• Happy New Year 2026! 🎉🌟 May this year bring new desires, deeper bonds, and unforgettable moments. If destiny hasn’t brought love to your door just yet, we've got you covered all year long.
  • Malware detected from member's upload: We have received a credible report potential CryptoMiner from jekson5865's upload. Please check if you had downloaded from this member. Full details here. マルウェアがメンバーのアップロードから検出されました: @jekson5865のアップロードから、潜在的なCryptoMinerの存在について信頼できる報告を受け取りました。もし、このメンバーからダウンロードした場合は、確認をお願いします。詳細については、こちらで確認できます。检测到来自成员上传的恶意软件: 我们已收到来自@jekson5865上传的报告,指出存在潜在的CryptoMiner。请检查您是否下载过该成员的文件。完整详情请点击这里查看。

PSA: Malware detected from member's upload

Hi! Thank you so much to everyone who's answering questions and contributing. It's a shame these things happen :(

I have a question, is the list of infected games final? Or is it still possible that more infected games will be found?
 
I have a question, is the list of infected games final? Or is it still possible that more infected games will be found?

The list is from what the member posted on ASF. For new member to post on ASF, they are subjected to throttling such as 1 thread per hour, all thread is held in the approval queue. Therefore, the member coudn't post many in the span of 1 month.

If you download your game from sources like Tokyo Toshokan or Nyaa Torrents, the same member may have shared more content since they aren't subject to the same throttling.

Unfortunately it's hard to say whether other Uploader/Contributor redownload somewhere else as well.
 
Add [RJ01524403] to this list, it was also most likely distributed by the well-known jekson5865/hentaigamer**
But I can't vouch for the game uploaded here. It was originally posted on a popular anime tracker similar to nyaa, and this torrent is also indexed by TokyoToshokan. (A hint to the site, because I'm not sure if it's allowed to mention/write names websites)
Why so many worries, just use Free antivirus tools. Many years, use CureIt, from Cd -> Dvd -> Flash.
https://free.drweb.ru/download+cureit+free/
ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe
Kaspersky Virus Removal Tool
https://www.kaspersky.ru/downloads/free-virus-removal-tool?ysclid=mjviudgnex23020704
If, you still worry, just install Full version, any Antivirus, you get 30 days free, for test.
https://www.av-test.org/en/
P.S If, you have Virus, (more important Troyan) , they can ease change, file name, regname. If, they already inside.
If you read the article published by Huorong and uploaded the infected files (if you had any, for example), you'd realize that currently only two antivirus programs detect them: Huorong and Rising, and nothing else. I got infected myself, and the first thing I did was, as an experiment, scan my computer for viruses using AV scanners (KVRT, Cureit, Minersearch), and they found nothing. The most CureIT could find was a modified line in REGEDIT, and that was it. As for the miner itself, it wasn't found.
 
  • Like
Reactions: yeahdat
Last edited:
  • Like
Reactions: PhantomMemos
By the way, this might sound pretty crazy to some, but one of the games on the list, namely — RJ01524136, was initially infected with a cryptominer (libegl.dll, cacheapp, etc.) and sold with it on DLsite.
How could this have happened? Who knows, most likely the developer was infected too, and the infected files "migrated" to their game. But that's just my theory. On one of the content sharing forums, a user posted a screenshot of this game purchased from them, and it was the game they bought that infected them.

01.jpg
 
To be fair I did mention there is nothing such 100% safety. Even if one buy it from DLSite, it will be lowest risk but not absolute.

Stay safe, we are stronger together.

I am looking into that possibility at the moment but it is the holiday...
 
Last edited:
  • Like
Reactions: bidlocat0
By the way, this might sound pretty crazy to some, but one of the games on the list, namely — RJ01524136, was initially infected with a cryptominer (libegl.dll, cacheapp, etc.) and sold with it on DLsite.
How could this have happened? Who knows, most likely the developer was infected too, and the infected files "migrated" to their game. But that's just my theory. On one of the content sharing forums, a user posted a screenshot of this game purchased from them, and it was the game they bought that infected them.

View attachment 85785
1767334693812.png

1767334709703.png


In that case, I find it strange if all ddl hentai game sites are not infected.
I downloaded the same thing from ryuugames and scanned libEGL.dll with virustotal, but Huorong did not detect it as
TrojanDropper/CoinMiner.d.
I cannot say for sure as I have not performed dynamic analysis, but since there is antivm, I cannot scan it without a sub-PC.
 
Add [RJ01524403] to this list, it was also most likely distributed by the well-known jekson5865/hentaigamer**
But I can't vouch for the game uploaded here. It was originally posted on a popular anime tracker similar to nyaa, and this torrent is also indexed by TokyoToshokan. (A hint to the site, because I'm not sure if it's allowed to mention/write names websites)

If you read the article published by Huorong and uploaded the infected files (if you had any, for example), you'd realize that currently only two antivirus programs detect them: Huorong and Rising, and nothing else. I got infected myself, and the first thing I did was, as an experiment, scan my computer for viruses using AV scanners (KVRT, Cureit, Minersearch), and they found nothing. The most CureIT could find was a modified line in REGEDIT, and that was it. As for the miner itself, it wasn't found.
My, Kaspersky Premium perfectly find, 3 days ago, when i try run game. Database Update, several times every day, for all Antivirus. Your, Old database, cant find, okay, that normal. Second need Activate, All check, not a light check, in side config, your Antivirus. And, i don`t remember, i write it help imideatly 100%, if you find, when i write it, give me. Or, you think, i need search load and check my self, virus <-> against antivirus.
-
when i check again (Reg) right now, i find only link to C:Users\''YourUsedName''\AppData\Local\Scacheapp
nothing more, no file no other changes, Kaspersky delete body virus, and folder, but automatic (Reg(Windows) create link, in Last used folder, anyway.
-
Windows Reg creat big ammount of garbage, need Clean, and Clean. Every month.
 
My computer has a "syscacheapp" folder, but the folder is empty and there is no SHELL in the registry, which makes me very confused as to whether I have been infected or not.
 
Late to know during holidays, seems it just a miner but not crypto your important files, but cannot guarantee next time...I'm away from .exe for a long time(main download doujin voice works).In general security aspect, if malware created too new to detect(like virustotal website), some ways may help for daily:
1,process auditing :lea rn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/command-line-process-auditing
2,other handy tools: w ww.nirsoft.net/utils/executed_programs_list.html
 
Yesterday I deleted it- -I didn't remember it
If the creation date is before December 10, 2025, it may have been created for a reason other than this issue. If the creation date is after December 10, 2025, the folder may have been created for this issue, but the file may not have been created for some reason (such as being deleted by antivirus software). Just to be sure, try searching for "cacheapp64.exe" on your PC.
 
Hey everyone, just a quick note regarding the recent CryptoMiner report affecting some uploads on Nyaa / Anime-Sharing. That's seriously worrying, and I'm really sorry this happened to people.

This is exactly why we started the DLsite Archive Project: we verify files by comparing hashes + file size against the official DLsite API. When a release matches the official reference, we can be far more confident it hasn't been tampered with.

Please stay cautious, and we'll keep doing our part to help the community verify what's safe.
 
This is exactly why we started the DLsite Archive Project: we verify files by comparing hashes + file size against the official DLsite API. When a release matches the official reference, we can be far more confident it hasn't been tampered with.
There's some problem with that, Uploaders and Contributors usually mix the original files a bit to prevent getting a watermark tracker against their account. Unless every main files are hashed, the archive hash may not tell anything.
 
I only really play hentai games on Steam, I wonder if my downloaded RPG Maker games are infected. Gaben, please give me strength.
 
There's some problem with that, Uploaders and Contributors usually mix the original files a bit to prevent getting a watermark tracker against their account. Unless every main files are hashed, the archive hash may not tell anything.
True, if uploaders modify files to avoid watermark tracking, a hash won't work. No system is 100% perfect. But that's also the point: a verified hash DB gives a baseline. Match = strong integrity signal, no match = user knows it's altered and can decide what to do. We're building this as a reference/source of truth as coverage grows, even if the DLsite API is messy.
 
Last edited:

Users who are viewing this thread

Latest profile posts

aute720 wrote on Mao Zedong's profile.
你会随身携带老式电话吗
マッチ wrote on ramori's profile.
こんにちは!よければこちらを再アップロードしていただけませんか?
https://www.anime-sharing.com/threads/240323-ハトマメ-bitch-family-on-the-village-rj01135233.1460442/
生きる糧 wrote on Otokonoko's profile.
Hello. Can you upload the video from
[kaosのファンティア (kaos)] 2025年10月投稿分まとめ
please