meteorrejects.net: a Minecraft cheat-addon site that URLhaus lists for SilentNet stealer files

meteorrejects.net is a polished website for a Minecraft addon called Meteor Rejects, and URLhaus lists three of its .jar files as malware tagged SilentNet and stealer. If you installed one of these files, treat the PC as compromised: change your passwords and Microsoft account from another device, then scan it offline.

Facts checked October 9, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If a meteor-rejects-addon .jar file downloaded from meteorrejects.net keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove meteorrejects.net (SilentNet, Minecraft .jar) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Part of the meteorrejects.net page in our test browser: the heading Why Meteor Rejects, four feature cards and a Module Library with version buttons 1.21.0, 1.21.4 and 1.21.11
What meteorrejects.net showed our test browser on 9 October 2026. The page looks like a normal open-source project site. Our capture starts part way down the page, below the Get Free button.

Meteorrejects.net (SilentNet, Minecraft .jar): summary

TypeA site offering Minecraft addon files; URLhaus lists its .jar files as malware tagged SilentNet and stealer
RiskHigh if you installed one of its files: game, Microsoft, Discord and browser logins and crypto may have been taken
SymptomsOften none. A meteor-rejects-addon .jar in the mods folder, sign-in alerts and messages you did not send are the signs
How to get rid of itClose the game, change passwords from another device, move crypto, run a Microsoft Defender Offline scan, then back up documents and reinstall Windows if in doubt
Our check (9 October 2026)One visit: a normal page, no pop-ups or notification request. A quiet site clears nothing; the danger rating comes from URLhaus
Running since / first seenDomain registered 24 May 2026; first file reported 14 September 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformMinecraft Java Edition addons; the sources we read describe Windows PCs
Detection namesNo Microsoft detection name is known for these files, because we did not open them. The tag SilentNet is the reporter's label, and a Triage report on a different SilentNet file also lists WeedHack; neither was checked against these files
NameMeteorrejects.net
Domain registered24 May 2026
Evidence3 write-ups by security sites; details still limited
First seen14 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked9 October 2026

Facts checked on 9 October 2026 against our copy of the URLhaus data for meteorrejects.net, RDAP, one browser visit of our own, Check Point Research, a Triage sandbox report and Microsoft Learn. We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What meteorrejects.net is, and what we know about it

meteorrejects.net is a website that looks like the home of a free Minecraft addon, and the abuse.ch project URLhaus lists three .jar files on it as malware. The files carry the tag SilentNet; two also carry stealer, minecraft and jar. We did not download them, so this page rests on what URLhaus shows, what we saw on the site, and what other researchers wrote about files with the same tags.

  1. 1

    What URLhaus lists

    Three files under the site's main folder, all reported by the same person (GhostTypes): meteor-rejects-addon-1.21.11.jar on 14 September 2026, and meteor-rejects-addon-1.21.0.jar and meteor-rejects-addon-1.21.4.jar on 30 September 2026. All three were listed as online. The threat type is malware_download.

  2. 2

    What the tags mean

    SilentNet is a name given to a family of malicious Minecraft mods; the tag is the reporter's label. stealer says the file steals data. jar and minecraft say it is a Java archive for the game. The oldest file has only the SilentNet tag.

  3. 3

    What we could not confirm

    We did not download the files, so we do not know what exactly each does, which versions are affected or whether every file on the site is bad. We also did not check whether the real open-source project that the site imitates or claims to be hosts clean copies elsewhere.

  4. 4

    What this means for you

    If you only visited the page, you were not infected by that alone. The danger is for people who downloaded one of the .jar files and put it into the Minecraft mods folder, or ran it.

Kind of threat
A website that offers Minecraft addon files; URLhaus lists three of them as malware tagged SilentNet and stealer
Looks like
An open-source project page: 58 modules, 14 commands, an MIT licence, a download section, an FAQ and a GitHub link (our reading of the page text)
Domain registered
24 May 2026, expires 24 May 2027, registrar Cloudflare, Inc.; record changed 9 September 2026 (RDAP, read 9 October 2026)
URLhaus entries
3 file addresses, added 14 and 30 September 2026; all online when we read them
Platform
Minecraft Java Edition addons. Java runs on several systems; the sources we read describe Windows PCs

What meteorrejects.net (SilentNet, Minecraft .jar) does on an infected PC

What we checked on 9 October 2026, and what we could not

We opened https://meteorrejects.net/ once, from Lithuania, in an automated Chromium browser set to English. The page loaded normally. That is exactly what a malware site that wants to look trustworthy would do, so it clears nothing.

Our site test, 9 October 2026

  • The page loadedStatus 200, titled Meteor Rejects, 58+ Modules and 14 Commands for Meteor Client. A dark red page with a feature list, a module library, a download section and an FAQ.
  • Notification request, pop-ups, redirects, ad networks, service workerNone seen on this one visit. The page loaded only Cloudflare's script library, Google Fonts and Cloudflare Insights. There was no other address contacted.
  • The claims on the pageThe page calls itself the definitive free addon, open source and MIT licensed. We did not check these claims, and a malicious site can copy a real project's description.
  • URLhaus listingThree .jar files on this domain, tagged SilentNet; two also tagged stealer, minecraft and jar. All were online when we read the data.
  • Why a normal-looking page is not a clean resultSites that hand out malware often show different things by country, device or visit. One visit that looks fine does not say the files are safe, and our test did not download them.

Dangerous: treat the files as malware The page itself did nothing alarming on one visit. The danger rating comes from the three URLhaus reports, not from our visit. Do not download or run files from this site.

What happened to meteorrejects.net, from registration to our test

The domain is about four and a half months old. The dates come from RDAP and from the URLhaus database.

  1. 24 May 2026

    The domain is registered

    RDAP shows meteorrejects.net registered on 24 May 2026 through the registrar Cloudflare, Inc., valid until 24 May 2027.

  2. 9 September 2026

    The registration record changes

    RDAP shows the record last changed on 9 September 2026. It does not say what changed.

  3. 14 September 2026

    The first file is reported

    At about 06:01 UTC the reporter GhostTypes adds meteor-rejects-addon-1.21.11.jar to URLhaus with the tag SilentNet. This is the first time URLhaus sees the host.

  4. 30 September 2026

    Two more files are reported

    At about 09:58 UTC the same reporter adds the 1.21.0 and 1.21.4 versions, tagged jar, minecraft, SilentNet and stealer.

  5. 9 October 2026

    Our test loads the site, and the files are still listed

    The site answers with a normal page. All three files are still marked online in the data we read the same day.

    Part of the meteorrejects.net page with feature cards and a module library
    meteorrejects.net in our test browser on 9 October 2026. Nothing on the page warns of the files that URLhaus lists.

We could not read the URLhaus pages themselves, because they ask for a browser check. The entries above come from the same data in our own database, which holds the URLhaus feed.

How a fake game addon gets you to install it

Nothing here uses a security hole. You download a file because it promises something, and you install it yourself. Check Point described the same pattern for fake Minecraft cheat mods; we did not see this site's download step.

  1. 1

    You search for a cheat or an addon

    Players of Minecraft utility clients look for extra modules. A site named after the addon, with a Get Free button and version buttons for 1.21.0, 1.21.4 and 1.21.11, fits that search.

  2. 2

    You download a .jar file

    A .jar is a Java archive. Fabric-style mods are put into the mods folder of Minecraft by hand, which is why a victim installs the file without any warning from Windows.

  3. 3

    The game starts the file

    Minecraft loads the mod when the game starts. Check Point describes a Java loader that checks for virtual machines and analysis tools, then fetches the next stage; a second Java stage runs inside Minecraft and collects account data.

  4. 4

    A third stage may follow

    In the Check Point case a .NET stealer was downloaded by the second stage and sent its results out through a Discord webhook. We do not know whether the meteorrejects.net files do this.

  5. 5

    Antivirus may stay quiet

    Check Point says Java loaders of this kind went largely undetected by antivirus engines and sandboxes, which often lack the Minecraft parts needed to trigger the payload. A quiet scan therefore proves little.

Check Point's report is about a different campaign, the Stargazers Ghost Network, which hosted fake mods on GitHub. We use it only for how the chain works; we do not say the two are linked.

What the SilentNet tag tells us, and what it does not

The tag comes from outside reporters, and the public record on it is thin. This is what the pages we read say.

Sources: the Triage sandbox page for Krypton_Client.jar and the URLhaus data, read 9 October 2026.
QuestionWhat we foundSource
What is SilentNet?A signature name used for malicious Minecraft Fabric mods. One Triage report on a file called Krypton_Client.jar scores it 10 out of 10, tags it RAT, stealer and trojan, and links it to the SilentNet and WeedHack familiesTriage report, read 9 October 2026
What does that sample do?The report's own text says it steals session tokens, downloads and runs more payloads, and persists through hidden means. It gives no domains, addresses or file names for theseTriage report
Is it the same as meteorrejects.net's files?Not known. The tag is the same; the sample is a different file. We did not compare the filesOur reading
How did antivirus do?In that report the static analysis matched SilentNet and WeedHack signatures, while two sandbox runs on Windows 10 and 11 raised noneTriage report
What is not known?Which servers the files talk to, what exactly they take, and whether they run on Mac or Linux. No source we read saysOur reading

What meteorrejects.net (SilentNet, Minecraft .jar) can steal or download

What a fake Minecraft addon can take

We do not know the exact list for these three files. Check Point lists what the stealer in a comparable Minecraft mod campaign collected, and Triage lists session tokens for a SilentNet sample. Plan for the wider list.

Reported as taken in comparable Minecraft mod malware

  • Minecraft session tokens and account files
  • Feather, Essential and Lunar launcher data
  • Discord data
  • Telegram data
  • Browser passwords (Chromium, Edge, Firefox)
  • Cryptocurrency wallets
  • VPN configs
  • Steam data
  • FileZilla data
  • Clipboard contents
  • A list of running processes
  • Screenshots
Sources: Check Point Research and the Triage report, read 9 October 2026.
DataWhat can happenSource
Minecraft session tokenSomeone else can use your game account and, through it, your linked Microsoft account sign-inCheck Point; Triage
Discord and Telegram dataYour chats and logins can be used to message your friends with the same lureCheck Point
Browser loginsSaved passwords and cookies for email, banks and shopsCheck Point
Crypto walletsFunds that cannot be recovered once movedCheck Point
More payloadsA downloader can add more malware later, so the first file may not be the lastTriage

What this can cost you

Visiting the page costs nothing. The risks below apply to a PC where one of the .jar files was put into the mods folder or run.

  • High

    Account takeover

    A stolen session token lets someone use your game, Discord or browser accounts without your password. A new password alone may not end a stolen session.

  • High

    Crypto theft

    Wallet files are a main target for stealers. Move funds first, from another device.

  • Medium

    More malware installed

    Triage says a sample with the same tags downloads and runs additional payloads. A hidden program may start again after you remove the mod.

  • Medium

    Friends and servers

    If your Discord is taken over, the lure can be sent to your friends. If you run a server, tell its members.

  • Medium

    Children's accounts

    Many Minecraft players are young. A parent should check the family's Microsoft account for sign-ins they do not know.

  • Low

    Nothing, if you only saw the page

    A page visit, a warning or a blocked link is not an infection.

What you may notice, and what you may not

Most victims notice nothing at first. The signs below follow from what the reports say these files do.

Sources: the URLhaus file names and the Check Point and Triage reports, read 9 October 2026; the last two rows are our reading.
SignWhat it means
A .jar named meteor-rejects-addon in the mods folderThe file you installed. Its name matches the URLhaus entries. Press the Windows key + R, type %appdata%\.minecraft\mods and press Enter to look
Game or launcher logged out by itselfA session that was stolen and used elsewhere can end yours
Discord messages you did not sendA taken-over account sending the same download link
Sign-in alerts for your Microsoft account from other placesSomeone else using a stolen token or password
Slow PC or an unknown java or javaw processA hidden second stage. This is our reading, and not every infection shows it
Nothing at allStealers are built to finish quickly and stay quiet

How to check the PC for meteorrejects.net (SilentNet, Minecraft .jar)

How people end up on a page like this

We do not know how visitors reach meteorrejects.net, and no source says. These are common routes for fake game mods.

  1. 1

    A search for the addon's name

    A page named after a popular addon can show up beside the real project when a player searches for a download.

  2. 2

    A video or a chat link

    A video description or a Discord message that says free cheats or the best addon points to a download page.

  3. 3

    A GitHub link that copies a real project

    Check Point describes fake mod repositories on GitHub that were starred by many accounts to look trusted.

  4. 4

    A friend whose account was taken

    A message from someone you know carries more weight, and it is how a stolen Discord account spreads the lure.

Check your PC before you delete anything

Start with the question that matters: did you download a meteor-rejects-addon .jar from meteorrejects.net and put it in Minecraft's mods folder, or run it? If yes, follow the numbered plan on this page, because a clean-looking check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.

While you check, do not start Minecraft, and do not use the PC for banking, email or crypto. If you can, disconnect it from Wi-Fi and the network cable.

Order of actions after installing a fake addon: close the game, change passwords from another device, run an offline scan, then decide whether to reinstall Windows
The order of actions after installing the file: accounts and crypto first, from another device; the PC last.
  1. 1

    Look in the mods folder

    Press Windows key + R, type %appdata%\.minecraft\mods and press Enter. Look for a file named meteor-rejects-addon with a version number, or any mod you do not remember adding. Do not open it; write down the name and date. Launchers such as Feather, Essential or Lunar keep their own folders, so check them too.

  2. 2

    Check Downloads

    Open File Explorer > Downloads and look for .jar files from the day you got the addon. Right-click a file and choose Properties to see its date. Do not double-click a .jar.

  3. 3

    Look for a scheduled task you did not make

    Press the Windows key, type Task Scheduler and open it. Select Task Scheduler Library and read the names and the Actions tab of any task that is new or has a random name. Do not delete anything yet.

  4. 4

    Look in the Startup folder

    Press Windows key + R, type shell:startup and press Enter. A file you did not put there is a sign of something that starts again. Note it.

  5. 5

    Check Windows Security

    Open Windows Security > Virus & threat protection > Protection history. On Windows 10 the same page is under Settings > Update & Security > Windows Security. Look for detections around the time of the download. A clean list lowers doubt; it does not remove it.

How to remove meteorrejects.net (SilentNet, Minecraft .jar)

How to remove meteorrejects.net

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to meteorrejects.net or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever meteorrejects.net installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Scan from outside Windows: Microsoft Defender Offline

An offline scan runs before the normal Windows starts, so a hidden program cannot hide from it as easily. Microsoft's page says it targets malware that tries to bypass the Windows shell, such as rootkits.

  1. 1

    Prepare

    Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. It needs an administrator account and Windows Recovery Environment turned on. To check, open a Command Prompt as administrator and run reagentc /info; if it says Disabled, run reagentc /enable.

  2. 2

    Suspend BitLocker if it is on

    If BitLocker protects the system drive, suspend it first. Otherwise the PC may ask for your recovery key when it restarts into the offline scan.

  3. 3

    Start the scan

    Open Windows Security > Virus & threat protection > Scan options. Choose Microsoft Defender Offline scan and select Scan now. Agree to the prompts. The PC signs you out, restarts into the scan and starts Windows again when it ends.

  4. 4

    Read the result

    Open Windows Security > Virus & threat protection > Protection history. Microsoft says the scan works on x64 Windows 10 and 11, not on ARM, and needs Microsoft Defender Antivirus as the main antivirus.

  5. 5

    Remove the mod and the launcher cache

    Only after the scan, delete the meteor-rejects-addon file from the mods folder. Download Minecraft mods only from the maker's own page or from a source you checked, and never reuse this file.

  6. 6

    Do not stop there

    A scan that finds nothing does not prove the PC is clean, because Java loaders of this kind can go unnoticed. If the file ran, the safest end of the plan is to back up documents and reinstall Windows.

If you play on a Mac, a phone or a console

The sources we read describe Windows PCs. A .jar can run anywhere Java does, so the file is not limited to Windows by itself.

Your deviceWhat we knowWhat to do
Mac or Linux with Minecraft JavaA .jar does not care about the system. Whether these files act on other systems is not stated by any source we readTreat it as the same case: change passwords from another device, remove the file and check our Mac guides for the cleaning steps; do not follow the Windows steps
Bedrock Edition, phone, tablet or consoleFabric-style .jar mods do not run thereNothing to remove. If you typed passwords on the page, change them

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

The PC is one half. The other half is everything that was on it, which the attackers may already have. The order matters: other device first, then crypto, then the PC.

  1. 1

    Change your Microsoft account password from a clean device

    Use a phone or another computer and the Microsoft account page. Then sign out everywhere. A stolen game token can ride on a Microsoft account sign-in.

  2. 2

    Change Discord and other passwords, and revoke sessions

    Change Discord, email, bank and shop passwords. In each account use the option to log out of all devices, because a token can outlive a password change.

  3. 3

    Warn your friends and your server

    If your Discord sent the link, tell people not to open it. Server owners should say which file name to avoid.

  4. 4

    Move crypto first if a wallet was on the PC

    If a recovery phrase may have been exposed, move the funds to a new wallet with a new phrase made on a clean device.

  5. 5

    Turn on two-factor sign-in

    Use an authenticator app or a security key where the account allows it.

  6. 6

    Back up documents and reinstall Windows if in doubt

    Copy only documents and photos to an external drive. In Settings > System > Recovery on Windows 11, or Settings > Update & Security > Recovery on Windows 10, choose to reset the PC and remove everything.

Keep a gamer PC out of this kind of trap

The rule that would have stopped this: a mod is code you run with your own rights, so it is only as safe as the place you got it from.

Do

  • Get mods only from the maker's official page, and compare the link with the one in the project's own repository.
  • Treat a polished page with a Get Free button and no named authors with suspicion.
  • Keep Windows and Windows Security up to date and turned on.
  • Use an authenticator app for your Microsoft and Discord accounts.
  • Run Minecraft under a normal account, not on a PC that holds work or banking logins.

Don't

  • Do not download cheat addons from sites that came from a video or a chat link.
  • Do not double-click a .jar file from the Downloads folder.
  • Do not rely on a quiet antivirus scan to say a .jar is safe.
  • Do not reuse one password for the game, Discord and email.
  • Do not keep a wallet recovery phrase in a file on a gaming PC.

Questions about meteorrejects.net (SilentNet, Minecraft .jar)

What is meteorrejects.net?

It is a website that presents a free Minecraft addon called Meteor Rejects, with a module list, a download section and a FAQ. URLhaus lists three .jar files on it as malware, tagged SilentNet, two of them also tagged stealer.

The domain was registered on 24 May 2026. In our test on 9 October 2026 the page loaded normally, with no pop-ups and no notification request.

A normal page does not make the files safe. If you only visited, you are not infected by that. If you downloaded or installed a file, use the cleaning steps on this page.

Is Meteor Rejects a virus?

The real name belongs to an addon idea, so we separate the name from this site. The files on meteorrejects.net are listed by URLhaus as malware, so do not use them. We did not download them and did not check whether the open-source project that the site describes has clean files elsewhere.

If you want the addon, find the project's own repository and check its links yourself, or skip it. A page that copies a project's description and offers a Get Free button is not proof that it is the project.

What is SilentNet?

SilentNet is a tag used for malicious Minecraft Fabric mods. A Triage sandbox report on a file called Krypton_Client.jar scores it 10 out of 10 and links the tag to the WeedHack family, with a RAT, stealer and trojan label.

The report says such a mod steals session tokens, downloads and runs more payloads, and persists through hidden means. It gives no more detail. We did not compare it with the meteorrejects.net files, so we say only that they carry the same tag and plan for the same kind of risk.

I installed a meteor-rejects-addon file. What do I do now?

Close Minecraft and its launcher and disconnect the PC from the network. From another device change your Microsoft account password, then Discord, email and bank passwords, and sign out of all devices. Move any crypto to a new wallet.

Then run a Microsoft Defender Offline scan on the PC and delete the file from the mods folder. Because Java loaders can go unnoticed, the safest end is to back up documents and reinstall Windows. Warn friends if your Discord could have sent the link.

What if I only visited the site and downloaded nothing?

Visiting a page does not usually infect a PC by itself. The danger starts when you download a .jar and put it into the mods folder or run it. If you downloaded nothing, close the tab, do not go back, and run a normal scan in Windows Security as a precaution.

If you downloaded a file but never opened it, delete it from Downloads and empty the Recycle Bin, and do not double-click it. If you did open it, treat it as installed.

Where is the Minecraft mods folder on Windows?

For the standard launcher, press the Windows key and R together, type %appdata%\.minecraft\mods and press Enter. The folder holds the .jar files the game loads. Look for meteor-rejects-addon with a version number, or any file you do not remember adding.

Launchers such as Feather, Essential and Lunar may keep their own folders, so check them as well. Do not open a suspicious file. Note its name and date, then remove it only after the offline scan.

Will a scan with Windows Security remove it?

Microsoft Defender can detect many malicious files, and you should run it. But we cannot promise it finds the files from this site, because we do not know what they install, and Check Point says Java loaders of this kind went largely undetected by antivirus engines.

The stronger step is the Microsoft Defender Offline scan, which runs before Windows starts. If the mod ran, reinstalling Windows is the surest cleaning. We know of no removal tool that we have tested against these files.

Was my Minecraft or Microsoft account stolen?

We cannot tell from the outside. The report on a SilentNet sample says it steals session tokens, and Check Point's account of a comparable campaign lists Minecraft account files and launcher data. Look at your Microsoft account's recent sign-in activity from another device, and sign out everywhere.

Change the password and turn on two-factor sign-in. If you see sign-ins from places you were not, assume the account was taken and tell Microsoft support, and check linked Discord and email accounts as well.

Why did our test of meteorrejects.net look normal?

Our automated browser loaded the page with a status 200, a feature list and a module library, and it saw no pop-ups, redirects or notification request. A malware site that wants downloads needs to look trustworthy, so a normal page is expected.

The harm is in the files, not the page, and we did not download them. Sites also can show different things by country, device or visit. One visit that looks fine clears nothing, and the URLhaus listing is why we rate the files as dangerous.

Will Fortect remove meteorrejects.net?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For meteorrejects.net, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove johnsonsvalves.cam: a Windows XWorm malware site that hides code in a PNG, and what to do if a script from it ran

johnsonsvalves.cam is a website that URLhaus lists for malware downloads: The site no longer answers when we look it up. If you ran a script or a pasted command from it on Windows, treat the PC as compromised: change...TRHigh riskUgnius Kiguolis ·

Remove stanarcservice.com: a Windows ClickFix malware site (s.ps1) and what to do if you pasted its command

stanarcservice.com is a website that URLhaus lists for malware downloads, one of them a PowerShell script (s.ps1) tagged ClickFix, and it refused our test connection. If you pasted a command from it into the Windows...TRHigh riskUgnius Kiguolis ·

Remove "Windows activation Error code:0x56102" Support scam virus

Windows activation Error code:0x56102: it‘s just another tech support scam Among recent support scams, Windows activation Error code:0x56102 virus is an interesting sample. Though it is based on a realMalwareHigh riskJulie Splinters ·

Remove "Windows Defender Prevented Malicious Software" Tech support scam

Reasons why you should not trust "Windows Defender Prevented Malicious Software" alerts Windows Defender Prevented Malicious Software virus may really scare the wits out of you if you do notMalwareHigh riskJulie Splinters ·

Questions and experiences: meteorrejects.net (SilentNet, Minecraft .jar)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year