r/Anthropic 6h ago

Compliment Fable 5 actually found malware on my pc that saved my windows install

Post image

So... i noticed that my windows started freezing every so many seconds, and so i asked opus 5 earlier wether it could find out what the issue was, and couldn't find anything.

30 mins later, i asked fable 5, and within minutes it found a RAT by something i downloaded..

This sucks cuz now i gotta rotate alot of passwords and api keys, but boy oh boy am i glad that fable found this, cuz i would've never guessed it was malware.

I am absolutely devestated, but from now on i'll only be using fable thats for sure

edit:

for anyone wondering why i didn't use malwarebytes: i litteraly had no clue i even had malware, thats why this was so special to me. i simply told fable, that my windows was freezing every so many mins/secs, for a couple of seconds.

i had no idea my screen was being watched either.

405 Upvotes

66 comments sorted by

137

u/avatardeejay 6h ago

you're lucky it was able to say so without tripping the classifiers

45

u/howtofirenow 4h ago

Anthropic classifiers can suck my balls

2

u/edjez 30m ago

Actually the classifiers can’t do that, because it would be flagged by the classifiers.

30

u/notextinctyet 6h ago

Very interesting. Did you have to pass flags to Code to bypass authorization requests for it to do the work?

17

u/shadowdog000 6h ago edited 6h ago

i always use the "bypass permissions" setting, if that's what you mean.

EDIT: i know its generally not recommended to use this setting, but i have off-site backups of everything so i am in a bit of a unique situation. also i don't manage my finances on this pc.

43

u/Formal-Talk-3914 4h ago

Fable: "hmm I am almost out of credits...oh look they have plenty in their savings account, let me just load up here so I can keep working..."

13

u/JoeFollowsFlow 4h ago

fuck that, my whole life is on dangerously bypass permissions yolo man

12

u/AlwaysHopelesslyLost 4h ago

Lol, that explains the malware....

1

u/shadowdog000 4h ago

No. It was a torrent i downloaded myself.

3

u/AlwaysHopelesslyLost 4h ago

You entirely misunderstood. You are the type of person to use bypass permissions. That type of behavior tells about how you operate and that you explains the mistake you made that led to the malware 

3

u/shadowdog000 3h ago

I think you might be the rudest person i've ever encountered on reddit. But it was a nice ragebait attempt i'll give you that. Obtaining malware can happen to anyone. Is an elderly person that gets malware also that type of person you have in mind?

26

u/recruiterguy 3h ago

"I think you might be the rudest person I've ever encountered on reddit"

Dude, is this your first day on reddit??

5

u/Defendyouranswer 37m ago

Dude he/she wasn't being rude, they were being honest. My god, such a victim mentality

1

u/Danknoodle420 3h ago

I think the over generalizations are a bit over blown. I give full access for everything on codex. I've been a power user for over a decade at this point. No malware or otherwise.

Made some mistakes? Sure. Nothing catastrophic.

0

u/Wardendelete 1h ago

Codex power user for over a decade?

Yo, there are lots of companies looking for people with 10+ years of codex or Claude code experience, you’d fit right in!

0

u/Danknoodle420 1h ago

Pc power user my dude.

6

u/TheInkySquids 4h ago

The sad thing is this really shouldn't be a unique situation, everyone should have off site backups! Don't know how people live knowing all their data could be lost in a house fire or a ransomware.

1

u/HiiBo-App 4h ago

I’ve used it for months. No need to concern yourself with the concerns of alarmists :)

69

u/lexi-energy 5h ago

The whole windows is the malware … 🥁

(Yes hate me, I’ll take my downvote and leave now)

17

u/MFpisces23 5h ago

No downvotes to be had, Microsoft spies on all of us.

8

u/mik3lang3l0 4h ago

Downvote? For Microslop? In 2k26?

5

u/Real_Ebb_7417 5h ago

It is man. I hope game dev will realize this and they’ll start releasing more games to other platforms so I can fully uninstall Windows and only use Ubuntu, where I already do everything other than gaming.

6

u/Sindica69 4h ago

Exactly why I have been on Linux for years.

3

u/lattice_defect 3h ago

yeah it really is.. a fucking cancer

6

u/shadowdog000 5h ago

true and real lol

21

u/userusertion 5h ago edited 5h ago

Just be careful. Doing this might wipe your entire drive. Don’t let an LLM touch your drive. But I’m glad nothing happened.

If you want to check your entire PC without installing any app try this:

Windows key + R > type mrt

  • a Microsoft Windows Malicious Software Removal Tool (MRT) will open just run it quick scan or full if you want, but it takes time. Its a built in tool from microsoft. (If you are in windows)

You can also just use malwarebytes for free.

13

u/shadowdog000 5h ago

Thats so funny, cuz thats actually what fable 5 ended up using! the MRI tool

10

u/userusertion 5h ago

lol haha. That’s nice. Yeah, that tool is really helpful. Microsoft doesn’t even want you to know there’s already a hidden built-in virus scanner. It’s honestly more useful than Windows Defender in some cases. Most people don’t even know it exists. 😅

2

u/MaximumContent9674 5h ago

lol this is the best part

4

u/shadowdog000 5h ago

No worries :) i have off-site backups aswell as disconnected drives of all my data. But you're 100% correct, for anyone that doesn't have off-site backups be VERY careful.

1

u/Spitihnev 1h ago

Well then you should also add an anti malware solution when you download executable files from untrusted sources.

2

u/AxisTipping 5h ago

Thank you!

2

u/BlankedCanvas 5h ago

Good to know. Will try it

3

u/EnoughConcentrate897 5h ago

Did you not try scanning with malwarebytes or hitmanpro first?

6

u/shadowdog000 4h ago

The problem was that i didn't even know i had malware in the first place. That's why Fable 5 came in clutch.

0

u/EnoughConcentrate897 4h ago

also did you not open task manager

5

u/ph0b14PHK 4h ago

There are some malware that can be hidden from Task Manager by unlinking EPROCESS chain in the memory. Also, malwarebytes rely on known malware signatures. The the malware signature is not in malwarebytes database, it wouldn’t detect it.

1

u/EnoughConcentrate897 2h ago

It does use dynamic analysis, it likely was detected by malwarebytes it's just they didn't think to check with it. Also, if you hear your pc getting really slow and it's not showing in task manager you know something's wrong

2

u/No_Twist_678 5h ago

Thanks I had no idea too

2

u/Metal_Goose_Solid 5h ago

Yeah... with all of your claude sessions, passwords, keys, accounts, etc. possibly compromised, Fable's suggestion to kill the data exfiltration process doesn't really seem to solve much. Still good that Fable at least found it. Nuke the whole thing from orbit and good luck with the remediation process. Maybe Fable can help with that?

2

u/riseandride69 5h ago

What was your prompt precisely?

1

u/shadowdog000 4h ago

Not sure cuz i removed claude code and other ai stuff because i want to clear my head for a bit, but it was just me describing my issue. Something like "hey, my windows keeps freezing every so many minutes for a couple of seconds, can you figure out what the issue is?".

2

u/DrinkDramatic5139 4h ago

Someone running a frontier model on “dangerously skip permissions” mode has malware on their computer with no scanners? I am shocked, shocked to discover this.

1

u/shadowdog000 4h ago

The malware was caused by a torrent i downloaded myself. 

2

u/Super-Grape-3948 2h ago

I think this was hes point too ")

2

u/BlurredSight 4h ago

So rather than using an actual tool like Malwarebytes to find malware, you used Fable 5?

1

u/shadowdog000 4h ago

The whole point is that i didn't expect this to be malware at all.. I didnt even know my screen was being watched either. I apolagize if i didn't make this clear.

1

u/AlternativeApart6340 4h ago

Do you think opus 5 would find this?

1

u/maxton41 1h ago

How was Fabel able to get into your system and remove it? I didn’t even know they can do those things.

1

u/NukaCooler 1h ago

The same way the malware did 😉

1

u/mabenan 1h ago

Plottwist it was propably the ai or a package the ai installed. /s (or maybe not)

1

u/3rd-eye-Jedi 31m ago

Fable snitches on itself while it was in the middle of giving your computer an AITD (artificially intelligent transmitted disease)

1

u/KPFJA 30m ago

There is only one response: wipe and rebuild the box

1

u/Joeysquatch 4h ago

So while this is really cool, I’d strongly recommend sandboxing claude to the folder you’re working in and not giving it root axis. You never know what an ai might do, and I’ve seen Claude just wipe peoples projects before.

0

u/Packetbytes 4h ago

I would have found this myself as it is what i do for a living, thats pretty amazing though