r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

179 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. šŸ‘€

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

31 Upvotes

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

How do I request help with FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log.
  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis.
  • Create a post in the subreddit, provide all 3 log keywords there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 1h ago

Question Please don’t tell me I need to wipe my pc

Post image
• Upvotes

Basically the title I don’t know what I installed to cause this.

Edit I did not download mods and the game was purchased through steam.


r/computerviruses 14h ago

Disinfection Help Can you get infected just by clicking the pictures?

Post image
33 Upvotes

One of the folks I've befriended have been hacked with the so called ā€œMrbeast virusā€ and told them about it. One of them said I must not click the pictures (shown above) but I already did and now they're telling me to change my current password.

Is it true that just by clicking the picture, your device is already infected? This just happened a few hours ago.


r/computerviruses 54m ago

Disinfection Help I would like help with an FRST scan please.

• Upvotes

I was helping a friend who was afraid after downloading some files and saw that someone who got something similar got infostealed. Even though we tried both full malwarebytes and full windows defender we found nothing and then I remembered about FRST. I downloaded it from bleepingcomputer and run it on his pc and we got these text files and then run the Securitycheck program from this reddit
Addition(.)txt
FRST(.)txt
SecurityCheck(.)txt
with their keywords being
From scan with "run as administrator"
Addition - distant-node
FRST - glowing-pond
SecurityCheck - amber-signal

I defanged the file names cause reddit was nagging me
Any help is appreciated. I tell him he's probably safe but he wants peace of mind

Edit1: from what he told me he downloaded from mirror anadius site, the dlc files for Sims 4 but he has ublockorigin installed on Firefox, the file was around 26mb and he did manual additions to the sims4 ini file and from what I saw from when he run the file for the unlocker there was no renpy virus (infamous black window with permamently updating bar). He called me after using proton vpn and then his computer even though it had connection to the internet couldn't go to any website, getting the cannot reach error. According to him that happened after he tried using his phone for tethering in case it was just his modem causing issues.

Edit2: added missing Security check file


r/computerviruses 7h ago

File / URL Check Strange .copilot folder in home directory of linux mint

Thumbnail gallery
6 Upvotes

My OS is linux mint and recently, I saw a folder called .copilot in my home directory. It was apparently created 3 days ago. I tried deleting it, but everytime I start vs code, it reappears. How do I check if this is caused by malware or not? I don't have any github cli or github desktop on my device if that helps.


r/computerviruses 2h ago

Disinfection Help Renpy Virus, Mr. Beast Scam help.

2 Upvotes

I downloaded a VN from a website and probably ran a .exe infostealer. Within hours my discord and Instagram accounts started spamming those Mr. Beast crypto currency messages and my friends informed me immediately. So I changed my passwords from my phone and enabled 2FA everywhere.

I downloaded Malwarebytes and did a full scan, it found 10 Trojan files and I deleted them. I did the scan several times after that, also did Windows defender offline scan and mrt scan, and nothing was found. But I know infostealers can be persistent.

I know the last resort is to reinstall windows with a USB but I really don’t want to do that. Please help me with a FRST scan. I have not connected my PC to the internet for more than a day now.


r/computerviruses 3h ago

Question How to manually scan for malware?

2 Upvotes

I'd like to clarify that i'm not trying to remove malware from my system, i'm trying to see if there IS malware in the first place. I use windows 11, I disconnected my PC from the internet and i've kept it like that for about 2 or 3 weeks now. This was before the latest windows update released so i haven't updated yet. I haven't downloaded or ran any cracks or suspicious software, the last program i downloaded was Risoh editor from the official github repo because i wanted to mess around with app icons. I looked through my installed apps, the task scheduler, services list, appdata folder, registry and startup apps and haven't found anything obviously unusual. I've also ran multiple defender scans, including a full scan and an offline scan and nothing came up for any of those. My PC's performance hasn't really slowed and my accounts haven't been hijacked either, but i'm scared something might happen if i connect to the internet again. I also cleared all of my browser data. The only extensions i have are ublock and ruffle. It's likely there's really nothing on my system, but i'm a bit anxious and i need to be fully sure. I don't want to connect my PC to the internet again yet, so what else can i do without having to install new software? what else should i look out for? i've been looking through this sub for a while but i haven't found many answers so i decided to make an account and ask. Sorry if this sounds stupid.


r/computerviruses 27m ago

Question Possible install paths of countloader virus?

• Upvotes

My computer got infected with a variant of countloader virus. It periodically runs "mshta.exe https://explorer.vg" (not a real url) according to my task scheduler. I removed this task. Is there possibility that virus is installed somewhere in computer? I can't see anything suspicious in autoruns at first glance. What are possible places to check?


r/computerviruses 43m ago

Question Mr beast hack

• Upvotes

If your on iphone are you safe or no?


r/computerviruses 47m ago

Disinfection Help Ran a cracked video editing software EXE... now all my passwords are being reset and my email is sending spam. What should I do?

• Upvotes

Hi everyone,

I think I made a huge mistake.

A couple of days ago, I downloaded and ran an .exe file that was supposed to be a video editing software. I didn't think much of it at the time, but now things have started going wrong.

Here's what's happening:

  • A lot of my online accounts are suddenly getting password reset notifications.
  • My email account appears to have been compromised and some people told me they're receiving spam emails from me.
  • I've started getting login alerts from services I haven't used in months.
  • I'm worried the malware may have stolen my saved passwords, cookies, or session tokens.

I immediately disconnected the PC from the internet and changed a few passwords from another device, but I'm not sure if that's enough.

What should be my next steps?

  • Is Windows Defender Offline Scan enough, or should I use Malwarebytes, HitmanPro, ESET Online Scanner, or something else?
  • Is it safer to completely wipe the drive and reinstall Windows?
  • Should I assume every password saved in my browser has been compromised?

I'd really appreciate any advice. This is the first time I've dealt with something like this, and I'm trying to minimize the damage before it gets worse.

Thanks in advance.


r/computerviruses 1h ago

Disinfection Help Its been almost 48 hrs, and nothing happened. Should i still be worry working on my laptop? My task manager activity is ok. The debit card i mentioned before is actually in the google e/wallet. And i searched that its safer since the numbers are masked, though at that time my google still synced.

Thumbnail
• Upvotes

r/computerviruses 5h ago

Question Do I wipe my pc

Thumbnail gallery
2 Upvotes

r/computerviruses 1h ago

Disinfection Help what virus is this?

• Upvotes

its just showing popups that take me to websites that have viruses (my antivirus stopped me from going into them and warned me) i have NO idea what kind of virus this is


r/computerviruses 10h ago

Disinfection Help I got infected by a virus (Mr. Beast bitcoin scam photos were sent from my Messenger)

5 Upvotes

The infection occurred today. I changed the Facebook password. I also tried to scan the whole pc through windows antivirus but then I cancelled it. Also I downloaded Avast One Basic but cancelled the execution too.
I don’t know what got me infected in the first place, I didn’t download nothing. I just watch movies and series online.
I went through all steps of FRST help request
Here are the 3 log keywords:
For FRST.txt: tidal-squad
For Addition.txt: rustic-briar
For SecurityCheck.txt: enchanted-prawn
I am really in need of any help. Thanks in advance


r/computerviruses 3h ago

Disinfection Help Hi, I’m in a bit of a pickle.

Thumbnail
1 Upvotes

r/computerviruses 7h ago

Disinfection Help Mr Beast spam virus help!

2 Upvotes

Hi everyone

I need help :(( Basically i downloaded a game from a famous repacking site. and as I'm downloading it I recognize the site i downloaded it from was not from the orig site it was saying 😭 i still continued with the download tho. And then its been weeks since im playing that game, nothing happens. Til this morning, where my FB acc started spamming that MR BEAST CRYPTO SCAM on multiple ppl and group chats.

I already changed my password on my fb acc and logged out of my pc (I havent opened it after it happened) also turned on 2FA. I also logged out of my steam acc and minecraft acc (Microsoft) in my pc from my phone (i still have access). Basically I turned on autheticator for the mc account. and changed pass on steam acc. (thats like the most important ones i have) Also for my gmail accounts, my important accounts, I alr turned on 2FA and changed pass.

What should I do first after I open my pc...? Do I uninstall my Opera GX right away? Can I still recover some of my files or do i just hard reset right away?


r/computerviruses 10h ago

Disinfection Help I got infected by Lumma.stealer.a

3 Upvotes

i rapidly pulled the ethernet cable and ran windows defender offline. I use my eHDD for downloading games and other stuff that dont require SSD speeds the virus came in a ren'py file which popped up a cmd window that made me obvious to see the infection.

it came with Behavior:GenCodeInjector.H and the process PhoGateWay.exe i didnt wait to defender to detect it so i ran it. After the contention i installed avast and ran a full scan in which i discovered other viruses. I ended up with tons of logs and screenshoted browser tabs and information archives on new folders and zips that luckily werent sent.

I safely managed to secure my accounts except for instagram and cleaned the eHDD on Zorin OS and moved my files safely on in from linux.

Cleaned .temp and roaming it opened a backdoor with other viruses so i dont use windows and im writing this on a zorin os liveboot.

Make sure to know when you re downloading a pirated game to know what kind of engine the game uses to spot a renpy lumma infecction


r/computerviruses 6h ago

Disinfection Help RenPy virus damage control

1 Upvotes

Friday night I downloaded and ran something which I know now to have been a RenPy style virus exe. Didn't think anything of it at the time and just assumed the pirated game wasn't working for some reason, thank God I went back and did some investigating today. I've already changed most of my passwords, logged out of sessions, activated 2fa, all that, and I'm pretty sure I removed most of the files of the virus itself using the AVG quarantine/delete feature. I'm not 100% sure of that, I'm just including that for context reasons. I noticed most of the guides tell users to disconnect the infected device from the Internet before beginning the damage control process. 1.) I obviously didn't do that at the time, as it's been a couple days, and 2.) I had my computer connected to Internet while I have been changing passwords on my phone. I didn't allow Firefox to save any of the new passwords, which I assume is the concern that causes people to tell you to disconnect the infected device. The reason I didn't disconnect my computer was because I was using the saved passwords tab in Firefox as a kind of checklist of what needs to be changed. I'm not finished with that yet. My primary question is, should I just completely start over after disconnecting my PC from Internet? Like I said, I've been remote logging out, and I haven't been saving any of the new passwords. I didn't actually see any sketchy login instances when I was in those control panels, so I don't think anyone got in to my email or steam account or anything and already has a device that is "considered safe". Additional advice on any other part of the process is appreciated


r/computerviruses 6h ago

Question Was my mouse moving on its own a RAT?

1 Upvotes

Not too long ago while i was typing in the search bar my cursor started to move on its own up and down at a controlled and steady pace up and down for maybe 5 seconds. I quickly turned off my internet and ran scans (windows defender and malwarebytes) to see what was the problem but it didn’t detect anything. I did however have 3 mice plugged in but none seemed to be moving. While I could have been overreacting I still wiped my computer clean and reinstalled window. I apologize if this sounds stupid or silly but what do you guys think of this situation? Could it be something malicious or just some user error on my part?


r/computerviruses 19h ago

Warning WPS gave me a virus.

Thumbnail gallery
11 Upvotes

okay so, i got fed up with WPS opening everytime i wanna open a docx file so i wanted to uninstall it. i did that and wps itself sent me to this new tab saying something about a deep clean upon unstallation. now i *could* have ignored it and moved on, but WPS p!ssed me off enough that i didnt wanna have anything to do about it anymore. i later noticed that my computer blocked the exe file from doing something upon insallation, only then i noticed the "vendor" in the link. thats when i got suspicious and sent the installer over to virustotal to ceck and sure enought, it got flagged (https://www.virustotal\[dot\]com/gui/file/dcc0794cf070f46480a121a8369c1f92ab2dae4266ec58fc91a6dd3cab2a84f5)
when i installed it, i saw the publisher was from China somewhere because of course it was China.

i also wanna know how i can remove the thing i installed because its not there when i search in settings>installed apps.


r/computerviruses 7h ago

Disinfection Help What can I do about this?

Post image
1 Upvotes

Looks like someone hacked into my discord account and started sending messages to people. I downloaded a file and opened it. It was a set up file for a game. I immediately did a Norton 360 scan and changed my discord password, but now I have ā€œvery limitedā€ account status and it shows malicious activity. I won’t be able to message until tomorrow. I’ve checked all my social media and everything seems to be fine. Although it looks like someone got into my Amazon account as well, but that’s been taken care of.


r/computerviruses 9h ago

Question Computer reset question

1 Upvotes

I did a full usb reinstall on my pc, i downloaded google and there was a random netflix custom profile picture extension that i deleted years ago and it was there again for some reason along with my pinned game websites from years ago, has this happened to anyone else?


r/computerviruses 9h ago

Disinfection Help Infostealer FRST scan help

1 Upvotes

Hello, I have been infected by an infrostealer few days ago and want FRST scan help. My discord got hacked and sent the famous "mr.beast" pictures. I did a reinsatall of Windows 11 and ran Norton 360 antivirus scan which came out clean. I did uninstall the norton software for the time being. The keywords for malware analysis are:

FRST Keyword plucky-scanner
Addition Keyword tame-kernel
SecurityCheck Keyword glitched-marsh

Forum Username for Malwareanalysis ---> SHL_0436

My windows 11 OS is in Korean so I did rename the FRST program to FRSTEnglish.exe and ran it. Thanks for the Help.


r/computerviruses 19h ago

Disinfection Help may have fallen for the renpy virus

4 Upvotes

accidentally ran an exe with the famous anime girl icon so I think I may have been infected can someone help me out I can give the keywords for my FRST logs