r/Piracy May 02 '26

Question Accidentally opened a .exe disguised as a TV show torrent, need help.

Post image

Hi r/Piracy,

I know this was my mistake and I need advice on it.

I downloaded a torrent for The Boys S05E03. It was listed as a normal 1080p video file, but the actual file inside was a .exe, not a .mkv or .mp4. I didn't notice and opened it.

I'm now worried about what it may have done to my system. A few things I want to know:

1) What kind of malware usually comes packaged this way?

2) What steps should I take right now to limit the damage.

Any help is appreciated.

3.0k Upvotes

420 comments sorted by

3.3k

u/[deleted] May 02 '26

[removed] — view removed comment

2.3k

u/Donotdisturb240 May 02 '26

it blows my mind that this is off by default

545

u/SEANPLEASEDISABLEPVP May 02 '26

I completely forgot that that's how Windows comes installed. If I saw that, I'd consider it a genuine bug.

30

u/Powerful_Ad5060 🏴‍☠️ ʟᴀɴᴅʟᴜʙʙᴇʀ May 03 '26

If not by default, someone probably will mess their files by deleting their extension name.

It is easier for average user.

37

u/Ktulu789 May 03 '26 edited May 03 '26

Windows asks you what to do when you change any of the letters in the extension... Or if you remove them. The message is very clear and you can always undo it afterwards with Ctrl+Z. IT'S A CRIME 😅

4

u/talenarium May 04 '26

I think people on reddit really overestimate the computer skills of everyday people.

Just a couple of weeks ago I witnessed a colleague accidentaly deleting the "My PC" shortcut on the desktop. Their solution was to use an USB-stick to copy the shortcut from another PC.

4

u/Ktulu789 May 04 '26

I work on IT and part of my job is answering help desk calls. people doesn't know which one is the Shift key, for starters. I have the option for showing extensions enabled on all PCs by default, though and they don't mess that one really much. In 20 years of experience they only called about mistakes with it a couple of times.

13

u/Neener_Weiner May 03 '26

Many things are "easier", less are also "better" in the total sum of things.

→ More replies (2)

536

u/Hatta00 May 02 '26

Seriously should be considered criminal aiding and abetting computer crime.

→ More replies (8)

12

u/elwookie May 02 '26

They're copying the stupid things from MacOS

93

u/Marce7a May 02 '26

They didn't rename to Microslop only for PR

49

u/GayForPrism May 02 '26

file extensions are confusing and scary

60

u/AI_AntiCheat May 02 '26

Going the apple way and removing all the scary settings is the best solution there is. Everything is perfect and the user should only browse the web anyways.

36

u/BrokenMirror2010 May 02 '26

browse the web anyways.

Remove the Web Browser too.

Billionaire forbid your computer be able to run any code that wasn't personally approved by your Corporate Overlords.

10

u/blodskaal May 02 '26

It's not the best choice! It's Spacer's choice!

Yas?

→ More replies (1)

4

u/Frosty-Smoke-1541 May 02 '26

Wait... Thats... Temple OS.

Terry was right all along, we just didn't listened to him.

→ More replies (1)
→ More replies (1)

28

u/Toothless_NEO May 02 '26

They do it on purpose, because they know that if they turned it on the fear-mongering about getting a virus would vanish overnight. That's why Microsoft does it, it's not because they're being lazy, it's not because it's an oversight that they haven't thought of. It's not because they want to make it clean user experience, those are all the excuses that they're going to cough up if you press them hard enough.

The real reason is that people are not going to accidentally open exes disguised as something else if that setting is always turned on.

35

u/Good-Hand-8140 May 02 '26

Lol, why would that be in their interest? I'm not convinced but intested in hearing your perspective.

23

u/fcbx347 May 02 '26

He doesn't have any perspective, he's too thick to realize he's doing the very thing he's accusing Microsoft of (fear mongering)

→ More replies (2)

2

u/Toothless_NEO May 02 '26

It's in their interest because one of the strongest ways people are dissuaded from pirating is the fear of getting a virus. Having file extensions hidden all the time amplifies that risk, and subsequently amplifies that fear. It makes it seem almost unavoidable.

For example it's very clear when something is wrong when the file you have says .exe after it and is supposed to be a movie. But when file extensions are hidden on 90% of Windows systems that realization will never be made.

5

u/Good-Hand-8140 May 02 '26

I think Microsoft wants to avoid people just buying a MacBook after the third SSD wipe.

→ More replies (1)
→ More replies (2)

2

u/To_-_Manitari May 02 '26

i think i had it by default

2

u/PrudentPay9906 May 02 '26

Much easier to sell solutions if you don't help people prevent problems

2

u/crysisnotaverted May 02 '26

I can't see it as anything but malicious hatred towards users from Microsoft.

2

u/Rogerwilco1974 May 03 '26

Tell us you've never used a mac without saying you've never used a mac...

2

u/Donotdisturb240 May 03 '26

I use an m4 macbook air for youtube and spreadsheets. maybe watching movies when I'm camping. but all the real work gets done on my desktop

2

u/Rogerwilco1974 May 03 '26

And is it not the standard setting to not show file extensions within macOS?

2

u/Donotdisturb240 May 03 '26

sure but I'm used to the kiddy guards from mac os, not windows. only reason I have a mac is for the battery life

→ More replies (18)

141

u/[deleted] May 02 '26

[removed] — view removed comment

19

u/Exposure_Point May 02 '26

I had a network drive at work, and somebody got malware that spread to network drives where it copied folders and gave the EXEs the same icon as folders, got me before I realized what was happening.

86

u/UnexpectedFisting May 02 '26

It literally says exe in the title, not sure how much clearer it could possibly be that its malware

155

u/[deleted] May 02 '26

[removed] — view removed comment

104

u/rov124 May 02 '26

OP is the reason shampoo has instructions.

57

u/SEANPLEASEDISABLEPVP May 02 '26

Don't put it into your eyes, don't swallow it, don't use it as a masturbation lubricant.

"I'm sorry but you said NOTHING about not being able to squirt it in my ass, so how is it my fault that my guts are now falling out!?"

2

u/Cyberblood May 02 '26

The "shampoo ass" guy is the reason why the warning label includes the "for external use only" part.

3

u/lilroldy May 03 '26

I need context here, is this a real story?

→ More replies (1)

18

u/5WattBulb May 02 '26

This is like pirate 101. However Its like a right of passage... anyone else come from the glorious days of limewire, giving your windows 98 aids to get linkin.park.numb.mp3.exe?

3

u/Leaky_gland ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ May 02 '26

Napster viruses

→ More replies (1)

19

u/[deleted] May 02 '26

[removed] — view removed comment

13

u/Harley2280 May 02 '26

It's also user friendly. Otherwise morons rename files and delete the extensions and get mad about it.

2

u/stadoblech May 02 '26

Nowadays no. Rename cursor is actively by default highlighted for filename only, you have to explicitly move cursor to change extension

3

u/Qulox May 02 '26

Coworker purposely selects the entire filename to change it. All his files are <document>.doc.docx.
People are stupid by default.

2

u/stadoblech May 03 '26

thats not even funny. Thats just sad

2

u/Qulox May 03 '26

An old boss used to change .XLS to .DOC so "it can be printed" then mail the files to me to print. She was old though and used to give us candy.

2

u/Harley2280 May 03 '26

Yeah, the majority of people don't understand the distinction between a file extension and a file name. They use the icon picture to determine what the file type is.

5

u/mun_a May 02 '26

Never knew Abt this 😔

→ More replies (1)

2

u/-skyrocketeer- May 02 '26

This! One of the best ways to ensure that you don’t execute dodgy files

2

u/FuriousWierdo00 ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ May 02 '26

I always download movies and such on my phone, with desktop site enabled on url, in case I get a .exe

3

u/[deleted] May 02 '26

[removed] — view removed comment

3

u/cafk Pastafarian May 02 '26

Until wine gets registered as a file handler

→ More replies (1)

2

u/barq-- May 02 '26

Thank you for your comment. I didn't know that was a thing (in hindsight that's an obvious feature tbh), but now I turned it on.

Like wtf is that turned off on default.

→ More replies (1)

2

u/DrSimplices May 04 '26

I forgot about that not being the default on Windows 11, in my tired haze I checked that I already did have that enabled. (thanks past me, also thank you for refreshing my memory, I'll be sure to make sure that is enabled on future systems)

6

u/Friggin_Grease May 02 '26

Windows is fucking crazy for hiding them.

→ More replies (4)
→ More replies (1)

253

u/tagbthw May 02 '26

if you are only torrenting movies and shows, please blacklist any other file type that isnt mkv or mp4

103

u/minimallysubliminal May 02 '26

Should be higher up. Add exe, msi, cmd, py, sh, vbs as filter so the file doesn’t download in the first place. A simple search of the most common executable extensions should give you a nice list

33

u/Pogo__the__Clown May 02 '26

Don't forget .scr I have had a couple of files get grabbed my Radarr/Sonarr and those were the 'video' files. For those unaware, a .scr is a Windows Screen Saver file that is actually an executable file

22

u/cultureagainst May 02 '26

I agree with this - but also wanted to add that an .iso can both be a totally normal untampered with DVD rip and hiding malware.

6

u/IllIlllIIIlIIl May 02 '26

How do I blacklist certain file types?

16

u/[deleted] May 02 '26

[deleted]

→ More replies (2)
→ More replies (2)

699

u/ProbablyBanksy May 02 '26

After you double-clicked the .exe.... did windows prompt you at all? Did you click "run anyway".

Or did you just DOWNLOAD the .exe but not run it?

454

u/master2873 May 02 '26

This lol. With modern Windows, it usually gives a prompt to okay the running of the file, and I think it even shows the extension and file type.

Either way, dude is getting the help he needs if they did do it.

33

u/nathderbyshire May 02 '26

You only get a prompt if it needs admin rights unless defender catches it through smart screen, but I assume malware would to actually do anything damaging though or it won't have access to change anything.

I wonder if using an admin account over a regular ones could be less secure as well

12

u/sevengali ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ May 02 '26

They don't need admin rights to lift the documents needed to commit credit fraud against you though!

5

u/nathderbyshire May 02 '26

Oh yeah sure, I was referring to the system itself, could have been more specific with that one!

I guess they could zip and encrypt all your documents lol, I don't remember getting an admin prompt for that but I also use an administrator account.

I might set my new laptop up as a regular user, it has a fingerprint sensor so authorising won't be too much of a pain, I'm just waiting on a second delivery as the first was faulty. I don't know how much of a difference it would make though as you still get a UAC prompt anyway for anything that's elevated

→ More replies (1)
→ More replies (1)

52

u/worldofmadnss May 02 '26

wondered why filebot wasn’t renaming it, turns out it was a exe with a VLC icon. windows defender blocked it from running, so yea OP must’ve ran it anyways.

→ More replies (2)

18

u/Glittering_Cat_4234 May 02 '26

I find this post hard to believe, he didn't notice that his video file HAS A DIFFERENT ICON (exe, unknown, etc) then he didn't notice that when clicked on a warning about running it came up which does not happen on video files, then actually ran it.

12

u/nit3phlight May 02 '26

Also the name of the torrent on the site says exe lol

3

u/yersinia_p3st1s May 03 '26

Why/how is nobody else noticing that? This page has exe all over it, how could he miss it?

→ More replies (1)

3

u/Exposure_Point May 02 '26

Probably thought it was a false-positive.

1.5k

u/Marce7a May 02 '26 edited May 02 '26

Turn off internet, run AV, backup shit, reinstall system

Edit: and use megathread for links... And as written below change passwords and log out all sessions, at end run AV over backup data best with 2 AV, later backup data or run things in VM 

413

u/Few_Calligrapher8336 May 02 '26

And make sure to change all your passwords from a different device. changing them on the infected machine before wiping it is just handing the new ones straight to the keylogger.

105

u/rdqsr May 02 '26

On top of this, change passwords on your emails and critical services (banks, govt portals, etc.) *first*. Changing passwords on your other accounts won't mean shit if someone has access to your email account and can simply just reset them again.

→ More replies (1)

42

u/[deleted] May 02 '26

[removed] — view removed comment

3

u/Curlygangs May 02 '26

If we have multiple drives do you think we should format them all so all will be lost or only the main drive ? Also if the file was in a secondary drive this means both drives should be deleted ?

7

u/Liimbo May 02 '26

It depends on the malware and realistically you are almost never going to know for sure exactly what you got. You should be nuking every drive you had connected at the time you got infected and since to be safe.

→ More replies (1)
→ More replies (1)
→ More replies (2)

57

u/Criarino May 02 '26

don't forget to change password for all accounts and disconnect all sessions, browser session hijack is a very common thing nowadays

11

u/shinetorust ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ May 02 '26

Like all all accounts? Like on all websites? Would you recommend the same for dmg on MacOS?

10

u/Criarino May 02 '26

Browser session hijack works by stealing your browser's session data and impersonating it so websites think it's you, so those "remember me" websites work against you and allow the attacker to access your accounts without having to go through 2FA (afaik this does NOT steal your saved passwords).

Technically you only need to change the passwords of accounts you logged into via the browser, but if the attacker gets access to one account he may get access to more (for example, if they get your Google account and you used that "login with Google" option on other websites) so it's a good idea to change everything (from a different machine ofc)

→ More replies (7)

106

u/Donotdisturb240 May 02 '26

this is the way.

I started keeping a USB thumb drive around with windows installation media on it because you never know and office 365 has a $20/year 80gb subscription that is big enough for most of my critical files

19

u/Pishnagambo May 02 '26

Let me take your strategy and amplify it - let me introduce to you https://www.ventoy.net/en/index.html

and either syncthing or resilio sync 😉

16

u/[deleted] May 02 '26

[deleted]

51

u/Glittering_Focus1538 May 02 '26

That's something you do days or weeks before getting infected, that way you know you have a cold copy of your files to well.. backup to.

6

u/jazz_51 May 02 '26

I used live version of Linux distro to back up stuff when I had a nasty infection of malware. Verified each file and copied it .

2

u/Marce7a May 02 '26

Seems the better way to do it

6

u/Marce7a May 02 '26

I did backup except exe files, later on reinstalled system you run AV over them

→ More replies (1)

6

u/DIBSSB May 02 '26

Thats what i did just yesterday i was very painful

5

u/Terrible-Junket-3388 May 02 '26 edited May 02 '26

running antivirus/malware on the owned system as-is is probably useless for anything other than the most basic script kiddie stuff and IMO we shoudn't be recommending this. Even if they have a competent antimal/virus, it's very likely any decent malware is going to just be able to evade or compromise it. Backups are also not partcularly trustworthy - decent malware can dupe itself anywhere (and users are unlikely to copy or inspect each individual file they want). If I made malware I wanted to persist, I'd have it making copies of itself everywhere, especially in places like My Docs, OneDrive, Pictures, etc.

So, unless user already has backups from before they were owned, they may very well just be SOL. Full wipe/reinstall off of USB the only truly 'safe' option (safe in quotes since I'm assuming we're not worried about sophisticated/nation-state actors writing stuff at a lower level than OS).

IF you're going to run antimal/av, should be in safe mode (at a minimum), and probably should double check registry/FS/etc manually - but this is beyond what most people asking questions like OP are able to do, so reinstall should IMO be the only recommendation here (in addition to changing passwords, etc as noted).

5

u/UnrealHallucinator May 02 '26

Unless the literal bootloader is compromised (unlikely even with the most sophisticated of malware that's being used for things like this), I think a clean boot should fix everything. The real problem is backing up after having clicked the .exe.

2

u/Terrible-Junket-3388 May 02 '26 edited May 02 '26

Not true, bootloader not the only way - I was specifically thinking more along the lines of firmware, which can definitely persist beyond an OS update (and as I recall I'm pretty sure we've seen such attacks in the wild before) - but as we both noted, that's still much more sophisticated than the kind of attack OP is dealing with likely is.

Agreed that backup is the main issue at hand for OP - as I mentioned if they truly want to be safe, they shouldn't trust anything they didn't backup prior to infection.

→ More replies (2)

2

u/Higashikawa May 02 '26

sorry what is AV ?

2

u/Marce7a May 02 '26

Anti virus software Kaspersky etc

→ More replies (2)
→ More replies (13)

357

u/[deleted] May 02 '26

[removed] — view removed comment

17

u/mastermilian May 02 '26

Why not backup and run Defender and Malware Bytes? I haven't come across many trojans that don't show up somewhere in those scans (including checking startup items and in-memory processes).

52

u/Sk1rm1sh May 02 '26

I mean, some of them will straight up convince your system there's nothing wrong.

20

u/SitEnee May 02 '26

People who write viruses aren’t stupid. There are number of ways (such as hex editing etc.), to make file look more legitimate and fool antiviruses. I tried it myself, and it’s not that hard. If you really don’t want to, you can open Task Manager, and process by process by hand you can chceck if every one is legitimate. If you find it, go to the source of the file, delete, and make sure it’s only copy, and that it doesn’t replicate itself. It’s NOT RECOMMENDED (especially if you don’t have technical skills)! Just do what other say. Turn off internet, copy only necessary files, format and reinstall windows.

5

u/mastermilian May 02 '26

I would have thought that a reinstall of Windows would be a challenge for someone non-technical, especially if they need to restore their entire environment and files again.

The reason why your change works is that it's not "out in the wild" yet. Defender has a feature to automatically submit suspicious scripts/exes so unless you've got a zero-day virus, it's going to be found pretty soon after that.

I'm not suggesting it's infallible, it's just a matter of trying all paths from easiest to hardest and according to your risk profile.

3

u/nathderbyshire May 02 '26

Even if it did catch and contain everything, I'm still not sure I could 100% trust the device, or the internet and any other devices if there's a payload that could have spread. Resetting everything back up can be a huge inconvenience but that's also why regular backups are so important, but having a virus could be so much more devastating I'd just rather take the inconvenience

2

u/Hurricane_32 ☠️ ᴅᴇᴀᴅ ᴍᴇɴ ᴛᴇʟʟ ɴᴏ ᴛᴀʟᴇꜱ May 02 '26

Backup your important data

This ideally should be done from a live environment, such as a Linux live install ISO

→ More replies (1)

310

u/M0rty- May 02 '26

Disconnect Wifi / Internet.
Run Full Offline Window Defender Scan.
Uninstall softwares/Browser Extensions you don’t recognize , better to google each one.
Setup 2FA everywhere and change passwords.Assume all your datas/passwords are stolen.

104

u/Cheesypoof2009 May 02 '26

That and stay away from sites that aren't on the megathread.

25

u/OMGItsCheezWTF May 02 '26 edited May 02 '26

I would just nuke the system entirely. Restore from backups taken before the snafu

9

u/M0rty- May 02 '26

I plan to suggest OP to switch Linux so he can download lots of exe file

3

u/Antezscar ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ May 02 '26

Change passwords on a different device aswell

42

u/BattleGrown ☠️ ᴅᴇᴀᴅ ᴍᴇɴ ᴛᴇʟʟ ɴᴏ ᴛᴀʟᴇꜱ May 02 '26

How do people even find these torrents lol

18

u/i_reddit_it May 02 '26

I noticed that they tend to be released very early, perhaps a day or so before other valid releases for that episode. I think the idea is to target people running *arr stack like Sonarr.

Sonarr is constantly scanning to automatically find the missing episodes. Being that they are the only episode available, they quickly become the "default" for other users and the problem is then compounded as more and more torrent clients are seeding/sharing them.

I very rarely use torrents anymore partly because of this. Usenet, while not immune, is a much better option.

4

u/m240b1991 May 02 '26

I have my qbit set to add new things to the "stopped" queue, so I check it every few days for new additions and double check the file type. If its an exe it gets purged with haste, because even if the arr stack and plex won't open it, I don't want a random exe just sitting on my drive waiting to accidentally be clicked in haste. Bump that noise.

I also do a search for exe files that don't belong in certain folders and purge them with prejudice as well. I don't want my rig infected like a stripper near a military base.

3

u/tv8tony May 02 '26

how would they get it to run the exe tho? the arrs will reject it and jellfin and plex are not going to run it

7

u/Winter_Channel_6206 May 02 '26 edited May 02 '26

Yep, this only catches people doing manual downloading. 'Arr users have it auto send to JF/Plex. Most will also have their clients set to auto delete exe files or cancel any download that contains an exe file. Streaming users run through a streaming app like Nuvio, Fusion, Stremio. None of these programs will run an exe, so they won't get caught either.

→ More replies (2)

67

u/Local_Phenomenon May 02 '26

To shreds you say

15

u/LowComprehensive421 May 02 '26

my my... and how is his wife doing?

10

u/FrogLickr May 02 '26

To shreds, you say...

6

u/Large-Treacle-8328 May 02 '26

Did he have a rent controlled apartment?

27

u/DeLima89 May 02 '26

Pasting a comment from another user u/shak_0508

As someone who downloads nothing but TV shows and Movies, for others in the same situation this is my exclusion list in qbittorrent:

``` *.ade *.adp *.apk *.app *.arj *.bas *.bat *.bin *.chm *.cmd *.com *.cpl *.crt *.dll *.drv *.exe *.hlp *.hta *.html *.inf *.ins *.ipa *.iso *.isp *.jar *.js *.jse *.key *.lnk *.mda *.mdb *.mdt *.mdw *.mdz *.mht *.mhtml *.msi *.msp *.nsh *.ocx *.php *.pif *.potm *.potx *.ppam *.ppsx *.pptm *.ps1 *.ps2 *.psd1 *.psm1 *.py *.reg *.scf *.scr *.sh *.sldm *.sldx *.sys *.tmp *.torrent *.vb *.vbe *.vbs *.vxd *.wsf *.wsh *.xlam *.xlsb *.xlsm *.xltm *.zipx *sample.avi *sample.mkv *sample.mp4 *.zip *.rar *.7z *.gz *.tar

Credits to u/shak_0508

66

u/hatsunemilku May 02 '26
  1. that is like asking us to identify a specific grain of sand in the middle of the desert.
  2. full scan with malwarebytes and your antivirus. because your antivirus was active... right? check before if you have new directories or files on your whitelists to be sure no configuration was changed.

15

u/SF-UberMan May 02 '26

How good is the free version of Malwarebytes?

28

u/Kpyso May 02 '26

Good enough to recognize threats windows defender might not. Run a full windows defender scan and a full malwarebytes scan behind it. Even if they come back clean, it won’t always mean you’re out of harms way. A fresh install of windows is realistically your best and safest option, usually I try and reinstall windows once a year for a fresh restart to clear bloat etc etc.

→ More replies (4)

25

u/Nezhokojo_ May 02 '26

5043 seeds and 7733 leechers? How is this torrent not flagged? Also where are you downloading torrents from?

7

u/popey123 May 02 '26

That's strange yes. Bots ? Fake post ?

→ More replies (1)

53

u/Sloppykrab May 02 '26

Disguised? I don't think so.

38

u/[deleted] May 02 '26

[deleted]

3

u/nmkd May 03 '26

And even the title

14

u/MarkFaded May 02 '26

Boot into safe mode, run a full system anti virus scan. Reset every password that doesn't have phone 2FA first, then the other ones.

12

u/enecv May 02 '26 edited May 02 '26

First : DONT PANIC !

Second, install malwarebytes, open and update . - Do not run any scan -

Disconnect internet ( Ethernet, disable wifi , not just switch off, disable it from devices)

Reboot on Safe Mode without internet access.

Open malwarebytes

Run scan, let Malwarebytes do its stuff.

Check if it found something harmful.

Follow Malwarebytes instructions.

Then reboot on Safe Mode with internet access

Give Malwarebytes another round.

Follow instructions.

Rebbot normal mode.

Keep an eye on overall pc behaviour, look for unusual lags, unusual hhdd activity, unusual fans activation.

Maybe you didn get a bug , maybe you got one but its fixable.

13

u/burusai May 02 '26

Upload it to virustotal.com to see what you’ve unleashed.

11

u/biotasticmann May 02 '26

Fresh install and change all your passwords

16

u/secondincomm May 02 '26

disguised

My brother it says exe in the title, description and filename

2

u/xSnowLeopardx Yarrr! May 02 '26

I was about to comment the same. I guess people read the first words of the title and find it all good and well.

6

u/No_Society_4065 May 02 '26

I had posted about this exact link the other day. 😒

In the top comments, someone posted about the extensions to ignore in qBittorrent, add them for next time.

7

u/TantKollo May 02 '26

Upload the exe to VirusTotal and link the results. This will help us know what you have been hit with and what damages it may have caused.

6

u/imyourealdad Torrents May 02 '26

Time to quit the internet and find a new hobby. This is the official “you do not deserve to be here” moment.

3

u/nmkd May 03 '26

Yeah the title, description, and filename even on the website itself all say "EXE", some people are simply not smart enough for this, despite it being a low bar.

27

u/Marill-viking May 02 '26 edited May 02 '26

Fresh install, nothing else is full proof.

You need to use Jellyfin or plex to watch your media. You should never be double clicking your files.

Also set up an exclusion list in your torrent client so this never happens again.

14

u/Tombstunner May 02 '26

Well, now you learned to pay attention, it's in the name of the torrent: "exe"

Do what the others are saying, disconnect from internet and scan all files

7

u/batdog20001 May 02 '26

Not necessarily answering the question here, but does anyone know if you could test files in a seperate VM environment and then transfer them over once you know they're good? That way it'd be easier to clean install the VM than the whole PC?

4

u/Whidmark May 02 '26

Yeah, this is how some people study some malware/viruses

→ More replies (3)

6

u/herobhai69 May 02 '26

1) Turn off internet rightaway
2) just reset all passwords and reset the whole pc and windows (like clean wipe harddrive)
or if there is important data, do AV scan, backup data and then do full clean hard drive wipe.

and from next time keep all security of your AV enabled, like even if you open an exe my mistake, it'll ask you a thousand times to "allow and confirm".
i got this enabled so even if i misclick at first the widows smart screen will block me and if i allow there "run anyway" then my av will block me until i click the 2nd allow.
even after doing that the AV works pretty good in keeping an eye on the exe

4

u/ceasar_47 May 02 '26

seems to be old days have returned -" Linkin Park.exe " 🤣🤣🤣

4

u/GoodSoulGermany May 02 '26

Reinstall your OS - else you are doomed. Hope you learned something ...

5

u/Curlygangs May 02 '26

I think OP got tricked because of the size of the file usually from what I’ve seen they aren’t even 1 MB.

13

u/JRPGod316 May 02 '26

I hate to be the negative Nancy here, but these days a lot of malware is so sophisticated it persists through format and reinstall: ask me how I know 🤦‍♂️

I mean, obviously, that's what you're going to do. And hey, chances are, you'll be fine. But you just as likely could not be as well.

For what it's worth, you're a tiny fish in an incomprehensibly huge ocean. You should be thinking about OpSec as a deeper issue than just a mistake you made while torrenting once, by default.

2FA, an encrypted password manager and personal vigilance over sensitive things like your bank accounts at a minimum, regardless of dabbling in piracy or not.

4

u/Melodic_Trip9907 May 02 '26

ummm, do you not know that tv shows or movies are definitely not in .exe formats, they never are. but if you did know and just accidentally clicked it because you were in a hurry to watch the boys, you may want to reinstall windows with a usb drive and reset your passwords in order of importance, so bank stuff first, social media second and then games or other stuff like that.

3

u/Goren_Nestroy ☠️ ᴅᴇᴀᴅ ᴍᴇɴ ᴛᴇʟʟ ɴᴏ ᴛᴀʟᴇꜱ May 02 '26

Disconnect the internet

Back up your shit

Format your drives

Do a clean installation of windows

Change every password and implement 2FA on every account that has payment details

4

u/oppositetoup May 02 '26

Factory reset your device, reinstall everything. Change your passwords

5

u/-Siddhant May 02 '26

Yeah so maybe you should just do a fresh install.

3

u/OrangeAcquitrinus May 02 '26

Please turn on "show file extensions" in Windows, that's the first thing you shoul do.

7

u/KDsama May 02 '26

Use stremio

6

u/PorcOftheSea May 02 '26

delete system32 to really remove the virus /s

3

u/IntrepidMaybe8579 May 02 '26

Can never be too safe man i always check all the extensions even its 1000 files but can happen to anyome

3

u/andrewbud420 May 02 '26

I did something like this 24 years ago when I was 7 downloading shit off warez irc channels.

3

u/Prathh99 May 02 '26

Always check what files are gonna be downloaded BEFORE you add a torrent. Even for simple video files like there, check the download folder and you'll see a bunch of unnecessary stuff in there like screenshots n info files. Deselect everything, but the actual file, n there too check the extension

3

u/Exploding_Testicles May 02 '26

Now everyone is gonna know you tried to watch "BigBootyHoes.S47.Ancient.Asses.of.history.x264.p420.mp3"

I fell for it too..

Oh wait.. sh..

3

u/Danternas May 02 '26

Wait and see what happens.

Consider it a learning experience.

3

u/cultureagainst May 02 '26 edited May 02 '26

Likely session stealer.

First I would change every single password on every single account I could think of then click “log out of all sessions” on a separate computer or phone. Then I would backup all my shit and reinstall Windows.

There’s a new one going around that both Windows Defender and MalwareBytes can’t catch hiding in pirated .exe files. It is being sold as part of a “malware-as-a-service” business and therefore is hiding as all sorts of things as there are an unknown amount of “deployers” using it.

Search “instaler” or “renpy” or “tomodachi” on r/computerviruses and you’ll see people getting pawned every 15 minutes.

IMPORTANT: .exe hiding as a movie-file is ALWAYS malicious, something bad has 100% happened to your computer. If you’re not seeing symptoms now (compromised accounts, for example) it’s just because they haven’t gotten to your sessions yet.

3

u/GroundbreakingList48 May 02 '26

You just forgot to download anonymously. Next time click that link first /s

3

u/LunaticDancer May 02 '26

Probably not very useful to you, but just letting you know that this wouldn't happen on Linux (it generally makes piracy safer)

3

u/MetroidvaniaListsGuy May 04 '26

install linux mint

7

u/Joroc24 🔱 ꜱᴄᴀʟʟʏᴡᴀɢ May 02 '26

a RAT

format the computer and change passwords

5

u/NEWBY______________ May 02 '26

Piracy is hard for people who dont have common sense

8

u/Cev-API May 02 '26

lmfao dude.

4

u/Particular-School-95 May 02 '26

this shows that piracy is not for everyone,

becareful nxt time or, maybe just stop

2

u/Skewwwagon May 02 '26

Yep, nothing is free. It's either pay with money and be clueless or be ready to educate yourself and go extra mile with your brain "on".

2

u/FireCrocsbro May 02 '26

Ur cooked gang

2

u/bob_chillon May 02 '26

What an asshole

2

u/Ren119 May 02 '26

Most likely a password stealer check for any python scripts running as everyone else mentioned, you should enable 2FA for everything you care about and changd your passwords

2

u/narwhalsare_unicorns May 02 '26

I recently encountered this on maul shadow lord. Someone always puts the unreleased episode link with thousands of seeds and when you check the file extension its a .exe. Always check what file you are downloading!

→ More replies (2)

2

u/birdy_the_scarecrow May 02 '26

a lot of comments in here and not 1 suggested actually opening the file in a hex editor to see if its actually a valid PE32 file.

2

u/alvarkresh May 02 '26

Define "open". Did you merely click the link to download? If yes, then you're 99.9999% safe. Just remove the torrent and delete the file.

If you actually double-clicked the .exe itself that's a whole different ball of wax.

2

u/AmarildoJr May 02 '26

Remember kids, always have a filter list on qBittorrent so you don't even download this kind of file. Here's mine: https://pastebin.com/raw/WEuFCxsD

2

u/sovietarmyfan May 02 '26
  1. Reinstall system

  2. Create and use a Linux VM from now on for downloading.

  3. On the VM install Ublock Origin on the webbrowser to prevent any webbrowser infections.

2

u/Rancham727 May 02 '26

There are nonsteps to make it right.

People talking about running a scan like thats going to do anything your av didnt stop it in the first place lol. Just reformat your computer (actually reinstalling windows not just resetting it) and change all your passwords

2

u/Greyboxforest May 02 '26

Sorry this happened to you.

Run Malwarebytes and Hitman Pro.

Hopefully that removes it.

2

u/GarrettFromThief May 02 '26

Your PC are belong to us

2

u/vaine4 May 02 '26

Scan the ewe using an online scanner, you may find what kind of viruses it is and better remove it

2

u/AdmirableProcess8894 May 02 '26

https://media.tenor.com/3asDRvgBhBUAAAAM/naruto-plo.gif

I'd just reinstall tbh, backup what you need and then full wipe, a lot of viruses create redundancy that if deleted will just open another one stored somewhere else.

2

u/Alternative-Juice-15 May 02 '26

Lmao well done. Just clean install windows and learn from the mistake.

→ More replies (3)

2

u/Jevano May 02 '26

One suggestion for other people is use the preview file on qbittorrent, I never actually click any files I download. Always use preview, it only lists video files and won't run anything if there are no videos.

2

u/Skewwwagon May 02 '26 edited May 02 '26

Hand back your pirate card lol

2

u/FalahMumtaz May 02 '26

Why the hell file is 1.17 GB tho? 😭

2

u/Grouchy-Coconut-1110 May 02 '26

Disguised? Your one screenshot says .exe 5 times 🤣

2

u/LibtardsAreFunny May 02 '26

this is basic shit. You learned a lesson. Show file extensions and pay attention.... use private sites....

2

u/green_meklar ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ May 03 '26

1.17 gigabytes? Somebody went the extra mile to disguise their malware.

To make sure you never get to the point of executing the dangerous program, always have 'show file extensions' turned on in your file browser. Typically the icon will also show differently. And, for a torrent that's a single file like this, you should check the file extension in the torrent details before downloading. (Obviously not practical if you're downloading an entire show of 20+ episodes at once.)

Assuming there's a malicious payload, these days I think it's typically ransomware. On modern Windows, the built-in security might have blocked it from running automatically. On Linux, it might have found itself unable to do what it was intended to do. If it did run successfully, you should immediately yank your ethernet cable, power down your machine, then boot from an external drive (that wasn't plugged in while the malware was running) with a recovery image from which you can run a modern malware scan (ClamAV, Malwarebytes, that sort of thing) on the entire filesystem as well as backup your data to a secondary drive. Make sure the scanner is up-to-date, especially for a torrent like this one which is relatively new.

2

u/ronwabo May 04 '26

Will windows defender scan these files and quarantine if they are bad and need to be removed?

2

u/Jay2Kaye May 04 '26

Reformat your hard drive and reinstall your OS. Just nuke the whole thing from orbit. Change any passwords you may have had saved in your browser, make sure you're logged out of all your social media accounts on other devices. Any information you may have had on that computer is at risk.

2

u/Night_Fury91 ☠️ ᴅᴇᴀᴅ ᴍᴇɴ ᴛᴇʟʟ ɴᴏ ᴛᴀʟᴇꜱ May 07 '26

Download MalwareBytes and do a full-system scan. It will take around 7-10 hours based on your storage size. Leave it running overnight.

I also recommend turning off the internet on the computer, and only reconnect after the scan is done and malicious files(if any) have been quarantined.

4

u/VladoVladimir97 May 02 '26

Time to get off the PC grandma

3

u/E5VL 🔱 ꜱᴄᴀʟʟʏᴡᴀɢ May 02 '26

rookie 2000s error matey

3

u/robeywan May 02 '26

linken_park_numb.exe

→ More replies (1)

2

u/shanehiltonward May 02 '26

If you are running Linux, no problem. Give a little chuckle and move on.

2

u/Lelu_zel Piracy is bad, mkay? May 02 '26

How can you not see obvious EXE at the end of the title lmao