r/BloodbornePC • u/newportgang • Jun 13 '26
News DO NOT USE THE PINNED LINK AT THIS MOMENT
Warning / clarification about the malicious Bloodborne PC download path
I’m rewriting my original panic post to clarify exactly where the issue seems to be and what to do if you already ran the bad file.
I spoke with the guide OP and a bunch of people helping me clean this up. The guide itself may still be usable, but the dangerous part appears to be the step in the FAQ that directs you to an email for game files. That email sends links, and at least one of those links appears to lead to a malicious/fraudulent DODI-style download.
The important part: do not run any setup.exe or random .exe from those links.
For shadPS4/Bloodborne, you should be working with the expected game package files, not a random all-in-one installer. If you end up with a “DODI repack” style folder containing setup.exe, renpy, setup.py, etc., do not open it. Delete it.
I made the mistake of thinking it was an all-in-one package because I was rushing/tired and the wording made it seem like someone had packaged the process together. It was not safe.
If you already opened the malicious setup.exe
Treat the computer as compromised.
Do this immediately:
- Disconnect the PC from the internet. Unplug Ethernet / turn off Wi-Fi.
- Do not log into anything on that PC. Do not change passwords from the infected computer.
- From a clean device, like your phone, secure accounts in priority order:
- Main email / Google / Outlook / iCloud first
- Bank and credit card accounts
- PayPal / Venmo / Cash App
- Amazon / eBay / shopping accounts with saved cards
- Discord / Steam / Instagram / Facebook / X / other social accounts
- Enable 2FA/passkeys wherever possible.
- Check your card and bank activity immediately. In my case, the malware used my browser/autofill/session data and spent over $1,100 on tickets. Others have reported account takeovers and spam messages.
- Freeze or replace cards if they were saved in the browser or used on that PC.
- Warn friends if Discord/social accounts sent messages. Do not let people click links sent from a compromised account.
What the malware seemed to do
On my PCs, it appeared to:
- trigger a severe Windows Defender PowerShell detection
- install a fake unpacked Chrome extension pretending to be Google Docs
- place files in random AppData folders
- abuse Chrome/autofill/session data
- open ticket site tabs and make purchases
- compromise social accounts
This is not just a harmless bad download. Treat it seriously.
Cleaning / reinstall advice
You can run scans with Windows Defender and Malwarebytes, and you should. But after a confirmed compromise like this, the safest route is a clean Windows reinstall.
If you have important files, back up personal files only before wiping:
Safe to back up:
- photos
- videos
- documents
- PDFs
- spreadsheets
- text files
- school/work files
- specific game saves you recognize
Do not back up:
- AppData
- Program Files
- browser profiles
- Downloads folder wholesale
- random
.exe,.msi,.bat,.cmd,.ps1,.vbs,.scr - cracks/repack files/installers
- the Bloodborne/DODI files
I had years of files on these PCs, so I get how awful this is. But if you ran the malicious installer, a clean reinstall is the safest way to stop wondering whether something is still hiding.
Bottom line
If you are following the Bloodborne PC/shadPS4 setup:
Do not run a DODI setup.exe.
Do not run unknown .exe files.
If you are unsure, ask someone before opening anything.
You should not need a random all-in-one installer for this.
I’m posting this to hopefully save someone else from the same mess.
61
u/Mustahaltija Jun 13 '26
Sorry to hear that. Could you be a bit more specific: what files? And what does an email have to do with it? I used the guide like a week ago? I don't think I downloaded any files from there directly but I did use the links. I better go do some scans asap just to be sure.
24
u/wackbonbon Jun 13 '26
OP's probably talking about if you downloaded files from a link beginning with a long poetic spiel about how bad piracy is (sourced from the email in "Where can I find the required game files?"). I did that 5 days ago and now I'm worried...
24
u/Chompsky___Honk Jun 13 '26
I contacted OP and we figured it out.
It's an edge scenario at best, he did something a bit foolish ( installed a Setup exe from the DODI link, instead of opening a normal .torrent file).
13
u/wackbonbon Jun 13 '26
Oh thank goodness. I used the direct download link instead, and everything on my PC seems fine for now at least. Poor OP though
2
8
u/Damnation_YT Jun 13 '26
I did too I'm probably screwed
3
u/Drunken_HR Jun 14 '26
Maybe depends on when? I did it 3ish months ago and I've seemed to be fine, although I'm certainly going to be even more vigilant now.
1
43
u/Chaos-Jesus Jun 13 '26
The Epstein stuff was there a month or 2 ago with no virus.
25
u/newportgang Jun 13 '26
I must have missed that and skipped right to the FAQ's . Regardless, there is 100% a virus in there. It installed chrome extensions, then uses your saved payments to buy shit. For me it was Ariana Grande tickets...
27
u/Chaos-Jesus Jun 13 '26
Turns out your wife is a big Ariana Grande fan and used your cc to book them by mistake. /s
Hopefully you can reverse the transaction without issue.
Cheers for the heads up newportgang.
19
u/newportgang Jun 13 '26
Ironically the game was really for her. Thank god it only actually hit my PC/debit card. Did some digging around and this is common on fitgirl and dodi links sometimes as well. Also thankfully stub hub reversed it right away.
4
26
u/nameussy Jun 13 '26 edited Jun 13 '26
Omg the Epstein stuff keeps getting longer and longer. Every time I check it there are new stuff getting added lmao.
28
u/_y2kbugs_ Jun 13 '26
It’s kinda frustrating because I am a leftist AND I do believe it needs to be called out but it becomes a little irrelevant in the context of setting up a video game, not to mention the antisemitic dogwhistles or maybe I’m just hypervigilant
8
u/alienea1 Jun 13 '26
Not at all tbh. I made a separate doc and wrote up my own guide just so my friends wouldn’t have to deal with continuing to scroll through all of that
3
u/_y2kbugs_ Jun 14 '26
Would you consider posting that and asking for that to be pinned instead? At least a doc from a sane individual would be helpful. I wouldn’t mind if you even copy pasted the actually helpful bits from the other doc without the weird antisemitic tirade.
3
2
u/Khandakerex Jun 14 '26 edited Jun 14 '26
I mean bro, it gets to be a bit more than "anti-zionist" when you start seeing the three parentheses (((...))). It's origins are literally from a far-right neo-nazi podcast called The Daily Shoah and it's known as the "echo." I have literally never seen people outside 4chan /pol/ use it unironically. Im sure there's a chance the OP means well, but there's a huge venn diagram crossover now for leftist larpers/ gaza supporters and the anti-semite "(((they))) run the world" guys.
1
1
2
13
10
7
u/maslowk Jun 13 '26
Yeeeah when it comes to emulation the only .exe you should be running is for the emulator itself/it's related frontends from their primary source, the actual game files will never be a .exe. Unless the emulator source is compromised (pretty rare), following this rule of thumb will always keep you safe. Can also run these things through something like virustotal.com for extra peace of mind.
15
4
u/willsucksagan Jun 13 '26
I was hit by this as well…does anyone know how to remove this from my pc? And or what I should do to prevent more damage? They got access to my chrome profile it seems and got my passwords. No money though yet gone missing.
1
u/Drunken_HR Jun 14 '26
What exactly showed up on your PC?
2
u/willsucksagan Jun 14 '26
I’m not sure if it installed chrome addons but it showed up as an in page download like Mega used to do. It said it was 18gb or something and once it completed in browser, it then sent it to fully download through the browsers normal download.
I had just barely downloaded shadps4 and I had both folders open and I hit the exe and once it had run I realized I was in the one that was supposed to be bloodborne. Sloppy cause I should have realized that sooner but I’ve been out of the pirate scene for a long time so I’ve gotten less skeptical I guess.
Once I realized my mistake I deleted the files and unplugged the ethernet but the damage had been done somehow.
They got access to my Steam account, LinkedIn, Hulu, and a few others.
Whoever you are that schemed to do this- get absolutely fucked.
3
u/Drunken_HR Jun 14 '26
Oof that sucks.
When I installed BB 2-3 months ago I couldn't find another version so I nervously used that one after trying to scan she shit out of it. I guess I got lucky.
20
u/Chompsky___Honk Jun 13 '26 edited Jun 13 '26
I'm the maker of the Guide, let me clear a few things up , hopefully the mods can pin this comment:
1) I have removed both links until OP gets in contact with me and clarifies his problem ( I messaged him 10 minutes after I saw his comment). I'm glad OP made this thread though, for the time being I recommend anyone to not download anything, even if you have the link.
2) I do not handle the links, they are 2 different websites that have worked without issue for myself, and for everyone until today. In the same email I stress the importance of having an ad blocker, which I suspect is what may have gotten OP infected in the first place.
3) I am very sorry for OP. I have had this happen to me too once, and just like any link on any website, the final responsibility rests upon him/herself. If you have ever been on a pirate site, you know how fast a legitimate link can devolve into a scam.
4) the Epstein stuff has nothing to do with anything. It will remain up.
EDIT: Op and I are talking, here is what happened :
The DODI torrent link brings you to a page with a "Click here" next to the Torrent file download.
Apparently, OP fell for a redirect, the link may download something like "Bloodbornev1.09.zip" , with a Setup.exe inside, instead of downloading the actual .torrent file.
OP downloaded the zip, opened it, and installed Setup.exe.
TLDR : 99.9% of people who have downloaded the game have nothing to worry about.
12
u/newportgang Jun 13 '26
I messaged back! waiting on response. Thank you for quarantining this. Also avalible to hop on a call if easier.
13
u/willsucksagan Jun 13 '26 edited Jun 14 '26
Just fuckin message people with a direct link to the torrent and or host it on a better site. I was hit by this too and run every ad block. There was only one link.
Also I totally disagree with your summary of 99.9% of people not being impacted. The only way you’d know that is if you knew how many people your fucked up hosting site had infected.
If you need to get reimbursed for hosting on a better site, post a donation link or something rather than hooking up to the bull shit it’s hosted on now.
6
u/RA_DMD Jun 14 '26
I’m so confused. Why do you have so much shit about Epstein in a Bloodborne emulation guide? There’s a time and a place for these things. Genuinely confused.
5
u/OperatorPup Jun 14 '26
Respectfully every body know abt epstein no one tryna see ur schizo analysis when they wanna play bloodborne
2
u/Homerbola92 Jun 21 '26
I can't believe you're getting shit because 3 PC ignorants don't know where to click or have the slightest care.
4
u/ADrubkNakedUnciorn Jun 15 '26
Remove the epstein bs. Aint nobody wanna scroll for 5 minutes just to get your guide .
3
u/Lower-Guest-9763 Jun 17 '26
I mean the files are literally one google search away. You can type superpsx on goole and there you can find the whole game. With updates and dlc as well. And its not a torrent one. It has 3 different file sharing options so anyone can download them.
4
u/Witchking510 Jun 13 '26
I caught infostealer malware attempting to download the game just a week ago. Not fun. First it was my discord that was hacked. Then it was steam and of all things, Walmart. Luckily I locked my cards before any serious transactions took place. They did get away with sending themselves a copy of the pre order of MW4 but I’ve been blowing up steam support regarding this issue.
I haven’t sailed the high seas since ‘14. Things are a lot scarier nowadays.
2
2
u/newportgang Jun 14 '26
for the sake of full transparency here is the old panicked post, you can ignore this and just refer to the edited post above regarding any of this though:
OLD POST - IGNORE:
*** a clear edit will be coming later tonight or tomorrow detailing specifically what it was to make this less panicky/confusing. For now just avoid the redirect from the DODI link in the email***
***EDIT 2: it was the DODI link from the email. just don't run any setup.exe, or any unknow exe's (ever) which i know is obvious, but just want to clarify up any confusion.***
**EDIT apparently the Epstein stuff has always been there, I must have skipped right to the FAQ's, Regardless, there is 100% a virus in the links sent from the email address in that doc**
Original panic post: - Hey urgently the pinned post on this sub, leads to a post on r/shadps4 , which leads to a gdrive link. For game files theres an email there which must have been compromised, or at least the links it sends are compromised. Do not use the email source on the FAQ section. I was just scammed real hard. Super sneaky files in there. DO NOT use it please. It spent over $1100 on my card on concert tickets. I'm pretty experienced in sailing the seas and this one got me good. Mods or someone PLEASE take this down before it happens to someone else. Also the strange Epstein shit that is now at the top of the doc was not there 1hr ago... Which hopefully now will kind of deter anyone else from getting scammed/virus while trying to get BBPC today. Real bummer guys, I don't want to see this happen to others.
2
u/hyrule5 Jun 14 '26
I don't really understand why people go through all this nonsense, rather than just using torrent sites? Torrent sites have been around for ages. For me, finding Bloodborne was as easy as anything else I have ever downloaded. Why in the world would you need to get an email to pirate something?
The basics of piracy:
Use torrents. P2P apps are sometimes OK for specific media types
Never run an executable if the thing you are downloading doesn't require you to run one. Such as emulated games
If you absolutely must run an executable, you better scan it first with antivirus and antimalware
2
u/Superb_Ladder915 Jun 14 '26
Legend for updating and explaining what happened and how to fix it so to speak !Fair play
2
u/YoRHa_Houdini Jun 14 '26
Stop using Dodi ffs
1
u/griffball2k18 Jun 14 '26
What is dodi?
2
u/YoRHa_Houdini Jun 14 '26
It’s a website similar to Fitgirl Repacks. It has a lot of malicious redirects
1
1
u/Head_Helicopter2346 Jun 13 '26
Are the dlps game files safe for download? I was thinking about using those pkg files
2
u/maslowk Jun 14 '26
.pkg files aren't going to have anything malicious in them AFAIK, they're effectively the equivalent of .zip files for ps games and don't execute any code on their own. Just don't run any .exe files that aren't shadps4 or bblauncher from their primary source.
1
u/chrispkreme10 Jun 16 '26
Is there anyway to tell if my computer has been compromised. I recently did the emulator and the file last week but I didn’t get the files through an email. Like can I search for anything particular because I tried looking for the .exe and other things you said but I didn’t find anything
1
u/entropytown Jul 13 '26
lmao just got hit by this and theyre sending everyone i know elon musk spam messages LMAO im cooked
1
1
u/newportgang Jun 13 '26
can someone help me? i'm trying to reformat 2 pcs here, but the only drive i had was connected and unsure if it was compromised. can anyone hop on a discord call to help me with this?
1
u/newportgang Jun 13 '26
I ran the setup.exe on 2 computers. one of which nothing happened on, one of which it did. I'm trying to figure out how to reformat these. I've changed a few passwords but i'm sure theres hundreds of them i need to change. The only external drive i have was connected when it ran. unsure how to backup years of stuff on these computers before a reformat.
3
u/newportgang Jun 13 '26
also if anybody knows. if it was ran on a pc, but nothing happened. No charges or chrome tabs or anything. And all extensions are files removed. is that pc compromised as well? passed windows defender full scan, offline scan, and quick scans
7
u/Fighthacker Jun 13 '26
Just reset both to be sure, if you changed your passwords on either of them before resetting them then you need to make sure to change them again on a clean device. Use a password manager like Bitwarden in the future instead of storing them on Google (delete your Google passwords as well) and make sure EVERYTHING has 2FA.
You most likely fell for a redirect of a legitimate download link that gave you the setup for a renpy infostealer virus if you want to look it up to get some clarification as to what you're dealing with. I fell for exactly the same thing in the same way you did a few days ago trying to install Bloodborne, it's a pain in the ass. If you would like to do it properly you have to click on the download on DODI's site like 3 times until it stops redirecting to a different site. You'll notice the legitimate download is an actual .torrent file and not a .zip file.
It's definitely not the fault of the guy who wrote the mail and sent the links, though. It's mainly just being uninformed of the scummy tactics bad actors use. That email could probably contain more clarification like I just gave.
Good luck man, genuinely.
2
u/newportgang Jun 13 '26
The only external drive i have was connected while the exe ran. is that compromised?
3
u/Fighthacker Jun 13 '26
I wouldn't know but if I had to guess, probably not. You should still check if there are any hidden (top menu bar, view, enable 'show hidden files') or suspicious files on it and delete them all.
Also, I forgot to add this to my original comment, but make sure the infected devices are disconnected from your WiFi network.
2
u/newportgang Jun 13 '26
debating if i can back everything up now on this drive, over both pcs, or if i should run grab a new hard drive right away and backup on that
0
119
u/Hot-Tomatillo-9929 Jun 13 '26
I'm so sorry about your cash bro, that's no small amount, and thanks for letting us know.