Skip to content

Safety notice. This is a defensive, educational guide for authorized use on your own computer. Every command is read-only. Nothing here claims your device is or is not compromised. If this device belongs to a company or to someone else, involve their IT or security team first.

Jump to a section

Defensive guide - for your own device

Infostealer triage

A calm, step-by-step incident response handbook for Windows users who think their computer may have been exposed to an infostealer. Work through it in order, take your time, and do not delete anything until you have documented it.

01

Contain and stay safe

Your first job is to stop the damage and keep evidence intact. Do not rush to delete or reinstall anything.

  1. Stop using the device for anything sensitive

    Do not log into banking, email, work, or shopping accounts from this computer. Do not enter passwords or credit card numbers on it.
  2. Disconnect it from the network

    Turn off Wi-Fi and Ethernet so the device cannot send or receive anything. The fastest way: open Settings > Network & internet and turn off Wi-Fi, or switch the device to Airplane mode. For a wired connection, unplug the cable.

    You can also use the Wi-Fi icon in the taskbar and choose Disconnect.

  3. Know that disconnecting does not erase evidence

    Turning off the network does not delete anything. Logs, installed programs, and files stay on the disk. Evidence is preserved by leaving the device alone, not by keeping it online.
  4. Switch to a clean device for recovery

    Use a phone or another computer you trust for the account and financial steps later in this guide. Do not reuse the possibly affected device for those.
  5. Do not run random cleanup tools yet

    Hold off on scan-and-delete "cleaners" and on reinstalling Windows. First document what is there (sections 2 through 6), then decide. Deleting too early destroys the evidence you need.

02

Browser extension triage

Infostealers often arrive as browser extensions. Review every extension, record the details, and only remove or disable after documenting.

Open the extension manager for the browser you use:

  1. List every extension

    Go through the list and pick out anything you do not remember installing, anything you did not choose, or anything you have not used.
  2. Record the details before changing anything

    For each unfamiliar extension, write down:
    • the extension name and its ID (the long code)
    • the version number and publisher
    • the permissions it asks for
    • when it was added, if the browser shows it
  3. Watch for permission red flags

    These permissions are a strong reason to be suspicious:
    • "Read and change all your data on all websites"
    • "Access your browsing activity"
    • "Read your emails" or "Manage your downloads"
    • "Access your tabs" or "Capture your screen"
  4. Remove or disable only after documenting

    Once you have recorded the details, remove the suspicious extension (or disable it if you want to keep the record). Keep your notes - you will use them later.

03

Windows AppData persistence

Malware often hides in your user profile folders so it starts again after a reboot. These are safe, read-only places to look.

Your user profile has three hidden data folders. Open them with File Explorer by pasting these paths into the address bar:

Safe places to inspect

  • Startup folder - paste shell:startup into the Run box (Win+R) or File Explorer. Anything here runs when you sign in.
  • Roaming and Local - browse the folders and sort by Date modified. Look for folders with random names (like "x9f2k4") that appeared recently.
  • Startup and run entries - at a high level, these live in the registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and the matching HKLM key. The Sysinternals section below reads these for you safely.

Red flags to look for

  • Folders with random names created in the last few days.
  • Executable files (.exe) sitting in AppData that you did not install - programs normally install to Program Files.
  • Unsigned executables, or files with no publisher or company name.
  • Startup entries that point into AppData instead of Program Files.

04

Safe PowerShell inventory

These commands are read-only. They list what is installed and running so you can record it. None of them delete, change, or download anything.

List installed Chrome extensions (IDs)

List installed Edge extensions (IDs)

List active Firefox add-ons

List startup items (registry run keys and startup folder)

List scheduled tasks

List services with their executable paths

List recently opened files

Get the SHA-256 hash of a suspicious file (replace the path)

Save a full inventory report to your Desktop (writes one text file)

05

Sysinternals tools

Microsoft's Sysinternals tools show you exactly what is running and starting on your machine. Download them only from Microsoft, verify the signature, and export your results.

Download safely and verify the signature

  1. Download only from Microsoft

    Get the tools from the official Microsoft Sysinternals page (linked in the resources section at the end). Never download "Sysinternals" from a random site, a search ad, or a message someone sent you.
  2. Verify the digital signature

    Right-click the downloaded file, choose Properties > Digital Signatures, and confirm it is signed by Microsoft Corporation and that the signature is valid. If it is not, delete the file and do not run it.
  3. Run as administrator

    Right-click the tool and choose Run as administrator so it can see everything.
  4. Export your results

    Use each tool's File > Save (or Export) to save the output to a text file. Keep these files - they are evidence.

The four tools you need

Verify a file's signature and hash with Sigcheck

06

Malwarebytes scan

Malwarebytes is a widely used scanner for Windows. Use it to update, run a scan, and quarantine anything it finds - then save the report.

  1. Update first

    Open Malwarebytes and let it update its detection definitions. Check Settings > General or the dashboard for the latest update, or restart the app so it downloads the newest definitions.
  2. Run a threat scan

    Choose Scanner and run a Threat Scan. For a deeper look, run a Custom Scan and select the drives and folders you want checked. A full scan takes longer but covers more.
  3. Quarantine rather than delete

    When Malwarebytes finds something, choose Quarantine. Quarantine isolates the file so it cannot run, but keeps it so you can restore it if it was a false positive. Only use Delete if you are certain.
  4. Save the report

    After the scan, export or save the report (usually under the scan results or a report/export button). Keep the report file - it is evidence for the next step.
  5. Run one scanner at a time

    Do not run Malwarebytes at the same time as another antivirus or anti-malware scan. Run them one after another, not together, so they do not interfere.

07

Evidence and escalation

Write down what you saw and when. Keep proof in a form a professional can use, and know when to call one in.

Preserve the evidence

  • Timestamps - note the date and time you first noticed a problem and when you did each step. Write them down as you go.
  • Screenshots - use Win + Shift + S to capture extension lists, Autoruns output, scan results, and suspicious files. Save them to a folder.
  • Hashes - record the SHA-256 hash of each suspicious file (see the PowerShell section). A hash is a fingerprint that stays the same even if you move or rename the file.
  • Reports - keep the Malwarebytes report, the Sysinternals exports, and the PowerShell inventory text file.
  • Store copies off-device - copy the reports and screenshots to a USB drive or another trusted device so they survive a reinstall.

When to bring in a professional

  • You manage this device for a business, or it holds other people's data.
  • You cannot tell what happened or what was accessed.
  • You have already lost money, or the amount at risk is large.
  • You need a trusted rebuild of the system and want it done right.
  • You simply do not feel comfortable doing this yourself.

08

Account and financial recovery

Do these from a clean device (your phone or another computer), not the possibly affected one. Move in order and do not skip the card step.

  1. Freeze your cards first

    Call the number on the back of each card (or use the bank's official app) and ask to freeze or block the card. Do this before anything else - it stops further charges immediately. Use only the number on the card or the official app, never a number from a search result or a message.
  2. Change passwords from a clean device

    On a device you trust, change the password for your email first, then banking, shopping, social, and work accounts. Use a strong, unique password for each.
  3. Revoke sessions and tokens

    For each important account, sign out of all other sessions and revoke any app or device tokens. Most services have a "sign out everywhere" or "manage devices" option in security settings.
  4. Turn on multi-factor authentication (MFA)

    Enable MFA on every important account, especially email and banking. Prefer an authenticator app or hardware key over SMS where possible.
  5. Contact banks and platforms

    Tell your bank and card issuer about the possible exposure, dispute any charges you did not make, and report compromised accounts to the platforms involved.
  6. Monitor your credit

    Check your credit reports and watch for new accounts opened in your name. Consider a credit freeze or fraud alert with the major credit bureaus.
  7. Notify relevant contacts

    If your email or messaging account was used to send phishing or scams, let the people who received those messages know to ignore them.

09

Reset and reinstall

Wiping and reinstalling Windows is a last resort. Do it only after you have collected evidence and recovered your accounts, because a reset destroys everything on the device.

Backup cautions

  • Back up only files you trust: documents, photos, and other data you created. Do not copy unknown executables or your whole profile.
  • Scan anything you plan to restore with Malwarebytes before copying it back.
  • Keep the backup on a separate, trusted device, not on the machine you are resetting.

Reset or reinstall overview

  • Reset this PC - go to Settings > System > Recovery > Reset this PC and choose Remove everything. This reinstalls Windows and clears your files and apps.
  • Reinstall from a Microsoft-created USB - for a cleaner result, create a Windows installation USB using Microsoft's official tool, then boot from it and choose a clean install. Wipe the drive during setup.
  • After reset - change your passwords again, re-enable MFA, and install only software you trust from official sources.

10

Checklist

Work through this in order. Check each item as you complete it. The last item is deliberately last.

0 / 19in progress

11

Decision tree

Use this to decide how urgently to act. The steps are the same either way - the difference is how fast you escalate and whether you plan a reset.

12

Glossary

Plain-language definitions of the terms used in this guide.

13

Official resources

Use only official sources for downloads and help. These are the direct links.