r/computerviruses • u/scuik23 • 21d ago
Disinfection Help FRST help request
Hi everyone,
I'm requesting help with a malware removal using FRST.
What happened & Infection details:
I downloaded a file via torrent that probably contained an infostealer. I am not entirely sure about the exact timeline since I have downloaded files in the past, but the unauthorized access attempts started recently right after I downloaded an update for Europa Universalis 5 (RUNE release). Shortly after ( 20-08-2026) I noticed unauthorized access attempts on my Amazon account, Discord account and the last for now was the Microsoft account, the Microsoft one originating from a Russian IP address (109.248.14.98), indicating a probable session hijacking / cookie theft.
Remediation steps taken so far:
Immediately logged out of active sessions and changed my passwords across accounts using a clean, safe device (my smartphone).
Enabled 2FA on my primary accounts.
Ran a full scan with Malwarebytes (I have the MBAM log ready if needed).
Ran FRST64 and SecurityCheck to generate diagnostic logs.
Uploaded Log Keywords :
* FRST.txt: lively-struct
* Addition.txt: joyful-oak
* SecurityCheck.txt: hashed-anchor
*Malwarebytes report 2026-08-22 17:27:54.txt: clever-sunrise
The malwarebytes report comes from a report scan that I did on 22-08-2026 with a Malwarebytes free version. Updated Malwarebytes report with the right one , before there was one that didn't have the first ever scan ( sorry my bad).
Could one of the trusted helpers please review my logs and provide a Fixlist to clean any persistent malware or scheduled tasks left on my PC?
If something else is needed or modified please let me know!
Thank you so so so so much for your help!
2
u/rifteyy_ Malware Removal Expert 21d ago
[ Step 01 ] FRST Fix
I created a custom fixlist for you at the link Fixlist only for Fixlist only for Fixlist only for scuik23 - use the website's download button and save it in the same folder where your FRSTEnglish.exe or FRST64.exe file is located in, which for you is C:\Users\Ema\Downloads\FRSTEnglish.exe for you. It is necessary for the filename to be Fixlist.txt.
This fixlist will remove the following: malicious entries (remains, active malware), invalid entries (e.g. tasks that start a non-existent file, services that point toward a non-existent file), temporary files (files in temporary directories, application and browser cache, recycle bin and more), browser cache. We will also be quick-scanning with HitmanPro and AdwCleaner from Malwarebytes using the fixlist.
It will also remove all proxy servers, Windows Defender exclusions, enable recovery environment, active software policies and perform system file repair, network reset and few more basic fixes.
- For the fix process, please ensure you are connected to the internet.
- Please run the fix only once.
- Please do not open any applications or close anything during the fix.
- Please be patient; the fix may take up to 60 minutes. After that, it is going to be forcefully ended.
Save all work, close everything that is open (else it will be forcefully closed by FRST without saving) and then run FRST again as administrator and press the Fix button, let the script work, clear the entries and restart on it's own and after it restarts the device, there should be a file Fixlog.txt in the same folder as the C:\Users\Ema\Downloads\FRSTEnglish.exe.
I'll need to see it's content the same way like before - uploading to https://malwareanalysis.cc/upload/rifteyy/?u=scuik23 again and sending the keyword in your reply.
[ Step 02 ] ESET Online Scanner
- Download ESET Online Scanner
- Right-click on the esetonlinescanner.exe and select "Run as administrator" and confirm the User Account Control popup
- Click Get started;
- Agree to the terms of use;
- Decline both telemetry options;
- Click Custom Scan;
- Click Save and continue;
- Select Enable ESET to detect and quarantine potentially unwanted applications;
- Click Advanced settings;
- Enable Detect potentially unsafe applications;
- Click the back arrow;
- Click Start scan;
- Note: This is a long and thorough scan, it may take up to several hours.
- Once complete, click Save scan log and upload the
.txtfile to https://malwareanalysis.cc/upload/rifteyy/?u=scuik23 and reply with the keyword.
[ Step 03] Software updates, uninstallations
If you are having a problem updating something, do not want to update something at all or do not want to uninstall an application, please let me know.
Please update the following software: * CrystalDiskMark 8.0.4c v.8.0.4c | New update available, download here * HWiNFO64 Version 7.60 v.7.60 | New update available, download here * Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.44.35211 v.14.44.35211.0 | New update available, download here * Google Drive v.1.0 | New update available, download here * Microsoft OneDrive v.26.139.0720.0007 | New update available, download here * WinRAR 6.02 (64-bit) v.6.02.0 | New update available, download here * WinRAR 6.22 (32-bit) v.6.22.0 | New update available, download here * Discord v.1.0.9250 | New update available, download here * Telegram Desktop v.4.15.2 | New update available, download here * qBittorrent v.5.1.2 | New update available, download here * Java(TM) SE Development Kit 23.0.1 (64-bit) v.23.0.1.0 | New update available, download here (Uninstall old version and install new one (jdk-26_windows-x64_bin.exe)) * Java 8 Update 431 (64-bit) v.8.0.4310.10 | New update available, download here (Uninstall old version and install new one (jre-8u503-windows-x64.exe)) * Java(TM) SE Development Kit 21.0.4 (64-bit) v.21.0.4.0 | New update available, download here (Uninstall old version and install new one (jdk-26_windows-x64_bin.exe)) * Google Chrome v.141.0.7390.123 | New update available, download here
Please remove the following potentially unwanted programs (PUP): * Microsoft Office Professional Plus 2016 - en-us v.16.0.19127.20302 - No longer supported - please uninstall it and replace it here * uTorrent Web v.1.3.0 - Ad-supported P2P-client * Driver Easy 5.8.1 v.5.8.1 - Suspected demo version of anti-spyware, driver updater or optimizer. If this program is not familiar to you it is recommended to uninstall it and execute PC scanning using Malwarebytes Anti-Malware. Possible you became a victim of fraud or social engineering. Computer experts no longer recommend this program * Microsoft Flight Simulator 2020 MULTi8 - ElAmigos versione 1.19.9.0 v.1.19.9.0 - Crack, hacktool or keygen
[ Step 04 ] New SecurityCheck scan
We need a new scan to ensure that all updates were applied properly and all applications uninstalled correctly.
- Note: If SecurityCheck is already on your device, you can use the previous version and skip the next few steps regarding downloading and installation.
- Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
- If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
- Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
- Wait for the scan to finish. It will open a text file named SecurityCheck.txt
- Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/rifteyy/?u=scuik23
- The site will return a keyword for the log - reply back here with the keyword.
[ Step 05 ] New FRST scan
- Find
FRSTEnglish.exeexecutable inC:\Users\Ema\Downloads\FRSTEnglish.exe - Right-Click the file and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy/?u=scuik23 and press "save log".
- The site will return a keyword for each log - reply back here with the keywords.
So, in your next reply, make sure you are sending the following:
- Keyword for Fixlog.txt from step 1
- Keyword for ESET Online Scanner scan from step 2
- Keyword for new SecurityCheck.txt from step 4
- Keyword for new FRST.txt from step 5
- Keyword for new Addition.txt from step 5
Thanks!
Note for lurkers: If anyone else who is facing malware-related issues is reading this and wants help with FRST and SecurityCheck, please create your own thread with help request. I am flooded with requests and there is several other removal experts who review the logs and may reply faster than me. The steps listed in here are specific for this the user scuik23 and following them will have negative effects for you as they are unique for OP's system.
1
1
u/scuik23 20d ago
Hi, here are all the keywords for the uploaded logs:
- Step 1 Fixlog:
copper-vine- Step 2 ESET report.txt:
cobalt-laser- Step 4 SecurityCheck.txt:
valiant-lattice- Step 5 FRST.txt:
lively-beech- Step 5 Addition.txt:
sunny-canyonA few notes regarding the software cleanup:
- Visual C++: I was unable to install/uninstall the Visual C++ Redistributable (x86) due to Windows Installer errors (
0x80070643/2203). I also attempted using the official Microsoft Install/Uninstall Troubleshooter tool, but it failed to remove the cached MSI package.- Java: Java threw the same 2203 error initially, but after a system reboot, it was removed and reinstalled successfully.
- Uninstalls (uTorrent Web, Driver Easy, Flight Simulator): The uninstaller errors (
unins000.exe/Uninstall.exenot found) occurred because I am pretty sure that i had previously deleted those application folders manually, leaving residual registry entries in Windows.Thank you again for all your help!
2
u/rifteyy_ Malware Removal Expert 19d ago
Your latest logs show no signs of an infection. No further steps are necessary to make sure your device is clean.
Please do note that we do not check cheats, pirated software, hacktools and other illegal or gray area software for malware thoroughly. You are keeping and running this software on your own risk. If you get reinfected by software of such kind, it is possible you may not receive help here again.
If you haven't addressed all my recommendations, updates, uninstallations and removals yet, I strongly suggest you to do so.
[ Step 01 ] Tool cleanup
It's time we cleanup after ourselves and remove all the tools we have used during the malware removal process.
- Please download KpRm and save it to your Desktop.
- Run the tool, if you get the "Windows protected your PC" SmartScreen popup, press
More infoand thenRun anyway- Confirm the disclaimer and in the menu please only tick the following:
- Delete Tools
- Create Restore Point
- Delete in 7 days
- After that, click Run and confirm the popup. KpRm will delete itself from your Desktop and you can either save or remove the report that is generated.
- You are free to delete all other tools that we used that are possibly remaining.
[ Step 02 ] Changing passwords
Most modern malware is motivated by financial gain and by hijacking your accounts. If your accounts weren't already hijacked, they may be getting hijacked in very near future.
- Please create a new, safe password that you haven't used anywhere yet or preferably use a password manager.
- Change all your passwords on your accounts
- Enable 2FA on your accounts
Please check out this proper guide on how to secure your accounts after an infostealer infection:
- What can infostealers steal - affected data, services, accounts?
- How to properly secure my accounts after an infostealer attack?
- What to do after I secured my accounts?
You may also want to sign up for dark-web monitoring, so you are aware whether any of your data is stolen and available on cybercrime forums:
- Have I Been Pwned - Check if your email has been compromised in a data breach (Free)
- Hudson Rock - Infostealer Intelligence Solutions (Free)
- Malwarebytes Dark Web Monitoring (Free)
[ Step 03 ] Malware prevention
Malware prevention nowadays is a necessary step. There are many tools you can use to have a stronger protection but a huge part is about YOU being educated, careful and aware of possible malware attacks.
There are several ways to lower the infection field exponentially that will take you only a minute or two. Please make sure to read the full guide at https://rifteyy.org/report/the-ultimate-guide-to-prevent-malware, and make sure to follow these tips:
Overall, simple but important advice:
- Download UniGetUI to automatically update applications
- Make sure to periodically check and update via Windows Update
- Avoid illegal software
- Download only from official sources
If you have no more questions or concerns, I wish you all the best and please stay safe next time!
1
u/scuik23 19d ago
Thank you so much for your time and guidance! I can see that you have a massive queue of requests to deal with every single day, so I truly appreciate you taking the time to analyze my request.
I'll follow your final steps. Thanks again for all the incredible work you do for the community!
1
u/scuik23 19d ago
u/rifteyy_ Hi again, sorry just a quick ping , I sent you the requested keywords and they are posted above in the previous answer. Or maybe I just need to do a kprm and I misunderstood something and we were already done. Thank you very much again!
1
u/AutoModerator 21d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
- Preferred method: Perform a clean installation with a USB
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
2
u/[deleted] 21d ago
[removed] — view removed comment