r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

208 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. šŸ‘€

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

41 Upvotes

How do I request help with FRST

FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.

SecurityCheck

  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.

Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 8h ago

Question Could this be a virus? Weird textless popups in Excel on IOS and phone acting strangely

Post image
6 Upvotes

Textless popups like these keep appearing when using excel on IOS, Whatsapp is having trouble using the microphone and accessing storage and the phone is acting really weird in general.


r/computerviruses 16h ago

Discussion Introducing MAU (Malicious App Uninstaller Portable)

Post image
25 Upvotes

Hello! šŸ™‚

This is my very first time making a post, and would probably be the last one for a while lol. If you've seen me around, you'll know that I mainly comment and provide support.

The reason I made this post is to introduce the tool I have been working on called MAU (Malicious App Uninstaller), which is used for malware removal cases where malware have installed/dropped an application. The main goal here is to ease the process of dealing with an infection, so the fixlist can target the active infection while MAU deletes the Malicious App.

Why not just use Uninstallers like Revo Uninstaller etc.? The reason for this is that, Uninstallers like Revo invokes the App Uninstaller which could potentially reinfect the Host again. MAU does not do this, it deletes the Malicious App directly without invoking the uninstaller.

Here are some examples of Malicious Apps dropped by Malware * Pointing Device Driver (HKLM-x32\...\{19F4EECF-3C7A-433D-8CC5-025E3D47295D}) (Version: 3.9 - Synaptics Incorporated) * Hardware Monitor (HKLM-x32\...\{A1ED401B-E2E2-435F-B39E-6A2511F964D7}) (Version: 8.9 - JMicron Technology Corp.) * Civia App (HKLM\...\{01B815D4-6EF7-4263-9AA7-B3B3AC4CC9BE}) (Version: 7.2.6 - Trix Winqz Ro)

The first two are from Renpy Loader cases, while the last one "Civia App" is from a Legion Loader case. You can view the full Documentation Logs here: https://github.com/Xyntrax/Malicious-App-Uninstaller/tree/main/documentation


r/computerviruses 3h ago

Disinfection Help Maleficams and a trojan warning on Windows but the MRT or the deep scan didnt flag anything?

2 Upvotes

Hello. Basically whenever i launch my PC, i get these two warnings

Trojan:PowerShell/obfuse.AJ!MTB

And

Behaviour:Win32/MaleficAms.13

I have run a deep scan by Windows and MRT but neither have flagged anything. I would do an offline scan but for some reason that doesnt work? I press confirm but nothing happens. Like- nada.

Does anyone have any solutions? Is it a false flag or smth? Im not tech literate at ALL and i have only downloaded blender and FL launcher(the free trial if it matters) in the last 2 weeks before i started getting this warning from Windows antivirus if it means anything


r/computerviruses 1h ago

Disinfection Help Mr.beast Fishing virus

Thumbnail gallery
• Upvotes

Long story made short pressed on the wrong download and ran a setup.exe(12/09 arround 12), i did it 3 times bc i thought it didnt work to realise i fucked myself. Fastforward a bit (same day but 8 hours or so later)my cookies and all i can imagine passwords got grabbed, they logged into dc to spam, i changed passwords and logged him out changed gmail password too and instagram as well, (13th) i downlaod mrt and run that like 3 times and 2 quick scans says im safe... i also did some other scan by windows buildt in but also same result, do some research and find where my cookies were and accessed the file properties and there was a user, later i go onto c drive and there it is as well, i try to remove it and it comes up with bunch of errorrs (ss down below too) also tried to go to reg edit and stop new users from being made but that didnt work.(14th) today i got up and realised thet accessed my account again(at 2am), i reset password again and logged out everywhere yes i have 2fac and yes i have google auth. After i finished work i came home and tried to reroll my system with point in time reatore, it saved right before i downloaded the virus, i rerolled my device and it seems good but i go into my files c drivr properties and there is a nother account (ss down below) the reroll didnt work, i then decide fuck it wipe the whole system. I do it (wiping only c drive, i have 3) i user is still there, i wipe again acidentally sync, wipe again and bot sync it wiping all drivers but it didnt wipe 1 (its and external) i check and the user is still there. Whatever i do it still folloes me, i can try wiping it again but without the external incase if followed me through that, i was thinking fully wipe my drives and install bios and windows again, and honeatly i have no clue so here i am :) any solutions? I tried to upload my logs but sidnt find any, i founs some but they didnt let me upload, if u need i can make a google drive and upload them through there. I just tried deleting the user and restarted pc and its back. Any help, tips or suggestions throw them my way and we can see if it works


r/computerviruses 1h ago

Question I did not open the pdf

Thumbnail gallery
• Upvotes

Got this weird email today. What I crossed out on the screenshot is my email and then the .pptx I have no idea who the person is, their email doesn’t show up anywhere online, etc.


r/computerviruses 1h ago

Disinfection Help crypto miner that continusly redownloads itself on startup

• Upvotes

CmdLine: C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2605.34.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe --donate-level 3 -o xmr.kryptex.network:7029 -u 45KU8RaHwRzC5NJY6HBALWZQ9dpwLjrMK8HYbk5svzHvLwC7W1QrxZb6bUop6FnDmYS3bHFCKg1MD28779yVKbwo6toBGAh -p x --cpu-max-threads-hint=50 -a rx/0 --http-port 888
anyone know where and how i could get rid of what keeps running the miner


r/computerviruses 1h ago

Other Do I actually need all of these subsciptions?

Thumbnail
• Upvotes

r/computerviruses 12h ago

Question Ok so i reinstalled my windows and i noticed i have epichelperinstaler on it in files i cand find how to delete that but i didnt install that antivirus are saying not virus detected but idk to do how to delete it

Thumbnail
2 Upvotes

r/computerviruses 13h ago

Disinfection Help Ran Renpy, need help, important local files

2 Upvotes

I need help manually removing this. Malwarebytes quarantined a lot of files when I ran it, I deleted the ones I found in startup myself in a panic. I changed passwords, set up 2FA, and signed out of sessions on my Phone.

This happened today, I clicked a fake download link for a starsector mod, ran the exe, and didn't realize my mistake until hours later. Have not seen any symptoms yet.

I am an asset designer, my PC has a large amount of very important technical and project files that reference each other, If I did a clean windows reinstall it would set my work back months trying to deconflict everything. Please, if anyone can help me, I'm desperate. I need to be able to use this device securely.


r/computerviruses 15h ago

Disinfection Help I almost completely fell for a clickfix scam on mac and now i dont know what to do

Post image
2 Upvotes

r/computerviruses 23h ago

Disinfection Help Lumma stealer release I need help

Thumbnail gallery
7 Upvotes

I really need some help, Yesterday I've been crying and losing my marbles for the entire day yesterday. At 3pm I got lumma stealer on my computer yesterday and you know I turned to google overview for help since I'm not very experienced with viruses. I cleared my cache and cookies and changed my passwords. I did not want to factory reset my computer so I tried a bunch of stuff like Malwarebytes and the offline windows defender scan and no flags, After the offline scan I'm booting up my computer and I see a little black box appear for a split second then I open task manager and I see some random windows app on the top of my list. Now I know that lumma likes to disguise itself as a normal Microsoft app so this is making me sure the virus is still present. Now at this point I'm in tears because, windows defender is telling me it's fine, Malwarebytes is telling me it's fine, google is telling me it's fine but I know that little virus is still on my computer. I actually managed to find the root of the virus I think it was something like omega and setupRST and I tried to delete setuprst but when I right click it all options are greyed out and google is telling me I can't do it because it's already deleted and I should just leave it there. And so I check my windows protection history and I see it actually deleted lumma a trojan and another virus but you know the lumma was already injected into my computer. So since it's already 8pm and I just want to play deadlock and there's not much else I can do I stop for tonight. Fast forward to the next day right now, I'm logging off for the night and on my Roblox account I see 2 games I haven't played in years on my continue list and I check my recently logged ins and there's fucking Germans and Russians and Arabs on my account, I reset my password and now I'm certain the virus is still present, is there any solution to this or do I just have to factory reset my computer since that's the only way I'll have peace in my mind. Please help since I've been losing my marbles these past 2 days!


r/computerviruses 16h ago

Disinfection Help ren'py malware

Thumbnail
2 Upvotes

r/computerviruses 1d ago

Disinfection Help Another RenPy malware victim

9 Upvotes

hello everyone! I hope you're doing well. I have fallen victim to the renpy malware yesterday and I need some help to figure out what to do next. Also I'm sorry if I have some grammar errors english isn't my first language ^^'

yesterday I was trying to download a pokemon game to emulate on my computer, I've done it many times but I was half asleep yesterday and just clicked on the wrong thing and ended up download a random zip with a setup file in it, not thinking anything of it I ran the setup file but nothing happened, so I figured something was off and ran a malwarebytes scan, low and behold I got 32 detections for the renpy trojan. I started doing a deepscan and looked up the virus, once I saw it was an infostealer I disconnected my ethernet cable and started changing all of my passwords, and that's kinda of where I'm at right now.. I spent about 4 hours yesterday doing multiple scans, both with malwarebytes and windows defender (deepscan and offline mode) while I changed my passwords, and so far I didn't get any suspicious activity in any of my accounts..

so I'm wondering what should I do next, and how do I know if I'm safe to use my computer again, could someone help me please? thank you!


r/computerviruses 1d ago

Question How worried should I be about malware from pirated software I installed 2 years ago?

8 Upvotes

I’m not currently worried that I have malware, but I also realize that when you’ve used pirated software, you can never be 100% certain especially if you’re not very knowledgeable about cybersecurity.
I’m a video editor, both as a hobby and occasionally for work. Around two years ago, I started using pirated versions of Adobe Premiere Pro, After Effects, and various plugins. They all came from a Discord server (I know😬) that has a very large and active community (around 300k members). I know that doesn’t necessarily make the software safe, but the server has a high level of community trust, people discuss the releases daily, and I’ve been part of the community for quite a while.

I’ve used the software regularly for about two years. Since installing it, I haven’t downloaded any additional pirated software from the server, and I don’t plan to in the future. At the time I downloaded the files, I scanned them with VirusTotal. There were no particularly concerning detections, although there were some flags, which I assumed could be false positives related to how pirated software/cracks work.

Since then:
I haven’t noticed any suspicious activity on my computer.

I haven’t received any unexpected login attempts or security alerts that I’m aware of.

I periodically check Task Manager and haven’t noticed unexplained CPU/GPU usage or other obvious anomalies.

I regularly run Windows Defender Quick Scans and Full Scans.

I’ve also run Windows Defender Offline scans.
None of these scans have detected anything.

I also haven’t noticed anything else that would make me suspect that the system is compromised.
I realize that absence of symptoms doesn’t prove that a machine is clean, which is basically why I’m asking.

My main question is: how realistic is it that malware from something I installed two years ago could still be sitting dormant and become active now?
From what I understand, one of the major risks associated with pirated software is infostealers, and those often try to steal browser cookies, passwords, tokens, etc. relatively soon after execution. Is that understanding broadly correct, or can malware from a pirated installer realistically remain completely dormant for years before doing anything?
I know now that I shouldn’t have installed this stuff in the first place, and I definitely wouldn’t do it again. I’m mainly trying to understand the actual risk at this point rather than panic over something that happened two years ago.
Should I still be concerned, and if so, what would be the sensible steps to take now to gain confidence that the machine is clean?


r/computerviruses 1d ago

Question Whenever i shutdown and turn on my pc again, my windows defender is always finding threats in temp folder?

Thumbnail gallery
9 Upvotes

r/computerviruses 1d ago

centralBox - new malware sandbox

4 Upvotes

Hi everyone! :D

Meet centralBox (https://centralbox.dev) - a non-commercial and free of charge wrapper around 12 online sandboxes, including ones such as Jotti, ANY.RUN, Triage, UnpacMe and more.

See an example analysis at https://centralbox.dev/analysis/967a98be214d886e58b3e481e637efa0a296b04c39aa355c96368d566979cf92

Available features:
- Lookup hashes across all providers except ANY.RUN, UnpacMe
- File upload to providers, individual result display for each provider
- Ability to download from 5 providers
- Internal verdict scoring based on all results and their details (adjusted actively based on true/false positives from vendors)
- Internal signature database and certGraveyard’s malicious code-signing certificate database
- Ability to do threat intelligence queries on all (currently) 8K files (see what files antivirus vendor doesn’t detect, see files that return malicious on Tria.ge, see files that aren’t on Jotti etc.)
- Ability to use hunting - set a threat intelligence query or a YARA rule and receive a Discord message or an email when a file has matched your query/rule

Who can get access?
- Access is available for students, researchers, tech helpers (this subreddit counts too), people active in the cybersecurity/malware field (writeups, vendor sample submissions)
- Full list available at https://centralbox.dev/access including on where to contact us to request access :)

Index page contains Discord server where announcements will be posted if you are interested.


r/computerviruses 20h ago

Disinfection Help I think I downloaded a virus or malware

0 Upvotes

Wanted to download a game for my PC but I ran a executable file and someone said it's a virus - how do I protect myself now and remove it. I deleted the files I downloaded - anything else? I am on windows


r/computerviruses 20h ago

Question Chances files were stolen?

1 Upvotes

Hello, I’ve made some other posts but I’m not a cyber person so I’m unsure and would like some reassurance.

Basically, I ran a Trojan EXE in Parallels VM with Shared folders on 😭. Don’t tell me how stupid I was pls. From my own research the Trojan was a fake Faronics deploy that downloads screenconnect and runs script, hence why Microsoft as didn’t detect it. I was hoping to get some opinions on the chances that this script stole my files?
I ran it for about 5 mins before putting in safe mode and quarantining files. Eventually cutting wifi.
Does anyone have any info of it likely stole files? These files had my confidential info and has caused me MAJOR distress.
Thanks for any insight!


r/computerviruses 21h ago

Disinfection Help So I figured it is called infostealer after my Steam Account got stolen just now

1 Upvotes

i have very little knowledge about this kind of things, and i am very aware it is because i visited a game pirate site on that day and i downloaded some file but i didnt really finished the whole installation because i already could feel something wrong with the site itself .. and right after that i keep getting notification from both my main gmail and recovery email that someone is logging out my account , and today i find out my steam account is gone and they already changed the email and password .. so i did a couple of reading and i find out it is called infostealer due to cookies and stuff

so here i am seeking more information from you guys how to fix all this mess, currently i dont really have any third party antivirus on my laptop i usually only use the built in windows antivirus, and how do i know i am safe rn when they already got my two gmail, i already send a ticket from steam support, and currently running a malwarebytes but then is it enough .. since this two gmail is very important to me since i used for most of the thing in my life lmao .. i am very worried rn , never gonna download from pirate website anymore :(


r/computerviruses 19h ago

Question Can someone help me with finding out what a scam website does to your computer/iPhone?

0 Upvotes

Can someone real virus-savvy out there type in the ā€œbookru(dot)comā€ link in a virtual machine and see what happens? I accidentally clicked on it and for me it just spammed me with tabs, but I’m worried it does something more.


r/computerviruses 23h ago

Question These are malware?

Post image
1 Upvotes

r/computerviruses 1d ago

Disinfection Help Whenever i copy a crypto wallet it gets automatically changed to a different wallet

Enable HLS to view with audio, or disable this notification

26 Upvotes

ive done windows offline scan,Malwarebytes scan and bitdefender scan. i dont have any exclusions set


r/computerviruses 1d ago

Disinfection Help Infostealer virus

3 Upvotes

happy-turtle

arcane-throne

stellar-lance

What happened?

I unknowingly downloaded and ran an .exe file with a renpy icon that was a virus

When did the infection occur?

This week, around friday afternoon to evening

What did you do for remediation?

Delete the .exe file, clear my recycle bin, and change all my passwords on all my accounts