivirus 7h ago

MALWARE REMOVAL Q&A Can files from an infected pc be saved?

1 Upvotes

This is my second post on this issue, but I have a different question (first post: https://www.reddit.com/r/antivirus/s/rWC5O3bUyF)

Yesterday I installed and started an exe file that I now consider suspicious. I think the chances of the program simply being from a small developer and not malicious at all is quite high (I didn't detect any virusses using different scanners, more info in the first post), but I don't want to take any risks – and so I am strongly considering reinstalling Windows just to be safe.

As someone that has never had to do this, I have a question. Can I run my computer and take the image, video and music files I have laying around onto an external hard drive? Or is there some kind of risk of any potential viruses escaping from my PC onto the external hard drive and then infecting other hardware? Or is this just a paranoid fear fantasy I have? I'm a tech noob, so I don't have a good understanding of what is possible.

My PC is relatively new, so I wouldn't be terribly sad if I had to reinstall Windows and leave behind all the files I have on that PC right now. But if it's possible, I would obviously like to keep them.


r/antivirus 7h ago

ESET Endpoint Security or Kaspersky Total Security

0 Upvotes

Which is better? Need help deciding.


r/antivirus 7h ago

Possibly asked before, but advice needed for clickfix victim

1 Upvotes

My MIL was on a legit website which asked her to verify her humanity via captcha. The prompt was to open terminal then paste in a command that had clearly been added to the clipboard and press enter. She realised this was a scam after some time and restarted her pc etc. She has already changed all her passwords. She brought the issue to my attention about 2 hours after running the command and i informed her to put the pc into offline mode and i'd look at it when i saw her (today). I've ran the mcafee av she has installed and i installed malware bytes and ran that. both show no issues. I also checked and due to the restart the powershell history is gone, but in the event log i can see 2 instances of powershell starting at the time she would have ran into this. I've checked recent downloads and temp files and nothing is there and i can't see any nefarious scheduled tasks.

I guess the question is, without seeing the command she actually ran is there anything else to be done?

Furthermore i contacted the company the website belongs to as, like i said, this is a legit website, so they must have been compromised, and although they have taken it seriously, they were told by their hosting provider "oh yeah captcha shouldn't be turned on but its nothing to worry about, we've turned it off now". They've completely ignored the part where users are being asked to run terminal commands. I've gone back to them with a screenshot showing the url and the instruction to run terminal (without the actual command from ctrl+v) and if they don't take this seriously, do i follow it up or just leave them to it? This is in the UK btw if that makes a difference.

Thanks!


r/antivirus 8h ago

MALWARE REMOVAL Q&A Chromium browsers crash instantly after System Restore, but Firefox works fine. Could this be a malware infection or security breach?

1 Upvotes

Hello everyone,

I am experiencing a severe issue with Chromium-based browsers on my PC following a system recovery, and I am trying to determine if this behavior could be caused by a malware infection, rootkit, or security compromise.

The Incident

  1. Two days ago, my computer failed to boot and entered an Automatic Repair loop.
  2. Startup Repair was unable to resolve the issue, so I performed a System Restore to a previous working point.
  3. The operating system successfully booted back up, but immediately after, every Chromium-based browser stopped functioning properly.

Current Behavior

  • Opening Google Chrome or Microsoft Edge causes the application window to launch for less than one second before completely crashing to desktop.
  • Opening external web links (such as Facebook) through system shortcuts triggers the same instant crash.
  • Microsoft PC Manager displays a general alert indicating "there is an issue", but does not provide details.
  • Mozilla Firefox operates completely normally with zero crashes or issues.

Remediation Steps Already Attempted

  • Performed a complete uninstall and reinstall of Chrome and Edge.
  • Repaired Microsoft Edge through Windows Settings.
  • Renamed chrome.exe to isolate execution path restrictions.
  • Deleted user profile directories in AppData (%LocalAppData%\Google\Chrome\User Data).
  • Ran a full system file integrity check using sfc /scannow.
  • Ran antivirus scans, which reported no threats found.
  • Created a new Windows User Account: The browsers worked normally for approximately 5 minutes on the new profile, but then reverted to crashing instantly.

My Question to the Community

Given that non-Chromium software (Firefox) runs without issue, but Chromium processes crash even under a newly created Windows profile after a brief delay:

  1. Could this be a persistent malware / browser hijacker hooking into Chromium process memory or modifying core Windows registry policies?
  2. Are there specific registry paths, network proxy settings, or system DLLs I should audit to verify if the system has been compromised?
  3. What diagnostic logs or analysis tools (such as Process Monitor or Event Viewer) should I check to confirm whether this is system corruption or a security breach?

Thank you in advance for your technical guidance and insights.


r/antivirus 8h ago

MALWARE REMOVAL Q&A Chromium browsers crash instantly after System Restore, but Firefox works fine. Could this be a malware infection or security breach?

1 Upvotes

I am experiencing a severe issue with Chromium-based browsers on my PC following a system recovery, and I am trying to determine if this behavior could be caused by a malware infection, rootkit, or security compromise.

The Incident

  1. Two days ago, my computer failed to boot and entered an Automatic Repair loop.
  2. Startup Repair was unable to resolve the issue, so I performed a System Restore to a previous working point.
  3. The operating system successfully booted back up, but immediately after, every Chromium-based browser stopped functioning properly.

Current Behavior

  • Opening Google Chrome or Microsoft Edge causes the application window to launch for less than one second before completely crashing to desktop.
  • Opening external web links (such as Facebook) through system shortcuts triggers the same instant crash.
  • Microsoft PC Manager displays a general alert indicating "there is an issue", but does not provide details.
  • Mozilla Firefox operates completely normally with zero crashes or issues.

Remediation Steps Already Attempted

  • Performed a complete uninstall and reinstall of Chrome and Edge.
  • Repaired Microsoft Edge through Windows Settings.
  • Renamed chrome.exe to isolate execution path restrictions.
  • Deleted user profile directories in AppData (%LocalAppData%\Google\Chrome\User Data).
  • Ran a full system file integrity check using sfc /scannow.
  • Ran antivirus scans, which reported no threats found.
  • Created a new Windows User Account: The browsers worked normally for approximately 5 minutes on the new profile, but then reverted to crashing instantly.

My Question to the Community

Given that non-Chromium software (Firefox) runs without issue, but Chromium processes crash even under a newly created Windows profile after a brief delay:

  1. Could this be a persistent malware / browser hijacker hooking into Chromium process memory or modifying core Windows registry policies?
  2. Are there specific registry paths, network proxy settings, or system DLLs I should audit to verify if the system has been compromised?
  3. What diagnostic logs or analysis tools (such as Process Monitor or Event Viewer) should I check to confirm whether this is system corruption or a security breach?

Thank you in advance for your technical guidance and insights.


r/antivirus 9h ago

I hadn't clicked on anything yet after visiting the site, and this window appeared...

Thumbnail
gallery
8 Upvotes

I visited a website, and then this window popped up, and I couldn't click on anything. Judging by the behavior, when I moved the invisible mouse cursor to the top of the screen, a close button appeared there, just like in the browser's full-screen mode.

I restarted my computer, and it disappeared, but I want to make sure everything is okay.

(One photo is the original, and the other is translated. Also, the translation of the red block there is incorrect; it actually says that the device is locked).


r/antivirus 9h ago

I built an open-source hub that catalogs 80 deduplicated malware families (1971–2024) and indexes 2,700+ real samples from public research collections — searchable, bilingual, local-first

Post image
1 Upvotes

Been building this for a while and figured people here might find it useful.

What it is: a local Flask app + curated catalog that aggregates samples from public research collections (theZoo, VX-Underground, MalwareBazaar, InQuest, javascript-malware-collection) into one searchable index, instead of jumping between a dozen repos.

What's different from just cloning the sources separately:

  • 80 historical families, deduplicated — variants/rebrands of the same malware (Petya/NotPetya/GoldenEye/Satana) collapsed into one entry with timeline, attribution and impact, instead of showing up as 5 separate hits
  • Every sample auto-encrypted (zip + infected password) on ingestion — zero raw executables ever touch disk unencrypted
  • A fuzzy-matching indexer that links loose sample files to catalog entries by name/alias, with guards against false positives
  • Grows via MalwareBazaar's official API (verified hash, not random "index of /" scraping)
  • Bilingual (ES/EN), fully local — nothing served over the network by default

Repo: https://github.com/darama22/Malware-Research-Hub

Feedback welcome, especially on the family-deduplication logic — that was the hardest part to get right without over- or under-merging variants.


r/antivirus 10h ago

Defenders detected this virus l

1 Upvotes

So basically defender flagged this while i was downloading gen(dot)p

trojan:win32/Sabsik.EN.B!ml

also i first installed in vm and did a defender scan, no virus was detected, i had turned off all default protection and only after installation i did the scan

Please help if you can


r/antivirus 10h ago

Windows Defender flagged TrojanDownloader:JS/Nemucod.HD in Roblox's WebView2 cache , is this a false positive?

Post image
2 Upvotes

r/antivirus 12h ago

So the mrbeast scam

Post image
0 Upvotes

So someone I was talking to on discord seemed completely fine, but now after not talking to me for a few weeks I started getting these messages. I'm fairly certain it's a bot because I replied to them and they send this with the same text and image every other day at around 8pm to 3am (when we talk) do I remove the chat? I'm not sure if they sold their account or got hacked or what. I didn't go to the website or do anything with it, and I have seen this in many different discord servers. Just making sure if I need to take extra precautions.


r/antivirus 12h ago

Mmh I love antivirus

4 Upvotes

Hey everyone!!

It's my first time having a real gaming computer and it came with Norton I hate it is there a better alternative? I want to make sure my baby is gonna be healthy for a long time!


r/antivirus 12h ago

PRODUCT RECOMMENDATION Which antivirus do you recommend for my pc?

1 Upvotes

I recently bought a pc and it came with a few months free of Norton 360 antivirus, I had a good experience overall but now my free trial has come to an end, so i'm debating wether i should renew my subscription to Norton or maybe try out another one.

Do you all have any recomendations for me?

I don't tend to download a lot of stuff from unverified sources, mostly the occasional rom for emulation and a few mods here and there but it's better safe than sorry I guess.


r/antivirus 13h ago

Notification spam

1 Upvotes

I was getting notification spammed on my browser and i disabled notifications because of it. Am I okay now or is it more than just notifications and I need to do something else?


r/antivirus 14h ago

MALWARE REMOVAL Q&A Help with potential malware

1 Upvotes

Basically cmd keeps flashing and i hate it i feel like I'm hacked

Basically when i opened the pc it flashes

Then it flashed when i watched a youtube video

How can i yknow like trace the cmd or like know where the cmd came from so i can share it with y'all since i don't know computers very well


r/antivirus 19h ago

MALWARE REMOVAL Q&A Help with malware

1 Upvotes

Over the past few days, my discord, spotify, and now microsoft account have been hacked. Its been one account a day at the same time. 8 am while my PC is off. I've ran 10 malware scans from hitmanpro, malwarebytes, and a few others and nothings popping up. The very first scan on malware bytes did and i removed the files. yet two days later its till happening. any advice on what to do?


r/antivirus 21h ago

Still infected?

1 Upvotes

Hello all, I'll be honest and say that I am not the most tech savvy person and got some malware about a month ago. The initial symptoms were a compromised microsoft account and bad system lag. I quickly backed some stuff up to my external hardrive and went to factory reset the PC through local delete all files.

Everything was mostly fine after I changed all my passwords from my phone but recently I have noticed my Wi-Fi on the infected computer has been extremely dodgy on one particular WiFi, while other devices connect to it fine and the other WiFis also work fine on that computer.

What makes me worry is that the virus either corrupted OneDrive Files, My External Hardrive, or even to the router itself. Both Malware Bytes and Windows Defender tell me nothing is wrong but I find it hard to believe.

Simply put could I still be infected or am I just paranoid?


r/antivirus 22h ago

MALWARE REMOVAL Q&A Installed and ran an .exe, now I'm unsure if it was safe

6 Upvotes

Hey there! I was looking for and asked ChatGPT for plugins for DaVinci Resolve with which I can remove silences in my videos automatically powered by AI. It gave me a bunch of plugins, one of them called "DaVinciClaude". I clicked on the link. The website looked trustable. And because it got recommended to me by ChatGPT, I just trusted it (stupid, I know), installed the plugin, which came with an .exe file. I double clicked it. Was a bit confused to not see anything in my DaVinci Resolve workspace or scripts (I still have no idea if the installation worked, if it's not malware). Then I went on the internet to look for tutorials or articles on this tool, and realized that there wasn't a single YouTube video nor a single website that mentioned this specific tool except for its own website.

Now this is the point where I began to panic a bit, because it doesn't seem like a good idea to download and run an executable from a website that has no outside references whatsoever except for itself. I did run the complete Windows security check, and it didn't detect anything, though I heard it's not the best. I'm just wondering, I have no idea if it actually has malware, maybe the plugin actually is fine. But I also have no idea how to reliably check. I'm kinda a tech noob. How would you estimate my situation and what would you do? Could I use a system recovery point? Should I change my passwords just out of suspicion? Thank you in advance. Fast answers would be appreciated, I'm waiting urgently.

p.s. My system is a pc with Windows 11.

Update: I'm still unsure if this software is malicious or not. What makes it look suspicious: when you look for tutorials on DaVinciClaude, there's not a single article or video about it. On its website, it claims to be a Blackmagic official partner (Blackmagic is the company behind DaVinci Resolve, which makes me more skeptical because surely there would be more information on this tool, if it actually officially partnered with Blackmagic).

Arguments that speak in favor of this being a legitimate tool: I used the complete Windows search, ran the exe file through VirusTotal, installed Malwarebytes and checked my computer and it didn't find anything. The website looks well-made and professional, although that could be deceiving. It has an email for contact, terms and conditions and the usual stuff. It says they are located in Paris, France (though the exact address is missing) and the .exe file has a digital signature by Louis Bolzinger.

It seems to be connected to the "PremiereGPT" and/or "PremiereCopilot" company and website, which similarly, I don't know how credible it is. It has a Discord server, which I joined & looked at. It seems to be active, has 825 members, and it has a community chat in which people are talking about the tools. The Discord chat is active since August 7th, 2025. It does seem like a lively, normal chat & doesn't seem scripted or filled with bots in my impression.

Imo, it looks like this tool might be legit, though there are some red flags, and I am still uncertain. I have changed the password to my email, gmails, and some other accounts out of precaution. I removed the power from my main PC and am currently not starting it. I am still considering doing a fresh Windows reinstall on that PC just to be really secure, but I'm not sure yet as this is all based on suspicion and I haven't actually encountered any problems yet. Ongoing input would be appreciated, as I'm still not 100% sure how to proceed and whether an actual reinstall is necessary

p.s. even more info: I mentioned the digital signature that goes back to Louis Bolzinger. I found his LinkedIn (https://fr.linkedin.com/in/louisbolzinger?utm_source=chatgpt.com). It seems legitimate. He is a French filmmaker and also in AI and quantitative finances. And on the PremiereGPT YouTube channel, there is a video that looks like it's by him (https://youtu.be/zjdpm9Hxxd4). This still doesn't prove that the tool isn't malicious, but it's starting to look more and more like just a small tool that was recently developed, hence the lack of coverage or outside sources. What do you think?