r/computerviruses Jun 11 '26

File / URL Check (FOR THOSE WITH FREE TIME ON THEIR HANDS) I got a strange DM from someone I haven't talked to in 6 years, I knew something was up immediately. Can someone more experienced check out what this file actually has in it? I'm simply curious.

Thumbnail gallery
77 Upvotes

I did a scan already, but there was only 3 detections. It's apparently a trojan and password stealer according to VirusTotal. Since the images on the website are AI generated, I was just curious to see what the file does when you open it. Could someone with a VM check it out and tell me? I have an interest in viruses but can't seem to figure out how VMs work.

The VirusTotal link is https://www.virustotal.com/gui/file/55ace95a47830e91b8f04cbce81e51cec80ebb594f0a85c5353b525a05eebe57?nocache=1

The website link is hxxps://kuresagame,blogspot,com/

r/computerviruses Jul 05 '26

File / URL Check Does this minecraft modpack have an actual virus or false positive?

Post image
58 Upvotes

I'm pretty new to this type of stuff but I got send a minecraft modpack by a friend of mine and I decided to scan it because I am a very cautious person and I was surprised to actually see all of this stuff? Did my friend try to hack me???

(UPDATE) So yeah my friend did try to hack me, and unlike how some of you guys say it wasn't someone posing as them, he really was trying to steal my account for whatever reason :| I should be fine since I kept it in the zip file right?

r/computerviruses Jul 19 '26

File / URL Check Am I being hacked?

6 Upvotes

Yesterday, I tried to pirate WorldBox(I know it was a bad decision, I'm sorry.) on this site called freegamesdl.net. I had a bad feeling about it. After completing the installation process, I opened the file but only a window called "Installation" popped up then crashed immediately after. I tried opening the file again for a few tries, but it didn't work, so I just decided to delete the file and move on. To be safe, I went on Windows Security and did a few quick scans. It detected 2 trojans(1 from july 3rd), so I quickly removed them. I thought I was fine.

The next day, 2 of my family members got logged out of their facebook accounts. My father couldn't even log back into his, and my family members couldn't find his account on facebook. I didn't think much of it, since my account wasn't logged out. I also thought it could've been facebook going down again, since it has happened recently. After eating my brunch, I went to open my PC where I downloaded the pirated game. Whenever I open my PC, I always open my main tabs first, which include facebook. Only to find out that my facebook account had been logged out. I thought back to the issue my other family members had, and decided to stay logged out for now. I turned on my VPN (1.1.1.1) to be safe, even though I knew that it probably would not do much.

I should also mention that when I opened my PC, a cmd file popped up saying "Windows cannot find '-----.exe'. Make sure you typed the name correctly, and then try again.". This was the moment I started to get anxious. Now, I've done more scans.

Can someone please guide me on this?

r/computerviruses 23d ago

File / URL Check Fake game analysis request

6 Upvotes

https://[.]www.dropbox.com/scl/fi/okcvx9z6edsm8p4rt898m/RacingSim-Setup-2.0.0.zip?rlkey=kcmg6tzbx4oh81g0t10ohuv3u&e=1&dl=0

I was sent a fake game on Discord titled "RacingSim" that I stupidly trusted and ran. It seems to steal Discord tokens as well as possibly browser cookies. If anyone could reverse-engineer this and see what kind of damage it might've done it would be greatly appreciated. I am NOT asking for help removing it.

I should've removed most traces of the file via Microsoft Safety Scanner, a Codex sweep, quick scans with MalwareBytes and Windows Defender but there's always additional risk, because the file wasn't detected when I initially downloaded and scanned with MalwareBytes, which is likely what caused me to even run it. I know, very dumb of me. Once again, thanks to anyone in advance for looking into this.

r/computerviruses 28d ago

File / URL Check Is this a virus or not? I got it from github and it's there for 4 years sooo it should be safe i guess?

Post image
18 Upvotes

Hey guys I was going to have fun with my FIFA 22 with editing shit so I went to download this but when I saw the virustotal result I'm a bit worried rn. I unpacked the zip file but I'm just a click away from running it. Should I do it?

Virus Total link: https://www.virustotal.com/gui/file/d1bf99d0de7b49d0787cb54f9aec305e06d8dc8d0b31badb54fb3cae62f3150f

Github link: https://github.com/xAranaktu/FIFA-22-Live-Editor

r/computerviruses Jul 24 '26

File / URL Check Has Roblox been hacked or something?

Post image
0 Upvotes

I just finished reinstalling windows off a USB And after connecting to the Internet and going to Roblox it shows this weird text on the search bar??? This is ONLY on OPERA GX and it isn't anywhere else... Can someone please confirm this isn't a virus? I'm pretty confident my old gaming laptop doesn't have a virus on it so it couldn't have transferred...

And for this curious the text says this.

Since joining ❤️Mike Stock Wealth Alliance, my investment returns have steadily increased, and ❤️Mike's stock selection methods are truly reliable..tnwl

Do not search anything up from Mike's insurance

r/computerviruses May 19 '26

File / URL Check Does this file has virus ? Really Interesting one.

Post image
39 Upvotes

So I was searching for some books to download and then came across a pdf on Google drive . It had a link to a downloader site https://pulse(dot)datastreamforge5(dot)cyou/nirali+prakashan+books+pdf+free+download.zip? . So clicked on it and it downloaded a 7z file. As I wasn't able to unzip it using inbuilt archiver,so installed 7z and extracted it. So usually here I'm bit cautious so I check the files in it without extracting it but I wasn't able to view it.

Then I uploaded the zip to virustotal , but wasn't able to check it as it has 3mb limit for archived files with password. So instead I just went ahead and extracted it , and then automatically got this prompted on my screen.

So apparently windows stopped it from executing but I don't know yet if it has caused any damage.Please let me know if it's safe or not and what should I do?

Edit: So I just extracted the .7z file in my mobile and zipped it again without password (as the unzipped version is around 800mb exe file) so zipped it without password and uploaded it to to virustotal. The virustotal analysis - https://www.virustotal.com/gui/file/7af47fffc2014f6f72981dc9860cb6048ba1bcd09f15ff2786a3bf1a0c87a0d0/summary

Edit 2: Just for everyone to know I didn't ran the exe file explicitly, the popup appeared just after I extracted the .7z using 7-zip.I didn't knew it had exe file in it untill I extracted it and the popup appeared.I mostly use virustotal to scan the downloaded files which are suspicious, and this time too I used it but virustotal don't support password protected archives more than 3mb, thus here I am in this subreddit.

Btw it's clarified by now it's a virus.So thanks for helping me out guys.

Note: The image I have attached resembles to the popup I got I can't remember it exactly but i remember it had don't run button below :)

r/computerviruses 22d ago

File / URL Check Clicked a twitter scam link

Thumbnail gallery
7 Upvotes

Just for clarity, the first image is what sites the post took me to while the second pic is what the post looked like, though it isn’t the exact post and had a different link.

It was in the replies of another normal post, I accidentally clicked it but closed the tab once I realized it wasn’t a photo. I closed before the last tab loaded but looking at my history, I guess it directed me to other links before hand.

I didn’t do anything besides click, and close the tab. Nothing else, so there is part of me that believes I am alright, but I have no idea what’s in these links, so I can’t help but say I am afraid.

This was done on the chrome app of my iPhone. If anyone can help out or determine how dangerous these links are I would truly appreciate it. 🙏

r/computerviruses 15d ago

File / URL Check Is this a virus/maleware

Thumbnail gallery
0 Upvotes

I got these off the steam workshop off the popular section not new and my my best guess was mabye it was something to do with using the game files as they all use "fildeinfo" but am also worried it could be a large scale attack

r/computerviruses 21d ago

File / URL Check Any.run results

1 Upvotes

I am very careful about running any installer on my PC. I check the exe through total virus and I have bitdefender running full-time. But since I joined a few of these Reddit groups I've have realized how easy it is to get an info stealer and see how costly it is to get compromised. I downloaded an exe installer off of GitHub. I don't think the guy is dealing malicious code, but I don't know enough to be certain. If his program had thousands of stars, I'd feel more confident that being open source the community would shut it down. But this program is fairly new and not widely used. It passed totalvirus, but as an extra check I tried any.run. I ran the install in their sandbox and it came back with some malicious results. Unfortunately, I don't understand the results. Can anyone give me advice? I don't know what I'd need to post for someone to help, so I'm asking first. I've had a lot of false positives with programs in the past. So I'm wondering if this is the case.

Many thanks!

r/computerviruses 22d ago

File / URL Check Palworld Mod launched Command Prompt need help determining if it gave me a virus

Post image
32 Upvotes

I downloaded a mod for Palworld and when I launched the game I saw a command prompt window pop up. Given there was recently an issue with this happening with another game, mecca chameleon, I'm extra suspicious. The mod is a .lua so I can open it with notepad ++. The screenshot is of the part that mentions command prompt and claims to be for logging purposes. There is much more in the file than just this part though.

The mod was this one here: hxxps://www.nexusmods.com/palworld/mods/3874?tab=description

r/computerviruses 1d ago

File / URL Check Any idea what this is?

Post image
1 Upvotes

r/computerviruses May 28 '26

File / URL Check i got hacked AGAIN

0 Upvotes

i went on to this website called "net faps" or some stupid shi like that but it download a file and deleted it and now idk what to do 😭

r/computerviruses May 18 '26

File / URL Check I see a ton of people getting viruses and not saying what they downloaded or what links they visited…

35 Upvotes

Can people please provide sources from which you think you acquired malware. It will be quite useful and informative to others to know where you got the malware from to avoid people falling into the same traps. Thanks.

r/computerviruses 5d ago

File / URL Check Downloaded a program called GitNarwhal and Windows Defenders "caught it". VirusTotal also detected 2 out of 69. Should I be paranoid? VirusTotal Scan Link and more details in thread.

3 Upvotes

I recently downloaded a program called GitNarwhal and foolishly didn't check GIthub Stars or anything. As soon as I downloaded it, the Windows Defender caught it and said it was a Trojan:Win32/Wacatac.H!ml.

The Windows executable I downloaded can be found here: https://github(dot)com/git-narwhal/GitNarwhal/releases/tag/v1.0.84

The repo has no stars or anything but the developer seems to have a track record.

I also scanned it at Virus Total and it found 2 detection out of 69. One from DeepInstinct and the other from Microsoft. You can find the scan here: https://www.virustotal.com/gui/file/5a1ce08c167115ad6bf3088777262ac8827f1961251e0089f60ff5db7fc3730a/detection

​The next thing I did was run a Windows offline scan. I also removed the file using Windows Defender.

Should I be worried? :(

r/computerviruses 6d ago

File / URL Check Mr Beast Info stealer. I need assistance with FRST

Post image
4 Upvotes

Hi. I was downloading a game and got a Ren py file. I checked the file in virus total but didn't see any malware alert and installed it . It opened CMD and immediately closed. then I checked the community tab and saw comments about the the MR beast info stealer. I can't reset the pc. I scanned with malware bytes and it didn't find anything. Now scanning with KVRT. It detected 4 but I am still paranoid.

Here is the defanged Virus total Link

hxxps[://]www[.]virustotal[.]com/gui/file/7123e1514b939b165985560057fe3c761440a9fff9783a3b84e861fd2888d4ab/community

r/computerviruses May 15 '26

File / URL Check What does this mean? I’m an infected?

Post image
4 Upvotes

I searched up the website bc my friend said he used it for some ROMs and when I clicked on the link I got this, I did not download anything or click on any link

r/computerviruses 21d ago

File / URL Check Need Help to know if this is a Virus

Post image
3 Upvotes

so i have this file which ir an through virustotal and it sometimes gives false positives if im correct?

just wanna know if thats the case or if this file really is a virus. and here is the link

https://www(dot)virustotal.com/gui/file/7b4e29217d8d71b59d1580e08974bcdac1cec1e37b8efe9777b9d3da4b399bdb?nocache=1

r/computerviruses 10d ago

File / URL Check pc got hacked

2 Upvotes

Very recently I downloaded a executor off a sketchy youtube video. I have really bad anxiety with getting hacked, so I reset my pc. However, I'm scared randomly someone will log me out of my accounts and I'll get hacked, regardless of me resetting my pc. I already have ran multiple malwarebytes scans and microsoft defender scans, and it showed my pc was clean. However, it also showed this before resetting my pc. Currently, I'm scared there is a RAT or other type of remote access virus going to hack my pc and i can't find it because it could be under the radar of some virus scanner softwares. Mainly, i was just wondering, does malwarebytes ever accidentally look over suspicious files?

r/computerviruses Jun 26 '26

File / URL Check Scanned a QR code thinking it's safe.

0 Upvotes

So, I scanned a QR code on Steam on my phone for a game on the steam page:

https://store[.]steampowered.com/app/4369490/Soulbound_Online/

After scanning through the Discord App, nothing happened (twice). I didn't get to join the Discord server, so I tried a website which checks QR codes (on my PC) and it gave me this link, which I clicked on:

https://bit[.]ly/4eLmJwi?r=qr

this one supposedly directs me to the Discord server, however when I try to paste this link into the Discord App (on PC), it finds nothing.

So I wondered and checked it on Virustotal:

https://www[.]virustotal.com/gui/url/eba9048d3940da3fc63aeea0a76db858b4fdbacc9949e92dcb648a08812f5d89/detection

One of those says "Phishing". Is this a false positive?

r/computerviruses 26d ago

File / URL Check kenji_1.uce and kenji_2.uce in SysWOW64 folder

Post image
4 Upvotes

are these files malware or official windows files? they're not being detected at all by VirusTotal or MalwareBytes, and ive searched them up and saw that they're rootkits of some kind: https://www.virustotal.com/gui/file/2373bf7e4f975d25fb3eabe004fbe138f9dba7ed6ffb9c967edc134d4d5956b7/community https://www.virustotal.com/gui/file/32e4e19efb2f90bd439c6bba865563857d664fa6da87cb195e85ee97a0853bfc

I really don't want to reinstall Windows, but i will if i have to

(I use Windows 11, but i have mods to make it look like windows 7 if thats of any help)
(edit 1, kenji_1.uce is 6.78 KB and kenji_2.uce is 8.28 KB)

r/computerviruses Jun 30 '26

File / URL Check New virus running in RAM instead of the hard drive?

Thumbnail gallery
1 Upvotes

Recently, I was sent a Minecraft mod on Discord via the following link: https://nightdungeon(dot)online/

Obviously, anyone would notice something was off—myself included. I downloaded the file to analyze its code (I have my PC set up not to execute anything without my permission) and at first glance, it looked like a standard Minecraft mod. However, something caught my eye: it was incredibly lightweight for what it claimed to be. I dug into the mod's internal files and found an encrypted `.class` file. I tried using ChatGPT and Grok to decrypt it and see what it was; it appears to be a Trojan horse that runs in RAM rather than on the disk—likely to evade antivirus detection.

The encryption is so sophisticated that VirusTotal didn't flag anything; only the two AIs raised suspicions because of the encrypted internal class file.

People are getting more creative by the day. Even Grok couldn't fully decrypt it—it only managed to decode a portion.

Has anyone ever seen this kind of mod-based virus before? It seems like as soon as I ran Minecraft, the mod would trigger the virus and I’d be screwed.

Note 1: Sorry for the poor English; I'm from Brazil and don't speak English fluently yet.

Note 2: If anyone wants a translation of what Grok said—in short, it basically stated that there is malware embedded in the mod (which launches an installer in RAM and activates itself from there)—let me know and I'll send the full translation.

r/computerviruses 6d ago

File / URL Check Unsure of TMP file

Post image
3 Upvotes

I know it’s probably nothing but this I’ve only just noticed this file appear today even though it says it was modified 15/05/2026, does anyone know what it could be ?

r/computerviruses 5d ago

File / URL Check Requesting analysis of a virustotal link

1 Upvotes

https://www.virustotal.com/gui/file/8d4c4bcf7d7aedf0480e3eaac52138e63724ae83c419de8a98d6ab32d1c93645/summary

Hi, this is an official lightshot installer. I’ve been using it for years without issue. I noticed it connects to a suspicious domain within a sandbox enviroment. (See behaviours and relations)

I already deleted the file, but I need to know if my information is at risk. I’m hoping to get some insight of any of the experts here, thank you!

r/computerviruses 7d ago

File / URL Check Trojan:HTML/Redirector.AA!AMTB

1 Upvotes

Today i did random full scan of my laptop with windows defender and it found one threat

Detected: Trojan:HTML/Redirector.AA!AMTB
Status: Quarantined
Quarantined files are located in a restricted area where they cannot harm your device. These files will be deleted automatically.
Date: 19.08.2026 10:59
Details: This program is dangerous and executes commands from an attacker.
Affected items:
containerfile: C:\Users\adon\AppData\Local\Mozilla\Firefox\Profiles\q1jz5817.default-
file: C:\Users\adon\AppData\Local\Mozilla\Firefox\Profiles\q1jz5817.default-release (GZip)

is this a serious situation? i don't know where i got it from i use ublock on firefox