r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

178 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

30 Upvotes

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

How do I request help with FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log.
  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis.
  • Create a post in the subreddit, provide all 3 log keywords there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 5h ago

Disinfection Help Video help for anyone struggling with rebooting their pc

Post image
9 Upvotes

I unfortunately was a victim of an info stealing virus. It got access to a few of my social media accounts hopefully. I hope this video can help anyone struggling with rebooting their computer it’s a really great video with in deep explanation of every step you need to make.

I used to be in denial thinking I didn’t need to reinstall windows on my pc but I HIGHLY recommend reinstalling it after changing all your passwords and backing up your stuff.

Good luck and stay low cortisol twin you got this !!!


r/computerviruses 4h ago

Question Malwarebytes detected some malware files

Post image
6 Upvotes

Hi, i did a deep malwarebytes scan and it detected some files as malware but i have them installed from a long time and i think they are from some cracked games i downloaded a while ago, should i be worried about these ?


r/computerviruses 13h ago

Disinfection Help Guys i need some help

Post image
23 Upvotes

i wanted to update my game and i downloaded the update from a site. fitgirl website but i didn't suspect anything suspicious because i was so clueless. after i tried to install using the 'installer' this came up and black screen pop-ups came up too from time to time.

i quickly installed Malwarebytes into my PC and deep scanned everything. and i quarantined a lot of stuff. did this solve any issues regarding my PC security? I'm scared. please help. the apps said my PC is free from virus which i don't believe at all. something's not right. i think i need to reinstall my windows. is that right?


r/computerviruses 2h ago

Question Found this while cleaning my laptop... is this a virus?

3 Upvotes

r/computerviruses 5h ago

Disinfection Help Need help with how to go about wiping multiple drives.

2 Upvotes

I have a 10 year old laptop which although I am unsure if there is a virus on it, it's way higher than a non zero chance based on the things younger me got up to. The laptop has an SSD and an HDD as well. I want to fully wipe both drives and I'm going to install arch on the laptop. My question is how can I wipe both drives at the same time? I see the option to do one then the other but I am worried that if there is malware on here that it could be on both drives and then move between each other as the drives are getting wiped. Not sure if this a a valid concern but could definitely see it be possible. So am I able to wipe both drives at once? Should I take out the HDD and wipe them separately while they are both not connected? Additionally is there a way to wipe the drive and not have windows reinstall itself? Or do I just do the wipe with the new windows install and then just unallocate the drive after that? Any help would be appreciated thanks :).

Quick side question. I also have an SSD in an external enclosure that I want to wipe. Because it is in the external case when hooked up to the computer it is recognized as the enclosure itself and not the drive so the drive does not show up in WD software. Is the best option in this case just to use diskpart and hit `clean all` on the drive?

When initially looking up how to wipe a drive properly I thought it was going to be fully clear what the best steps are but it seems to be less than the case. Most of the advice I see just says that unallocating the drive is enough but I want the data to be written over as well. I don't need it to be perfect but I would like at least one pass to be done over the drives. Again any help is appreciated, thank you :)


r/computerviruses 2h ago

Disinfection Help Infostealer only pirated discord then stopped after I added more security measures to my accounts. 2 months later no acting back up, am I safe or not?

1 Upvotes

Fell for the play my game scam from a friend that was actually in the programming scene.. dumb I know but I didn’t know anything about those scams

I added double factor authentification and changed every password to 20+ characters passwords with symbols capitalization punctuation etc .. started using Authenticator and made some accounts require face id from my phone (clean device). The hacker only logged onto discord and DM’d only a few people from my friend list before I changed everything with the Mr beast scan. No other account was logged onto, and No more log in attempts after that. I didn’t know what infostealers were so I never reset or reinstalled anything (I don’t have a second computer or any available usbs so I can’t reinstall windows), and there’s been absolutely nothing for two months. Checked if any file was excluded from antivirus scans and nothing, as well as scans coming back negative. Should I still factory reset now?


r/computerviruses 3h ago

Question Microsoft store does not work

1 Upvotes

My brothers Microsoft store doesn’t work, alongside when he presses the windows key to type, it doesn’t work. Also on settings, it doesn’t let him click anything. On certain apps that’s the same case too. He downloaded a file from somewhere and it was a zip file, when the website he gets these things from are usually torrents. He opened the exe and after that, it was an installer, a fake one. It was stuck on 99%, I checked the comments on the website and somebody said “that’s a virus, do not open the exe”. What should he do?


r/computerviruses 15h ago

Disinfection Help My friend got a virus?

Thumbnail gallery
9 Upvotes

Hi so my friend accidentally installed a virus and we went through getting rid of most of it with windows defender doing a lot of the work and malwarebytes to check the rest but theres a program that it keeps flagging. We found its activity in task manager and tracked the file down to the temp folder but every time the laptop boots up the program reappears and malwarebytes blocks whatever connection its trying to make. I covered the address in case it ends up being identifiable towards my friend.


r/computerviruses 8h ago

Question Am I safe after all?

2 Upvotes

I accidentally downloaded an infected renpy and ran the installer, but after a minute or two my antivirus suddenly quarantined the file and I backed out.

I found out about how quickly the virus can steal your info, how it can be nearly impossible to remove, etc. BUT I only just found this out, and the time I ran the exe was weeks before. And in that time I've had NO compromised accounts (obviously I'm going through and changing passwords just to be safe) and I've checked, no weird logins on Steam or elsewhere, no sus password resets, no email forwards, etc.

I've also ran deep scans with both AVG and Malwarebytes that turn up nothing, but here everyone seems to be REALLY cautious about these infostealers and how pernicious they are, did I get absurdly lucky with this?


r/computerviruses 10h ago

Other What The Font EXTENSION IS SHOWING ADS

Post image
2 Upvotes

Lately, I've been constantly seeing widget ads in Chrome. At first, I thought it was a virus, but when I right-clicked and looked at the code, I realized it was inside Chrome itself. So I deleted all the extensions, and the ads went away. For a few days, I checked all the extensions one by one and realized the extension was "what the font". I took the extension's URL and put it in CRX Viewer. And I found this in the code. If you are using "what the font", I recommend deleting it. ((((As pointed out in the comments, I completely missed that this is actually an optional feature disclosed in the extension's description. You don't have to delete it! You can simply disable the sponsored banner in the extension options (chrome://extensions/ -> What the Font Details -> Extension options -> Disable sponsored banner). I'm leaving this post up in case anyone else gets confused by the sudden ads like I did.))))


r/computerviruses 11h ago

Disinfection Help Windows Defender detects LummaC stealer in recycle bin

Post image
1 Upvotes

Hello everyone, tonight at 2am (as seen in the screenshot) windows defender detected a trojan on my computer. Recently I haven't downloaded anything except a replay file from my cs2 game personal data (.dem.bz2 zipped). I unzipped it got .dem file in csgo folder and then put the zipped file and an empty folder associated to that replay in the recycle bin which apparently made defender detect the virus 2 minutes after. I do not know how did that even happen and if this is defender giving a false positive but this type of detection is almost never a false positive. I had a false positive due to some rootcerts and Microsoft's error but this one doesn't look like it. What should I do (I changed all my credentials to important apps and services)?

edit:

I have some questions:

1: Can I know when did Lumma install and with what did I install it? Also, does it include a keylogger?

2: Could it be a false positive?

3: Why did Windows detect it just when I deleted the replay file and does that mean that Lumma came when it was found or it was hiding it self and came before?

4: Why is the detected file in the recycle bin and not somewhere like AppData?


r/computerviruses 1d ago

News The malware arrives as a legal file from a police department email and passes SPF, DKIM, and DMARC.

Post image
28 Upvotes

r/computerviruses 17h ago

File / URL Check I put Logi Device Assistant exe in virustotal and got this

Thumbnail
1 Upvotes

r/computerviruses 23h ago

Disinfection Help Need help to ensure im safe.

2 Upvotes

I downloaded a virus dowloading random shit at internet. They tried to steal some accs y had running on my pc. I changed every pasword of my accs and used the "restore pc" tool in the security Windows tab deleting everything i had in my pc. Is my pc safe now?


r/computerviruses 21h ago

Disinfection Help Unsure if RenPy/MrBeast infostealer is fully gone, would appreciate a look at my FRST logs

1 Upvotes

As everyone and their grandma did, I ran the stupid infostealer / session stealer despite knowing RenPy could in no way be used for an installer, simply because I believed that RenPy couldn't be used for infostealers either! I had some issues with these before, however, I would appreciate an educated look at my FRST logs to make sure I'm clean. Previous malware scans back after when I was affected say I'm fine, however I'm actively running a deep scan which won't be finished in a bit.

Keywords:

arcane-robot

quick-crest


r/computerviruses 1d ago

Disinfection Help Mrbeast scam virus

2 Upvotes

I got hacked by mrbeast virus can someone help me get rid of this virus i sent message on discord to people play on their website my brother called me what are you sending when i login in my discord i was suspended i did FRST scan can someone help me out plz ;<

FRST:

keyword: glassy-hare

Addition

keyword: runic-fox

Both channel is: struppigel

Please just help me


r/computerviruses 1d ago

File / URL Check Housemate virus link

Post image
4 Upvotes

Without opening this, can anyone tell me or find out if this is a virus?


r/computerviruses 1d ago

Question pop up persisted until i signed out of microsoft edge?

1 Upvotes

ok so my laptop caught a virus so i did whatever i could to “delete” the virus using built in window tools like the safe mode and mrt. i ran a scan it said there was no malicious software detected but when i got out of safe mode the weird popups started again but it stopped after i signed out of microsoft edge so my question is is there really no malicious software??? do i have to change all my passwords etc??


r/computerviruses 1d ago

Question Hi everyone,I am severely stressed and haven't slept for over 30 hours because of intense anxiety regarding TLauncher malware rumors. I need a solid, definitive technical answer from experts to help me clear my mind.Here is exactly what I did on my old Windows 7 (32-bit) PC:I uninstalled TLauncher.

Thumbnail
2 Upvotes

r/computerviruses 1d ago

Disinfection Help I got havked help

2 Upvotes

A friend of mine i tought got hacked and I downloaded a thing he can see my computer and he wants monry i need help like rn


r/computerviruses 1d ago

Disinfection Help Ran an infostealer. I've reinstalled Windows, changed passwords, and replaced my card. Did I miss anything?

8 Upvotes

About 3 days ago (July 18), I made a huge mistake. I was trying to download Acrobat and thought I was on 1337x, but I didn't notice I had actually landed on what appeared to be a typo-squatted "1377" site. I downloaded and ran what I thought was Acrobat, but it turned out to be malware, almost certainly an infostealer.

I realized something was wrong about an hour later, disconnected my PC from the internet, and reinstalled Windows 11 from a USB installer.

The next day (July 19), I learned that during the first reinstall I hadn't deleted all of the SSD partitions. Out of caution, I performed another complete Windows reinstall, this time deleting all SSD partitions during setup before installing Windows. I did not format my secondary HDD because it only contained personal files and no applications.

Then on July 20, my Facebook account was hacked. The attacker used my Messenger account to send scam/phishing messages to my most recent contacts. That was the first clear indication that my credentials or session had been compromised.

After discovering that, I:

  • Changed my Facebook password.
  • Changed my Google password.
  • Signed out of active sessions where possible.
  • Reinstalled my applications from scratch.
  • Checked my Microsoft account and other account login history.
  • Blocked and requested a replacement for the one debit/credit card that had been saved in my browser as a precaution.

My biggest concern now is what the infostealer may have exfiltrated before I disconnected the PC. I know these malware families can steal browser passwords, session cookies, autofill data, and saved payment cards.

At this point:

  • Facebook and Google passwords have been changed.
  • Sessions have been revoked.
  • Windows has been reinstalled twice (the second time after deleting all SSD partitions).
  • My saved payment card has been blocked and is being replaced.
  • I haven't seen any unauthorized banking transactions or compromises on other accounts besides the Messenger incident.

Based on these recovery steps, is there anything important I've missed? If you've dealt with an infostealer before, I'd appreciate any advice on additional steps or anything else I should monitor.

Edit: I forgot to mention a few additional recovery steps I've already completed:

  • Changed the passwords for every account that was saved in my Chrome Password Manager, not just Facebook and Google.
  • Enabled 2FA on all of my important accounts wherever possible.
  • Switched to Bitwarden as my password manager going forward.

r/computerviruses 1d ago

Question Could this be caused by a virus?

Post image
0 Upvotes

r/computerviruses 1d ago

Disinfection Help Post Ren’Py removal issues

5 Upvotes

I was infected by a fake Ren’py loader around 2 days ago, this was in the form of a pirated game with the well known ‘setup’ file that has an anime girl as the profile picture… Unlike others, i never got a fake loading bar; i was simply met with the very pleasant feeling of watching your cmd open and close instantly after opening a suspicious file from shady sources🙂I had deleted the folder (nowhere near enough) and just ignored it since it was late at night and i couldnt be bothered. Approximately 7 hours later, my discord account flooded all of my friends/servers with the infamous mr beast crypto scam (i was watching this happen live and i found it quite amusing) and i simply deleted all of the messages sent and changed my password(on my phone not pc). After this, i ran multiple full scans on malware bytes; from which i had 35 detections which had all stemmed from the single file i had ran…I then ran a windows security full scan, checked exclusions, ran an offline one, ran ANOTHER full one (i know this likely doesnt do anything im just an extremely paranoid person). I didnt really think much of it after the multiple scans said i was clean; i was too lazy to fully reset my pc as i have no usb large enough to back up important files and i would have to pay for sufficient cloud space. Since then, cmd will pop up for a split second before disappearing again. One time i managed to catch a glimpse of what cmd said and it was something to do with network (i assume either its due to the new usb wifi adapter i recently obtained OR it could be a file from the virus which broadcasts my information to a C2 server but due to malwarebytes removing the malicious files it has no way to send anything, hence the ‘error’ message that greets me about every 5 minutes. Fast forward to today, i received a notification that someone had tried to log into my Riot Games (thankfully i have 2fa). I have now been taking more action frantically reading other people’s experiences to see what extra steps i can take. First i changed my school email’s password to avoid any potentially awkward situations, then i changed my 2 main gmail’s passwords as well as turning on 2FA using an authenticator app. I havent bothered changing any of the more trivial passwords yet i figured i’d just do that when i wake up as i was rudely awoken by an omen in my dream related to the riot games login (very strange i know). Can anyone give me steps to verify that the cmd popup is/isnt related? And/or any further things i may have to do

TLDR: Got virus, Virus compromised discord, Removed virus, Weirdly frequent cmd popup, Another account almost compromised, Paranoid of cmd popup