Help/Safety & Privacy

Safety & Malware Guide

This is everything you need to know to stay safe. Read it once, set things up properly, and you'll be fine. Skip it and you're one misclick away from losing your accounts.


What GameBounty Controls (and What It Doesn't)

What we guarantee on every release:

  • Archives are never password-protected. If you see a password prompt, the file is not from us
  • Every archive contains a README.html with installation instructions from us
  • Files are distributed as .rar part files only, never as a standalone .exe downloader or setup wizard
  • No ads, trackers, or bundled software inside the archives

What we don't control:

The file hosting sites we link to (FileDitch, FileQ, Gofile, etc.) run their own ad networks. We have no say in what ads they serve. Those ads can be malicious: fake download buttons, redirects to malware, browser-locker pages. The archives themselves are clean. The danger is the pages you download them from.

This is not a disclaimer to cover ourselves. It's a real distinction that affects how you should behave while downloading.


Step 1: Get a Proper Ad Blocker

This is the single most important thing you can do. Without a proper ad blocker, visiting a file host is genuinely risky. With one, the risk drops to nearly zero.

Why most blockers aren't enough

Brave's built-in blocker is good for everyday browsing but it is not sufficient for file hosts. Brave Shields uses a more conservative filter list that doesn't cover the aggressive ad networks these sites use. It will let through the exact categories of ads that hurt you.

uBlock Origin Lite (available on Chrome) is a stripped-down version built to comply with Chrome's Manifest V3 extension policy. It lacks dynamic filtering, has fewer filter lists, and cannot block the same range of threats as the full uBlock Origin. It is not a substitute.

AdBlock / AdBlock Plus have historically accepted payment from advertisers to whitelist certain ad networks. They cannot be trusted for this use case.

What you need: uBlock Origin (full version)

uBlock Origin is the only ad blocker that reliably stops malicious ads on file host pages. It's free, open-source, and has been independently audited.

The problem for Chrome users: Google removed uBlock Origin from the Chrome Web Store in 2025 due to Manifest V3 restrictions. You can no longer install it on standard Chrome or Edge.

Your options:

  • Firefox: uBlock Origin works perfectly on Firefox. It's the easiest solution and what we recommend.
  • Helium: a Chromium-based browser that ships with uBlock Origin (the real, full version) pre-installed. If you're committed to a Chromium browser, Helium is the right choice. You get the Chromium engine you're used to plus proper protection out of the box.
  • Don't keep using Chrome or Edge with uBlock Origin Lite thinking you're protected. You're not.

Setting up uBlock Origin properly

After installing (Firefox or Helium):

  1. Click the uBlock Origin icon → confirm it shows a green power button (active, not paused)
  2. Open the dashboard → Filter lists tab
  3. Under Malware domains, enable everything in that group
  4. Enable uBlock filters – Badware risks
  5. Click Apply changes at the top
Warning

If a file host page tells you "please disable your ad blocker to continue", close the tab. Legitimate file hosts do not require this. The only reason they'd ask is to expose you to the ads they profit from, which are the exact ads that can harm you.


Step 2: How to Behave on File Host Pages

File host pages are deliberately designed to confuse you. The ads are often bigger, brighter, and more prominent than the actual download button. Here's how to navigate them without getting caught.

Before you click anything

  • Check the URL bar. Make sure you're on the file host's own domain, not a redirect or lookalike page.
  • The real download button is boring. It's usually a small, plain text link or a simple button with no animation. The giant green "DOWNLOAD NOW" button is almost always an ad.
  • Wait for countdown timers on their own. A lot of file hosts make you wait 5–10 seconds before the real link appears. Do not click anything during this time. The ads are trying to catch you off guard.
  • Pop-ups and new tabs that open automatically: close them immediately without clicking anything inside.

Things that are never legitimate on a file host

If you see this...It's actually...
"Disable your ad blocker to download"Attempt to expose you to malicious ads
"Your download is ready, click to claim" overlayFake download button leading to malware
A CAPTCHA to "unlock" or "generate" your download linkSocial engineering. No legitimate host does this
"Install our Download Manager for faster speeds"Malware disguised as a utility
A prompt to log in with Google, Discord, or SteamCredential phishing. Close the tab immediately
A browser pop-up saying your PC is infectedFake security alert / tech support scam
Browser asking to show notificationsDeny it. File hosts have no reason to push notifications

The real download link leads straight to a .rar file. If what you got is an .exe and not a .rar part file, do not run it.


Why Your Antivirus Flags Game Files

Cracked games require modified .exe files and DLLs that bypass store authentication. Antivirus software flags these because the modification technique looks identical to what malware does. This is a false positive: the AV is matching a behaviour pattern, not an actual known virus.

Files that will almost always get flagged:

  • The game's main .exe (patched to skip license checks)
  • steam_api.dll and steam_api64.dll (replaced with Goldberg Emulator)
  • Goldberg Emulator DLLs: steamclient.dll, steamclient64.dll
  • .asi plugin loaders in some games
  • Proxy DLLs used to load the crack, commonly named winmm.dll, dinput8.dll, or version.dll. These are legitimate Windows system DLL names being reused as loaders, a standard crack technique, not a sign the file is fake
  • A custom Launcher.exe provided by the release group instead of the game's original executable

Detection names that are safe to ignore

These are generic heuristic labels. Every cracked game triggers them. They mean nothing specific:

  • HackTool / HackTool.Win32.*
  • RiskWare / RiskTool
  • Patcher / Crack / Keygen
  • Wacatac / Wacatac.B!ml
  • Win32/Generic / Gen:Variant.*
  • Trojan.GenericKD.*, only when flagging steam_api.dll, not the game's own .exe

These are only safe to ignore when the detection is on a file inside the game's own folder: the .exe, steam_api.dll, or emulator DLLs. If the same name shows up on a file in %AppData%, %Temp%, or anywhere outside the game folder, that's different.

Detection names that are not safe: stop immediately

Danger

If your antivirus names any of the following, do not proceed. Run the flagged file through Hybrid Analysis (free, quick signup) and ask in our Discord before doing anything else.

Stealers: Lumma, LummaC2, RedLine, Vidar, Raccoon, Amadey, FormBook, Phorpiex

Remote access: AsyncRAT, njRAT, Quasar, DarkComet, Emotet

Miners: Coinminer, XMRig, BitcoinMiner, Monero

Also stop if:

  • Any detection fires on a file outside the game folder (C:\Windows, %AppData%, %Temp%, %ProgramData%)
  • A .bat, .ps1, or .vbs script inside the archive gets flagged
  • A sandbox run (Hybrid Analysis or any.run) shows real network connections, registry persistence, or access to your browser/credential files
  • Your antivirus reports outbound network connections to unknown domains immediately after launching the game

Malware Types: What They Are and What They Do

Malvertising

Malvertising is malicious advertising: ads served through legitimate ad networks that redirect you to malware, exploit pages, or fake software. It's the most common threat when downloading games because file hosts are heavy ad publishers.

The dangerous part: you don't have to click. Some malvertising exploits browser or plugin vulnerabilities just by loading the page. A single unprotected visit to a file host is enough. uBlock Origin stops this at the network level before the ad even loads.

Fake download buttons

Ad networks place convincing fake download buttons on file host pages, often bigger and more colourful than the real button, sometimes with fake progress bars or download counters to look credible. Clicking them downloads an .exe file disguised as the game, a "download manager," or a codec pack.

These files are almost always info-stealers or adware droppers. The tell: the file you downloaded is an .exe, not a .rar part file. Game downloads from GameBounty are always multi-part .rar archives. If you clicked a button and got an .exe, you got the wrong thing.

Info-stealers: the most dangerous threat

Info-stealers (Lumma, RedLine, Vidar, Raccoon and others) are the most common malware distributed through piracy sites. They are designed to be completely silent and complete their job within seconds of execution.

What happens when you run one:

  1. The stealer scans every browser profile on your PC: Chrome, Firefox, Edge, Brave, all of them
  2. It extracts every saved password, autofill entry, credit card, and session cookie
  3. It copies cryptocurrency wallet files and any seed phrase text files it can find
  4. It harvests your Discord token, Steam session data, and any other gaming credentials stored in config files
  5. Everything is compressed and sent to the attacker's server, all in under 30 seconds
  6. The process exits silently. The game may even launch and work normally.

You will see nothing. No pop-up, no slowdown, no error. The stealer is already done. The first sign is usually an email alert that your Google account was accessed from another country, or your Discord being used to send DMs you didn't write, or your Steam inventory suddenly empty.

The session cookie problem: Stealers don't just steal your password. They steal your session cookies, which are the tokens your browser uses to stay logged in. An attacker with your session cookie can access your account without knowing your password and bypasses 2FA entirely because the session was already authenticated. This is why changing your password alone isn't enough. You also have to invalidate all active sessions.

Ren'Py games are a common stealer delivery vehicle, especially in the adult visual novel scene. Ren'Py is a Python runtime: every .rpy and .rpyc script in the game/ folder executes code at launch. An attacker can embed a stealer payload directly in the game scripts, and the game will load and play normally the whole time. Red flags specific to Ren'Py: any .exe or .bat file inside the folder besides the main launcher, the game asking for admin (UAC) privileges (Ren'Py never needs this), or your AV flagging something inside the renpy/ or lib/ folder with a specific malware name rather than a generic one. .rpy files are plain text, so open them in Notepad before running if something feels off. Look for import subprocess, import socket, exec(, or base64.b64decode(.

RATs (Remote Access Trojans)

RATs give the attacker live, interactive control of your PC. They can see your screen, move your mouse, open files, run commands, and access your camera and microphone. They're usually delivered as a second-stage payload dropped by a stealer after the initial infection.

Signs: unexplained mouse movement, processes in Task Manager you don't recognise, the webcam indicator light activating when you haven't opened anything, PC waking from sleep on its own.

Cryptominers

Miners use your CPU and/or GPU to mine cryptocurrency for the attacker. They're less immediately destructive than stealers but can cause hardware damage over time from sustained 100% load.

Signs: unusually high CPU or GPU usage when no demanding programs are open, PC running loud and hot at idle, significantly reduced game performance, electricity bill increase, system fans spinning at max.


Red Flags Checklist

Run through this before launching anything you downloaded:

  • The archive was not password-protected
  • Inside the extracted folder there is a README.html file
  • No unexpected .exe, .bat, .ps1, or .vbs files appear alongside the game files
  • The file size matches approximately what was listed on the download page
  • Your AV detection (if any) is a generic name, not a named stealer or miner
  • The download came from a link on the GameBounty download page, not a search result or third-party repost

If any box is unchecked, don't run it. Ask in Discord first.


Verifying a File Before You Run It

VirusTotal checks a file against 70+ antivirus engines at once, but those engines mostly work from static signatures and heuristics. That's a bad fit for cracked game files: the patch that removes a license check looks, structurally, like what malware does to bypass protections, so static engines routinely flag perfectly clean cracked .exe files with vague names like HackTool or Gen:Variant. A wall of generic VirusTotal detections tells you almost nothing about whether a file is actually dangerous.

A sandbox gives you a real answer instead. Sites like Hybrid Analysis and any.run run the file in an isolated virtual machine and show you what it actually does: which processes it starts, what it writes to disk, what domains it contacts, whether it touches your browser profiles. That's a genuine signal, not a pattern-matching guess.

  • Hybrid Analysis is free with a quick signup and no approval wait. This is the one to use if you've never done this before.
  • any.run is excellent too and worth knowing about, but its free tier is gated behind manual approval that isn't always easy to get. Use it if you already have access; don't block on signing up for it.

How to read a sandbox report:

  • No suspicious network activity, no writes outside the game folder, no browser or credential file access: almost certainly clean.
  • Connections to unfamiliar domains (especially right after launch), or access to browser profile folders: stop. Don't run the local copy either.
  • Registry persistence entries, process injection into unrelated programs, or attempts to disable your antivirus: stop immediately. This is a real threat regardless of what any static scanner said.

VirusTotal is still fine as a five-second first look, and a single detection from a reputable engine (Kaspersky, ESET, Malwarebytes) naming a specific threat like Lumma is worth taking seriously even without a sandbox. But treat a pile of generic detections there as noise, not a verdict, the sandbox result is the one that actually matters.

Note: both Hybrid Analysis and any.run share uploaded files with other users. Don't upload anything that might contain personal data.


Antivirus Exclusions

Because cracked game files trigger false positives, you need to tell your antivirus to ignore your games folder. Do not disable your antivirus. Just exclude the folder where you keep games.

Windows Defender

  1. Open Windows Security → Virus & threat protection
  2. Click Manage settings under Virus & threat protection settings
  3. Scroll to Exclusions → click Add or remove exclusions
  4. Click + Add an exclusion → Folder → navigate to and select your games folder (e.g. D:\Games)

Malwarebytes

Malwarebytes only scans on-demand by default, so it usually doesn't interfere with games at launch. If it quarantines a game file, go to Detection History, right-click the quarantined item, and choose Restore and add exclusion.

Kaspersky / ESET / Bitdefender / Norton

All of these have an Exclusions or Trusted Zone section in their settings. Add your games folder path there. The exact menu path varies by version, so search "[your AV] add folder exclusion" for the specific steps.


Browser Security

Which browser to use

BrowseruBlock OriginNotes
FirefoxFull uBlock OriginBest option. uBlock Origin MV2 works fully.
HeliumShips with uBlock Origin built inBest Chromium option. Full uBlock Origin pre-installed, no setup needed.
BraveBuilt-in Shields onlyNot sufficient. Shields don't cover malicious file host ad networks. Install Firefox or Helium instead.
Chrome / EdgeOnly uBlock Origin Lite availableLite lacks dynamic filtering and key filter lists. Not a substitute. Switch browser.

If you use Brave and don't want to switch your main browser, at minimum open file host pages in a Firefox or Helium window with uBlock Origin enabled.

Extensions to install

ExtensionPurposeVerdict
uBlock OriginBlocks malicious ads and fake download buttonsRequired
FastForwardSkips link shortener wait pages automaticallyRecommended
Warning

Never install any extension that claims to "generate premium links," "accelerate downloads," or "bypass captchas automatically." These are consistently malware or data harvesters. Also be suspicious of any extension with "read and change all your data on websites you visit" permissions that you didn't deliberately install. Malicious extensions are a common second-stage infection vector.

Browser settings

  • Turn off the built-in password manager. Every major browser's password saving is the first thing a stealer empties. Use a dedicated password manager instead: Bitwarden (free, open-source) or 1Password.
  • Turn off "offer to save payment methods." Same reason.
  • Don't stay logged into accounts you don't actively use. An idle session cookie is just as valuable to a stealer as an active one.

Account Security

Info-stealers don't need your password. They steal session cookies that grant access without one. Knowing this changes how you should think about account security.

Preventive steps (do these now, not after something goes wrong)

  • Enable 2FA on everything that matters: Steam, Discord, Google, Epic Games, and any account with money attached. Use an authenticator app (Google Authenticator, Authy, or Bitwarden TOTP) rather than SMS, since phone numbers can be SIM-swapped.
  • Use a password manager. Bitwarden is free, open-source, and works on every platform. If your passwords are unique and not stored in the browser, a stealer can only capture your session cookies, not your actual credentials.
  • Don't store crypto seed phrases on your PC. Not in a text file, not in a screenshot, not in a notes app. Write them on paper and store them physically.
  • Check your Steam API key: go to steamcommunity.com/dev/apikey right now. If a key exists that you didn't create, your account has already been accessed by a third party. Revoke it immediately and change your password.

If you ran something suspicious (but aren't sure you're infected)

Don't wait to find out. Do these immediately, from a clean device:

  1. Change passwords for Google, Discord, Steam, and your email provider
  2. Log out of all active sessions on each account
  3. Revoke the Steam API key
  4. Check Gmail → Settings → Filters and Forwarding for anything you didn't set up
  5. Check Discord → User Settings → Authorized Apps, and revoke anything unknown

If You've Been Infected: Act Immediately

Time matters. A stealer finishes its job in seconds, but most attackers don't access accounts immediately. They sell or use the data later. Changing credentials quickly still locks them out.

Danger

Do every step below using a separate, clean device: your phone, a family member's PC, anything that isn't the infected machine. Using the infected machine to change passwords just gives the attacker your new passwords.

Step 1: Disconnect from the internet now

Pull the Ethernet cable or turn off Wi-Fi. If any data hasn't been exfiltrated yet, disconnecting stops it. Do this before anything else.

Step 2: Change every important password

Priority order, do not skip any:

  1. Primary email first (Google, Outlook, iCloud). Attackers use email to reset everything else
  2. Discord. Frequently targeted, tokens are easy to steal
  3. Steam. Check Guard mobile authenticator settings, remove any unauthorized devices
  4. Gaming platforms: Epic, EA, Ubisoft, Battle.net, Riot, Xbox, PlayStation
  5. Every password stored in your browser. Treat the entire browser as compromised

Step 3: Kill all active sessions

Every platform has a way to sign out of all devices at once. Do this for each account after changing the password. It invalidates any session cookies the attacker already has, even if they haven't used them yet.

  • Google: myaccount.google.com → Security → Your devices → manage all devices → sign out all
  • Discord: User Settings → Devices → Log out all known devices
  • Steam: Account details → Manage Steam Guard → Deauthorize all other devices

Step 4: Hunt for persistence

Attackers often set up ways to maintain access even after you change your password.

Gmail: Settings → See all settings → Filters and Blocked Addresses (look for rules forwarding your email to an unknown address) → Forwarding and POP/IMAP (check if forwarding is enabled to an unknown address)

Discord: User Settings → Authorized Apps, and revoke everything you didn't intentionally add. Check your sent DM history for messages you didn't write.

Steam: steamcommunity.com/dev/apikey. If a key exists, revoke it. Check trade history and market listings for unauthorised activity.

Step 5: Contact your bank

If your browser had any saved payment cards, or if any compromised account had a stored card, call your bank immediately. Ask them to flag unusual transactions and consider issuing a replacement card. You don't have to wait for fraud to appear. Being proactive is faster and easier than disputing charges later.

Step 6: Reformat Windows

Danger

A full Windows reformat is the only safe recovery from a stealer or RAT. Running an antivirus scan after infection is not enough. Sophisticated stealers and rootkits are built to evade detection tools. The only way to be certain the machine is clean is to wipe it.

  1. Back up personal files (documents, photos, game saves) to an external drive. Do not back up any executables, installed software, or game folders from the infected machine. They may carry the payload.
  2. On a clean device, download a Windows ISO from microsoft.com/software-download and create a bootable USB using Rufus or the official Media Creation Tool.
  3. Boot from the USB, select Custom install, and format the drive Windows is installed on before reinstalling.
  4. Reactivate Windows using Microsoft Activation Scripts, the only trusted open-source activator. Run it from PowerShell: irm https://get.activated.win | iex. Do not download it from any other site.

Network

  • You don't need a VPN to download from GameBounty. All file transfers happen over HTTPS, so the contents are encrypted in transit. A VPN adds nothing here.
  • A VPN is only useful if your ISP specifically throttles traffic to certain file hosts. If you use one, use a paid no-logs provider. Free VPNs routinely sell your traffic data, so you're trading one risk for another.
  • Switching your DNS to Cloudflare 1.1.1.1 or Quad9 hides your domain lookups from your ISP and adds basic malware domain filtering. It takes five minutes and has no downside.

Quick Reference

SituationWhat to do
AV flags steam_api.dll as HackToolSafe. Add your games folder as an AV exclusion
AV flags winmm.dll, dinput8.dll, version.dll, or Launcher.exeSafe. These are standard crack loader names, not fake files
AV flags a file as Lumma, RedLine, or any named stealerStop. Do not run, delete the archive, ask on Discord
Archive is password-protectedStop. GameBounty never uses passwords on archives
No README.html in the extracted folderStop. Likely a tampered or wrong file
File host says "disable your ad blocker"Close the tab
File host asks you to log in with Google or DiscordClose the tab. It's a phishing page
Downloaded an .exe from a file host buttonDon't run it. Game downloads are always .rar part files
Accounts accessed from unknown locationChange all passwords from a clean device immediately
You ran something and aren't sure what it wasAssume infected. Follow all 6 steps above