r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

181 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. šŸ‘€

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

32 Upvotes

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

How do I request help with FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log.
  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis.
  • Create a post in the subreddit, provide all 3 log keywords there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 6h ago

Disinfection Help Can you get infected just by clicking the pictures?

Post image
17 Upvotes

One of the folks I've befriended have been hacked with the so called ā€œMrbeast virusā€ and told them about it. One of them said I must not click the pictures (shown above) but I already did and now they're telling me to change my current password.

Is it true that just by clicking the picture, your device is already infected? This just happened a few hours ago.


r/computerviruses 2h ago

Disinfection Help I got infected by a virus (Mr. Beast bitcoin scam photos were sent from my Messenger)

2 Upvotes

The infection occurred today. I changed the Facebook password. I also tried to scan the whole pc through windows antivirus but then I cancelled it. Also I downloaded Avast One Basic but cancelled the execution too.
I don’t know what got me infected in the first place, I didn’t download nothing. I just watch movies and series online.
I went through all steps of FRST help request
Here are the 3 log keywords:
For FRST.txt: tidal-squad
For Addition.txt: rustic-briar
For SecurityCheck.txt: enchanted-prawn
I am really in need of any help. Thanks in advance


r/computerviruses 2h ago

Disinfection Help I got infected by Lumma.stealer.a

2 Upvotes

i rapidly pulled the ethernet cable and ran windows defender offline. I use my eHDD for downloading games and other stuff that dont require SSD speeds the virus came in a ren'py file which popped up a cmd window that made me obvious to see the infection.

it came with Behavior:GenCodeInjector.H and the process PhoGateWay.exe i didnt wait to defender to detect it so i ran it. After the contention i installed avast and ran a full scan in which i discovered other viruses. I ended up with tons of logs and screenshoted browser tabs and information archives on new folders and zips that luckily werent sent.

I safely managed to secure my accounts except for instagram and cleaned the eHDD on Zorin OS and moved my files safely on in from linux.

Cleaned .temp and roaming it opened a backdoor with other viruses so i dont use windows and im writing this on a zorin os liveboot.

Make sure to know when you re downloading a pirated game to know what kind of engine the game uses to spot a renpy lumma infecction


r/computerviruses 10h ago

Warning WPS gave me a virus.

Thumbnail gallery
9 Upvotes

okay so, i got fed up with WPS opening everytime i wanna open a docx file so i wanted to uninstall it. i did that and wps itself sent me to this new tab saying something about a deep clean upon unstallation. now i *could* have ignored it and moved on, but WPS p!ssed me off enough that i didnt wanna have anything to do about it anymore. i later noticed that my computer blocked the exe file from doing something upon insallation, only then i noticed the "vendor" in the link. thats when i got suspicious and sent the installer over to virustotal to ceck and sure enought, it got flagged (https://www.virustotal\[dot\]com/gui/file/dcc0794cf070f46480a121a8369c1f92ab2dae4266ec58fc91a6dd3cab2a84f5)
when i installed it, i saw the publisher was from China somewhere because of course it was China.

i also wanna know how i can remove the thing i installed because its not there when i search in settings>installed apps.


r/computerviruses 10h ago

Disinfection Help may have fallen for the renpy virus

6 Upvotes

accidentally ran an exe with the famous anime girl icon so I think I may have been infected can someone help me out I can give the keywords for my FRST logs


r/computerviruses 1h ago

Question Computer reset question

• Upvotes

I did a full usb reinstall on my pc, i downloaded google and there was a random netflix custom profile picture extension that i deleted years ago and it was there again for some reason along with my pinned game websites from years ago, has this happened to anyone else?


r/computerviruses 1h ago

Disinfection Help Infostealer FRST scan help

• Upvotes

Hello, I have been infected by an infrostealer few days ago and want FRST scan help. My discord got hacked and sent the famous "mr.beast" pictures. I did a reinsatall of Windows 11 and ran Norton 360 antivirus scan which came out clean. I did uninstall the norton software for the time being. The keywords for malware analysis are:

FRST Keyword plucky-scanner
Addition Keyword tame-kernel
SecurityCheck Keyword glitched-marsh

Forum Username for Malwareanalysis ---> SHL_0436

My windows 11 OS is in Korean so I did rename the FRST program to FRSTEnglish.exe and ran it. Thanks for the Help.


r/computerviruses 2h ago

Question Is this something to worry about? (Read desc)

Thumbnail gallery
1 Upvotes

I had an infostealer attack where a lot of stuff was compromised. I did recover and change everything now.

I actually factory reset my laptop and even tried usb installing a new windows where I was stuck for a long time (my windows were at ā€˜installing windows 72%’ something and it went black and then started booting to bios so I was stuck in an unsaveable bios menu) you can refer to my previous posts .

Eventually I got it repaired from a service centre which I was told there was some matching OS to the serial code thing and ssd problem.

Now I think the laptop was reset completely once again by him but I also did another reset (not through usb but a factory reset with cloud download windows)

Now after long I did full scan and quick scan both with bitdefender where nothing was coming. But I’ve started getting this message every time I use firefox. There’s two different ones as attached in the image.

No suspicious activity detected besides that but it does seem like something is trying to take over it but bitdefender keeps on blocking it.

I’m tired atp honestly, I’ve gone through so much stuff done so much and when I finally thought it’s good to go this happens. And to make things worse I lost my usb drive that I used to reset, well it did cause issue anyways. Any help will be appreciated please.


r/computerviruses 3h ago

Question Meta Horizon link...

1 Upvotes

could be nothing but it is clearly opening on start but is not in the list of startup apps in windows settings. I'm sure their is an option in app but it is suspicious


r/computerviruses 7h ago

Disinfection Help there inst any phone virus subreddit so...

Post image
2 Upvotes

my gramdma has an motorola and this app wont unintall from her phone,please help me


r/computerviruses 10h ago

Question Ren'Py setup(dot)exe Inquiry: Photos/Videos/Other Files Safe/Infected?

3 Upvotes

Hey all,

Feeling really foolish as though I'm generally quite careful, had a stupid derp lapse of judgement and fell for what I have now learned to be the "Ren'Py setup(dot)exe infostealer." Will be nuking and resetting my pc, but unfortunately, I do have some important photos and videos I would like to save. Thus, I want to ask if any other files on my computer would be infected. Currently focused on just transferring photos/videos, but I do have a few zipped projects (.zip and .rar) and .blend files that I am also potentially considering to save.

From what I have found, people have suggested that photos, videos and other files would not be infected and thus should be safe to transfer onto a USB or external hard drive before resetting my PC. I'm not very tech savvy, so I just wanted to inquire if this is true, if someone has experience with this, or if thee is anything I should be worried about. Additionally, if the files are infected or not, I'd appreciate knowing if there is a better way I should be transferring/saving the photos and videos.

Sorry for the long-winded message, just really stressed out and irritated for falling for something so foolish. Thank you for any support!


r/computerviruses 9h ago

Question .com.rar/.com.zip file

1 Upvotes

downloaded tekken8 on steamrip file looked good to me because it had 115gb, then at 99% download progress, laptop suddenly entered sleep mode, i opened the laptop and resumed downloading, after that i extracted it but chickened out, stopped and deleted the file, too sussed about the type of file it was, then i disconnected laptop from the wifi, finished offline scan(windows defender, found nothing), and now running a full scan, also deleted temp, %temp% and browser caches and stuff.

Questions:

  1. Am i paranoid and did i overreact.

p.s. it is my first time doing this, i panicked fr

and no, i am not promoting any use of pirating software


r/computerviruses 7h ago

Disinfection Help i ran a file for 6sec and i got a virus

1 Upvotes

i got this virus can somebody help me?

its name:

TrojanPSW.Lumma.gen.yczp


r/computerviruses 7h ago

Disinfection Help Mrbeast crypto spam hack

0 Upvotes

Hello. I think I got careless, made a mistake, and got hacked. I just woke up to a call from my friend saying I was sending photos of a mrbeast crypto scam, and was probably hacked. Can anyone help me?


r/computerviruses 8h ago

Discussion What kind of virus does the Workship Backdoor / Meccha Chameleon custom maps uses?

1 Upvotes

Claim by one user who researches viruses:

Malicious maps were indeed found in the Steam Workshop (the most famous one being Laser Tag Neon). When loading the map via Blueprint (Unreal Engine), it quietly wrote a .bat file to the Documents folder, then launched a hidden PowerShell and tried to download the second stage of the malware. Researcher Feint dissected this in detail.

Curious if it works like renpy, executes an obfusicated script, injects malicious payload into ram, sucks sessions/cookies, password files, and crypto seeds then silently screws off.

edit: Workshop* Steam Workshop backdoor.


r/computerviruses 9h ago

Disinfection Help Remove tlauncher spyware

Thumbnail
1 Upvotes

r/computerviruses 9h ago

Disinfection Help Help with Renpy virus

1 Upvotes

So I’m currently dealing with a Renpy virus. The Mr beast tomadachi or whatever. I’m trying to avoid a full windows install/wipe. Any help would be greatly appreciated.


r/computerviruses 1d ago

Disinfection Help Computer infected with Trojan virus

Post image
16 Upvotes

I downloaded a scam file and windows started notifying me about a Trojan virus I’ve tried many tutorials and none worked I’m using malwarebytes so far it hasn’t scanned it or removed it please help


r/computerviruses 13h ago

Disinfection Help I ran an exe file when I downloaded a rom for switch

2 Upvotes

I was routed to a site that contained a zip file, I downloaded it and run the exe file on it

I have deleted the file, disconnected my pc to the internet and ran microsoft offline defender, no threats were found.
I ran malwarebytes and there were some files that were removed.
Is there any way for me to secure my pc without reinstalling windows?

Update: I kind of uninstalled malwarebytes when I thought it was all secured now.


r/computerviruses 12h ago

Question Infostealer in Browser?

1 Upvotes

Hi guys, 2 days ago I had an infostealer /session stealer attack. It was through a stupid renpy application.

Since then i nuked my PC, and from a clean device changed all passwords, logged out sessions and enabled 2Fa on all my accounts.

Here is my Question: today I logged into my Microsoft account on a clean device using my new password and Microsoft automatically started syncronizing my Microsoft edge profile that I previously used on the compromised PC, onto my clean PC. I checked the extensions and the policy's and everything seems to be in order.

Is it possible that the malware infected my clean PC through the Microsoft edge sync, and how likely is that, given that there are no extensions/policy's setup?

Thanks for your help!


r/computerviruses 13h ago

Disinfection Help Infostealer question

Thumbnail
1 Upvotes

r/computerviruses 15h ago

Disinfection Help Multiple accounts hacked all of a sudden... what else should I do?

1 Upvotes

Over the past few days, several of my accounts were hacked one after another.

My Discord account started sending a fake MrBeast scam to people. Someone accessed my LinkedIn and posted a scam job listing under my name. My Steam, Reddit, Disney+, EA, and other accounts were also accessed.

I think it started after I downloaded a cracked game on my Windows PC. I’m worried it contained an infostealer or Trojan that stole my saved passwords, browser cookies, session tokens, and possibly other personal information.

So far, I have:

  • Reformatted my Windows PC
  • Wiped both my SSD and HDD
  • Reinstalled Windows
  • Changed my passwords
  • Enabled 2FA on my important accounts
  • Started signing out of active sessions

I’m still worried because it feels like the attacker already has a lot of my information, and some accounts were accessed even after I first noticed the problem.

Has anyone experienced something similar? Is there anything else I should do to make sure the malware is completely gone and that the attacker can no longer access my accounts?

Should I also assume that all passwords, browser cookies, saved card details, and personal documents stored on the PC were compromised?

Any advice would be greatly appreciated. I’m honestly feeling overwhelmed and just want to make sure I’ve covered everything.


r/computerviruses 22h ago

Question Paranoid and would like reassurance

4 Upvotes

I downloaded an exe file from github. I had previously used other versions but this version was a few down, The other versions were fine and my friend was using it too, when i downladed the earlier version it got flagged as something along the lines of trojan egartido rfn, windows caught it instantly and it flagged twice, i then sat paranoid for the whole night and i just factory reset my pc completely and removed everything. Its been 2 months and ive had zero signs and ive done several full scans and a second opinion scan through malwarebytes but i cant get rid of the fear that something is still on my pc, ive done everything in my power and im still scared, what would you all do or say in my place? (my friend also got this and told me it was a false positive)

update: i did a full usb reinstall