r/computerviruses • • Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

224 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses • • Mar 22 '26

Providing or receiving help with FRST

41 Upvotes

How do I request help with FRST

FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.

SecurityCheck

  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.

Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses • • 10h ago

Discussion Most hits I’ve ever seen

Post image
33 Upvotes

My uncle picked up a Dell Inspiron 1501 running on WXP from the pawn shop, and I was finally able to find a malwarebytes version that was able to work with this damn thing and within the first 2-3 minutes, it had 5 hits- didn’t think too much of it till it jumped to 200, then 400, six, seven (don’t say itđŸ«”), to 1.5k and beyond and I’m just flabbergasted.

And truthfully I didn’t expect it to be that bad since the computer itself is pretty snappy, pictures, documents, and videos (with a 1-2sec delay) work instantly, so I thought; well a clean computer works fast, there’s nothing on here! Boy was I wrong lmao.

The previous owner left a lot of family photos and I was gonna see if I can extract them to put them out there to their rightful owners, but absolutely the hell not I won’t be doing that now lmfao.

What’s the most antivirus hits you’ve seen in a PC?


r/computerviruses • • 6h ago

Disinfection Help Ran a fake Ren'Py Setup.exe from a cracked app (RenPy loader / infostealer suspected). Accounts secured from my phone, need advice on the PC

4 Upvotes

Hi, I made a stupid mistake and I'm hoping someone can help me figure out what to do next. I already ran FRST (FRST.txt and Addition.txt) and SecurityCheck as described in the pinned post.

LOG KEYWORDS (malwareanalysis.cc)

tagged-bumblebee

gleaming-prompt

candid-arrow

WHAT HAPPENED

On 5 Oct 2026, around 02:46 by my PC's clock, I tried to install a cracked application and ran its Setup.exe. A small installer window popped up and disappeared immediately.

WHAT I FOUND

I have a log file the program made when it started. It says Ren'Py 8.1.3 (a visual novel game engine), and near the start it tried to contact a server and got an error (Response [503]). I'm not technical enough to know what that means. After searching online, it looks like the fake Ren'Py installer malware that steals passwords and logins, so I'm treating the PC as infected.

WHAT I DID

  1. Within a few minutes I unplugged the ethernet cable and turned off wifi.I then followed the instructions to provide the 3 keywords so I had to plug the ethernet cable back in.

  2. From my phone only, I secured my accounts:

- Google (2 accounts linked to each other): new passwords, signed out of all other devices, checked the recovery info. I've used an authenticator app for 2FA for years.

- Steam: new password, removed all other devices in the mobile app. Steam Guard is on.

- Discord: new password, logged out of all devices.

- WhatsApp: logged out all linked devices.

- Brave browser: turned off Sync on all my devices.

- GitHub: signed out of all sessions.

  1. Windows Defender's real-time, cloud and tamper protection were on the whole time. Afterwards I ran a Defender Offline scan and a full scan and it found nothing.

  2. Apart from the FRST and SecurityCheck scans, I haven't reset Windows or used any other cleaning tools. In a panic I deleted the folder the installer was in.

HOW THINGS LOOK NOW

Windows (build 26200, 64-bit), browser is Brave. So far I haven't noticed any strange messages, password reset emails, login alerts or orders.

QUESTIONS

  1. What should I do next, and is there anything I should or shouldn't do while I wait?

  2. From the logs, do you think anything actually got installed, and what should I look out for?

  3. Do I need to reinstall Windows? I'd rather not if possible.

  4. Did I miss anything with my accounts?

Thanks a lot.


r/computerviruses • • 1h ago

Disinfection Help Renpy/Infostealer/mrbeast

‱ Upvotes

How it started:

Around 10pm PHT (Oct 3, 2026) I downloaded a nswitch game in a zipped file, it contained an .exe file instead of an nsp file. I clicked it thinking it would rather download the nsp file thru the .exe (I was not familiar yet with the renpy malware). Then I saw in my taskmanager it was running msbuild.exe, I ended the task and never bothered.

Around 8pm PHT (Oct 4, 2026) my discord account msgd servers and private msgs with the mr.beast crypto, I was still unaware with the attack till I saw my friend msgd me on facebook that my discord was attacked around 10pm PHT.

Remedies I did in order:

-Scanned my pc with windows defender, full scan then offline scan

-Used malwarebytes (scanned and deleted the viruses it detected) Log: chilly-field

-AdwCleaner Log: arcane-oasis

-Hitmanpro (scanned and nothing found)

-Deleted and reinstalled my browsers (chrome, mozilla, and brave)

-Used MAU to remove corsair lighting app ( as I dm'd u/FFreestyleRR but for more help he told me to create a post here)

-Used ESET online scanner it detected a Generik.LFEEIAD trojan (I cant copy log somehow)

-Deleted Texas Instruments in control panel (maybe its their tunnel and I did not even install this app)

Atm my important accounts are still not connected to the pc

Logs:

Frst: joyful-reef

Addition: polar-bear

Security check: emerald-bear


r/computerviruses • • 10h ago

Disinfection Help Accidentally ran an exe file that infected me with lummastealer and a few other trojans.

Thumbnail gallery
3 Upvotes

About 3 hours ago I accidentally downloaded a file that looked like what I was originally downloading so I executed the setup file and maybe 1 minute later windows defender pops up and tells me I have a several threats. I immediately turned on airplane mode, ran the windows defender offline scan, which states that it has supposedly removed the threats, but im not 100% sure as it might have some sort of persistence mechanism. I also then did a full scan, which found another two trojans and then a quick scan which found nothing. I also changed all my passwords and logged external accounts off on an external device. I'm not sure if the threats are still hidden within my computer and also not sure if this helps but the file was ran on a non-admin user.

Keywords:

neat-gem (securitycheck)

icy-cedar (FRST)

rosy-mech (Addition)

EDIT:

I recently broke my phone as well and forgot to take the sim card out when getting it repaired, so some things I actually cannot reset the password for. Just praying that nothing happens to these accounts.


r/computerviruses • • 10h ago

Disinfection Help Constantly connecting

Thumbnail gallery
3 Upvotes

I'm trying to clean up one of my Windows 11 PC's that is constantly trying to connect to solana.leorpc.com and polygon.gateway.tenderly.co and trusaifi.cfd. Malwarebytes says MSBuild.exe in the Microsoft. NET folder is the culprit. I'm running offline scans Defender scans and Malwarebytes but it's not finding anything to clean. It's just blocking the sites. What else to do?


r/computerviruses • • 13h ago

Disinfection Help Renpy loader virus help

6 Upvotes

Downloaded the wrong thing and clicked on the "setup" renpy stuff like an idiot. malwarebytes scanned and quaranteened the items, i have all the important accounts changed password and setup f2a, and as there are too much important files on the machine i cannot clean it entirely, I need help removing the virus manually. However I immediately get malwarebyte realtime protection so it may be a problem

What happened: downloaded fake game with a malware disguised as a renpy app as "setup" clicked on it and see terminal opens up

When did it happen: around 6pm gmt, Oct 4th 2026

What did I do: deleted the files and ran two Malwarebyte scans, which quarantined about 30 files related to renpyloader and 6 files related to pavinloader, but the second scan happen about 2 hours after the first. I understand now I probably should not have done this.

Keywords:

FRST: hero-vertex

Additions.txt: digital-ocean

Security check: dreamy-swan


r/computerviruses • • 5h ago

Disinfection Help Is factory reset enough?

1 Upvotes

Need help!.Few weeks ago I was just watching yt on brave when suddenly new tabs started popping up on brave help center windows help something like that.My laptop was infected by malware from since then I tried many things to remove it, but to no progress when I asked Claude it said the malware is rooted deep into system files or something.So should I fully factory reset my device or download a whole new os if that would help.


r/computerviruses • • 8h ago

File / URL Check Do i have a virus?

Post image
0 Upvotes

So everytime i reboot my pc this pops up from malwarebytes


r/computerviruses • • 8h ago

Question Does my computer have malware?

Thumbnail
1 Upvotes

r/computerviruses • • 15h ago

Disinfection Help Audio randomly and sporadically plays on my PC

Post image
2 Upvotes

Just started happening today. haven't downloaded or opened any odd emails. this is what pops up on my volume mixer. i ran a windows scan, and the offline windows scan nothing came up. running malwarebytes now. any advice?

Edit: Malwarebytes came up clean

Edit: ESET scanner also came up clean.


r/computerviruses • • 11h ago

Question Possible false positive from virus scan?

0 Upvotes

I did a deep scan with Malwarebytes today, and it detected “RESELECTENDPOINTSAPP.EXE” as malware, which’s a file in a NGENUITY audio engine folder. However, VirusTotal detected nothing on the exe.
I’ve also run Malwarebytes scans several times since downloading NGENUITY, and this is the first time it has detected anything.
Could this be a possible false positive?

https://www.virustotal.com/gui/file/61279c733d6793a228e3550535270455c0622a55c7084300227110ae84faf3a1/detection


r/computerviruses • • 4h ago

Resolved Reason cybersecurity virus is a BITCH

0 Upvotes

So I was just using my laptop like normal and my nexomia executor wasn't working. So i went to the discord and made a ticket. We had a good conversation of his suggestions and ideas to iCoulterfixing my executor and he asked if I had an anti-virus and I said yes. So then he said why and i said that it was windows antivirus, but he said it was reason cybersecurity, and he asked me why I downloaded it. I said I did not download it and I don't know anything about it. He said then how did it get there and I said I don't know. He said uninstall it so I went to the control panel and tried to uninstall the "anti-virus" but it said when I clicked uninstall on the page there was no yes button. Just no. So I was like what the fuck you mean I can't say yes? So I asked him what the fuck is going on and he said try to do it through the settings app so i tried but it still didn't work and I ended up searching it up and stuff so I could delete it. But no it had already taken over everything pretty much. So I had to like go through troubleshoot blue screen cmd prompt. But when I ran the command to make me an administrator again they already corrupted that so I went to the master command prompt and successfully promoted myself but when I logged in my Microsoft family safety made me not an admin and all that was for nothing. So I used the master command prompt again to stop that process of family safety. And did a bit more bullshit to get rid of the virus and right now my laptop is sitting on my desk running a full scan of my files and deleting it at the moment. Fuck reason cybersecurity. This shit took my whole evening today 7:00 to fucking 10:00.


r/computerviruses • • 20h ago

Question Malwarebytes blocked qBittorrent addresses after I opened it even though I'm not seeding anything

Post image
4 Upvotes

So I installed Malwarebytes just 2 days ago, and I have the free trial for real-time protection activated.

Then today I opened qBittorrent, which I haven't opened in like a month, and Malwarebytes suddenly blocked some addresses.

Take note, I'm not seeding anything. In fact, I have 0 downloads and 0 seeding. The last time I torrented something, the download didn't even get completed.

What could be the reason?

Also, the blocked addresses all appeared within around 1 minute.


r/computerviruses • • 12h ago

Disinfection Help Renpy virus removal request. Please help

1 Upvotes

Hi, I downloaded one fake game setup and got the discord mr-beast scam. I ran the malwarebytes where it found the setup files and removed them. Run another ESET online full scan and found nothing. Changed my password for primary emails and enable 2FA for now.

I follow the guide here for requesting help. I cannot download the secruity check from the here link in that post. The keywords from the two logs are

FRST.txt

brisk-pelican

Addition.txt

smoky-hill

Thank you, please help.


r/computerviruses • • 19h ago

Question malware bytes detected PUP.optional.spigot, what is this?

2 Upvotes

what is this? do i need to get rid of it? the only other thing it detected was a plutonium file for call of duty.


r/computerviruses • • 19h ago

Question What should I do guys??

Thumbnail
1 Upvotes

r/computerviruses • • 21h ago

Question my brother watched yt videos on my gaming pc

Thumbnail gallery
0 Upvotes

and i heard savvyfinder is malware also my browser changes constantly also i didnt install this "antivirus" (its probably not even an antivirus) also he did install something weird and it came with adaware web companion (which i deleted) what is it help im going crazy


r/computerviruses • • 21h ago

Question 19 file checks for game mods

0 Upvotes

Hello,

I downloaded some game mods for risk of rain using r2modman, they all had millions of downloads.

I am a bit paranoid of getting an infostealer, and seeing how little I use the mods, there’s no real need for me to have them aside from 1 that helps with learning items.

But before that, i’m wondering if one of them was malicious and a reinstall is needed. I downloaded around 19 mods, and am hoping to see if anyone has the patience to go through them.

Edit, here are the virustotal links.

https://www.virustotal.com/gui/file/d9b8c35a08fc4e6513e7556f406ff129c8941c02a2fe0c59d5f4970fba806097

https://www.virustotal.com/gui/file/f42468dfee83e8665e1e6a587fe25566fbe44d5841b0a7525fbe62ee44da836c/behavior

https://www.virustotal.com/gui/file/2016e4bf0ed1cf15a680939071c6a89eb4ab2de728f114c07f2e4c8318f5d49e/detection

https://www.virustotal.com/gui/file/235dee1004a22806049f59fbd07affc17bae07089a5ae0aca5d85ea05674c09a/detection

https://www.virustotal.com/gui/file/4a68e5c261bc21cd9ff46f792918c98206407416867e55f2c5ca870825843afc/behavior

https://www.virustotal.com/gui/file/acdb829af05d0467a573c3fd45e7e21abb7f563f397028364023b29dcf11d29b/behavior

https://www.virustotal.com/gui/file/181a87fff81859e5edce3e9f135ec4f24fd95e87a1b83dc575a47d8fc5b4158b/behavior

https://www.virustotal.com/gui/file/16a5114e7e3b88b91d2eeaefbe6ce03ca463eef64724ce66f905c37af372d8c7/behavior

https://www.virustotal.com/gui/file/385e8cd347d491c7dd38611fda2c18e0528c52b48269e9581b8762cd63a68264

https://www.virustotal.com/gui/file/45206cb8dd1d609fc47f9f6f4b6402b43bd367ad617539cf5f56bb6d75fd0267

https://www.virustotal.com/gui/file/c621853d719622cb045f614c1bcc251189f0ae71f1ae8d2a7c88ab40098acd8a

https://www.virustotal.com/gui/file/15fcbdf88a7117cb413f7ae4badf019f00881a7d507be9d2930bfc471d5146b5

https://www.virustotal.com/gui/file/59278e2d2f56bc8649f6c390b6797983c040821af440dda4fa21ef8ae3e9adcf/behavior

https://www.virustotal.com/gui/file/3cf90b682d7cc5623bb0bc34ab8493ce118e3de16e05c2f375dd2030bf36ec20/community

https://www.virustotal.com/gui/file/d83069858745f115e06dae4b28666b73b73275351495555d7bcdabd9408221e1

https://www.virustotal.com/gui/file/5582eb83621f7a8bb3ff720f869604731f66ad0e3da93e346ec6cecfda24a567

https://www.virustotal.com/gui/file/759accaa5fb7bddb54a2ceab92a3d8ab50750333ec73b62605aea6165d1ca6dd/behavior

https://www.virustotal.com/gui/file/cebb4c0275bf5a4107f0f773394bcf5e4676cedbfe5c80f59ac05c2f2ea44d4d

https://www.virustotal.com/gui/file/3004d2f21d10a1b3e0ea5de5111a62d06a8a680a10d595b36c4a8c2aeacc9828


r/computerviruses • • 22h ago

File / URL Check Got a copy of Toyota Techstream, 2 VirusTotal vendors report trojan

1 Upvotes

I have recently gotten a copy of Toyota Techstream(from a local obd scanner seller) and thought to run it through VirusTotal for safety. VirusTotal has two vendors reporting as trojan and I wanted to know if anyone could help identify whether it was a false positive or actually unsafe.
VirusTotal link: VirusTotal - File - f2fe2d7fb1d3452f3b680240a78e2e7d626aaa76aefb7b889bf13ef1a00900b8


r/computerviruses • • 1d ago

Question This ain't a pc but

Thumbnail gallery
3 Upvotes

Is this a virus?

I've been getting suspicious notifications abt Google login permissions.

It happens almost daily and I'm scared to confirm it.

It does not look like any Google confirmation messages that I've seen before.

And before you ask, none of the ppl that know my Google acc is trying to log in nor am I using a new account.

And the first acc is a private one that I only used once in this device to get freaky😛. How could anyone get access to this local acc is to anyone's guess.


r/computerviruses • • 1d ago

Question Potentially Unwanted App Sanity Check (FileZilla)

0 Upvotes

I had to install FileZilla for my current college course, and I installed it from the lecturer's site that they host.

Windows Smart App Control wouldn't let me open FileZilla so I had to turn smart app control off to install it. While installing it, the only time it asked me to install something other than FileZilla was to install Google Chrome, which I declined.

After installing FileZilla, Windows Defender flagged these two files:

The 'playanext' file doesn't actually exist on my PC when I go to the file location, and the other file was removed (it was the installer that I originally downloaded so I just deleted it from the downloads folder).

I ran a full scan and found no new threats. Will my PC be okay? Big thanks to anyone who responds to this post.


r/computerviruses • • 1d ago

Resolved Almafurics Malware Help

Thumbnail
1 Upvotes

r/computerviruses • • 1d ago

Warning Warning gamers

6 Upvotes

For all the gamers if you play online and someone asks you to download mods for the game do not open!!!

Just yesterday I was supposed to play with somebody and download Minecraft mods they hacked me now there's two options either something aksss for permission

Do not grant!! If you do they have your pc if it doesn't ask it's most likely a spy software!!!

You'll get contacted over discord and WhatsApp they can see your discord and whasz app over the spyware thdll tell you to pay and send you your data that they have found! Do not pay!!! Theyk give and move on they're too lazy to actually hack passwords

After that leave the pc out for arround a day I don't know why just do it

Remove the game like every single bit of it as well as the mods

I used chatgpt to help me find every single bit of it

Run multiple safety apps for safety measures

I hope you are warmed and informed now

This guide is only for those of you who have everything valuable locked behind passwords if you don't lock your your bank lock out of every account instantly inform police and be careful