Credential-stealing trojans
Delivered by cracked software, fake installers and malicious ads. Scrapes saved passwords and session cookies within minutes, then usually deletes itself.
Virus & Spyware Removal
Most infections we see were already cleaned once by a scanner that removed the payload and left the persistence behind. We look at scheduled tasks, registry run keys, services, WMI subscriptions and browser policy before we call anything fixed. And when a rebuild is genuinely the safer answer, we tell you that instead of billing hours.
Overview
Antivirus finds the file. It frequently misses the four mechanisms that put the file back.
When a machine gets reinfected a day after being cleaned, it was almost never reinfected. Something on the box survived. We start every cleanup by enumerating persistence rather than by running another scanner. That means walking registry Run and RunOnce keys, scheduled tasks (especially ones with innocuous Microsoft-sounding names), Windows services with unsigned binaries, WMI event subscriptions, startup folders, Winlogon shell and userinit values, DLL search-order hijacks sitting next to legitimate executables, and browser policy keys such as Chrome's forced-extension list, which quietly reinstalls a hijacker every time the browser launches.
A large share of what walks in the door is adware, a browser hijack or a scam, not malware in the classic sense. Search redirects and injected ads usually trace to a malicious extension, a modified browser shortcut with a URL appended to the target, a proxy or DNS override, or a policy key. Endless popups claiming your PC is infected, complete with a phone number and a siren noise, are a tech support scam page abusing full-screen mode. Nothing is infected until you call the number and let them in.
Browser notification spam deserves special mention because it fools experienced users. A site asks for permission to send notifications, someone clicks allow, and now fake virus warnings arrive on the desktop even when the browser is closed. There is no malware to remove. The fix is revoking the notification permission, and no scanner will ever find it.
We clean when the infection is well understood and its scope is limited: adware, a hijacked browser, a bundled toolbar, a single known trojan caught early by EDR before it executed fully. We rebuild when we find anything that touched the boot path or the credential store, bootkits and UEFI-level persistence, rootkits hiding processes from the OS, or an infostealer that had free run of the machine.
That last category is the important one. Modern commodity malware is mostly credential theft. It scrapes saved browser passwords, session cookies, VPN profiles, saved RDP credentials, crypto wallets and Windows Credential Manager entries, then exfiltrates them within minutes of landing. Once that has happened the machine can be perfectly clean and you still have a problem, because the attacker has your logins and, worse, valid session tokens that can bypass MFA. Cleaning the machine does not un-steal them.
So our rule is blunt. If there is credible evidence of credential theft, or if the persistence mechanism is not fully explained, we recommend a flat rebuild from known-good media. Reimaging a workstation takes a few hours. Untangling a compromised Microsoft 365 tenant takes days.
Whichever path we take, the credential work is not optional. From a known-clean device, change passwords for email, banking, payroll, remote access and anything reused, do not do this from the infected machine. Then revoke active sessions in Microsoft 365 or Google Workspace so stolen cookies stop working, re-register MFA methods, and check the mailbox for the tell that gets missed constantly: inbox rules quietly forwarding or deleting messages, and unfamiliar OAuth app grants. Our free breach check and dark web scan are a useful sanity pass afterward.
Timing matters more than most people realize. The window between an infostealer landing and the stolen data being used is often hours, not days, and the machine frequently looks and behaves completely normally throughout. That is why we treat “it seems fine now” as an observation rather than an all-clear, and why the first instruction we give over the phone is to disconnect the machine from the network while leaving it powered on. Pulling the network cable stops exfiltration and lateral movement immediately; pulling the power destroys the volatile evidence that tells us what ran and what it reached.
For businesses there is a further step home users can skip: containment and scope. One infected endpoint on a domain is a question, not an answer. We isolate it, check whether the same credentials were used elsewhere, look for lateral movement, and review whether this was a precursor. Infostealer and loader infections are frequently the reconnaissance stage that precedes a ransomware event days or weeks later, which is why our ransomware protection work treats a single minor infection as a serious signal rather than a nuisance.
If we cannot explain how it got persistence, we do not tell you it is clean.Orca IT, Gilbert AZ
What We See Most
Threat reports are abstract. This is what we handle week to week in the East Valley.
Delivered by cracked software, fake installers and malicious ads. Scrapes saved passwords and session cookies within minutes, then usually deletes itself.
A page tells you to press Windows and R, then paste a verification command. It is a PowerShell downloader, and the user runs it with their own hands.
Modified shortcuts, forced extensions, proxy or DNS overrides and policy keys that reinstate the hijacker on every launch.
Full-screen scare pages with a support number. Nothing is infected yet. The damage begins when someone calls and grants remote access.
Shipped alongside free utilities and driver updaters. Not dramatic, but it degrades performance and often carries a data collection component.
Quiet footholds whose job is to sell access on. Treating one of these as a minor cleanup is how businesses end up encrypted a month later.
Our Process
Off the network, still powered on where forensics matter. On a business network we also check whether anything else is showing the same indicators.
We enumerate persistence, review recent process and network activity, and identify what the malware family is known to take before we touch anything.
Targeted removal where the scope is clear and limited. A clean rebuild from trusted media where credentials or the boot path were in play.
Password resets from a clean device, session revocation, MFA re-registration, mailbox rule review, then EDR and patching so it does not happen again.
Disconnect from the network before you do anything else, then call us.
Business vs Home
A home PC needs the machine fixed. A business needs the blast radius understood.
Fast turnaround, data preserved, browsers reset, banking and email passwords changed, and a straight conversation about how it arrived so it does not repeat.
Isolation first, then scope: which accounts logged into that machine, what network shares it touched, what credentials were cached on it.
Cached domain credentials mean one workstation can expose far more than itself. We check for lateral movement and force resets where warranted.
Stolen session cookies can bypass MFA outright. We revoke sessions, audit sign-in logs, inspect inbox rules and review OAuth grants.
For medical, dental, legal and financial clients an infection may carry notification obligations. We document what we found and when, so you can advise counsel properly.
EDR with behavioral detection, removing local admin rights, application control and patching close the doors that let it in the first time.
That is persistence, not reinfection. Bring it to us in Gilbert or let us look remotely.
Scanners are good at deleting known files and much weaker at reversing configuration. A removed payload can leave behind a scheduled task, a policy key, a modified browser shortcut or a proxy setting that keeps the symptoms alive. Those are found by inspection, not by scanning again.
Not always. Adware, hijacks and a single trojan caught early are usually cleanable. We recommend a rebuild when there is credible evidence of credential theft or the persistence mechanism cannot be fully explained, because at that point you can no longer trust the machine.
No. Even on a rebuild we copy your data off first, scan it separately, and restore documents, photos and profile data to the fresh install. Programs get reinstalled properly rather than copied, which is also a good opportunity to leave the junk behind.
Email first, then banking, payroll, remote access and anything you reused. Do it from a different, known-clean device, not the infected one. If the machine was compromised for any length of time, treat every password saved in the browser as public.
MFA is essential but it is not absolute. Modern infostealers take session cookies, which represent an already-authenticated session and can be replayed without a second factor. That is why we revoke active sessions rather than only changing the password.
Almost always a scam page, not an infection. Close the browser with Task Manager, do not call the number, and clear the site's notification permission. If someone did call and granted remote access, treat it as a full compromise and get the machine looked at properly.
No. Mac adware and browser hijacking are common, and macOS infostealers targeting keychain and browser data are an active and growing problem. The persistence lives in launch agents, configuration profiles and login items instead of the registry.
Usually the same business day. Remote cleanup can often start within the hour if the machine is still usable, and we cover clients in all 50 states. For East Valley businesses we can be onsite, and drop-off is available in Gilbert.
Talk to Your Pod
Unplug the network cable, leave it powered on, and get in touch. We can usually look the same business day.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.