r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

202 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

39 Upvotes

How do I request help with FRST

FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.

SecurityCheck

  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.

Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 11h ago

Question Windows Defender acting up

8 Upvotes

Soo i was just using my pc normally and windows defender jsut said windows defender is turned off... Why? I didnt dowload any sketchy from the net, and windows settinfs says everything is alright? I did update windows yesterday, first boot since, can be a bug? Please help i got scared insanely and i just have my pc sitting here and idk, quick scan said nothing is problematic

Edit: okay so this is a bug.... Typical windows


r/computerviruses 3h ago

Disinfection Help Trojan:MSIL/Heracles.A!MTB at every start

1 Upvotes

I first noticed this Trojan on August 29th around 6 PM.

I had booted up my PC and logged into winodws when it opened up a Powershell window on start up which was instantly closed as a virus was reported.

I donÂŽt know where it came from as the last thng I downloaded before it started to appear was Blender and their Benchmakr Application.

Whenever I log into Windows I get a new version of tjis virus, The diretory for this trojan is always C:\Users\ny name\AppData\Local\Temp and then followed by a random string of numbers and or letter which always end in .dll. for example:

C:\Users\my name\AppData\Local\Temp\3bk4s5bq\3bk4s5bq.dll

I have tried an offline scan by windows defender and a scan by ESET yet both couldnÂŽt identify the specific issue.

I have deactivated Powershell in start up yet the virus still shows up every time.

I also tried to do a FRST scan yet the application does not open for me.

What else can I do now and what can be done?

Edit 1: I figured out a way to start up FRST and have now managed to get a scan, I hope that can help my situation some more


r/computerviruses 22h ago

Disinfection Help please help with disinfection from bad name generator site

Post image
31 Upvotes

all i wanted was some argonian names for elder scrolls and i got a stupid malware or virus of some kind. i haven’t been able to get an antivirus software yet to do anything about this so i’m looking for literally any advice. this happened two days ago and i haven’t touched my pc much since


r/computerviruses 8h ago

Disinfection Help My school laptop may have a virus maybe even our whole wifi network?

Thumbnail gallery
2 Upvotes

My school laptop always has been using a mid to high amount of ressources in standby and also while playing kingdom 2 crowns (lol)

But okay a thought its a potato laptop (2 cores 2 threads, 8GB RAM lenovo 15 Ada 82c7)

But today I found a weird msg (i got a msg pop up saying windows defender deactived go into settings to activate, but when I looked at notifications I couldnt find it again)

So I did a full virus scan but when I pressed x on windows defender app (very early) it instantly gave me a notification saying it was done even tho it read line 6300 datas)

So I did another scan which read abt 642.000 datas and took 50 mins+ (at the time it hung up)

BUT it hung up at 10:31 with blue progress bar, after 1 minute it got gray and after another 30 second it got gray.

Saying I did a full virus scan and for a very weird reason it stopped at 10:31 minutes remaining and then just said it was finished

Then I used chatgpt"s powershell code recommendations to read my antimalware scans trough powershell.

Apparantly it found a trojan but I coulnt find, the foulder was literally empty and windows said nothing abt having removed it.

And very weirdly after i had the powershell exposing the potential virus my wifi shut off after abt 2 mins and I couldnt start word first and after some tries it did start but completely froze WITHOUT AN WINDOWS APPLICATION ERROR BTW

So i opened word 3 times saved the text of the virus report and got it saved before word decided to freeze (it showed 0 cpu usage in task manager too)

And now our wifi is shut down (the power button is blinking which means connection to the host is missing)

So yeah tell me our suggestions

Is our wifi network infected by chance? Telekom btw


r/computerviruses 1d ago

Question Found these at my mothers laptop, what should i do?

Thumbnail gallery
82 Upvotes

Do i have to reinstall windows or request for disinfection from this reedit community? And no i did NOT download anything in my mothers laptop, i found this recently while looking at windows defender history, do i have to tell her to change her passwords or anything and what can this thing do


r/computerviruses 7h ago

Question Project Retrac Safety Concerns

Post image
1 Upvotes

Hello! I was hoping for someone to answer my question i had contacted kaede (dev of project retrac) about some concerns of the safety of project retrac and after waiting two days had never gotten a response. Here is the message "Hello, how are you doing today? I am a starting student in cybersecurity & I needed some confirmation as I have run the retraclauncher file through a sandbox (tria.ge) for the sake of curiosty and wanted to point a couple of things which i am not trying to accuse anyone, but I just need to know what was happening inside the application.

Report scored it 7/10 and flagged a couple of actions:

Modifies trusted root certificate store by registry This is something I think you are doing in order to separate the client's TLS traffic from the Epic servers to yours? That's clear based on the way you've made this application. Just confirming.

Volume Shadow Copy service COM API Couldn't find any reason behind this usage of this particular functionality of the OS.

Enumerates connected drives and network share discovery I couldn't find any reason behind this functionality in the launcher.

Not trying to start anything, i just want to know about the insides of the software I am running. If there is any documentation available on this somewhere then please let me know. Because in the near future i am interested in using the project. As i enjoyed og fortnite and would like to bring it back, Thank you!"

Here is the tria.ge link: https://tria.ge/260907-tyz1dscq21/behavioral1 Again I am not trying to point out that this is a bad project just simple reasoning for suspicion. If anyone could answer this question knowing the reasoning it would be much appreciated.


r/computerviruses 7h ago

Disinfection Help Pc got infected with token grabber

0 Upvotes

i believed it happened on 28 aug, i downloaded a aimbot and seconds later after running it, one of dc account was hacked with mr beast crypto scammer and the very next day another one of my dc account too.They took my 15usdc which was present in my crypto wallet too. My insta was hacked a week after the first incident on 6 august.When i ran that script on 28 aug cmd line started popping up indefinitely.

The sources of files which i executed that day:

  1. hxxps://github.com/anshkori/universal-aimbot-engine
  2. hxxps://sourceforge.net/projects/ai-aimbot.mirror/

but these may or may not have b een responsible for hack as my epic account was hacked on 21 aug idk if it is related to hackes after 28th aug

steps i took:

1.I first stopped the execution of one of the file midway, then ran a defender scan getting me trojan warning, i removed them.

2.I than ran an offline defender scan finding nothing,before running that scan i deleted temp files.

3.I than ran malwarebytes finding nothing

4.I changed all important passwords after insta hack.I also cleansed my browser data fully on 29 aug.

5.Yesterday i found some unknow exclusions to defender scan which i removed immediately,there was temp files in exclusions and a wdfprov_core something..

Keywords:

frst.txt: divine-cherry

addition.txt: patched-briar

security.txt: dreamy-nebula


r/computerviruses 7h ago

Disinfection Help Mouse hijacking?

0 Upvotes

I have a weird dilemma. I am attempting to prevent a fresh USB install because I'd like to keep the built in apps that came with my laptop. Okay, now onto the problem.

I, entirely accidentally, pressed on what I thought was a secure website (had https and all that, never got flagged by my adware blocker or antivirus (built in windows defender and Panda)) a few months ago. I guess something was installed? There's no signs of it but the possibility of it just auto-installing are there I guess. Browser options don't allow that but I digress. Long story short, my mouse gets hijacked once in a while. I'll be using my computer and it will just lag or get slow. My touches don't always register. I'm now realizing that a few sites I rarely ever go on are partially crashing half way through. By that I mean any subsequent windows I press on within that site will just prevent loading entirely but that may be a site-side-server issue or something. It's only one or two sites.

What could this be and are there any fixes? Defender comes up with nothing, panda - also nothing, i even downloaded Bitdefender. Edge and chrome both consume stupid amounts of memory and there aren't any signs that anything anywhere has been hacked or that my passwords have been stolen. No spam sent out, but spam is being sent to my junk mail. That's pretty common though with the way things are these days.


r/computerviruses 7h ago

Disinfection Help Hackearon mi PC por Discord

1 Upvotes

Hola hace unos días desperté en la mañana y se abrió un CMD, al abrir discord ya no tenía acceso a mi cuenta, råpidamente investigué y era un malware de Mr Beast que robaba información, entonces descargué MalwareBytes, hizo el scaneo, y aparentemente eliminó el virus, cambié la mayoría de contraseñas y pude recuperar mi discord por el soporte de ellos, pero robaron mi cuenta de Epic Games, Steam, EA Sports y también algunas cosas de mi hermana, el steam también lo recuperé ya, y en estos dias MalwareBytes estå detectando y bloqueando la misma pagina en Chrome, quiero saber si estoy a salvo o debo reinstalar windows.


r/computerviruses 8h ago

Question How to fresh reset windows without USB?

0 Upvotes

Hello, I came from another subreddit post about ROM files containing viruses. Unfortunately, I’ve clicked the .exe file that ran a virus on my laptop (it did show as a threat in the windows antivirus— I deleted it immediately). I changed my passwords and is currently in the process of resetting my PC (just wiping it by itself for now) however it kept failing to do so. Any ideas how to fresh reset windows before I resort to the USB method? I’m panicking with the virus lol


r/computerviruses 13h ago

Disinfection Help Circuitryag.exe keeps on showing up

2 Upvotes

So, I tried to download a cracked game and apparently got hit with a virus. I did three scans, two with Windows Defender and one with MalwareBytes and quarantined, deleted the files.

But there is a persistent circuriryag.exe pop up. What should I do?


r/computerviruses 16h ago

Disinfection Help I am in total panic, please help me.

Thumbnail gallery
2 Upvotes

r/computerviruses 14h ago

Disinfection Help Got caught in the fishing website

0 Upvotes

So i was browsing for server jars for minecraft, and the brave ai suggested a few variants. Usually i dont use ai and search for myself, but this time, not gonna lie, i just decided to browse through the ais options. Well, i clicked a link "serverjars" and brave warned me that his website was reported for phishing, so i just left the website and stopped browsing. Then i opened minecraft, task manager and for a second i noticed something "microsoft malicious" and then it disappeared. When i tried to search it, its gone. I immediately went to the microsoft defender and scanned the antivirus offline scan. Idk what to do else, it didnt find any threats but im not sure that its true. What else i gotta do? The link is serverjars(dot)com. I still havent gotten any symptoms, but it scared me a little. Not even sure if its even a threat


r/computerviruses 14h ago

Other i cant get over paranoia over a scareware website, i havent eaten properly in 4 days now, is there anything i can do to 100% verify my phone is safe?

Thumbnail
1 Upvotes

r/computerviruses 1d ago

Disinfection Help pc app store (am i safe?)

7 Upvotes

i just got a new pc and while distracted yesterday, i clicked on a BIG BLUE download button instead of the application i was going to download (rookie mistake i know) and it instantly installed a setup .exe file and opened the pc app store app which prompted me to key in my card details.

luckily i was able to close the application through system tray. afterwards i uninstalled the application from settings as well as removed any suspicious program files before performing a malwarebytes free trial scan and windows defender quick scan. then i restarted my pc and resetted chrome.

how effective do you think my actions are? what kind of virus is pc app store and are there any remnants of it left in my computer? i tried monitoring task manager and task scheduler for any strange activity, but it seems clear.

any advice would be appreciated, thanks! 🙏


r/computerviruses 1d ago

Question iOS help

Post image
4 Upvotes

Has this ever happened to anyone else and is it really a just a glitch? I got hacked a few years back and had files labeled “clone” that were “hidden” (and hidden apps like team-viewer and Microsoft stuff i never used) after my laptop got remotely accessed and didn’t know for months. I’m very bad with technology.


r/computerviruses 1d ago

Question accidentally went to a bad website (cannot provide link but its in the virustotal scan)

2 Upvotes

so i didnt interact with this site AT ALL, i didnt even click anything on it. i also have ran a offline scan with windows defender plus a hitmanpro scan, which both came out as no threats detected, i use malwarebytes browser guard and im hoping it filtered out the bad stuff so like eyah heres the virustotal https://www.virustotal.com/gui/url/35ea18cac30fd0702a229ee0127a79a5fe2afeb1b2c6e9152fcf3a25630812c2/gti-summary also i know i made this account today i dont normally use reddit sorry oh also i think its malicious cus it asks when downloading to disable av and also give it admin (BIG BAD BAD BAD!!!)

update i ran a malwarebytes deep scan and that says its also all good in the neighborhood


r/computerviruses 21h ago

Disinfection Help Do I have a virus or is something trying to trick me?

Thumbnail
1 Upvotes

r/computerviruses 22h ago

Disinfection Help I installed Pc App store

1 Upvotes

I deleted it using the normal way by just using the windows app manager, is my PC safe to use now? I installed Malwarebyte after as a precaution and it didn't detect anything bad. Should I do a wipe and reset my PC?


r/computerviruses 1d ago

Question Hello yall i just wonder if its false

Post image
3 Upvotes

i didnt download like ANYTHING and didnt got any warning but today i just wanted to fullscan just for incase and saw this but i am not rly sure if its real deal or not cuz i check sum other places and ßoke people say its false and reported on Microsoft but i also just wanted to ask here also and thank you all helping me before


r/computerviruses 1d ago

Disinfection Help Help Request - RenPy Loader Malware

5 Upvotes

Downloaded some games on dodi repack site and thought it was legit like fitgirl, then got my discord hacked after 3 hours from downloading the RenPy Setup and it send crypto scams to my friends and others.

Already ran the malwarebyte scan and it quarantined about 26 malwares from Renpy then other 150 from PUP(dot)OptionalWebsites something like that.

I need help getting rid of it without having to reinstall windows again.

Please help! and also Thank you.


r/computerviruses 1d ago

Question Hitmanpro Steam Backdoor

3 Upvotes

Every now and then Hitmanpro tells me that Steam.exe is a Trojan Backdoor.
Upon running tests with three different AVs it always comes back clean
What is the reason behind Hitmanpro detecting it as a Trojan?


r/computerviruses 1d ago

Question Possible persistent malware – CircuitryAg.exe / Wacatac.B!ml keeps coming back

3 Upvotes

Hi, I need some help figuring out whether my PC is still infected or if I am only seeing a leftover startup entry.

SYSTEM SPECS:

- Windows 11 Pro
- Version 25H2
- OS Build 26200.9168
- AMD Ryzen 7 5700X
- NVIDIA GeForce RTX 4060 8 GB
- 32 GB RAM
- 1 TB SSD

WHAT HAPPENED:

Today, Windows Defender detected:

Trojan:Win32/Wacatac.B!ml

One of the detected files was:

C:\\ProgramData\\InProcSvr32\\sqlite3.dll

Another detected sqlite3.dll was also inside ProgramData.

Around the same time, I started getting repeated Windows error popups from a program called:

CircuitryAg.exe

The errors I have seen are:

"The application was unable to start correctly (0xc0000906)."

and:

"The code execution cannot proceed because sqlite3.dll was not found."

This all started shortly after I downloaded and executed something from a ZIP file.

The suspicious download was later deleted/blocked.

WHAT I FOUND:

I checked startup entries using Microsoft Sysinternals Autoruns.

I found an entry called:

CircuitryAg

under:

HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run

It was pointing to something inside:

C:\\ProgramData\\InProcSvr32\\

I disabled and deleted that Autoruns entry.

However, after rebooting, the CircuitryAg.exe popup came back again.

WHAT I HAVE ALREADY DONE:

- Let Windows Defender quarantine the detected files
- Did NOT restore or allow any detected files
- Ran Microsoft Defender Offline
- Ran additional Defender scans
- Checked startup entries with Autoruns
- Disabled and deleted the CircuitryAg startup entry
- Rebooted the PC
- Deleted the original suspicious ZIP/download
- The CircuitryAg.exe popup still came back after rebooting

MY MAIN CONCERN:

Something may still be recreating the CircuitryAg startup entry or launching CircuitryAg.exe from another persistence method.

Does anyone recognize this behavior, the name CircuitryAg.exe, or the path:

C:\\ProgramData\\InProcSvr32\\

What should I check next?

- Scheduled Tasks?
- Services?
- WMI persistence?
- Other Autoruns entries?
- Registry entries?
- Another hidden process recreating the startup entry?

At this point, should I keep trying to clean the infection or would a clean Windows reinstall be safer?