
r/antivirus

Harvard and 140 other legitimate websites compromised
Harvard and ~140 other compromised legitimate sites are now spreading ClickFix malware.
hxxps://hir.harvard.edu/israel-and-international-football-a-breaking-point/
hxxps://hir.harvard.edu/a-better-way-forward-an-interview-with-paul-ryan/
Both contain a remote load script in it's HTML that reverses it's C2 sj.ssc/ipa/orp.eralfduolccitats to original form and then displays the ClickFix box from it.
C2: hxxps://staticcloudflare.pro
AnyRun identifies the loading pattern well:
- https://app.any.run/tasks/2ac73567-8bdf-41b0-999e-08057deb3dd3
- https://app.any.run/tasks/8362c5f5-11ab-4b34-b7a5-8e2fb2d6355c
Sandbox detonation of one of the ClickFix payloads:
Original post and more discovered compromised URL's: https://x.com/rifteyy/status/2057842147630411877
There's supposedly a virus in my PC, how should I approach this
Virustotal analysis:
https://www.virustotal.com/gui/file/afd2542891c7767380bd813543489bfa570d731cbfa7492bb0034d11805b8348
and
https://www.virustotal.com/gui/file/67246a7b73226c57ea4c2e388c11f1e92ff9ee5138181b59cab9ae97e462ffb1
I use 3 AVs, MalwareBytes, HitmanPro and ESET Online Scanner, only HitManPro has detected this file as malware but how can I be sure this isn't a false positive?
This file was downloaded from where it should be downloaded, in this case, the Modrinth website, so it's a legitimate file.
Recommendations for AV & Password Managers
I've been using Norton for so long, there HAS to be a better alternative to offer some decent features at a better price. Bloatware password manager essentially is all I'm paying for. Any recommendations would be greatly appreciated.
Not sure if this is a thing, but a way to import login credentials from Norton to this new service would be HUGE lol but if it has to be done manually, it just has to be done.
Thanks guys!
Need help with what to expect from a suspicious link?
Saw a link I absolutely should not have clicked. It ended in .mp4, and I clicked it - and it opened a tab, and immediately closed itself. I'm somewhat figuring ublock origin simply caught a popup or redirect and stopped it, but I don't know.
I'm running a malwarebytes deep scan, but I wanted to know if this should be something to seriously worry about before I go doing anything sensitive on my computer as it seems it'll be a WHILE before it's done, and need to know if I can continue or not.
I found an emulator called Gamenative. I don’t know if it’s safe, so I scanned it with Total Virus. The result is in the comments (Fortinet W32/PossibleThreat)
Question about antivirus protection
Me and my family were using Trend micro antivirus but it expired already and I want to know if we should renew it or get a different one, or do we just stay with the Windows Defender. My family likes to have an extra protection just in case.
Help scanning these two files , are them all false positive?
I scanned them yesterday on different platforms but I don't have the knowledge to understand if they are false positive or not.
Fl studio ( I scanned the extracted files separately cause of the size limit):
- Full result : https://tria.ge/260521-3avkfadv9z/behavioral1
- exe file : https://hybrid-analysis.com/sample/273ecdc1c2421628402b0e69ec927fda2d110fd2e7d55c2ffcd3a6c14cf78e8f
- cmd file: https://hybrid-analysis.com/sample/50ce6f1f5f5df76029f26625dd9ad45caf824eb21e9179edf29de4f7e6764fcb
- FLEngine_x64.dll: https://hybrid-analysis.com/sample/7753bb8b16752f0b31627d18f8fec6c33150ad490f66d96d290564ad0f548035
- engine_x64.dll: https://www.virustotal.com/gui/file/536926cea7910a4b3e7f34918ffd3f060f0abb9a2fa032fd2aaf6b9a857cf400?nocache=1
- engine_x64.dll: https://hybrid-analysis.com/sample/536926cea7910a4b3e7f34918ffd3f060f0abb9a2fa032fd2aaf6b9a857cf400
NeatVideo:
-Result 1: https://hybrid-analysis.com/sample/b6e7146c8dd2dac4dd19588647df1f4216fa2e6ce1560668899e2d25e7ed2b1f
-Result 2: https://www.virustotal.com/gui/file/b6e7146c8dd2dac4dd19588647df1f4216fa2e6ce1560668899e2d25e7ed2b1f
what is wrong with hitmanpro?
why has it suddenly been telling me about false positives and now it is showing me alot of tracking cookies suddenly?
there is nothing wrong with steam or the game it marked, why is it even marking marking steam of all things?
these were on 2 different days and it also kept marking steam as malware
what happened in the second pic was new
my ssd is running at 100% mostly writing speed looking to see if this is signs of a virus
I accidentally opened a sketchy .docx file, wondering what I should do
I woke up tired this morning and checked my outlook email on my iPhone right away. I received an email that looked like it was from my school, but related to nothing about any of my classes or anything. There wasn’t much text but there was a DOCX word file there. I tapped on the docx to open it, which was stupid, but when I tapped it, a grey screen immediately popped up and said something like it failed. I then quickly realized that it’s probably a scam and I shouldn’t have tapped it so I deleted the email. Should I be worried about malware on my phone?
Do you think it's worth switching from Defender to BitDefender in 2026?
Hi, so I've used Defender for a lot of years but last week I downloaded an untrusted app and the next day my Facebook and Discord accounts were hacked.
I formatted my PC protected all my accounts by closing current sessions, changed passwords, added 2SV. Also did a scan on the other drives/partitions to remove old malicious apps I had stored.
Since then I've been super cautious with my safety and did a browser extensions curation, installed Malwarebytes, and stopped using untrusted software.
Right now I'm considering switching from Defender to another Antivirus as Defender has improved over the years but it obviously didn't protect me enough.
Is BitDefender the best free Antivirus alternative to you?
Is my google chrome infected ? I keep getting this
Sorry for the potato pixel, but since this come out i dont dare to open anything on my browser so im posting this on my phone, anyone have any clues on this ? I tried google but seems like no one have anything similar to this issue
Update*
I tried opening google related websites on microsoft edge and it turns out the same too, now doing the offline virus scan thru microsoft defender
I don't know of this is actually a virus
Any help is very appreciated as im very nervous
i got hacked
idk why i sometimes like going on to porn website😭 but this time i got hacked by this website i just saw a comfirm your not a robot and i clicked it and my pc bugged out went green then pitch black and i had to shut it down and im never ever doing this again
Weird pop up
This is a new account cuz i got worried and figured I would ask reddit for advice
I was on the Harvard International Review site (.edu) and received this message as soon as I opened the site. While I didn't follow the instructions, I did hit the initial captcha arrow, and I am worried that something might still be on my computer. I cleared the history and cache from my browser, and ran the windows malware scan. Is there anything else I should do to keep myself protected? Would it be possible that I got malware from merely clicking the "I'm not a robot" prompt without following the instructions?
Trojan! Pls help
I have gotten virus into my laptop, I was using a vpn which asked me to copy paste a url/key (idk what it is) on my laptop using control+r
I did that and the vpn worked, but I also downloaded a couple of files. I think you know what I was doing. So in the mean time a couple hours after all this, my social was hacked and a mrbeast story was uploaded. I scanned my laptop for viruses and I came across 3. Let’s just say I can delete those downloaded files, what do I do next? Help me idk what to do. I can’t really format my laptop cause I have some important audio files.
Is this sonic.exe game malware?
I was looking at some sonic.exe files, then I found this one where everyone kept saying is the "original sonic.exe (2011)" one? I'm curious and I don't want to download any malware, It looks familiar to one a YouTuber known for testing malware and viruses out (tranium) played, but I'm not certain if it's the exact same one. It's file name is "SRK0K1FC" *I haven't downloaded anything*
Windows Defender detected VulnerableDriver:WinNT/Winring0. What should i do?
What should i do? Defender fails to remove it when clicking actions. Offline scan doesnt remove it and malwarebytes free doesnt detect it.
Hacking de mon compte discorde
Bonjour, il y a peut je me suis fait hacker mon compte discorde, le hacker s'amuser a envoyer a tout mes contacts des photos pour faire installer une appli de jeux d'argent en disant que c'était un évènement de mister beast et que si on le faisait on gagnera 2700 dollars canadien.
J'ai d'abord changé le mot de passe de mon compte et déconnecter tout les appareils mais quelques heures plus tard je me suis rendu compte qui avait réussi une deuxième fois a a hacker mon compte discorde mais c'était fois si il avait utilisé l'authentification a 2facteur. Depuis impossible de récupérer mon compte, mais plus bizarre c'est qu'il c'est aussi pris a mon compte chatgpt et mon compte Microsoft. Sur chatgpt il a envoyé des 10ene de demande de génération d'image.
C'est a n'y rien comprendre, si quelqu'un pouvait m'éclairer merci.
Ps, si des personnes sont intéressées par des photos des prompt qu'il a demandé je peux les envoyer.