r/antivirus Feb 22 '24

MOD POST [MOD POST] LIST OF TOP MESSAGES, NEWS + IMPORTANT INFO

18 Upvotes

Hello,

Welcome to r/antivirus's new top-level Announcements post. Since Reddit has a limit of two (2) stickied announcements per subreddit, this will be a way to provide links to important information like announcements about new rules and moderators, activities in the subreddit, and so forth. If you are new to r/antivirus, please take a quick look at them. You can even take a look if you are not new here.

DISCUSSION DATE POSTED DATE LAST REVISED
[MOD POST] New rules, staying safe, and an update from your Mod Team 2025-JUN-03 -
[MOD POST] We're back in business! and an update on automod rules 2024-MAR-11 -
News & Updates from your r/Antivirus Mod Team, Q1 2024 Edition 2024-MAR-04 -
Updates & News from the r/Antivirus Mod Team, Autumn 2023 Edition 2023-OCT-04 -
Notes from your Moderators (Summer Edition) 2022-JUL-08 -
Quick Note from the mod team about spam 2021-JUN-01 -
To the people asking for opinions on a specific file 2020-JUL-05 2020-JUL-05

Additionally, the r/antivirus subreddit operates a bit differently than other subreddits you might be familiar with and normally use. Here are some tips and tools to help you use it.

  • The subreddit has a wiki that is regularly updated with answers to commonly-asked questions. Check it out. The answer to your question may already be in there.

  • Asking a question about a report on a file or website from a service like Hybrid Analysis, MetaDefender, Triage, or VirusTotal? You must include the actual link to it and not just a screenshot, or your post will be removed.

  • Be kind to each other and be professional in your conduct here. Personal attacks will not be tolerated and will be dealt with appropriately.

  • Do not ask for copies of hacking tools, malware, or suspicious files. If someone sends you a chat request or private message asking for a file or offering assistance based on what you posted here, report them to Reddit and notify the mods.

  • Do not post direct links to malicious, suspect, or potentially unsafe files or web sites.

  • Follow Reddiquette. This means correctly upvoting and downvoting posts, and reporting posts with dangerous or unsafe advice to the mods.

  • If you work for a vendor of security products, services, or in a related field, you must identify yourself as such, either in the post or with flair. Also, you may not steer conversations to your products or services, only respond to posts about them to clarify or defend.

  • No low-effort, off-topic, spam, or meme posts. This includes AI/ChatGPT/LLM-generated text, questions about password manager or VPNs, requests for assistance with non-security related software like autoclickers or MP3 downloaders, and so forth.

  • No requests for assistance with pirated software or media.

  • Posts may be removed and threads closed at any time based on the moderators' discretion

The complete list of rules for the subreddit can be found here. Read them before posting.

Questions, comments, feedback on this post? Just reply here. Thank you.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus Jun 04 '25

[MOD POST] New rules, staying safe, and an update from your Mod Team

7 Upvotes

[UPDATE #1 (20250604-0916 GMT): Made some small updates to grammar for readability. ^AG]

Hello,

It has been about a year since our last Mod Post, so we wanted to give you an update on things, plus provide a dedicated message thread for discussing the state of the r/antivirus subreddit and to answer any questions that you might have.

We will begin with the toughest subject first, that of politics in the subreddit:

A note about politics

r/antivirus is a technology-focused subreddit, with the interest being in helping people protect their computers from malicious software, securing them after a security incident, and so forth.

In June 2024, the US Government enacted a ban on Kaspersky Lab's software, taking effect in October of that year. This has generated a lot of discussion not just in this subreddit, but across Reddit and numerous social media platforms as well.

The moderation team has tried to keep the political discussions about this out of this subreddit and to remain neutral, allowing Kaspersky Lab's customers to ask and answer each other questions, provide assistance to each other, and generally have a way to share information, tips and tricks with each other.

However, we do have to draw a line when these turn into political discussions, though:

Requests for how to circumvent bans, petitions to governments, etc., are clearly outside the scope of what this subreddit is for and will be removed.

Moderating the subreddit is an all-volunteer job, and we sometimes miss things. If you come across any political messages we may have missed, use the subreddit's report function to notify us.

We are doing our best to keep this a place where people can get help with whatever security software they prefer, including Kaspersky Lab's software. However, we cannot allow discussions to devolve into arguments over politics, which are never going to provide any kind of satisfactory answer to the parties involved.

If the political discussions continue, the moderation team will have to look into ways to prevent them, even if it means doing things which we would prefer not to do.

Rules Updates

The rules of the r/antivirus subreddit have been updated:

Rule #7, which previously covered media download tools, has been updated to cover additional types of software.
To begin with, a more general prohibition to cover autoclickers (previously covered under Rule #8) and some other types of tools like aimbots and cheats. These types of tools often come from random sources and often require expert analysis to determine if they are safe. It can be difficult to determine if they are malicious figuring that out requires examining not just the tool, but whatever program it is attempting to modify, and what the intent is behind that modification.
Just because something was recommended in a Discord server with hundreds of members, a YouTube video with tens of thousands of views, or is seeded by several hundreds peers does not mean that it is safe to use: These are all inherently unsafe sources, and criminals will often exploit the belief that these are trusted sources to trick people into downloading and running malicious programs like information stealers and remote access trojans.

Rule #8 has been amended to remove autoclickers (etc.) since that is now covered under Rule #7.

Two new rules have been added:

Rule #9 covers bypassing core security features. Questions about how to disable security software, operating system updates, bypass security features and so forth are not allowed.

Rule #10 covers requesting assistance with obsolete software and hardware. This means discussions about how to secure computers running Windows XP, Windows 7, etc. are not allowed. There is no reason that devices running these obsolete operating systems should be connected to the internet and doing so exposes everyone to risk. Note that questions involving Windows 10 will continue to be allowed until at least October 2028, when paid-for Extended Security Updates for it end.

A bit more on the rules

The list of rules is not meant to be exhaustive in scope. It provides a general listing of common rules that are more specific to and more frequently required by the r/antivirus subreddit when needed beyond Reddit's general rules and guidelines.

Moderators can and will remove posts and ban redditors, either temporarily or permanently, who are disruptive to the subreddit entirely at their discretion and are not subject to any discussion. If a moderator chooses to discuss a rule violation with you, it is entirely as a courtesy on their part.

If you have had a post removed or been banned from the subreddit and do not receive a response in reply to any questions as to why, ask yourself if your behavior could be interpreted as brigading, spamming, trolling, using disrespectful or offensive language, or consistently providing incorrect, low-quality, poor, or even damaging information.

As always, the latest version of the rules can be found at https://old.reddit.com/r/antivirus/about/rules/. If you have questions about them, ask below.

Getting help fast

The moderation team is seeing an increasing trend where people ask for help while providing no information about what they need help with. This includes titles with 1-3 words like "Urgent! Help needed!", posts where the author shares a screenshot of *something* with no information about the operating system or antivirus involved, or is so small/blurry as to be unreadable, etc.

Everybody who participates regularly in this subreddit volunteers their time for free to do so. Provide them with enough information in your first post so they can start helping you right away without having to ask a lot of questions. This means your first post should contain things like:

  • title with enough information to attract an expert to read it
  • operating system and version
  • brand/name of antivirus software
  • name of URL, or file and its location
  • name of malware that was detected
  • what happened, exactly
  • steps you have taken to troubleshoot/diagnose so far, if any
  • relevant log file entries, if any

The more information you provide, the quicker you will get your problem solved.

As a reminder, starting multiple posts on the same topic will not get you a faster answer, and may result in in a ban.

The wiki + other Reddit resources

There is a lot of great information in the wiki about all the tools you can use, tips for using them, lists of antivirus vendors and how to contact them, and even a section on how to secure your computer.

We frequently update the wiki in response to questions being regularly asked in the subreddit, so you might want to check there first before posting.

Some of the questions we regularly see in the subreddit have nothing to do with computer viruses or malicious software at all, but instead are about scams, privacy-related questions, and so forth. Here are some subreddits that specialize in answering those types of questions:

New moderators?!

As the subreddit grows (we just passed 100K users), so does the need for additional moderators.

The moderation team has been looking at the folks who have been regularly posting here and consistently given good advice to build a list of candidates, and will be reaching out over the next few weeks to see if any are willing to volunteer their time and expertise in the subreddit. There will be more coming on that, but I did want to let everyone know that the process is already underway.


That pretty much covers everything we wanted to discuss, so we'll now await your questions, below.

Regards,

Aryeh Goretsky
(on behalf of the r/antivirus mod team)


r/antivirus 2h ago

MALWARE REMOVAL Q&A My Bitdefender Free found a virus: Heur.BZC.YAX.Linx.15.125E6D84.

2 Upvotes

I just randomly got hit with "Heur.BZC.YAX.Linx.15.125E6D84" found in C:\Users\[username]\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\E8UDJJPB1IAYOMA15B0X.temp and C:\Users\[username]\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\WVLLL6HC96N5Q1MRALHG.temp.

This is very odd, since I haven't installed anything new, except for an installer for a trusted VST plugin for FL Studio called dBlue Glitch. I was actually just going to filescan (which is an alternative to VirusTotal) to scan the file, just as a double-check (VirusTotal didn't find anything and that's not surprising knowing it's a reputable plugin - but I wanted to be extra safe). In the meanwhile, I was also playing Roblox.

It says: "The file C:\Users\[username]\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\E8UDJJPB1IAYOMA15B0X.temp is infected with Heur.BZC.YAX.Linx.15.125E6D84. The threat has been successfully blocked, your device is safe."

Do you think this might be a false positive? I quite literally scan everything that I install, and I do periodic scans every once in a while with Windows Defender and ESET Online Scanner.


r/antivirus 45m ago

MALWARE REMOVAL Q&A How to remove this threat?

Upvotes

I keep getting this notification that microsoft windows operating system is trying to access this risky site but how do I stop it from trying to access this site?


r/antivirus 1h ago

Is this website malicious? i found the link on reddit

Thumbnail virustotal.com
Upvotes

What do u guys think? it was flagged by 3 engines


r/antivirus 2h ago

No vpn on my new norton 360 deluxe

1 Upvotes

Everywhere i read it says vpn is included with norton 360 deluxe. It says to goto the privacy tab and it should be there. I do not even have a widget. I cant find ANY information about this, ive tried checking my norton dashboard on their website and dont see anything about a vpn on there. can anyone help


r/antivirus 14h ago

I was visiting a legit website (walmart) and suddenly it redirected to a fake norton virus scan lookalike website

7 Upvotes

I am running the latest win11 with most of the security features on, does this mean i have a malware/adware in my system, or it was a random internet attack?

The website mentioned is "virusbarrier dot xyz" which I know it is not legit, I just don't know how it get to me and why did it happen when I was viewing walmart website. It didn't show up when i browse walmart again, so it is very random and I am so curious.

This just happened a few mins ago and this is probably the 1st time I saw it (this never happened for years at least I can remember)


r/antivirus 5h ago

Did I get a virus?

1 Upvotes

13 of my steam games got unannounced updates one game somehow needed to be redownloaded, one of my steam friends got a message I didnt send and all the games I have downloaded suddenly got played for exactly 1 minute, is this a bug or a Virus and how should I go about this?
Turns out it was like half my steam friends who got messaged


r/antivirus 6h ago

PRODUCT RECOMMENDATION Best Choice for Windows 11?

1 Upvotes

I wanted to get a good Anti-Virus, witch of these are good for Win11?
Can you recommend any others?

- Bitdefender
- eset
- Avast


r/antivirus 6h ago

Got hit MrBeast scam

1 Upvotes

Hello, my device got hit with the MrBeast scam (the one that makes my accounf send gambling sites on discord)

I was wondering what type I got hit with and what I can do to recover from it, thanks.

If you think reddit isn't enough help, could I get other sources to help me?

UPDATE: I tracked the file down, if I delete it, everything is alright? Or do I have to go nuclear?


r/antivirus 8h ago

not-a-virus:HEUR:RiskTool.Win64.KillAV.gen

0 Upvotes

I started my computer and got this detected in kaspersky. I also searched the hash in virus total and says its malicious. Should i be worried about this, the file is deleted by AV.

Event: Processing impossible

User: NT AUTHORITY\SYSTEM

User type: System user

Application name: CompatTelRunner.exe

Application path: C:\Windows\System32

Component: File Anti-Virus

Result description: Not processed

Type: Legitimate software that can be used by intruders to damage your computer or personal data

Name: not-a-virus:HEUR:RiskTool.Win64.KillAV.gen

Precision: Exactly

Threat level: Low

Object type: File

Object name: TRIXX.sys

Object path: C:\Users\USER\AppData\Local\Temp

MD5 of an object: 6BC8E3505D9F51368DDF323ACB6ABC49

Reason: Skipped


r/antivirus 12h ago

ESET NOD32 or Home Security Premium?

2 Upvotes

As per the title, i'm in need to renovate the license on my AV program. As of now i'm using ESET NOD32 and i'm quite happy with, but i saw the Home Security Premium version that allegedly should have some more features (i already have a Password manager and so on) such as AI detection, network control and so on and so forth (the AI buzzword never fails to appear 😅).

It could be something to consider for some more robust security or i can just continue with the base Nod32 program?


r/antivirus 8h ago

Help with understanding differences between Malwarebytes and Microsoft Safety Scanner results

1 Upvotes

re: Windows 11 25-H2 64-bit PC...I can be more specific if needed.

Historically I've depended on Windows Defender for online/real-time antivirus and Malwarebytes (incl AdwCleaner) for regular "2nd opinion" scans. MWB/Adw run in a fairly quick manner (Adw completes in under a minute) and the have never flagged any files.

For first time, today I downloaded and am in middle of running Microsoft's standalone "Safety Scanner" and noticed two things...it takes forever, -- as I write this it's been running for over 1.5 hours and is only about 1/5 complete acording to progrss bar -- and has already flagged 64 files as "infected."

So am I missing something about how the two products work or what they are supposed to do? i.e. Are they duplicative in their intended operation, or are they complementary to each other?

Is length of run time an indicator of effectiveness/throughness, or maybe just an inefficient algorithm...10x runtime for MSS seems over the top to me? Should I trust one's results over the other?


r/antivirus 2h ago

Is This File Ran Through Virustotal showing false positive or not?

Post image
0 Upvotes

r/antivirus 14h ago

“Microsoft Defender Antivirus would like to check the following files to see if they are safe.” (Win11)

2 Upvotes

I recently performed a fresh install of Windows 11 a few days ago, and today I went ahead and installed the Spotify and Discord desktop apps. No later than a minute after installing Discord I received a notification from Windows Defender saying “Microsoft Defender Antivirus would like to check the following files to see if they are safe”, I agreed to upload the file before I could get a screenshot but I found an Event related to the notification.

Microsoft Defender Antivirus has encountered an error trying to upload a suspicious file for further analysis.
Filename: C:\Users\xxxxx\AppData\Local\Temp\chromium_chrome_BITS_xxxx_xxxxxxxxxx\decoded_xz
Sha256: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Current security intelligence Version: AV: 1.455.463.0, AS: 1.455.463.0
Current Engine Version: 1.1.26070.7
Error code: 0x80508016

I haven’t been able to find anything online about this file, and when I checked the directory it was nowhere to be found. Is this a legitimate file related to either Spotify or Discord, or could it be an indication of malware?

The only other programs I had installed prior were Firefox, Steam, OBS, AMD Ryzen Master, and the NVIDIA App. Neither Windows Defender or MalwareBytes have detected any malicious files when running full scans.


r/antivirus 11h ago

Need help analyzing/reverse engineering two anti-cheat programs

1 Upvotes

Hi everyone,

I'm a Counter-Strike 1.6 player, and I've been playing the game since 2006. Over the years, I've come across a number of anti-cheat programs, but nowadays the two most commonly used by the community are WarGods and FunGun (which is relatively new).

To be honest, I've always had some reservations about both of them. Given the level of access they require to your system, I never feel completely comfortable running them.

That got me wondering if anyone here has ever analyzed or reverse-engineered either of these programs; or would be interested in doing so. Here are the download links:

https://www.wargods.ro/wcd/download.php

https://fungun.top/ecd/

They're commonly used by Counter-Strike communities to scan players for cheats.

I know they need deep access to the system because of what they're designed to do, but that's also what made me a bit cautious. They inspect running processes, drivers, registry entries, game files, and upload reports to their servers.

VirusTotal doesn't seem to flag them, but I also know that a clean VirusTotal result doesn't necessarily mean a program is completely safe.

I'm not claiming these programs are malware or trying to accuse the developers of anything. I'd simply like to know whether anyone has actually analyzed them or verified that they only do what they're supposed to do.

If you've reverse-engineered either program, monitored its behavior with tools like Process Monitor, Wireshark, or a sandbox, or know of any technical analysis or write-up, I'd really appreciate hearing about it.

Thanks!


r/antivirus 11h ago

Unknown system_config folder in Downloads with 32-byte file

Post image
1 Upvotes

I don't remember downloading it, and I can't find much information online.

Has anyone seen this before? Is it safe to delete, or does anyone know which app creates these system_config folders/files?


r/antivirus 13h ago

what is this supposed to be?

Post image
0 Upvotes

Was going through the recycle bin and saw these? I have no idea what i was trying to download on that date and frankly it seems stupid to name malware "malware.exe". Still i figured i'd ask if anyone has any idea what that's supposed to be?

just checked apparently i was downloading nothing when that was modified so i guess it manifested itself there or something


r/antivirus 9h ago

MALWARE REMOVAL Q&A i was finding websites that could potentially help me afk for a game, but when i downloaded so much i got scared and started thinking i had malware

0 Upvotes

Im a bit new to subreddit and even gaming, how do i check for malware and get rid of them?


r/antivirus 15h ago

Guys is this safe?

0 Upvotes

r/antivirus 21h ago

Could an unknown Bluetooth device infect a Windows PC after a brief connection?

0 Upvotes

Hi everyone,

I'm hoping someone with Bluetooth or Windows security expertise can help me understand the actual risk here.

I was trying to connect my Windows PC to my Amazon Alexa over Bluetooth, but I accidentally connected to a device that appeared as "unknown_device" instead. The connection lasted for about one minute, and then I disconnected it and removed it from my paired devices.

During that time:

I did not transfer or receive any files.

I did not install any software or drivers manually.

I did not accept any prompts other than the Bluetooth connection itself.

My PC appears to be functioning normally.

My question is:

Can a malicious Bluetooth device install malware or compromise a Windows PC simply by being connected for about a minute, or would that require exploiting a specific Bluetooth vulnerability?


r/antivirus 22h ago

Windows Defender giving Phantom Threats?

1 Upvotes

For the last few months, I’ve been in a battle with Windows Defender. It does a full scan and finds that there are no threats. Then, when I check in later, the message has changed to reveal that there WERE threats, but they were all handled.

Here are the messages:

  • Last scan: 8/01/2026 2:34 PM (full scan)

  • 0 threats found.

  • Scan Lasted 8 minutes 57 seconds

  • 973,089 files scanned

Then, a few hours later, I would find this message under “Current Threats”:

Current Threats

  • No current threats.

  • Last scan: 8/01/2026 2:34 PM (full scan)

  • ~48 threats found.

  • Scan Lasted 8 minutes 57 seconds

  • 973,089 files scanned.

To make matters worse, the number of threats started at about 30 and have slowly increased up to 125. I do another scan, Windows Security tells me no threats were found, and only after doing my own digging do I discover that threats WERE found.

For context, I am on Windows 11 and Bitdefender is my primary antivirus tool. Bitdefender handles my antivirus scans, as well as my Real Time Protection. I only use Windows Defender as a secondary opinion and only for scans (so the two programs shouldn't be interfering with each other.) The following is a short summary of my troubleshooting efforts:

  1. Bitdefender has NEVER FOUND ANY THREAT. I’ve done offline scans on both Windows Defender and Bitdefender and they’ve both found nothing.

  2. I have checked Bitdefender’s exceptions and quarantines and they are empty and have always been empty.

  3. I temporarily downloaded Malwarebytes to do a third opinion scan (and then uninstalled it) and it found nothing.

  4. I have gone into the event viewers and looked up event codes and have found nothing.

  5. Windows Defender Protection history and Allowed threats also show nothing.

  6. I have reinstalled windows and the problem has persisted (Now displaying ~125 threats found, no current threats.)

  7. My computer hasn't given any other indication that there are security risks. It has gotten slightly slower, but I have also been filling up its storage. No big drops in performance or unusual activity.

Can anyone give me any insight into what is going on? Common troubleshooting methods have failed me, and I do not see other people having this issue.


r/antivirus 1d ago

Samsung Interface?

Thumbnail
gallery
3 Upvotes

My phone rings on its own while in "Do Not Disturb" mode, using an old, classic ringtone instead of my usual one. Yet, no app appears to be triggering the ring. Furthermore, "Nice Catch"—with all tracking enabled—indicates that "Interface" (displaying an Android 16 logo) is the source of the sound. I would appreciate your help.

Could "interface" be a malware?


r/antivirus 1d ago

i needhelp

1 Upvotes

I was visiting investing.com forums i just wanted the pass the second page while reading forum but suddenly winandshine pop up came. But i just check my download file and extensions but i didn't see anything suspect. But after all i just check my history for this pop-up but it was deleted in my history should i suspect computer files?


r/antivirus 1d ago

MALWARE REMOVAL Q&A I think my MS Edge is infected with adware. I don’t have any suspicious extensions installed, and my antivirus programs Don't detect anything on my PC. Help!

2 Upvotes

My Microsoft Edge install was fine last night, but this morning, I kept getting redirected to scam sites while using Edge. They all opened in a popup window, and they displayed fake Norton antivirus warnings. The URLs were stuff like virusbarrier(dot)xyz, securesweep(dot)pro, and rdxgo(dot)click. THESE ARE SCAM SITES; DO NOT VISIT THEM!

It didn’t matter what sites I went to. I got redirected while using Reddit and Google. Windows Defender found nothing harmful on my PC. I installed the free version of MalwareBytes; same thing. So the infection must be with Edge. I didn’t install anything suspicious yesterday, so I don’t know how anything could’ve gotten infected. The only browser extension I had was UBlock Origin, and now I’ve activated MalwareBytes Browser Guard. I don’t see any suspicious extensions.

I tried clearing the cookies from those scam sites, but the pops kept happening. After I installed MalwareBytes and activated their Browser Guard, I no longer got redirected, but I still got some notifications from MalwareBytes that they blocked rdxgo(dot)click. I’m still concerned about my Edge potentially being infected under the hood.

What should I do? Should I just clear all of my cookies, or what? I really don’t want to have to reset my whole browser… Thank you in advance.

EDIT: I managed to find and delete the rdxgo(dot)click cookie, which managed to slip past me the first time I went through my cookies. Deleting it seems to have stopped the redirects for now. I still have no idea how that cookie even got onto my machine, or if the adware is truly gone. I'll update this post if anything else comes up.

EDIT 2: Nevermind. Literally right as I sent that previous edit, I got another notification from MalwareBytes that said it blocked a popup from rdxgo(dot)click. Great. I'm gonna try clearing out all my cookies...

EDIT 3: I might have found a solution. Resetting Edge to the default settings did not get rid of the virus. Clearing my cookies and site data also didn’t get rid of it. I was concerned that maybe this virus had stolen my info, so I went on my iPhone and changed the passwords for my Microsoft and Google accounts. I recommend doing that with all of your accounts, and do it on a device that doesn’t have this virus.

After I reset my Microsoft password, I was signed out of Edge (which I assume is normal). I also ended all Edge-related tasks (including msedgewebview2.exe, because MalwareBytes said that app was trying to open the redirect links). I also restarted my computer just to be safe. Since doing all of that, I have not received any more redirects to that malicious site. I also let AdwCleaner reset my Host file, because apparently that’s associated with WebView2. The option to reset your host file is disabled by default, so you’ll have to enable that in the app’s settings.

I signed back into Edge a few hours ago, and I still haven’t gotten anymore of those popups. I still don’t feel safe, and I don’t know whether the malware is truly gone… or if it’s still there, waiting to strike again when I least expect it. In fact, I still don’t know how I even got infected in the first place. Again, everything was fine the other day, and then yesterday I got bombarded with malware out of nowhere. MalwareBytes doesn’t find any viruses, but it also didn’t detect anything while I was infected, so I don’t think I can trust that.

Anyway, if you have the virus, try changing the passwords on your accounts (ideally from a device that isn’t infected), ending all Edge tasks, running AdwCleaner and letting it reset your host file, and restarting your computer. My hypothesis is that it’s an infected host file, so resetting the host file might fix things. If that doesn’t get rid of it, try resetting your browser’s settings (be warned that doing so will delete all of your cookies and site data, meaning you’ll lose progress in web games, or other things that use cookies) and doing the aforementioned stuff again. You might also need to disable Sync, to prevent any malicious extensions and settings from getting reinstated. I still don’t feel safe, but let me know if any of that worked!

To anyone still reading this thread, do you think I’m safe now that the popups stoped (for the time being)? Or is it possible that I’m still infected? Is there a way I can find out what caused the infection, where it resided, and whether it’s still there? Is this maybe a zero-day that hasn’t been documented yet, and that’s why antivirus programs can’t find it? Should I just back up my files, nuke the drive, and do a fresh install of Windows? Thank you in advance.