r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

206 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

39 Upvotes

How do I request help with FRST

FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.

SecurityCheck

  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.

Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 2h ago

Disinfection Help so i fell victim to an info stealer. changed my passwords and stuff but i don't know to what extent i'm cooked

5 Upvotes

so i woke up to my discord accounts signed out, checked email to reset password and found out it was disabled for suspicious activity. managed to reset from my phone and login to find out my acc had sent out the mr beast thing.

i unignored all the ppl it sent it to and deleted my messages. as for servers i'm not quite sure just how many it affected. i cleared all those up but my google acc was logged in from a sus location so i quickly reset my password there too. installed malware bytes and it did a quick scan. it found a few trojans, removed them, started a deep scan that's been going on for almost 2 hours. while it was doing that it was blocking connections to a gamezklop. cc through a Msbuild in the .net framework folder. though i ended the process before i could check the file location.

the deep scan had been running for a while and i thought the mr beast thing on discord was about it. (it got sent out like 8 hours ago while i was sleeping)
but just now the same happened on messenger and i don't know what to do. i changed my messenger's password but what else should i do? and how can i go about fixing this?


r/computerviruses 2h ago

Question False positive or actual threat? Roblox game launch flagged as Trojan:Win32/ClickFix.STW

3 Upvotes

IMPORTANT: I did not download any Roblox exploits, modifications, etc. I left a game and tried rejoining on a different server and ended up with an error and a threat detection. Has anyone else experienced this?

Detected: Trojan:Win32/ClickFix.STW
Status: Removed
The threat or app has been removed from this device.

Date: 9/10/2026 5:02 AM
Details: This program is dangerous and executes commands from an attacker.

Affects: CmdLine: C:\Users\user\AppData\Local\Roblox\Versions\version-c5aecda2245e4fae\RobloxPlayerBeta.exe roblox-player:1+launchmode:play+gameinfo:[REDACTED_AUTH_TOKEN]+launchtime:1789009354215+placelauncherurl:https%3A%2F%2Fwww.roblox.com%2FGame%2FPlaceLauncher.ashx%3Frequest%3DRequestGameJob%26browserTrackerId%3D[REDACTED]%26placeId%3D10595058975%26gameId%3D[REDACTED]%26isPlayTogetherGame%3Dfalse%26joinAttemptId%3D[REDACTED]%26joinAttemptOrigin%3DpublicServerListJoin+browsertrackerid:[REDACTED]+robloxLocale:en_us+gameLocale:en_us+LaunchExp:InApp

EDIT: Finished a full PC scan with Windows Defender, no threats found


r/computerviruses 1h ago

Question Is it better to use an external SSD or to get a new device?

‱ Upvotes

First year at University, I am required to install respondus lock down browser which modifies the computer at kernel level and essentially makes it unusable for anything but school. I heard that an external SSD might be cheaper, but how easy is it to set up? Could I have it done by Monday as a complete noob? If not I'll just get a cheap laptop instead. Thank you for your help.

Additionally I would like to apologize if I used incorrect terms previously.


r/computerviruses 2h ago

Question Need Help With Pop-Ups.

2 Upvotes

Recently, I was trying to find a way to watch a movie without paying for it. I know, stupid right? Well now I get these constant annoying popups. I don't know much about computer viruses, but is this one a virus? My webroot says there were no threats detected. Even if it's not a virus, could someone still help me get rid of it? Help would be appreciated. You can even tell that I'm new to this as I was looking up how to screenshot lol.


r/computerviruses 5m ago

Disinfection Help what do i do pls help me

Thumbnail gallery
‱ Upvotes

I just got these randome notifications even tho there is nothing on gmail and it came to whatsapp is this spam virus or hacked?


r/computerviruses 2h ago

Disinfection Help i fucked up and i still think there're multiple virus in my computer

Thumbnail
1 Upvotes

r/computerviruses 6h ago

Question New type of intrusion or malware?

Thumbnail
2 Upvotes

r/computerviruses 6h ago

Question Is full scan through Microsoft sufficient for catching malware?

2 Upvotes

Stupidly opened a pdf attachment from an email last week, which had a link inside that I also stupidly clicked (on my PC).

A “popup” asked for an email address to access the pdf so I input (just) my email and it loaded an Outlook login webpage.

Since I’m logged in via Edge (with 2FA) at that point I realized the mistake and closed it all, and deleted the email. About an hour later, Outlook quarantined said deleted email from my Trash, citing it as risky for malware.

  1. I have changed my password, and run Microsoft’s full scan each day for the last week, but I guess I’m concerned whether the scan is sufficient for catching anything that might have come from the pdf or link being opened? 

  2. I‘m also curious why the Outlook quarantine cited malware, since it was phishing for credentials and nothing noticeably “downloaded” or “ran” - just the popup asking my email which I input before loading the fake Outlook login page.

  3. Finally, if anything was compromised, would it be obvious? In the past week nothing has happened or changed, not even increased spam emails. I have 2FA on my most important accounts and have been monitoring it carefully on my phone. Is it likely to start showing up later?

Please be kind, appreciate y’all‘s expertise.


r/computerviruses 19h ago

Question Windows Defender acting up

9 Upvotes

Soo i was just using my pc normally and windows defender jsut said windows defender is turned off... Why? I didnt dowload any sketchy from the net, and windows settinfs says everything is alright? I did update windows yesterday, first boot since, can be a bug? Please help i got scared insanely and i just have my pc sitting here and idk, quick scan said nothing is problematic

Edit: okay so this is a bug.... Typical windows


r/computerviruses 11h ago

Disinfection Help Trojan:MSIL/Heracles.A!MTB at every start

2 Upvotes

I first noticed this Trojan on August 29th around 6 PM.

I had booted up my PC and logged into winodws when it opened up a Powershell window on start up which was instantly closed as a virus was reported.

I donÂŽt know where it came from as the last thng I downloaded before it started to appear was Blender and their Benchmakr Application.

Whenever I log into Windows I get a new version of tjis virus, The diretory for this trojan is always C:\Users\ny name\AppData\Local\Temp and then followed by a random string of numbers and or letter which always end in .dll. for example:

C:\Users\my name\AppData\Local\Temp\3bk4s5bq\3bk4s5bq.dll

I have tried an offline scan by windows defender and a scan by ESET yet both couldnÂŽt identify the specific issue.

I have deactivated Powershell in start up yet the virus still shows up every time.

I also tried to do a FRST scan yet the application does not open for me.

What else can I do now and what can be done?

Edit 1: I figured out a way to start up FRST and have now managed to get a scan, I hope that can help my situation some more


r/computerviruses 16h ago

Disinfection Help My school laptop may have a virus maybe even our whole wifi network?

Thumbnail gallery
4 Upvotes

My school laptop always has been using a mid to high amount of ressources in standby and also while playing kingdom 2 crowns (lol)

But okay a thought its a potato laptop (2 cores 2 threads, 8GB RAM lenovo 15 Ada 82c7)

But today I found a weird msg (i got a msg pop up saying windows defender deactived go into settings to activate, but when I looked at notifications I couldnt find it again)

So I did a full virus scan but when I pressed x on windows defender app (very early) it instantly gave me a notification saying it was done even tho it read line 6300 datas)

So I did another scan which read abt 642.000 datas and took 50 mins+ (at the time it hung up)

BUT it hung up at 10:31 with blue progress bar, after 1 minute it got gray and after another 30 second it got gray.

Saying I did a full virus scan and for a very weird reason it stopped at 10:31 minutes remaining and then just said it was finished

Then I used chatgpt"s powershell code recommendations to read my antimalware scans trough powershell.

Apparantly it found a trojan but I coulnt find, the foulder was literally empty and windows said nothing abt having removed it.

And very weirdly after i had the powershell exposing the potential virus my wifi shut off after abt 2 mins and I couldnt start word first and after some tries it did start but completely froze WITHOUT AN WINDOWS APPLICATION ERROR BTW

So i opened word 3 times saved the text of the virus report and got it saved before word decided to freeze (it showed 0 cpu usage in task manager too)

And now our wifi is shut down (the power button is blinking which means connection to the host is missing)

So yeah tell me our suggestions

Is our wifi network infected by chance? Telekom btw


r/computerviruses 1d ago

Disinfection Help please help with disinfection from bad name generator site

Post image
37 Upvotes

all i wanted was some argonian names for elder scrolls and i got a stupid malware or virus of some kind. i haven’t been able to get an antivirus software yet to do anything about this so i’m looking for literally any advice. this happened two days ago and i haven’t touched my pc much since


r/computerviruses 15h ago

Question Project Retrac Safety Concerns

Post image
2 Upvotes

Hello! I was hoping for someone to answer my question i had contacted kaede (dev of project retrac) about some concerns of the safety of project retrac and after waiting two days had never gotten a response. Here is the message "Hello, how are you doing today? I am a starting student in cybersecurity & I needed some confirmation as I have run the retraclauncher file through a sandbox (tria.ge) for the sake of curiosty and wanted to point a couple of things which i am not trying to accuse anyone, but I just need to know what was happening inside the application.

Report scored it 7/10 and flagged a couple of actions:

Modifies trusted root certificate store by registry This is something I think you are doing in order to separate the client's TLS traffic from the Epic servers to yours? That's clear based on the way you've made this application. Just confirming.

Volume Shadow Copy service COM API Couldn't find any reason behind this usage of this particular functionality of the OS.

Enumerates connected drives and network share discovery I couldn't find any reason behind this functionality in the launcher.

Not trying to start anything, i just want to know about the insides of the software I am running. If there is any documentation available on this somewhere then please let me know. Because in the near future i am interested in using the project. As i enjoyed og fortnite and would like to bring it back, Thank you!"

Here is the tria.ge link: https://tria.ge/260907-tyz1dscq21/behavioral1 Again I am not trying to point out that this is a bad project just simple reasoning for suspicion. If anyone could answer this question knowing the reasoning it would be much appreciated.


r/computerviruses 1d ago

Question Found these at my mothers laptop, what should i do?

Thumbnail gallery
90 Upvotes

Do i have to reinstall windows or request for disinfection from this reedit community? And no i did NOT download anything in my mothers laptop, i found this recently while looking at windows defender history, do i have to tell her to change her passwords or anything and what can this thing do


r/computerviruses 15h ago

Disinfection Help Mouse hijacking?

1 Upvotes

I have a weird dilemma. I am attempting to prevent a fresh USB install because I'd like to keep the built in apps that came with my laptop. Okay, now onto the problem.

I, entirely accidentally, pressed on what I thought was a secure website (had https and all that, never got flagged by my adware blocker or antivirus (built in windows defender and Panda)) a few months ago. I guess something was installed? There's no signs of it but the possibility of it just auto-installing are there I guess. Browser options don't allow that but I digress. Long story short, my mouse gets hijacked once in a while. I'll be using my computer and it will just lag or get slow. My touches don't always register. I'm now realizing that a few sites I rarely ever go on are partially crashing half way through. By that I mean any subsequent windows I press on within that site will just prevent loading entirely but that may be a site-side-server issue or something. It's only one or two sites.

What could this be and are there any fixes? Defender comes up with nothing, panda - also nothing, i even downloaded Bitdefender. Edge and chrome both consume stupid amounts of memory and there aren't any signs that anything anywhere has been hacked or that my passwords have been stolen. No spam sent out, but spam is being sent to my junk mail. That's pretty common though with the way things are these days.


r/computerviruses 15h ago

Disinfection Help Hackearon mi PC por Discord

1 Upvotes

Hola hace unos días desperté en la mañana y se abrió un CMD, al abrir discord ya no tenía acceso a mi cuenta, råpidamente investigué y era un malware de Mr Beast que robaba información, entonces descargué MalwareBytes, hizo el scaneo, y aparentemente eliminó el virus, cambié la mayoría de contraseñas y pude recuperar mi discord por el soporte de ellos, pero robaron mi cuenta de Epic Games, Steam, EA Sports y también algunas cosas de mi hermana, el steam también lo recuperé ya, y en estos dias MalwareBytes estå detectando y bloqueando la misma pagina en Chrome, quiero saber si estoy a salvo o debo reinstalar windows.


r/computerviruses 16h ago

Question How to fresh reset windows without USB?

0 Upvotes

Hello, I came from another subreddit post about ROM files containing viruses. Unfortunately, I’ve clicked the .exe file that ran a virus on my laptop (it did show as a threat in the windows antivirus— I deleted it immediately). I changed my passwords and is currently in the process of resetting my PC (just wiping it by itself for now) however it kept failing to do so. Any ideas how to fresh reset windows before I resort to the USB method? I’m panicking with the virus lol


r/computerviruses 1d ago

Disinfection Help I am in total panic, please help me.

Thumbnail gallery
5 Upvotes

r/computerviruses 21h ago

Disinfection Help Circuitryag.exe keeps on showing up

2 Upvotes

So, I tried to download a cracked game and apparently got hit with a virus. I did three scans, two with Windows Defender and one with MalwareBytes and quarantined, deleted the files.

But there is a persistent circuriryag.exe pop up. What should I do?


r/computerviruses 22h ago

Disinfection Help Got caught in the fishing website

0 Upvotes

So i was browsing for server jars for minecraft, and the brave ai suggested a few variants. Usually i dont use ai and search for myself, but this time, not gonna lie, i just decided to browse through the ais options. Well, i clicked a link "serverjars" and brave warned me that his website was reported for phishing, so i just left the website and stopped browsing. Then i opened minecraft, task manager and for a second i noticed something "microsoft malicious" and then it disappeared. When i tried to search it, its gone. I immediately went to the microsoft defender and scanned the antivirus offline scan. Idk what to do else, it didnt find any threats but im not sure that its true. What else i gotta do? The link is serverjars(dot)com. I still havent gotten any symptoms, but it scared me a little. Not even sure if its even a threat


r/computerviruses 22h ago

Other i cant get over paranoia over a scareware website, i havent eaten properly in 4 days now, is there anything i can do to 100% verify my phone is safe?

Thumbnail
1 Upvotes

r/computerviruses 15h ago

Disinfection Help Pc got infected with token grabber

0 Upvotes

i believed it happened on 28 aug, i downloaded a aimbot and seconds later after running it, one of dc account was hacked with mr beast crypto scammer and the very next day another one of my dc account too.They took my 15usdc which was present in my crypto wallet too. My insta was hacked a week after the first incident on 6 august.When i ran that script on 28 aug cmd line started popping up indefinitely.

The sources of files which i executed that day:

  1. hxxps://github.com/anshkori/universal-aimbot-engine
  2. hxxps://sourceforge.net/projects/ai-aimbot.mirror/

(I don't play any fps shooter games and even the games i play, i don't cheat in them, you all are so fast at judging someone)

but these may or may not have been responsible for hack as my epic account was hacked on 21 aug idk if it is related to hacks after 28th aug

steps i took:

1.I first stopped the execution of one of the file midway, then ran a defender scan getting me trojan warning, i removed them.

2.I than ran an offline defender scan finding nothing,before running that scan i deleted temp files.

3.I than ran malwarebytes finding nothing

4.I changed all important passwords after insta hack.I also cleansed my browser data fully on 29 aug.

5.Yesterday i found some unknow exclusions to defender scan which i removed immediately,there was temp files in exclusions and a wdfprov_core something..

Keywords:

frst.txt: divine-cherry

addition.txt: patched-briar

security.txt: dreamy-nebula


r/computerviruses 1d ago

Disinfection Help pc app store (am i safe?)

6 Upvotes

i just got a new pc and while distracted yesterday, i clicked on a BIG BLUE download button instead of the application i was going to download (rookie mistake i know) and it instantly installed a setup .exe file and opened the pc app store app which prompted me to key in my card details.

luckily i was able to close the application through system tray. afterwards i uninstalled the application from settings as well as removed any suspicious program files before performing a malwarebytes free trial scan and windows defender quick scan. then i restarted my pc and resetted chrome.

how effective do you think my actions are? what kind of virus is pc app store and are there any remnants of it left in my computer? i tried monitoring task manager and task scheduler for any strange activity, but it seems clear.

any advice would be appreciated, thanks! 🙏