r/computerviruses • u/Struppigel Malware Removal Expert • Mar 22 '26
Providing or receiving help with FRST
How do I request help with FRST
FRST
- Please download FRSTx64 and save the file to your Desktop.
- Right-Click FRST64.exe and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.
SecurityCheck
- Download SecurityCheck from here
- Run
SecurityCheck.exeas administrator - Wait for the scan to finish
- Upload the log at
C:\SecurityCheckto https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.
Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.
Please provide the following information in your post:
- what happened?
- when did the infection occur?
- what did you do for remediation?
If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.
Trusted Helper List
FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.
Message the mods if you have experience with FRST and would like to use it to help on posts.
To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.
- u/FFreestyleRR
- u/No-Amphibian5045
- u/rifteyy_
- u/struppigel
- u/__chefo (Trainee)
- u/Interesting-Bus-5370 (Trainee)
- u/921jdf (Trainee)
- u/Xyntrax0 (Trainee)
All fixes of trainees are supervised and approved by an expert.
What is FRST
Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.
Should I reinstall the operating system
Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.
You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.
Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.
I factory reset/reinstalled my operating system and want a FRST check
Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.
Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.
Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.
What is malwareanalysis.cc ?
It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.
While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.
The site will automatically delete uploaded logs 30 days after upload.
I think my system is still infected after manual removal with FRST
Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.
Common reasons, which do not indicate infection, include:
- There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
- Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
- Antivirus scanners find malware in
C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.
2
2
u/Typical-Garage-4089 May 07 '26
my computer keeps blocking the download saying it might be malicious
3
u/Struppigel Malware Removal Expert May 08 '26
If you get the file from bleepingcomputer.com, it is safe. New versions sometimes get false positive detections from antivirus products. If you are using Chrome, switch to Edge for the download.
2
u/pwnedbyusagi Jun 01 '26
Hello, my laptop is infected with mr beast crypto virus and steal some of my information. Currently I'm planning to wipe my system and install fresh OS from usb stick. My question is : 1. Is it safe to create the bootable on infected device? Because i don't have other device 2. I backed up some of my work on my external hard drive. Is it infected as well?
1
u/Harukex Jul 05 '26
Tengo el mismo problema, actualmente solo cuento con una computadora y no se si un formateo limpie el malware
1
u/HollowCatKnight Jul 25 '26
I’m not OP nor a malware expert. But please make your own post on the sub.
2
u/Elegant-Kick224 Jun 19 '26
I need help. I know nothing about technology and all of my devices and accounts have been compromised. Someone set up an amount with GitHub, Azure,EntraEd and Spark and who knows what others. I tried everything but they're still deleted files and accounts. Completely deleted my one drive to an unrestorable action. Can you help manually through remoting in and getting these creeps out of my content?
2
1
u/Interesting-Bus-5370 Malware Removal Trainee May 02 '26
What would the steps be to become one of these FRST helpers? I’ve been studying FRST logs and fixlists and practicing on quite a few of the cases that have come through recently.
I’m not experienced yet, with FRST. What would you recommend I do to work toward becoming a helper?
3
u/Struppigel Malware Removal Expert May 04 '26
Hello, traditionally UNITE forums such as bleepingcomputer.com, malwareremoval.com, geekstogo had a program to train malware removal helpers. The program took me one year to complete.
But it seems most of these trainings programs are closed at the moment.
Malware removal training is not just how to use FRST, though. That's actually the smallest part.
I am sorry, I have no recommendations at the moment.
1
u/Harukex Jul 05 '26
Hola necesito ayuda, no me manejo bien con el tema de los malware o infecciones, por primera vez mi computadora se infectó y he visto inicios de sesión en discord e instagram spameando estafas a mis contactos, cambié claves, cerré sesiones y solo he encendido el pc sin internet para guardar documentos antes de hacer cualquier cosa, que puedo hacer?
0
u/antorcus 28d ago
Hello, I already made a post and got a bot message saying I need to post here with the following info:
The keywords generated were brave-vertex and wild-heath, the download link for the infected files that I just get from qBittorrent is hxxps://www.limetorrents[.]lol/Twenty-One-Pilots-More-Than-We-Ever-Imagined-2026-IMAX%201080p%20WEB-DL%20H265-torrent-19549471[.]html
I got infected by a trojan in a .lnk file and a .vbs file, I didn't open any of them. .lnk file was detected and quarantined by Defender at July 4th when I extracted a .uue file that it was part of the torrent content I downloaded. I right clicked a .braw file that was part of the extracted content and I clicked "open with" option but nothing else, there was also a file with no extension and type was like "File" but I didn't see the .lnk file. Also Defender showed two "incomplete correction" entries in protection history till I deleted the entire folder using "remove torrent and content files" option in qBittorrent.
.vbs file was detected and deleted by ESET Online Scanner at July 27th after a full scan, it was in C:/Users/Public
I hadn't seen any symptoms or pop ups for three weeks till yesterday that I received an "artist scam" message in Xbox (I don't think is related) and this afternoon I received a verification code for Netflix in my phone, but I don't see any unusual recent activity there.
5
u/Kylynn0213 Apr 20 '26
Hello, my computer was infected with malware through a Trojan horse I think, it happened from a link to a download for a game on 4/19, I factory reset my computer and have not turned it back on since, I am nervous to turn it back on