Safety & Malware Guide
This is everything you need to know to stay safe. Read it once, set things up properly, and you'll be fine. Skip it and you're one misclick away from losing your accounts.
What GameBounty Controls (and What It Doesn't)
What we guarantee on every release:
- Archives are never password-protected. If you see a password prompt, the file is not from us
- Every archive contains a
README.htmlwith installation instructions from us - Files are distributed as
.rarpart files only, never as a standalone.exedownloader or setup wizard - No ads, trackers, or bundled software inside the archives
What we don't control:
The file hosting sites we link to (FileDitch, FileQ, Gofile, etc.) run their own ad networks. We have no say in what ads they serve. Those ads can be malicious: fake download buttons, redirects to malware, browser-locker pages. The archives themselves are clean. The danger is the pages you download them from.
This is not a disclaimer to cover ourselves. It's a real distinction that affects how you should behave while downloading.
Step 1: Get a Proper Ad Blocker
This is the single most important thing you can do. Without a proper ad blocker, visiting a file host is genuinely risky. With one, the risk drops to nearly zero.
Why most blockers aren't enough
Brave's built-in blocker is good for everyday browsing but it is not sufficient for file hosts. Brave Shields uses a more conservative filter list that doesn't cover the aggressive ad networks these sites use. It will let through the exact categories of ads that hurt you.
uBlock Origin Lite (available on Chrome) is a stripped-down version built to comply with Chrome's Manifest V3 extension policy. It lacks dynamic filtering, has fewer filter lists, and cannot block the same range of threats as the full uBlock Origin. It is not a substitute.
AdBlock / AdBlock Plus have historically accepted payment from advertisers to whitelist certain ad networks. They cannot be trusted for this use case.
What you need: uBlock Origin (full version)
uBlock Origin is the only ad blocker that reliably stops malicious ads on file host pages. It's free, open-source, and has been independently audited.
The problem for Chrome users: Google removed uBlock Origin from the Chrome Web Store in 2025 due to Manifest V3 restrictions. You can no longer install it on standard Chrome or Edge.
Your options:
- Firefox: uBlock Origin works perfectly on Firefox. It's the easiest solution and what we recommend.
- Helium: a Chromium-based browser that ships with uBlock Origin (the real, full version) pre-installed. If you're committed to a Chromium browser, Helium is the right choice. You get the Chromium engine you're used to plus proper protection out of the box.
- Don't keep using Chrome or Edge with uBlock Origin Lite thinking you're protected. You're not.
Setting up uBlock Origin properly
After installing (Firefox or Helium):
- Click the uBlock Origin icon → confirm it shows a green power button (active, not paused)
- Open the dashboard → Filter lists tab
- Under Malware domains, enable everything in that group
- Enable uBlock filters – Badware risks
- Click Apply changes at the top
If a file host page tells you "please disable your ad blocker to continue", close the tab. Legitimate file hosts do not require this. The only reason they'd ask is to expose you to the ads they profit from, which are the exact ads that can harm you.
Step 2: How to Behave on File Host Pages
File host pages are deliberately designed to confuse you. The ads are often bigger, brighter, and more prominent than the actual download button. Here's how to navigate them without getting caught.
Before you click anything
- Check the URL bar. Make sure you're on the file host's own domain, not a redirect or lookalike page.
- The real download button is boring. It's usually a small, plain text link or a simple button with no animation. The giant green "DOWNLOAD NOW" button is almost always an ad.
- Wait for countdown timers on their own. A lot of file hosts make you wait 5–10 seconds before the real link appears. Do not click anything during this time. The ads are trying to catch you off guard.
- Pop-ups and new tabs that open automatically: close them immediately without clicking anything inside.
Things that are never legitimate on a file host
| If you see this... | It's actually... |
|---|---|
| "Disable your ad blocker to download" | Attempt to expose you to malicious ads |
| "Your download is ready, click to claim" overlay | Fake download button leading to malware |
| A CAPTCHA to "unlock" or "generate" your download link | Social engineering. No legitimate host does this |
| "Install our Download Manager for faster speeds" | Malware disguised as a utility |
| A prompt to log in with Google, Discord, or Steam | Credential phishing. Close the tab immediately |
| A browser pop-up saying your PC is infected | Fake security alert / tech support scam |
| Browser asking to show notifications | Deny it. File hosts have no reason to push notifications |
The real download link leads straight to a .rar file. If what you got is an
.exe and not a .rar part file, do not run it.
Why Your Antivirus Flags Game Files
Cracked games require modified .exe files and DLLs that bypass store authentication. Antivirus software flags these because the modification technique looks identical to what malware does. This is a false positive: the AV is matching a behaviour pattern, not an actual known virus.
Files that will almost always get flagged:
- The game's main
.exe(patched to skip license checks) steam_api.dllandsteam_api64.dll(replaced with Goldberg Emulator)- Goldberg Emulator DLLs:
steamclient.dll,steamclient64.dll .asiplugin loaders in some games- Proxy DLLs used to load the crack, commonly named
winmm.dll,dinput8.dll, orversion.dll. These are legitimate Windows system DLL names being reused as loaders, a standard crack technique, not a sign the file is fake - A custom
Launcher.exeprovided by the release group instead of the game's original executable
Detection names that are safe to ignore
These are generic heuristic labels. Every cracked game triggers them. They mean nothing specific:
HackTool/HackTool.Win32.*RiskWare/RiskToolPatcher/Crack/KeygenWacatac/Wacatac.B!mlWin32/Generic/Gen:Variant.*Trojan.GenericKD.*, only when flaggingsteam_api.dll, not the game's own.exe
These are only safe to ignore when the detection is on a file inside the game's own folder: the .exe, steam_api.dll, or emulator DLLs. If the same name shows up on a file in %AppData%, %Temp%, or anywhere outside the game folder, that's different.
Detection names that are not safe: stop immediately
If your antivirus names any of the following, do not proceed. Run the flagged file through Hybrid Analysis (free, quick signup) and ask in our Discord before doing anything else.
Stealers: Lumma, LummaC2, RedLine, Vidar, Raccoon, Amadey, FormBook, Phorpiex
Remote access: AsyncRAT, njRAT, Quasar, DarkComet, Emotet
Miners: Coinminer, XMRig, BitcoinMiner, Monero
Also stop if:
- Any detection fires on a file outside the game folder (
C:\Windows,%AppData%,%Temp%,%ProgramData%) - A
.bat,.ps1, or.vbsscript inside the archive gets flagged - A sandbox run (Hybrid Analysis or any.run) shows real network connections, registry persistence, or access to your browser/credential files
- Your antivirus reports outbound network connections to unknown domains immediately after launching the game
Malware Types: What They Are and What They Do
Malvertising
Malvertising is malicious advertising: ads served through legitimate ad networks that redirect you to malware, exploit pages, or fake software. It's the most common threat when downloading games because file hosts are heavy ad publishers.
The dangerous part: you don't have to click. Some malvertising exploits browser or plugin vulnerabilities just by loading the page. A single unprotected visit to a file host is enough. uBlock Origin stops this at the network level before the ad even loads.
Fake download buttons
Ad networks place convincing fake download buttons on file host pages, often bigger and more colourful than the real button, sometimes with fake progress bars or download counters to look credible. Clicking them downloads an .exe file disguised as the game, a "download manager," or a codec pack.
These files are almost always info-stealers or adware droppers. The tell: the file you downloaded is an .exe, not a .rar part file. Game downloads from GameBounty are always multi-part .rar archives. If you clicked a button and got an .exe, you got the wrong thing.
Info-stealers: the most dangerous threat
Info-stealers (Lumma, RedLine, Vidar, Raccoon and others) are the most common malware distributed through piracy sites. They are designed to be completely silent and complete their job within seconds of execution.
What happens when you run one:
- The stealer scans every browser profile on your PC: Chrome, Firefox, Edge, Brave, all of them
- It extracts every saved password, autofill entry, credit card, and session cookie
- It copies cryptocurrency wallet files and any seed phrase text files it can find
- It harvests your Discord token, Steam session data, and any other gaming credentials stored in config files
- Everything is compressed and sent to the attacker's server, all in under 30 seconds
- The process exits silently. The game may even launch and work normally.
You will see nothing. No pop-up, no slowdown, no error. The stealer is already done. The first sign is usually an email alert that your Google account was accessed from another country, or your Discord being used to send DMs you didn't write, or your Steam inventory suddenly empty.
The session cookie problem: Stealers don't just steal your password. They steal your session cookies, which are the tokens your browser uses to stay logged in. An attacker with your session cookie can access your account without knowing your password and bypasses 2FA entirely because the session was already authenticated. This is why changing your password alone isn't enough. You also have to invalidate all active sessions.
Ren'Py games are a common stealer delivery vehicle, especially in the adult visual novel scene. Ren'Py is a Python runtime: every .rpy and .rpyc script in the game/ folder executes code at launch. An attacker can embed a stealer payload directly in the game scripts, and the game will load and play normally the whole time. Red flags specific to Ren'Py: any .exe or .bat file inside the folder besides the main launcher, the game asking for admin (UAC) privileges (Ren'Py never needs this), or your AV flagging something inside the renpy/ or lib/ folder with a specific malware name rather than a generic one. .rpy files are plain text, so open them in Notepad before running if something feels off. Look for import subprocess, import socket, exec(, or base64.b64decode(.
RATs (Remote Access Trojans)
RATs give the attacker live, interactive control of your PC. They can see your screen, move your mouse, open files, run commands, and access your camera and microphone. They're usually delivered as a second-stage payload dropped by a stealer after the initial infection.
Signs: unexplained mouse movement, processes in Task Manager you don't recognise, the webcam indicator light activating when you haven't opened anything, PC waking from sleep on its own.
Cryptominers
Miners use your CPU and/or GPU to mine cryptocurrency for the attacker. They're less immediately destructive than stealers but can cause hardware damage over time from sustained 100% load.
Signs: unusually high CPU or GPU usage when no demanding programs are open, PC running loud and hot at idle, significantly reduced game performance, electricity bill increase, system fans spinning at max.
Red Flags Checklist
Run through this before launching anything you downloaded:
- The archive was not password-protected
- Inside the extracted folder there is a
README.htmlfile - No unexpected
.exe,.bat,.ps1, or.vbsfiles appear alongside the game files - The file size matches approximately what was listed on the download page
- Your AV detection (if any) is a generic name, not a named stealer or miner
- The download came from a link on the GameBounty download page, not a search result or third-party repost
If any box is unchecked, don't run it. Ask in Discord first.
Verifying a File Before You Run It
VirusTotal checks a file against 70+ antivirus engines at once, but those engines mostly work from static signatures and heuristics. That's a bad fit for cracked game files: the patch that removes a license check looks, structurally, like what malware does to bypass protections, so static engines routinely flag perfectly clean cracked .exe files with vague names like HackTool or Gen:Variant. A wall of generic VirusTotal detections tells you almost nothing about whether a file is actually dangerous.
A sandbox gives you a real answer instead. Sites like Hybrid Analysis and any.run run the file in an isolated virtual machine and show you what it actually does: which processes it starts, what it writes to disk, what domains it contacts, whether it touches your browser profiles. That's a genuine signal, not a pattern-matching guess.
- Hybrid Analysis is free with a quick signup and no approval wait. This is the one to use if you've never done this before.
- any.run is excellent too and worth knowing about, but its free tier is gated behind manual approval that isn't always easy to get. Use it if you already have access; don't block on signing up for it.
How to read a sandbox report:
- No suspicious network activity, no writes outside the game folder, no browser or credential file access: almost certainly clean.
- Connections to unfamiliar domains (especially right after launch), or access to browser profile folders: stop. Don't run the local copy either.
- Registry persistence entries, process injection into unrelated programs, or attempts to disable your antivirus: stop immediately. This is a real threat regardless of what any static scanner said.
VirusTotal is still fine as a five-second first look, and a single detection from a reputable engine (Kaspersky, ESET, Malwarebytes) naming a specific threat like Lumma is worth taking seriously even without a sandbox. But treat a pile of generic detections there as noise, not a verdict, the sandbox result is the one that actually matters.
Note: both Hybrid Analysis and any.run share uploaded files with other users. Don't upload anything that might contain personal data.
Antivirus Exclusions
Because cracked game files trigger false positives, you need to tell your antivirus to ignore your games folder. Do not disable your antivirus. Just exclude the folder where you keep games.
Windows Defender
- Open Windows Security → Virus & threat protection
- Click Manage settings under Virus & threat protection settings
- Scroll to Exclusions → click Add or remove exclusions
- Click + Add an exclusion → Folder → navigate to and select your games folder (e.g.
D:\Games)
Malwarebytes
Malwarebytes only scans on-demand by default, so it usually doesn't interfere with games at launch. If it quarantines a game file, go to Detection History, right-click the quarantined item, and choose Restore and add exclusion.
Kaspersky / ESET / Bitdefender / Norton
All of these have an Exclusions or Trusted Zone section in their settings. Add your games folder path there. The exact menu path varies by version, so search "[your AV] add folder exclusion" for the specific steps.
Browser Security
Which browser to use
| Browser | uBlock Origin | Notes |
|---|---|---|
| Firefox | Full uBlock Origin | Best option. uBlock Origin MV2 works fully. |
| Helium | Ships with uBlock Origin built in | Best Chromium option. Full uBlock Origin pre-installed, no setup needed. |
| Brave | Built-in Shields only | Not sufficient. Shields don't cover malicious file host ad networks. Install Firefox or Helium instead. |
| Chrome / Edge | Only uBlock Origin Lite available | Lite lacks dynamic filtering and key filter lists. Not a substitute. Switch browser. |
If you use Brave and don't want to switch your main browser, at minimum open file host pages in a Firefox or Helium window with uBlock Origin enabled.
Extensions to install
| Extension | Purpose | Verdict |
|---|---|---|
| uBlock Origin | Blocks malicious ads and fake download buttons | Required |
| FastForward | Skips link shortener wait pages automatically | Recommended |
Never install any extension that claims to "generate premium links," "accelerate downloads," or "bypass captchas automatically." These are consistently malware or data harvesters. Also be suspicious of any extension with "read and change all your data on websites you visit" permissions that you didn't deliberately install. Malicious extensions are a common second-stage infection vector.
Browser settings
- Turn off the built-in password manager. Every major browser's password saving is the first thing a stealer empties. Use a dedicated password manager instead: Bitwarden (free, open-source) or 1Password.
- Turn off "offer to save payment methods." Same reason.
- Don't stay logged into accounts you don't actively use. An idle session cookie is just as valuable to a stealer as an active one.
Account Security
Info-stealers don't need your password. They steal session cookies that grant access without one. Knowing this changes how you should think about account security.
Preventive steps (do these now, not after something goes wrong)
- Enable 2FA on everything that matters: Steam, Discord, Google, Epic Games, and any account with money attached. Use an authenticator app (Google Authenticator, Authy, or Bitwarden TOTP) rather than SMS, since phone numbers can be SIM-swapped.
- Use a password manager. Bitwarden is free, open-source, and works on every platform. If your passwords are unique and not stored in the browser, a stealer can only capture your session cookies, not your actual credentials.
- Don't store crypto seed phrases on your PC. Not in a text file, not in a screenshot, not in a notes app. Write them on paper and store them physically.
- Check your Steam API key: go to steamcommunity.com/dev/apikey right now. If a key exists that you didn't create, your account has already been accessed by a third party. Revoke it immediately and change your password.
If you ran something suspicious (but aren't sure you're infected)
Don't wait to find out. Do these immediately, from a clean device:
- Change passwords for Google, Discord, Steam, and your email provider
- Log out of all active sessions on each account
- Revoke the Steam API key
- Check Gmail → Settings → Filters and Forwarding for anything you didn't set up
- Check Discord → User Settings → Authorized Apps, and revoke anything unknown
If You've Been Infected: Act Immediately
Time matters. A stealer finishes its job in seconds, but most attackers don't access accounts immediately. They sell or use the data later. Changing credentials quickly still locks them out.
Do every step below using a separate, clean device: your phone, a family member's PC, anything that isn't the infected machine. Using the infected machine to change passwords just gives the attacker your new passwords.
Step 1: Disconnect from the internet now
Pull the Ethernet cable or turn off Wi-Fi. If any data hasn't been exfiltrated yet, disconnecting stops it. Do this before anything else.
Step 2: Change every important password
Priority order, do not skip any:
- Primary email first (Google, Outlook, iCloud). Attackers use email to reset everything else
- Discord. Frequently targeted, tokens are easy to steal
- Steam. Check Guard mobile authenticator settings, remove any unauthorized devices
- Gaming platforms: Epic, EA, Ubisoft, Battle.net, Riot, Xbox, PlayStation
- Every password stored in your browser. Treat the entire browser as compromised
Step 3: Kill all active sessions
Every platform has a way to sign out of all devices at once. Do this for each account after changing the password. It invalidates any session cookies the attacker already has, even if they haven't used them yet.
- Google: myaccount.google.com → Security → Your devices → manage all devices → sign out all
- Discord: User Settings → Devices → Log out all known devices
- Steam: Account details → Manage Steam Guard → Deauthorize all other devices
Step 4: Hunt for persistence
Attackers often set up ways to maintain access even after you change your password.
Gmail: Settings → See all settings → Filters and Blocked Addresses (look for rules forwarding your email to an unknown address) → Forwarding and POP/IMAP (check if forwarding is enabled to an unknown address)
Discord: User Settings → Authorized Apps, and revoke everything you didn't intentionally add. Check your sent DM history for messages you didn't write.
Steam: steamcommunity.com/dev/apikey. If a key exists, revoke it. Check trade history and market listings for unauthorised activity.
Step 5: Contact your bank
If your browser had any saved payment cards, or if any compromised account had a stored card, call your bank immediately. Ask them to flag unusual transactions and consider issuing a replacement card. You don't have to wait for fraud to appear. Being proactive is faster and easier than disputing charges later.
Step 6: Reformat Windows
A full Windows reformat is the only safe recovery from a stealer or RAT. Running an antivirus scan after infection is not enough. Sophisticated stealers and rootkits are built to evade detection tools. The only way to be certain the machine is clean is to wipe it.
- Back up personal files (documents, photos, game saves) to an external drive. Do not back up any executables, installed software, or game folders from the infected machine. They may carry the payload.
- On a clean device, download a Windows ISO from microsoft.com/software-download and create a bootable USB using Rufus or the official Media Creation Tool.
- Boot from the USB, select Custom install, and format the drive Windows is installed on before reinstalling.
- Reactivate Windows using Microsoft Activation Scripts, the only trusted open-source activator. Run it from PowerShell:
irm https://get.activated.win | iex. Do not download it from any other site.
Network
- You don't need a VPN to download from GameBounty. All file transfers happen over HTTPS, so the contents are encrypted in transit. A VPN adds nothing here.
- A VPN is only useful if your ISP specifically throttles traffic to certain file hosts. If you use one, use a paid no-logs provider. Free VPNs routinely sell your traffic data, so you're trading one risk for another.
- Switching your DNS to Cloudflare 1.1.1.1 or Quad9 hides your domain lookups from your ISP and adds basic malware domain filtering. It takes five minutes and has no downside.
Quick Reference
| Situation | What to do |
|---|---|
AV flags steam_api.dll as HackTool | Safe. Add your games folder as an AV exclusion |
AV flags winmm.dll, dinput8.dll, version.dll, or Launcher.exe | Safe. These are standard crack loader names, not fake files |
AV flags a file as Lumma, RedLine, or any named stealer | Stop. Do not run, delete the archive, ask on Discord |
| Archive is password-protected | Stop. GameBounty never uses passwords on archives |
No README.html in the extracted folder | Stop. Likely a tampered or wrong file |
| File host says "disable your ad blocker" | Close the tab |
| File host asks you to log in with Google or Discord | Close the tab. It's a phishing page |
Downloaded an .exe from a file host button | Don't run it. Game downloads are always .rar part files |
| Accounts accessed from unknown location | Change all passwords from a clean device immediately |
| You ran something and aren't sure what it was | Assume infected. Follow all 6 steps above |