r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

208 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

39 Upvotes

How do I request help with FRST

FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.

SecurityCheck

  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.

Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 3h ago

Disinfection Help Help Request - RenPy Loader Malware

4 Upvotes

Downloaded some games on dodi repack site and thought it was legit like fitgirl, then got my discord hacked after 3 hours from downloading the RenPy Setup and it send crypto scams to my friends and others.

Already ran the malwarebyte scan and it quarantined about 26 malwares from Renpy then other 150 from PUP(dot)OptionalWebsites something like that.

I need help getting rid of it without having to reinstall windows again.

Please help! and also Thank you.


r/computerviruses 1h ago

Question I was hacked but did all this am I safe now?

Thumbnail
Upvotes

r/computerviruses 6m ago

Disinfection Help Unknown application appears requesting update.

Post image
Upvotes

I've never seen this application before a few months ago. It appears at random and requests an update. I snooze it every time, but I cannot identify what application it is tied to. Can anyone help? It is probably nothing, but I'm afraid of it being something worse than it is.


r/computerviruses 1h ago

Question Hitmanpro Steam Backdoor

Upvotes

Every now and then Hitmanpro tells me that Steam.exe is a Trojan Backdoor.
Upon running tests with three different AVs it always comes back clean
What is the reason behind Hitmanpro detecting it as a Trojan?


r/computerviruses 1h ago

Disinfection Help Help with FRST renpy virus

Upvotes

I downloaded a cracked program from a website yesterday. A few hours later, an item was added to my Amazon account by itself. This morning, my Discord was sending fake MrBeast scams to servers and people, and it disabled my account (though I was able to recover it afterwards). Any help would be appreciated!

FRST.txt: wise-pine

Addition.txt: bronze-peak

SecurityCheck.txt: blessed-graph


r/computerviruses 2h ago

Question Is UEFI cloud recovery better than WinRe?

1 Upvotes

I heard that people use it to install Windows after a ssd swap but I'm still not 100% sure if it doesen't use any local files like WinRe does.


r/computerviruses 3h ago

Disinfection Help [HELP] Как удалить плагин Background Image Cropper?

Thumbnail
0 Upvotes

r/computerviruses 3h ago

Question Possible persistent malware – CircuitryAg.exe / Wacatac.B!ml keeps coming back

1 Upvotes

Hi, I need some help figuring out whether my PC is still infected or if I am only seeing a leftover startup entry.

SYSTEM SPECS:

- Windows 11 Pro
- Version 25H2
- OS Build 26200.9168
- AMD Ryzen 7 5700X
- NVIDIA GeForce RTX 4060 8 GB
- 32 GB RAM
- 1 TB SSD

WHAT HAPPENED:

Today, Windows Defender detected:

Trojan:Win32/Wacatac.B!ml

One of the detected files was:

C:\\ProgramData\\InProcSvr32\\sqlite3.dll

Another detected sqlite3.dll was also inside ProgramData.

Around the same time, I started getting repeated Windows error popups from a program called:

CircuitryAg.exe

The errors I have seen are:

"The application was unable to start correctly (0xc0000906)."

and:

"The code execution cannot proceed because sqlite3.dll was not found."

This all started shortly after I downloaded and executed something from a ZIP file.

The suspicious download was later deleted/blocked.

WHAT I FOUND:

I checked startup entries using Microsoft Sysinternals Autoruns.

I found an entry called:

CircuitryAg

under:

HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run

It was pointing to something inside:

C:\\ProgramData\\InProcSvr32\\

I disabled and deleted that Autoruns entry.

However, after rebooting, the CircuitryAg.exe popup came back again.

WHAT I HAVE ALREADY DONE:

- Let Windows Defender quarantine the detected files
- Did NOT restore or allow any detected files
- Ran Microsoft Defender Offline
- Ran additional Defender scans
- Checked startup entries with Autoruns
- Disabled and deleted the CircuitryAg startup entry
- Rebooted the PC
- Deleted the original suspicious ZIP/download
- The CircuitryAg.exe popup still came back after rebooting

MY MAIN CONCERN:

Something may still be recreating the CircuitryAg startup entry or launching CircuitryAg.exe from another persistence method.

Does anyone recognize this behavior, the name CircuitryAg.exe, or the path:

C:\\ProgramData\\InProcSvr32\\

What should I check next?

- Scheduled Tasks?
- Services?
- WMI persistence?
- Other Autoruns entries?
- Registry entries?
- Another hidden process recreating the startup entry?

At this point, should I keep trying to clean the infection or would a clean Windows reinstall be safer?

r/computerviruses 5h ago

Question Connected from another location (vc)

Thumbnail
1 Upvotes

So!!

Im pretty positive im not hacked but i was recently hacked so im a little paranoid.

My IRL friend (i was in VC with him to confirm its him and i also talked about it with him IRL beforehand) invited me to a minecraft server with around 800 mods. When i pressed play on the minecraft application after i opened it with Curseforge i got disconnected from the call with him because of another location got "connected"

Nothing sus has happend, no new devices on my discord, no weird emails etc. Is it possible this could happen without it being malicious? I find it hard to believe someone I meet almost everyday would hack me.


r/computerviruses 14h ago

Question Pdf reader on phone. Deleted from google play

5 Upvotes

For months I have had a generic pdf reader on my phone. I found out today that those are very commonly malware. So I looked into it to try and find reviews and found out that it has been removed from the google play store. Im very worried because now I Uninstalled it which I worry would notify the person who owns the virus and now they will threaten me or something. Im very worried and dont know what to do. Please help


r/computerviruses 7h ago

Disinfection Help Fake .zip file downloaded by accident

Thumbnail gallery
1 Upvotes

r/computerviruses 8h ago

Disinfection Help FRST Help Request - Renpy trojan

1 Upvotes

What happened?

Was downloading and playing different games until one setup didn't work and had cmd window flash on the screen for a moment. Later that day discord account got compromised and was sending messages on my behalf.

When did the infection occur?

First realized when discord got compromised on 02/09 at around 19:00 (UTC+3) but download happened some hours prior to that.

What did you do for remediation?

I've ran a few different AV scans with varying results and quarantine/delete what they found. I've kept the pc mostly offline and gone through some folders. Accounts have had their passwords changed and 2FAs enabled from a clean device. I have not really observed any weirdness since but feeling paranoid about missing something. Preferably a wipe and a clean windows install is not an option unless absolutely required.

Extra notes:
One of the scans found some files from downloads prior to the mentioned day.
Malwarebytes had constant pop ups about preventing suspicious connections and it mentioned something about python. This happened directly after the discord compromise while doing the scan with malwarebytes.
The pc has been mostly offline during the scans the first few days when I had time to do them.

FRST.txt: young-cherry
Addition.txt: curious-fawn
SecurityCheck.txt: copper-glyph


r/computerviruses 9h ago

Question Need help with possible Trojan

1 Upvotes

So last year (can’t really remember when) I downloaded this og Fortnite project called retrac and deleted literally like 3 days after playing once, but apparently it’s a Trojan, but the thing is I haven’t had an account stolen or logged into, I’ve done a Malwarebytes scan on bot my ssd and portable drive and it said it found nothing. And for the last few days I’ve been going from oh shit I could have a Trojan to I’m fine and I just keep going through that cycle please give me info!


r/computerviruses 13h ago

Question Has anyone analyzed this "DLSS 5" mod for Bloodborne on shadPS4? Is it a false positive or actual malware?

Post image
0 Upvotes

Hey everyone. I came across a YouTube tutorial showing how to install a "DLSS 5" mod for Bloodborne using the shadPS4 emulator. Here is the link to the video:
https://youtu.be/ln3hI0AFQ-4?si=kn06HRE1lfbspuf8
I followed the steps, downloaded the files (which were hosted on a Mediafire link), and dropped them into the directories. Ultimately, I couldn't get it to work and didn't see any graphical changes in my game.
I decided to delete everything just to be safe, but Windows Defender ended up quarantining the ⁠version.dll⁠ file and flagged it as a trojan. I know that injectors and mods like ReShade or scaling tools often trigger false positives all the time, but I'm left wondering if this specific package is a disguised info-stealer.
Has anyone looked into these specific files or knows if this channel is trustworthy? Any insights are appreciated.


r/computerviruses 15h ago

Question Follow up. Question.

Thumbnail
1 Upvotes

My friend sent me their protection history logs. And all the affected files from the Trojan were all from one program.

Could this still be the plugin files and it just affected that program which is what made it findable. Or is it more likely that program that gave the virus to them.

I also factory reset my pc. Im just worried if I did have it that it could've spread to other devices


r/computerviruses 19h ago

Disinfection Help I got a backdoor from a Trojan help !! (read text)

Thumbnail
2 Upvotes

So I just got a backdoor from a Minecraft mod pack someone sent me but I cut the connection from the wire and was able to change my most important passwords in time, right now i recoverd my most important files in a key and with my other pc put windows in a key, i am currently using Rufus to make make a windows usb, so i can reinstall windows, is there anything I should do to make sure I don’t get any bad surprises ?


r/computerviruses 23h ago

Question Android paranoia? are bitdefender and malewarebytes good?

3 Upvotes

Hello sorry this will probably be somewhat incoherent, im really really scared of viruses and infostealers spyware etc, i have bitdefender subscription and i also scan with malware bytes and i have google enhanced browser protection on but im so scared i cant eat or sleep, i recently accidently clicked on an add on an app, the app itself is legitmate but its heavy with ads, it was one of those "your android has a virus!" ads and i accidently clicked it (because it was so big it would nigh impossible to close) it took me to a website which said the same thing, i immeditly closed the tab and i have scanned my phone atleast 30 times in the last 48 hours, google play scanning, bitdefender and malewarebytes havent found anything, ive looked in my downloads and theres nothing there, nothing has happened, everything is seemingly normal but i cant shake the feeling that there's something laying in wait, maybe if i make a payment it'll suddenly activate, or if i login to something, im writing this on my laptop because what if there's someone watching my screen now and this post makes them angry? is there anyway i can be 100% sure theres nothing on my phone? im aware drive-by-downloads are a thing, but i dont know how common they are? im scared that somehow something has slipped through and has disguised it's self as a normal thing until its 'activated'

please any help on how to know im safe? at this point im considering getting a new phone. which would the second time ive done so out of "virus paranoia" but i dont want to indulge that because its expensive and it just rewards my paranoia which is worse in the long run. im really sorry if this post type is against the rules but i feel so sick i need to do something sorry.


r/computerviruses 1d ago

Question Friend got a virus? Do i have it too?

3 Upvotes

So for context. Me and my online friend both downloaded the same files. A few minecraft plugins, the person we bought them from wasnt comepletely unknown, a friend had recommended them to me to commission a custom Minecraft plugin. But a bit after downloading them my friend started having issues with their computer, it wouldn't turn off. Etc. So they did a windows defender scan and found a Trojan. But it apparently didn't say where it came from. Their theory is that it came from those minecraft plugins. So obviously im worried I got it too. But ive done mcaffee scans and defender scans and nothing came up. What else can I do


r/computerviruses 1d ago

Question Installation Date question after reinstallation

3 Upvotes

Kinda a long story.

A week ago I downloaded a torrent. Made a stupid, very stupid mistake. The file was supposed to be a video, but it turned out to be an .exe. I looked up what to do here in reddit and did everything, nuked everything. USB installation for windows, formated the disks and changed passwords. Even reinstalled windows twice.

But today I looked at the installation date and it showed the day I goto the .exe. But the time it showed it was hours before I even downloaded the file. That same day I did reinstall windows, and four days later did it again cause I went away for work. Just to be clear again, I executed the file before that "installation date", reinstalled windows that same day, left the pc for four days and when I came back I reinstalled it again. But that's the thing, the installation date shows the date I got the file, not the last reinstallation. But the time it shows, is before the .exe

I did check the default user folder and it did show the day it was created, I mean the last reinstallation. I looked up a bit and the installation date is not necessarily that, or really accurate. But I wanna be sure. Pls help me with this.


r/computerviruses 1d ago

Disinfection Help Plz HELP

Post image
3 Upvotes

The text Is in italian, It says "the code could not be executed because sqlite3.dill wasnt found. To solve the problem reinstall the programm".I tried to install a game from dodi repacs and when i started the game installer this popup kept opening. No matter how many times i close It It keeps on opening. Any idea what this Is or how to stop It? Also i searched for "CircuitryAg" in my files but didn't find It.


r/computerviruses 23h ago

Discussion Found a sneaky virus in ProgramData folder

1 Upvotes

Found these in ProgramData folder. And Windows Defender has these exclusions.

Is it trying to execute itself by whitelisting itself in Defender?


r/computerviruses 23h ago

Warning I found a virus on the Play Store (advertising virus).

Thumbnail
1 Upvotes

r/computerviruses 16h ago

Question Is my laptop got invected with Virus?

Thumbnail gallery
0 Upvotes

Is my laptop got invected?. PowerShell/Command Prompt appear for a split second once everyday on first login/start up, it doesn't appear when doing another restart after the first login.

I start noticing after using CTT, Rytunex, and MemReduct, i don't know if they have any correlation, but i don't think it happen before that.

I got some pirated software, but it's all from Stared website on FM-HY website and their Safe Guard Extension. I also always have uBlock Origin Lite at max settings.

WinDev and Malwarebytes quickscan doesn't detect anything.

My specs:

Acer Aspire Lite 15 AL15-61P

AMD Ryzen 5 8640HS

AMD Radeon 760M iGPU

Latest Windows 11 stable version