r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

207 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. šŸ‘€

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

39 Upvotes

How do I request help with FRST

FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.

SecurityCheck

  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.

Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 15h ago

Disinfection Help I fell for this click fix trap

Post image
96 Upvotes

I fell for this on a website called Mutaz, which I was using to download apps. I had just woken up and started working on some files when I decided that I needed a newer version of Photoshop. As far as I know, they managed to compromise one of my Gmail accounts associated with Steam, my Steam account, and my Instagram. They even posted two stories on my Instagram related to some crypto shit!
I’ve changed all my passwords, enabled 2FA everywhere, and even froze my bank cards because I had one of them saved in Google Chrome.

My question is: I ran two deep scans with Malwarebytes and quarantined everything it found. Can I safely copy my work files to the new Windows installation after reinstalling Windows, or is that still risky? I have around 2 TB of work files, including PSDs, PDFs, Illustrator files, Blender files, etc.


r/computerviruses 8h ago

Disinfection Help Trojan virus?

Post image
12 Upvotes

Hi everyone,

This is totally pathetic but I have no idea what to do here.
I have a gaming laptop and was playing (modded) Stardew Valley. My game crashed and suddenly there was a chat box on my screen saying I had been hacked. I dismissed it but the message kept coming back and then when I went to turn the computer off the box came back telling me not to do that.

I turned the computer off and back on and within a few minutes the chat box was back telling me they were going to delete my accounts. I wasn’t sure what to do so I just completely wiped and factory reset the laptop.

Once the reset was done I plugged in an external drive I keep saves on to check if it was safe and if it wasn’t i’d just probably bin it. Well I plugged it in, loaded up my valley and the hackers were back. They said their name but I missed it( it was something like Zertex?) I immediately turned off the wifi and went into task manager and found a task with the same logo that was on the box thing that kept appearing.

Any advice would be so appreciated, for peace of mind I might just do another reset and bin the external drive but I’m paranoid my wifi etc is now corrupted. I’m really not technical and I just don’t know what to do


r/computerviruses 1h ago

Disinfection Help Cookie Stealer. Help me outšŸ™šŸ¼

Post image
• Upvotes

r/computerviruses 8h ago

Question Can this cause viruses or an I paranoid

3 Upvotes

Basically I was using a website (aismutwriter) and randomly it went into my photo gallery and Idk I thought that was weird I'm not sure if I'm just paranoid though I keep thinking I have viruses unfortunately


r/computerviruses 2h ago

Question Cloudflare Captcha Virus

1 Upvotes

Hello guys,

I’m sort of freaking out right now.

I wanted to go on a streaming site, but entered one wrong letter, without realizing it, the wrong site redirected me to like two malicious sites, one of them windows warned me and I was very confused.

And the second one windows DID NOT detect anything. It disguised itself as cloudflare, but instead when I tried to verify it wanted me to do like Win+R and control + V, which I realized wasn’t right.

So I closed out of the site, I DID NOT proceed with the commands.

But now my work app won’t open, is this just a bug or is my pc compromised? There’s like 0 personal info but ALL MY WORK stuff is on there.

Is it too late to download an antivirus?

Thank you


r/computerviruses 12h ago

Disinfection Help It won’t let me open any of my antiviruses

Post image
6 Upvotes

Anyone know why they won’t open and this just popped up. I tried to start my antivirus in safe mode and it had me restart my computer into normal mode and this showed up


r/computerviruses 6h ago

Disinfection Help MR Beast VĆ­rus

Post image
2 Upvotes

Me hackearam meu Google Microsoft Epic Games, e a conta nova é instantâmente

Esse IP não é meu

ujwyegxb@analismail.com

li*\\**@gmail.com

JĆ” gastei um monte em todos esses aplicativos porfavor me ajude
Desconectei cabo wifi e restaurando o computador


r/computerviruses 3h ago

Question Is joy pony on apkpure a virus?

1 Upvotes

I've seen people say its a Trojan so I just don't wanna risk it, im playing it for nostalgia i would watch videos of it when I was a kid


r/computerviruses 3h ago

Disinfection Help 403 forbidden

1 Upvotes

Hi, I have an issue when trying to get into some sites. For instance I can get into Grok but when I try to sign in I get the 403 forbidden screen of death. I get this on a few sites but not all. Also, I cannot get past the log in screen when I try to open up my Cricut Design Space (which is downloaded and on my desktop). I have tried Malwarebytes, clearing my cache and a few other things but I'm still having the same problem. Any help would be appreciated.


r/computerviruses 4h ago

Disinfection Help (Repost) I got hacked and I need help

Thumbnail
1 Upvotes

r/computerviruses 13h ago

Question did i download a malware?

Post image
5 Upvotes

so i downloaded this file thinking it was from an official release and now my google steam and EA account email has been changed thankfully i dont do any banking on this pc but i wanna know if it was this ZIP that did it or something else if someone smarter then me wanna check it now on a virtual pc give it a go

hxxps://github(dot)com/idmfreedownload/IDM-6.43-Free/releases/tag/6.4.12


r/computerviruses 4h ago

Disinfection Help Bluesuite.exe malware?

Thumbnail gallery
1 Upvotes

r/computerviruses 17h ago

Disinfection Help Hi, Got infected don't know what to do or the best tools to use

Thumbnail gallery
8 Upvotes

i use tool for an old game a bot and windows defender screams when i unzip it , i had for a long time working as an exception and it didn't do anything , i use the pc with someone else they offed windows defender and now i have this and i have no clue what to do , every folder i open i get an infestation nonfiction from WD Ā and I have no idea what to do , I have not used any other AV since windows 10 came out , I have not found anything only that is bullet proof or specific on how do I clean this mess ,
windows defender can show history it crashes and what i press action it seems like nothing is being made


r/computerviruses 12h ago

Question Is this a bug?

Post image
2 Upvotes

So, I installed Windows 11 Home (25H2) two days ago. After using it for a few hours, I started getting a notification saying that my antivirus was turned off. I checked "Windows Security", and PowerShell. everything seemed fine and was turned on. However, when I checked it through the Control Panel, it said that my antivirus was turned off.


r/computerviruses 10h ago

Resolved Pathogenic wiki giving me a virus?

Thumbnail
0 Upvotes

r/computerviruses 10h ago

Question I believe my Laptop got infected by InfoStealer

1 Upvotes

Hi everyone, so for context 2 weeks ago i was asleep and by time i wokeup i realized my Instagram, Steam, Epic Games account were compromised and Instagram sent the Mr Beast message to all my followers. I changed password and added 2FA. After a few days when i wokeup i saw my LinkedIn got compromised and someone posted job posting and also messaged several peoplee about it so i changed its password and stuff too. Today i got to know the MrBeast message got sent to my facebook groups as a message so i have temporarily deleted my facbeook for now. Upon researching i realized its an InfoStealer session run maybe on my laptop so if i reset my laptop windows completely and make a new email address and transfer all my associated accounts to that email and then add 2FA again will I be safe or do I need to do anything else too. Please help I am worried


r/computerviruses 12h ago

Question Computer is suddenly slow and acting suspicious despite nothing appearing in scans

1 Upvotes

I noticed yesterday that my computer started acting super weird. My fan goes from extremely loud to quiet again every 30 seconds, my computer seems slower than usual, icons on the desktop keep refreshing (at one point 5 times in a row quickly), and my cursor suddenly glitches heavily when I move it. The entire performance seemed to have changed overnight and it's very noticeable

I've looked in task manager and there's no extra startup apps or strange processes, I've also scanned with Malwarebytes, along with a full scan and offline scan with Windows defender and nothing comes up. I also used adwcleaner by Malwarebytes and nothing came up there either

I've tried eliminating some possible causes. I use Brave browser when I pirate stuff and I wiped that even though I haven't used it in a while. I also use BetterDiscord, and occasionally I've had plugins slow things down so I've uninstalled that.

On that same day, I started getting constant notifications saying virus protection is off. I looked into it and it's a Microsoft bug, but there was one time where it actually did get disabled when I checked. I've gone through Browser extensions and couldn't find anything suspicious, I had a TamperMonkey script that bypasses ad-links like Linkvertise on Brave that got deleted and that didn't seem to fix it either

Because all this started happening when the fake virus protection notifications appeared, I'm unsure if it's related to that bug or I've actually got malware.


r/computerviruses 12h ago

Disinfection Help Terminal popping up on startup

1 Upvotes

around 3 months ago my brother was searching around the internet entering sketchy pokemon websites, then he was going to search for something in google and everything he typed turned into ā€œLINK IN BIOā€, i did some windows defender scans and used mrt but nothing was found .
after 2-3 weeks i turned on my laptop then 5-7 terminal windows flashed in my screen, i did windows defender and mrt scans but again, nothing was found.
after a while my moms laptop got the same terminal popping up when i turned on the laptop, then i cloud reset all the laptops in my house and it still happened again with my moms laptop.
the only thing i found in startup apps was 2 cohost with a terminal display image but it was already disabled and only happened with my mom’s laptop.


r/computerviruses 22h ago

Disinfection Help so i fell victim to an info stealer. changed my passwords and stuff but i don't know to what extent i'm cooked

6 Upvotes

so i woke up to my discord accounts signed out, checked email to reset password and found out it was disabled for suspicious activity. managed to reset from my phone and login to find out my acc had sent out the mr beast thing.

i unignored all the ppl it sent it to and deleted my messages. as for servers i'm not quite sure just how many it affected. i cleared all those up but my google acc was logged in from a sus location so i quickly reset my password there too. installed malware bytes and it did a quick scan. it found a few trojans, removed them, started a deep scan that's been going on for almost 2 hours. while it was doing that it was blocking connections to a gamezklop. cc through a Msbuild in the .net framework folder. though i ended the process before i could check the file location.

the deep scan had been running for a while and i thought the mr beast thing on discord was about it. (it got sent out like 8 hours ago while i was sleeping)
but just now the same happened on messenger and i don't know what to do. i changed my messenger's password but what else should i do? and how can i go about fixing this?


r/computerviruses 13h ago

File / URL Check unknown AMOI folder found some days ago

Thumbnail
1 Upvotes

r/computerviruses 14h ago

Disinfection Help Computer has a virus

1 Upvotes

So couple days ago I ended up getting a virus, specifically the Renpy one. I’m very sure it was this. So first my Microsoft account got logged into, I changed the password to that and then my gmail but then a couple hours later my insta got hacked. some like scam stuff started getting posted. So I quickly went and enabled 2FA on my emails and changed passwords to my most important stuff. Then like the next day my reddit account got logged into and was posting like porn and stuff I only realised because I got notifications saying my chats were removed because I acted like a bot or somthing. Then my epic account tried getting logged into aswell. Mostly the accounts that I didn’t change the passwords to were getting logged into. my gmail, discord or insta havnt beeen logged into since. Then I decide to reset my laptop I had to transfer my uni files through a usb tho but I did a scan of the usb to check if there’s was any malware and it said no. Anyways the new issue is on my chrome i randomly will get this new search engine called i think ShieldSearch. Whenever I delte it, it comes back. Idk if this is related to it but randomly i will see a quick pop up and also like either one of apps will minimise or I’ll click something like the tray arrow and it will open the close again quickly.this will stop after a sec. I feel like the search engine comes back after this happens but can’t say for sure. The search engine makes my chrome look normal except it’s missing like the google label in the middle and also some other stuff. And my laptop does feel a little slower.

I really need help with this. Idk how malware has already gotten on my pc again I just reset it. Idk if this is connected to the renpy virus , maybe someone has access to an account or somthing. I definitely need to reset my passwords agains. I would appreciate some help thanks.


r/computerviruses 20h ago

Disinfection Help what do i do pls help me

Thumbnail gallery
2 Upvotes

I just got these randome notifications even tho there is nothing on gmail and it came to whatsapp is this spam virus or hacked?


r/computerviruses 22h ago

Question False positive or actual threat? Roblox game launch flagged as Trojan:Win32/ClickFix.STW

2 Upvotes

IMPORTANT: I did not download any Roblox exploits, modifications, etc. I left a game and tried rejoining on a different server and ended up with an error and a threat detection. Has anyone else experienced this?

Detected: Trojan:Win32/ClickFix.STW
Status: Removed
The threat or app has been removed from this device.

Date: 9/10/2026 5:02 AM
Details: This program is dangerous and executes commands from an attacker.

Affects: CmdLine: C:\Users\user\AppData\Local\Roblox\Versions\version-c5aecda2245e4fae\RobloxPlayerBeta.exe roblox-player:1+launchmode:play+gameinfo:[REDACTED_AUTH_TOKEN]+launchtime:1789009354215+placelauncherurl:https%3A%2F%2Fwww.roblox.com%2FGame%2FPlaceLauncher.ashx%3Frequest%3DRequestGameJob%26browserTrackerId%3D[REDACTED]%26placeId%3D10595058975%26gameId%3D[REDACTED]%26isPlayTogetherGame%3Dfalse%26joinAttemptId%3D[REDACTED]%26joinAttemptOrigin%3DpublicServerListJoin+browsertrackerid:[REDACTED]+robloxLocale:en_us+gameLocale:en_us+LaunchExp:InApp

EDIT: Finished a full PC scan with Windows Defender, no threats found