Need help getting rid of an info stealer / session stealer


Ruiwenation

New member
Local time
11:50 PM
Posts
1
OS
Windows 11
Hello! So recently, I downloaded a sketchy software thinking it was fine, as after a week or two nothing had happened. Fast forward more than half a month later, I get an email letting me know that one of my accounts was hacked. I've since got it back, but I've been really anxious these past few days wanting to get rid of the info stealer, and would like to get some advice on what else I can do on my pc to get rid of any remnant of the info stealer. So far I've done these things:
  • Change all my passwords and enable 2FA where I can (Passwords which I just made up and placed safely so I remember them, so they cannot be past ones. Also have enabled passkeys)
  • I've cleared all browser cache (Since I the malware was targeted towards a specific game, and hence only got info from the browser)
  • Downloaded Malwarebytes and conducted multiple scans, and windows defender offline scan
  • Looked in task scheduler and autorun to find suspicious generic name tasks. I deleted them in the appdata folders
Additionally: After the scans, there were lots of viruses found, and deleted. However, even after the scan saying all clean, there was still a trojan loader that was trying to load something which malwarebytes stopped every day, so the antivirus missed some deep malware. They were in the appdata Microsoft folder with names like "Vault, Defender" and had dll files. However, after looking at the files and deleting more scheduled tasks like "update" and "update browser", I still cannot rest easy knowing it might still be on my computer.

My thoughts so far is that since I downloaded the software for a specific game, it would have stolen the data off my browser. Could it also have stolen other things on my pc? I don't think its ransomware.

I know I can reset my pc, however, I have so many things on my pc that I think I cant back it up, lots of offline things and photos. I do not have an external drive, or online storage.

I would really appreciate some help on how to do the most to get rid of the info stealer without resetting my pc, any good scanners that can help me find the root of the malware? I just want to be very sure. Any help is greatly appreciated. I can send any logs or screenshots needed.
 
Windows Build/Version
Windows 11

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
PC/Desktop
From Google
When a Trojan keeps regenerating in the AppData folder (under names mimicking legitimate tools like "Vault Defender" or "Edge Defender"), it means a persistence mechanism is actively running in memory or a hidden script is re-downloading it every time it's deleted.
Because Malwarebytes can't easily stop this loop while the threat is actively running, you need a precise combo to break the cycle remotely.

Step 1: Kill the Active Malicious Processes (Rkill)
Before running another scan, you must terminate the hidden background processes keeping the Trojan alive.
1. Download Rkill via BleepingComputer. (This is a free tool designed to kill known malware processes without deleting any files).
2. Run rkill.exe.
3. Crucial: Do not reboot the computer after running Rkill, or the Trojan will just start up again. Leave the PC exactly as it is.
Step 2: Remove the Startup Triggers (Autoruns)
Trojans in AppData usually trigger via hidden Registry entries, scheduled tasks, or startup links.
1. Download Autoruns for Windows from Microsoft Sysinternals.
2. Extract the ZIP file, right-click Autoruns64.exe, and select Run as Administrator.
3. In the search/filter bar at the top, type Vault (or whatever specific name was found in AppData).
4. Look through the results under the Everything or Logon tabs. If you see an entry matching that file path in AppData, uncheck the box next to it to disable it, then right-click and select Delete
Step 3: Run an Aggressive Second-Opinion Scan
Since Malwarebytes is hitting a wall with this specific payload, switch to a specialized aggressive engine.
Download the Norton Power Eraser (NPE) or the Kaspersky Virus Removal Tool (KVRT). Both are completely free, portable, and specialize in deeply embedded Trojans.

Step 4: Run a Microsoft Defender Offline Scan

If the Trojan is still stubborn, hand the task over to Windows before it even boots up.
1. Go to Settings > Update & Security > Windows Security > Virus & threat protection.
2. Click on Scan options.
3. Select Microsoft Defender Offline scan and click Scan now.
4. The PC will restart into a secure, pre-boot state and clean out the AppData folder before the Trojan has a chance to execute code.
 

My Computer My Computer

At a glance

Windows 11AMD Ryzen 8700G64 GBOnboard
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Generic
CPU
AMD Ryzen 8700G
Motherboard
Gigabyte B650 UD AC
Memory
64 GB
Graphics Card(s)
Onboard
Sound Card
Onboard
Monitor(s) Displays
Del U2723QE
Screen Resolution
3840 x 2160
Hard Drives
Corsiar MP600 1TB
PSU
Silverstone 750 GOLD
Case
Silverstone FARA 513
Back
Top Bottom