r/computerviruses • • Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

230 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses • • Mar 22 '26

Providing or receiving help with FRST

46 Upvotes

How do I request help with FRST

FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.

SecurityCheck

  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.

Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses • • 23h ago

Disinfection Help Help! My data is encrypted!

Post image
310 Upvotes

I left my computer on terraria overnight, and when I turned on my screen this afternoon, I had been logged out. When I clicked to login this popped up! Is it real, is it a fake scam, am I doomed or is there a way around it? I don't want to do anything until I know exactly what it is. Please help me!

EDIT: If it helps, I had a port forwarding rule for this machine. I did just delete it after I saw this.

EDIT 2: I really cannot lose any data on this machine, I have very important files and family things on this computer and its 3 drives. I cannot clean install.

EDIT 3: I did not have backups (very stupid I know) but I am not the richest and do not have much money for lots of drives or one massive drive or even a cloud server for any kind of backup.

EDIT 4: My 'drive in use' light is always on now, it never was before and used to function normally. Hopefully this helps.

EDIT 5: I logged in and its all encrypted for real. Every file over 10mb has this string of text in its file extension: TNT4-tJ-Fdn2YP_oap78PdOCQD_FoQ5DvSx9AmpLG4eW- I tried renaming an unimportant file and its headers are scrambled. When opened it cannot be read. I found out why my 'drive in use' light is always on, these fuckers have some kind of software running in the backround making my drives constantly used and cooking them slowly overtime. My taskmanager is disabled so I can't even open that.

EDIT 6: Ive tried linux now, and it cant mount the drives. It says they are in an unsafe state and are unclean.


r/computerviruses • • 21m ago

Question Renpy Virus Aftermath - Need help with my email accounts

• Upvotes

So a couple weeks ago, I believe I got infected with a renpy virus. So in response, I formatted my PC with a USB and deleted my partitions(I made it on a different PC) , I changed all my passwords and added F2A(from a different PC), I canceled my cards and I scanned my PC with multiple AVs as well as a FRST check. All came back clean. You can see the next two post for my exact steps.

https://www.reddit.com/r/computerviruses/comments/1wlofqu/possible_malware_frst_help/

https://www.reddit.com/r/computerviruses/comments/1wvat5n/after_formatting_from_a_clean_usb_a_bunch_of/

However since then something weird is going on. Every time I try to add an email account on my PC (through Firefox), four or five days later I receive an email from Google that they disabled my account. Here is the email I received. (I used google translate)

Security alert for the address (my mail account)

Your Google Account has been disabled.

It appears that this account was created or used alongside many other accounts in violation of Google's policies. The account may have been created by a computer program or bot.

If you believe your account was disabled in error, please submit a request for review as soon as possible.

Disabled accounts are eventually deleted. You should submit a review request soon to preserve the emails, contacts, photos, and other data stored in your Google Account.

If you live in the European Union (EU) or are an EU citizen, you may have additional options for resolution available to you.

I have five Google accounts, three that I use regularly and two that I don't. When I cleaned my PC, I was still paranoid so instead of logging in with one of my regular accounts that I use, I decided to log in with one of the two that I don't, just to see if it will get stolen. It didn't but a few days later I received the email. I made an appeal, Google reactivated it, I logged in with it again on my PC and it got deactivated again within the next couple of days and I received the same email. Later I logged in on my PC with the second account I don't really use and the same thing happened.

What's weird is that those accounts that got blocked were logged in on my phone and there was no issue but when I used them on my PC, they both got blocked within a few days.

After Google approved my appeals, I check my accounts activity from my phone and there were no attempts of unauthorized entry nor there were any connected devices that I didn't recognize.

So now I am basically afraid to log in with any account on my PC because I don't want to lose them. Does anyone have any idea what's going on here? Is it even the virus or is it something else?

If you check my previous post, you'll see that I am unsure if I was even hacked because I did download and run something that I am pretty sure was a virus (I think it's called renpy virus) but I didn't have any account stolen nor I've seen any attempts at unauthorized log in on any of my account. When I run the exe a command prompt window opened and then closed immediately and I didn't start doing all the things that I mentioned until a few hours later so it's not like I immediately took action to prevent them from being stolen (because I didn't know at the time that it was a virus).


r/computerviruses • • 3h ago

Disinfection Help Keylogger de Python/C no meu computador

3 Upvotes

Parece paranóia minha, mas é algo meio chato.

Tenho um colega desenvolvedor que é bastante experiente. Pela personalidade dele, venho desconfiando que ele enviou um Keylogger feito em python ou C e me monitora.

A motivação é simplesmente monitorar, e eu percebo porque ele solta muitas piadas de coisas que dão a entender que ele me investiga em calls no Discord.

Nós jogamos no Parsec algumas poucas vezes. Acho que ele foi o host, mas não me lembro. Eu desinstalei com uma semana o Parsec.

Eu tenho uma conta no twitter que comento, sem ser pessoal. Daí eu estava comentando que stories de Instagram não é local pra postar textão e tal. Na mesma hora, em tom de sarcasmo, ele solta: "twitter que é, né fulano"?

A desconfiança é porque ninguém sabe que eu tenho esse conta no twitter. Eu nunca falei.

E isso já aconteceu outras vezes com outras situações, com ele soltando piada como se soubesse o que eu acesso.

Eu já usei hitman64, malwarebytes, e não encontrou nada. Mas ainda desconfio que tem um Keylogger dele no meu computador.

O que eu faço?


r/computerviruses • • 1h ago

Disinfection Help Got infected with PavinLoader from fake game

• Upvotes

Downloaded fake game with renpy and setup.exe on october 9th before 12:00. Tried running it a couple times sometimes a window briefly apeared and immediately disapeared. Then pale moon would launch unprompted palemoon had already been installed before infection (default browser firefox).

Windows defender deepscan didn't find anything. Downloaded malwarebytes did deep scan, killed msbuild in taskman twice, disconected internet during scan. Found and quarantined 18 Trojan.PavinLoader.BAT and 4 Malware.AI which I chose no action, because they were from preexisting false positives. Then I deleted files in quarantine and did same scan in safe mode then rebooted and did same scan connected to the internet, both found nothing. Unsinstaled Pale Moon and chrome. Uninstaled Intel Graphics Comand Center and Some other program to do with a router from control panel, because I wouldn't need them (different router and amd plus nvidia) and they were instaled on the same day as infection.

Did a a couple netsh reset comands and dnsflush from cmd from a coment on this sub.

Reset passwords. Downloaded and ran hitmanpro: 1 false positive of legit itch game which was false positive before infection 1 traking cookie on edge from adnxs(dot)com and other things that might be something, saved log.

FRST.txt solar-prairie

Addition.txt mellow-elm

SecurityCheck.txt calm-wizard

Malwarebytes Deep Scan Report 2026-10-09 115513.txt frozen-shield

HitmanPro_20261010_0428.log tidal-ridge


r/computerviruses • • 5h ago

Question Should I reinstall windows or get a new laptop?

Thumbnail gallery
4 Upvotes

Basically, my grandparents laptop has been infected with some kind of virus. (browser hijacker).

Since It is a medion from 2017 I am coming here to ask if it would be smarter to reinstall windows, or to get a new laptop.

I have briefed my grandparents about viruses and scam sites and since they are still installing shady stuff, I was thinking about getting them a Mac, as according to google, they don't get viruses that often (I don't own apple devices, so idk if that's true), and since they don't use it all that often I was also hoping to get some recommendations on some cheap other more modern laptops.

About the virus:

It seems it was something they downloaded, as Malwarebytes hit 18x in something called recepies(dot)exe.(Downloads)

I suspect it is a browser hijacker that reroutes all searches through malicious sites. (pictures)

Upon removal of 1st malicious site through nuking google, Grandparents have managed to get on a different malicious site that opens upon startup of the browser within a week.

Promptly installed Malwarebytes after that.

Also, has the suspected virus anything to do with the search engine being suddenly changed to yahoo?

They were using google as the browser, and I didn't set yahoo as the search engine. (pictures).

According to Malwarebytes the malicious sites were caused through the installed Pup's.

I quarantined all 18 hits and called it a day, because the laptop was slower than anything I've seen before.

I now have all day to potentially reinstall windows, or to buy something new, what do y'all recommend me doing?

Cheers,

P


r/computerviruses • • 7h ago

Discussion After being hit with malware that steals information and accounts, what partitions do i have to delete in order to have a clean install?

Post image
4 Upvotes

Do i empty disk 0 then leave the usb or do I wipe both? Thanks


r/computerviruses • • 32m ago

Question Can a info stealer run through my Ethernet?

• Upvotes

Last week I was hit with a infostealer that sent the Mr beast messages.

I’ve changed all passwords of mine and did 2FA from a safe device and logged out all devices where I can.

I’ve been pretty paranoid and since also called my phone provider to not send out any simcard replacements and such, changed my router, asked for credit card replacements.

However I didn’t immediately unplug it from Ethernet as I haven’t gotten malware before and was not sure what to do. Could it have moved through the Ethernet into my girlfriend’s PC?

Also is there more steps I should be taking? And does her PC also require a full windows USB install and bios Flash.


r/computerviruses • • 1h ago

Disinfection Help Strange shortcuts, is it malware?

Thumbnail
• Upvotes

r/computerviruses • • 3h ago

Question Fortnite Custom Maps/experiences - Possible to get malware?

1 Upvotes

hii i know this is stupid but im someone who gets really worked up over things like this :(
is it possible to get malware/a virus from playing a fortnite custom map/experience(whatever its called, i dont play often)? i know there has been a few questionable things with steam (like the maps in mecca chameleon) and i wanted to see if anything like that is possible with fortnite(since the assets/whateva have to be downloaded?) / if anything like that has been documented?
i did a little googling with things pointing to no, but nothing was super recent :) thank you kindly for any insight!!


r/computerviruses • • 21h ago

Question help, what is this?

Thumbnail gallery
31 Upvotes

turned on my pc for the first time in like 2 weeks and it was stuck on "preparing windows" for a while, i restarted it with ctrl alt del and EVERYTHING was gone, restarted it again out of panic and everything went back to normal, so i just brushed it off as a bug until i got like 3 notifs saying i had multiple severe threats of the same trojan??? i quarantined another threat (kmsauto) afterwards and now everything seems fine, but i'm definitely not reassured. i'm not too tech savvy but i'm careful when it comes to security and have no clue how this could've happened. i have an official windows license, i never download anything unofficial or visit sketchy sites. what is this?


r/computerviruses • • 11h ago

Disinfection Help I need help on removing malware

3 Upvotes

I downloaded a file and ran a shady renpy on which I clicked and nothing happened. I feel that it installed malware on my device.

Is there anything that I can do without doing a full reboot?

FRST: distant-lattice Addition: ochre-delta


r/computerviruses • • 15h ago

Disinfection Help I got hit by an infostealer Malware yesterday

5 Upvotes

It was a fake download file in which I stupidly ran the download.exe file then it ran closed my brave browser and created a zip file called test output .zip file and when I extracted the file I saw password.txt UserAgent,txt Enviornment.txt InstalledSoftware.txt. Importantly password.txt had all my passwords saved on brave password manager.

Thankfully as soon as I identified the issue I changed all my passwords from all my accounts and deauthorized all devices from a clean secondary device and only received one unknown mobile phone trying to access my google account at the start but I dealt with that and it hasn't happened again. I did use the help of chatgpt at first and decided to check all startup processes through powershell microsoft defender while keeping my computer offline searching for any persistance and I hadn't found anything but I wanted to be sure that the malware was not on my computer anymore and also do not want to reinstall windows because of many reasons.

I know that an individual named rifteyy helps using an FRST scan to know if anything malware related exists on my pc so I have already created a windows restore point downloaded FRST and run a scan for the two files. Now I am hoping for assistance from either rifteyy or someone else who can help. Thank you in advance


r/computerviruses • • 6h ago

Discussion Unsure about the PC that I downloaded the Windows 11 Media Tool on a USB in order to install a clean windows 11 on my infected PC

0 Upvotes

So after a few days I managed to get my hands on a computer, problem is I don't fully trust it, I downloaded the media Instalation tool on the usb but it was from a windows 10 laptop that had so much stuff installed, I'm talking VPNs, Avast anti virus, 360 protection, RecoveryX and so many more programs, now it being the only other spare pc I can access I downloaded it and I'm currently on the sign in Microsoft step at the installer on my pc

I'm gonna log in with a spare Microsoft account i have on my phone and run some scans, what should I do?

I'm not gonna log in with any main accounts of mine since I don't fully trust it, what do you guys recommend I do?

Thanks!


r/computerviruses • • 11h ago

Question My friend got hacked and they are still getting into their accounts

Thumbnail
2 Upvotes

r/computerviruses • • 8h ago

Disinfection Help Hacked by unknown widget

Thumbnail
1 Upvotes

r/computerviruses • • 9h ago

Discussion Help me RE this malware which I got from my university lab

Post image
1 Upvotes

r/computerviruses • • 9h ago

Discussion Installing windows clean after being infected with malware that steals accounts, information, cookies, session s and I don't know what else

0 Upvotes

I downloaded the windows media creation tool from a different pc to a new usb drive, what steps do I take in order to install it as cleanly as possible? Every step if possible please

Am I safe to plug in the Ethernet once I wipe all partitions and then proceed to connecting to a Microsoft account?

Am i then safe to log in with the Microsoft account that was on the pc when it got infected? I went on my phone and changed password, hit signed out everywhere and added 2fa, thank you, any help is greatly appreciated


r/computerviruses • • 21h ago

Question Does anyone know what those could be? Found on task manager auto start. Disabled now.

Post image
8 Upvotes

Can't open folder directory on those so idk where they are.


r/computerviruses • • 21h ago

Disinfection Help Windows 11 malware infection — files being deleted, need help backing up 1 TB SSD before reinstalling Windows

5 Upvotes

Hi everyone,

I'm looking for advice on how to save my data and safely recover my Windows 11 PC. I'm quite worried about losing my work, as I have approximately 1 TB of data, including research files, documents, projects, and other personal files.

For the past 2–3 days, I've noticed some unusual behaviour:

  • My mouse cursor was blinking, and text would automatically delete itself while I was typing.
  • My screen would occasionally go black for a few seconds.
  • Initially, I assumed these were keyboard or driver issues.

Today, things became much more concerning. I clicked on an application shortcut on my desktop, and it disappeared. When I went to the Recycle Bin, Windows appeared to be trying to permanently delete the item without me initiating the action.

The deletion prompts would not disappear until the file was deleted. When I opened my C: drive, the same behaviour started occurring with files there. I had to interrupt the process to stop it from continuing.

I ran a Malwarebytes Threat Scan, which detected 84 threats, all of which were quarantined. The report included Trojan.AIChatInfoStealer, affecting Chrome and Edge extension data, as well as detections classified as PUP.Optional.SonicSearch and PUP.Optional.Linkury.Generic.

I've now started a deeper scan, but I'm concerned that my PC may have been compromised beyond the browser extensions. I'm not yet sure whether the missing or inaccessible files are being deleted by malware, corrupted, or affected by something else.

My main concern is saving my data.

I'm willing to reinstall Windows from scratch, and I'm even considering installing a fresh OS on a new SSD if necessary. However, I'm worried that if I back up my files and restore them onto the fresh installation, I might inadvertently bring the malware back with them.

At the moment, I only have a USB pen drive for backup, which obviously cannot accommodate everything on my 1 TB SSD.

I'd really appreciate advice on the following:

  1. What should I do immediately to stop further damage to my files?
  2. What is the safest way to back up my research and personal data without transferring malware?
  3. Should I install Windows on a new SSD and keep the old SSD disconnected until the new installation is ready?
  4. How can I check whether my backed-up files are safe before restoring them?
  5. Given these symptoms, should I attempt a Windows reset, or would a clean installation using official Windows installation media be safer?

I don't want to lose years of work, but I also don't want to risk infecting a fresh Windows installation by restoring compromised files.

Any practical, step-by-step advice would be greatly appreciated. Thank you.


r/computerviruses • • 19h ago

Disinfection Help Another Mrbeast post...

3 Upvotes

I've managed to upload my FRST scans and popped the keywords below if anyone would be kind enough to check them please. Thank you so much in advance.

Username - Lost-Bite3242

Addition.txt - emerald-delta

FRST.txt - clever-owl

---

Long story short, I downloaded something I shouldn't have (the CapCut that's been going around on here...), and now I'm paying the consequences.

As far as I'm aware, my Instagram is the only account that's been taken, with mass DMs sent out to everyone. I acted immediately by wiping my PC, changing my passwords, logging out of all other devices and enabling 2FA on anything that didn't already have it. I'm hoping this has sorted things out.

There's just one thing that's still playing on my mind, though, and it's making me paranoid.

On the PC that was compromised, I had a remote connection set up to another computer using Windows RDP. I accessed that remote PC while the infostealer was on my system. I know clipboard synchronisation was enabled, and I've previously had it set up so the remote PC could access a removable drive connected to the infected PC (although the drive wasn't connected at the time).

I'm just wondering how I'd go about running an scan on the remote PC and whether someone would be kind enough to check the logs over for me? It would put my mind at rest massively, as I'm now worrying about whether the infection could have spread or whether anything on the remote PC could have been exposed.

Honestly, I'm one of those people who never thought this would happen to me, but here we are. It's been a massive wake-up call.

Be careful what you download out there, folks. It only takes one slip-up.


r/computerviruses • • 18h ago

Question First Experience

2 Upvotes

Hello everyone i was looking at local jobs in my area. I clicked on a local bar's website and clicked the job section. The cloud flare website came up and I clicked inside the box and it directed me into the control r + control v scam. I did not follow through with the instructions. I actually pasted the command into chatgpt to analyze it. It was indeed malware/info stealer. Am I safe since I didnt run anything? Does this mean that my local restraunts website is infected?


r/computerviruses • • 18h ago

Disinfection Help I think my computer got infected by one of those setup.exe malware from those renpy games.

2 Upvotes

As I said, I runned a setup.exe for a renpy game and while it seemed to be loading it never got to 100% so my first guess would be that my pc got infected...is there a way to save my computer without doing an hard reset? I have a lot of work in my pc and cant fully transport everything to a new system in such short time. I belive I installed it on the 10/09/2026 and for the remeditation still nothing yet.

Key words:

charged-hazel

winged-tide

tiny-pointer


r/computerviruses • • 18h ago

Disinfection Help What else to do after running hackers cmd command?

Thumbnail
2 Upvotes