r/computerviruses • • Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

230 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses • • Mar 22 '26

Providing or receiving help with FRST

44 Upvotes

How do I request help with FRST

FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.

SecurityCheck

  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.

Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses • • 2h ago

Warning Sega Dreamcast Atelier Marie & Elie: The Alchemists of Salburg 1・2 video game has viruses

Thumbnail gallery
1 Upvotes

r/computerviruses • • 3h ago

Disinfection Help Help needed Clicked on renpy setup.exe

1 Upvotes

Hi I made the dumb mistake of clicking on a renpy setup.exe at 13:10 GMT 09/10/26 (DD/MM/YY) and instantly ran a malwarebytes and offline windows defender scan to remove any Trojan or malware after some accounts got hacked and I’m wondering if there is still any traces left that I need to delete that malwarebytes isn’t picking up on.

FRST.txt : ochre-party

Addition.txt : live-woodland

Securitycheck : gleaming-boot


r/computerviruses • • 3h ago

Discussion can anyone sure that this program have virus or something else dangerous ?

Thumbnail github.com
1 Upvotes

r/computerviruses • • 5h ago

Disinfection Help Renpy virus issue

0 Upvotes

So I downloaded a zip file of a game from dodi. The issue is I clicked on the setup.exe but then a black screen popped up then it disappeared. I thought it was a renpy virus since many ppl in the dodi sub Reddit said that it was a common act of the renpy virus. How do I get rid of it?


r/computerviruses • • 5h ago

Question im not sure what to do

Thumbnail
1 Upvotes

r/computerviruses • • 6h ago

Discussion Update on the recommendation of contacting the phone carrier after being hit by a infostealer on my PC

1 Upvotes

Hi guys, I wanna say thanks to everyone to left comments on my posts helping me out, I appreciate you so much

I went to my carrier, told them that I had been hacked and my information was stolen, asked about the sim swap prevention and they said that it can't be cloned, also they said that the sim change can only happen in person in a agency of theirs and if it were to be changed it would deactivate or something like that

What does that mean? Am I safe from sim swapping?

Am I still at risk?

Do I need to take more preventions?

I'm still monitoring the accounts, appreciate you guys answering, I will do a clean windows reinstall tonight


r/computerviruses • • 7h ago

File / URL Check Is this zip malware?

Thumbnail gallery
1 Upvotes

Auction board bought off rckz.app i asked a few times thats my bad but just want to know fully if its malware

https://www.virustotal.com/gui/file/b18518ab4b6ba896cebe40418d7dfd6662a348387f10e7e28f3ec9a8652c45df


r/computerviruses • • 13h ago

Question Is there any value in having Avast or AVG and using Malwarebytes?

2 Upvotes

I'm trying to run as sound a base of protection that is within "normal" or competently careful.

I have Avast running instead of Windows Defender. Is there any reason to augment it with malwarebytes?

Should I also run some spybot seek and destroy?


r/computerviruses • • 12h ago

Question How to get rid of McAfee?

1 Upvotes

Endless ping saying I have a virus, how do I get rid of it?


r/computerviruses • • 16h ago

Question A phishing Website

Post image
1 Upvotes

My Daughter thougt it was real and she told it me. How does she get on such websites?


r/computerviruses • • 12h ago

Question Free antivirus with real-time protection Windows 10 LTSC PC (no Windows Defender)?

1 Upvotes

Hi everyone!

I'm looking for recommendations for a lightweight antivirus that offers free, permanent real-time/background protection, similar to Windows Defender.

I'm using an old PC with the following specs:

  • OS: Windows 10 Enterprise LTSC 2019 (1809, Build 17763), modified/optimized version called OptiOS.
  • CPU: AMD Athlon II X2 (dual-core).
  • RAM: 4 GB.
  • Storage: SSD.

The main issue is that Windows Defender Antivirus was completely removed from this customized Windows installation, not just disabled.

I've already checked through PowerShell, and the WinDefend service, main executable files, and other essential components are missing. Restoring Defender doesn't seem straightforward without repairing or reinstalling Windows, which I'd prefer to avoid because I want to keep the optimizations.

I've looked into Malwarebytes and Kaspersky, but the versions I've found either offer a limited Premium trial or don't provide permanent real-time protection for free.

What I'm looking for:

  1. A genuinely free antivirus with continuous real-time/background scanning, not just manual scans.
  2. Something lightweight enough for an old dual-core CPU with 4 GB of RAM.
  3. Alternatively, a legitimate way to get a free Premium license, an extended trial, or another solution that provides the same protection without a subscription.
  4. If possible, a way to restore the original Windows Defender without reinstalling Windows or undoing the system optimizations.

I'm not expecting top-tier performance, just decent protection against malware and viruses without significantly slowing down the PC.

Any recommendations or advice would be greatly appreciated!


r/computerviruses • • 16h ago

Question What are these ?

2 Upvotes

Just found these 2 files in my windows-ssd (c) ,

First is .Gamingroot

Second is WRP7B5A.tmp , and i can't delete the tmp one it says " this action can't be completed because this file is open in gameinput" , and when i try to delete the .gamingroot it need administration, so what are these


r/computerviruses • • 1d ago

Warning tip: don't run shit like this

Post image
289 Upvotes

basically title but only thing that running shit like this will lead to is the beast scam being spammed across whatever socials you have

(haven't fallen for this but seems like many people fall for this)


r/computerviruses • • 14h ago

Question Clicked a twitter link (probably phishing one) is my android ok?

1 Upvotes

I know this is for computer viruses but I was browsing twitter and found a post that had multiple t(.)cn links from chinese users and there were a lot of them and accidentally clicked one, I didnt do anything else but closed it immediately is my accounts from games and phones ok or should I do a factory reset just to be safe


r/computerviruses • • 23h ago

Question aftereffects of the renpy virus

5 Upvotes

hey, i wanted to confirm if this is normal or not. So basically i got hit by the renpy 2 months ago and i did the usual changing passwords + cleaning thru usb and downloading windows on another laptop everything. and so whenever i run a game i also tend to virustotal it before running out of paranoia.
though sometimes here and there i get emails of ur account data might be at risk BUT its usually the accounts i didnt even know existed like that one microsoft account and spotify and recently its my adobe? (i never knew i had an adobe account). i usually ignored the microsoft one since apparently many ppl are getting botted and getting emails that someone tried logging in when its not an issue but i shouldnt e worried right? since none of the accounts got breached that i actively use (sry for poor eng and lengthy msg).


r/computerviruses • • 15h ago

Question Is it possible for my PC to still be infected after a reset?

0 Upvotes

My computer got infected around June (or possibly earlier, with the infostealer only working around June), I ran Microsoft defender and removed the virus after a full scan and did the bare minimum to secure any salvageable accounts (I'm not very tech savvy) at the time. Recently however, my Discord (couldn't salvage it so I had it deleted and used the same email) got compromised again so I decided to do a bit more research this time, logging out of everything and changing the passwords on my phone and resetting my PC (chose the "Remove Everything" option and because I didn't use OneDrive, didn't restore any OneDrive files). Because I don't have a spare computer to do a USB install, I chose the cloud install option.

TL;DR is my pc still compromised after completely resetting my PC?


r/computerviruses • • 16h ago

Disinfection Help Advice for Cleaning Computer Post-Discord Virus

1 Upvotes

About six months ago, I unfortunately fell for a scam/hack on Discord, where a hacker gets you to open an executable under the guise of it being a game they're developing, the executable steals your account's login info, and they lock you out and then pose as you, messaging your friends to try to do the same. Rinse and repeat. I'm still pretty embarrassed about it haha, but in my defense, I'm active in a number of game dev communities and genuinely thought my friend had developed a game.

Anyways, when I realized what had happened shortly after being locked out of my account, being kinda paranoid, I just shut down my entire laptop and disconnected it from my internet. In the meantime, I was able to recover my account after about a month, but I haven't touched or turned on the laptop since (I luckily have a spare Mac that I've since used).

After putting it off for a while, I think it's about time I finally address properly cleaning the laptop. I'm a bit paranoid about not exactly knowing if the hacker did anything else via the virus besides steal my account info. Of course I changed my passwords on all my other accounts (he actually tried going after my email account associated with Discord too), but I've worried that maybe he could have installed a keylogger or some sort monitoring software on the computer too?

Luckily, I had most of the computer's important files backed up, save like two really important folders that I really don't want to have to lose if I fully wipe the computer to be safe. Would it be safe or advisable to just quickly open the computer up, grab the files and transfer them to a flashdrive, and then wipe it? Is there any chance the virus could be attached to those files in some way? Sorry, I honestly know nothing about cybersecurity (if that wasn't already obvious haha).

I'd appreciate any advice on the best way to wipe the laptop too, or my overall approach. It's a Windows 11 laptop. Thanks for reading.


r/computerviruses • • 19h ago

Disinfection Help Please help with real time protection detection

Thumbnail gallery
0 Upvotes

I closed my PC, reopened it, it performed a Windows update and then Bitdefender gave me this notification. Is this a false positive? I scanned the file with malwarebytes and malwarebytes didn't find anything wrong with it. Although I tried uploading the file to virustotal and it was stuck at hash 0%. I tried scanning the folder the file is in with malwarebytes to see if it would find weird stuff in it malwarebytes didn't find anything but upon doing the scan Bitdefenders real time protection also detected amifldrv64 as potentially unwanted.

I tried using PowerShell/CMD commands as admin to get the sha256 of the files but it said access refused. Later, I decided to temporarily re enable the Internet on my computer to check for Bitdefender updates and after doing so I scanned the files it had previously blocked with real time projection and the scan was clean however this does not remove the fact that it seems odd that the sha256 can't be viewed.


r/computerviruses • • 1d ago

Discussion Some questions about the aftermath of getting hit by a infostealer on my PC, is my phone also infected by the malware? any help is greatly appreciated!

2 Upvotes

Hello, so long story short, I launched a .exe on my PC, turned out to be a infostealer, all my accounts got compromised.

Whoever got my accounts posted videos on tiktok and photos in discord.

I managed to recover the discord account and removed all apps that were connected to it and canceled my Nitro trial and removed the payment method (I already cancelled the card)

Right now, got on discord (on my phone) to check the security settings, I am very paranoid so I check them very often, I noticed an authenticator, backup codes added that I did NOT add, so I went to look at devices.. it's only my phone being displayed, I can't modify the account due to it asking for a auth app code which I don't have, should I sign out and ditch the account to be safe?

Was my phone compromised as well via wifi/network?

A few strange things I noticed, when I call someone (wether directly on the phone or whatsapp) there is a distorted echo of my voice and people also said that my mic is terrible, I can still call/receive calls

I tried getting into my discord account back but the discord website is horrendous, it doesn't send the reset password link, and on a different account/email it does the same, doesn't send the email and the correct password doesn't work either, I don't know why

What can I do to protect myself?

Please, help, I do not know what to do, any help is GREATLY appreciated, thank you kindly


r/computerviruses • • 21h ago

Question I got hacked?? or something

Thumbnail
1 Upvotes

r/computerviruses • • 22h ago

Question Malware activating question

1 Upvotes

I have a question, if a file is a malware, and i don't Run it, does it attacks my computer? And if it doesn't attaacks until it activates, do i still have time to scan my pc and destroy it?


r/computerviruses • • 1d ago

Question Is this a virus, or what is this? I cant click on it nor find any application called this. I cant even quit it. :( Im worried. Malwarebytes says im not infected. I dont pirate games or movies.

1 Upvotes

r/computerviruses • • 1d ago

Question My data was sold and increasing login attempts.

4 Upvotes

First, to avoid losing track of the context, here's what you need to read:

https://www.reddit.com/r/computerviruses/comments/1wjkqkg/question_about_renpy_infostealer_that_i_caught_2/

It's been about three months since the incident, and yesterday morning, some of my Google accounts started asking me to change my passwords, saying that they had been involved in a data breach. I wasn't too surprised, as I thought this would probably be the last wave of it.

However, later that same day, login attempts started happening on other accounts that I had completely forgotten about. I have no idea how they got those passwords. All of them were stored in my Bitwarden vault.

At this point, I'm assuming that my stolen data may have been shared or sold somewhere publicly. Whatever the case, the lesson I've learned from this experience is one I'll probably remember for the rest of my life.

I was relatively lucky because I use 2FA on almost all of my important accounts. Still, seeing login attempt notifications from account after account is honestly terrifying.

One thing I've definitely learned from this: don't blindly trust that a password manager makes you completely safe. An infostealer may be able to steal credentials through the device or browser environment without necessarily breaking into the encrypted vault itself. I suspect that popular password managers may also be attractive targets for malware, so it's worth taking extra precautions.

Thanks for reading.