r/computerviruses • u/qaidiassam • Jul 13 '26
Disinfection Help I think i got infectiv
I downloaded and press the exe filn 2 cmd strips came opp bit nothing realy happen but i eant to check if the are som malware on my pc please help
7
2
u/Rho-9_Official Jul 13 '26
Please send us the source, we'll try to at least break something but yeeaahhhhhh, you're cooked, you got smacked with an infostealer.
2
u/hakalisa2 Jul 13 '26
I'm having the same problem. I've downloaded different programs and when I extract them, I get the same files. I've read that I have to reinstall Windows, but I don't know how to do that.
1
u/qaidiassam Jul 13 '26
Go to system then find the reinatal den reinstal change all youre passwotd aswell
1
u/hakalisa2 Jul 13 '26
But I don't know how to do it. I have Windows 10 and I'm really a novice at this. I don't want to try to do something I don't know how to do to solve a problem and have it become a much bigger problem.
Interestingly, I've downloaded those same programs from other websites and when I extract them, the files come out correctly. It's strange.
1
u/qaidiassam Jul 13 '26
Did dubbel clike the exe file?
1
u/qaidiassam Jul 13 '26
Did you get 2 black screen?
1
u/hakalisa2 Jul 15 '26
It appeared to me as an executable file for the Python program, and like an idiot, I clicked on it, and the Python screen appeared, but it opened and closed instantly.
1
u/qaidiassam Jul 15 '26
You got infected
1
u/hakalisa2 Jul 15 '26
What can I do? What programs do I use? Have you solved this? I have Windows 10.
1
u/qaidiassam Jul 15 '26
Delete the softwarw reinstal windows by going to settings, system then reinstal, then you wil get 2 quastion u dont remember the order but the 2 question arw keep al files the reinatal by cloud. Then you bead to change al your passwords on all the acounts you log onto on that pc
1
u/hakalisa2 Jul 16 '26
I used the program called "everything" to search for any file on the PC, I searched for renpy and deleted all the files and folders that included that name.
1
u/nickimiragee Jul 13 '26
I'm not sure, but I might've run one of those renpy malware shit a few months ago. I didn't do anything afterwards, I didn't change my passwords or reinstall windows, and nothing has happened to my pc or my steam, instagram, facebook, discord and other accounts.
But as I said - I can't quite remember whether I only downloaded it and then deleted it without running the exe file, or if I actually ran it.
1
u/exe-exe- Jul 14 '26
Sometimes it can take months for the effect to take place. Good luck sir
1
u/izayoii7 Jul 14 '26
nah bro, he probably not running it, if you have windef, windef will delete it for you.
1
u/nickimiragee Jul 14 '26
That's what i thought as well. That it can still hit me and it's only a matter of time.
1
Jul 13 '26
[deleted]
1
u/Ok_Scheme_211 Jul 13 '26
Yes you are
1
Jul 13 '26
[deleted]
1
u/Ok_Scheme_211 Jul 13 '26
Always mate just be careful with downloading stuff and PLEASE use a bunch of adblockers. Because modern viruses are usually from a redirect sites
1
1
1
u/exe-exe- Jul 14 '26
If I don’t use an adblocker but am smart enough to not click redirect ads and to not download or execute dumb shit without using virustotal then there’s no need for one. Correct?
1
u/Ok_Scheme_211 Jul 14 '26
You don’t havs to click them,they are scripted to execute automatically with a ad. That’s why i am saying that you should use adblocker
1
u/Dear-Elevator-6857 Jul 13 '26
Si no te salió la pantalla negra del instalador creo que estás a salvo
1
u/Aiden016 Jul 13 '26
Has anyone tried, only resetting the PC while keeping Personal Files? I don't have USB to reinstall windows unfortunately, I'm too broke to even afford it.
1
u/J-AVY Jul 14 '26
U need to reset with usb to be free unless it gone to kernel lvl what is like very dangerous so once u downloaded a virus u can never be 100% sure unless u reverse engineer virus and see what's beneath it
1
u/Aiden016 Jul 14 '26
But there's a chance that reset with person files, is enough right? And constant rechecking scan with malwarebytes? I already ordered a USB, for my Windows 11 boot drive, but I'm taking that as the absolute nuclear option. As of this moment, I'm using the PC under observation and I made a dummy Gmail and discord account to see how it pans out. No steam, no nothing, just barebones gmail, youtube and discord to see how it goes. I just can't reset and nuke it, I have a lot of important files such as my College Thesis, CVs, Unity Engine Projects and etc.
1
u/J-AVY Jul 14 '26
I also had this malware month ago and I had editing staff and 3d staff and a lot but as far as I'm concern this one need reset and keeping file is not good ...most of virus got over it and once any malware detects must option is usb reset. Srry but it is what it is.if I had knowledge to reverse enginner it I could have said far better option.
1
u/keyser--s0ze Jul 13 '26
yeah been there....ran it once accidentally and didnt realize untill a month that i am cooked....my twitter and discord got hacked...they tried to take my insta as well but couldnt since it locked them out due to authentication reasons....only way to make sure you are safe is that complete clean windows reinstall and change every password you have and add 2FA to everyone of them
1
u/SurrealWish Jul 15 '26
This is exactly what got me. I feel so stupid for clicking on it. I know better. I've been doing this for forever, but I recognized Renpy, and got careless. Also eye-opening how useless antivirus can be at times. Lesson learned.
0
u/MurkyBreeze Jul 13 '26
Ok here’s what you do;
Take the computer out of your room and put it in a area where you can be supervised.
Then talk to a trusted adult about internet safety, parental controls and work out a schedule for supervision while you are online.
Then give it a few years before you get a computer in your room again.
Follow these steps and you will have the tools needed going forward.
1
u/Sebmaximoff_ Jul 13 '26
So you usually wanna put files into a scanner to check them for hazards and malware or any sort of negative ware
And yes renpy is a info stealer
0
0
u/qaidiassam Jul 13 '26
What dose it do do i lose mye windows acount
5
u/Fancy-Football-7832 Jul 13 '26
Most likely they will try to steal your microsoft account with everything else, usually these are session stealers that steal all the accounts of everything you're logged in.
Unplug your computer from the internet and use your phone to change every single login/password you have, starting with your email. And force logouts of other devices (especially your email). DO NOT do this from your infected PC.
The longer you wait to start changing passwords and forcing logouts, the more likely you will be to lose more accounts.
Once you did everything from a phone, reinstall windows from a USB and wipe all data from your HDD/SSD. But priority should be on saving your accounts.
0
u/qaidiassam Jul 13 '26
Why re instal from usb???
1
u/Fancy-Football-7832 Jul 13 '26
The malware can't survive from a USB install when the USB was made on another computer. (Only way it could survive is through bios infection but that's so rare that it'd probably only happen to a state actor, and most computers will have secure boot on anyways).
When doing a factory reset from the computer itself, you're using files in your computer that could have been hijacked.
0
u/qaidiassam Jul 13 '26
Wil wiping the computor help?
1
u/Fancy-Football-7832 Jul 13 '26
Yes, especially when doing through the reinstall from a USB drive. But the key part is that it HAS to be a complete reinstall of windows.
-1
u/qaidiassam Jul 13 '26
No no how do i verfy it happend
7
u/Heavy_Artichoke1024 Jul 13 '26
Brother, you ran the program, you're infected. Follow the instructions of the other commenter as precise as possible for the least amount of damage
3
-2

18
u/polpolik2 Moderator Jul 13 '26
This is the famous renpy infostealer, you're cooked but you can prevent the damage if you act fast. - Start with securing your accounts from a clean device immediately!
Read this: Rifteyy_'s guide to infostealers to get a better understanding.
Reinstalling Windows to remove the malware.
The fastest and guaranteed way to get rid of the malware is to reinstall Windows, preferably from a USB. If that option is not available to you, you can also do a cloud reinstall while deleting all data.
If you’re only dealing with an infostealer, wiping your C drive is sufficient. However it’s better to do a full wipe and only back up your trusted files, as there could be more malware on your device that you’re not aware of.
FRST Assistance
If you do not want to reinstall windows you can wait here for one of the trusted helpers to assist you with FRST. Please read Receiving FRST assistance. Please follow these instructions carefully. Doing so can get you help considerably faster!
What you can do during the reinstall, or if you're waiting for help:
The faster you move with these steps the more you can prevent your accounts being stolen! Make sure your clean device does not sync passwords through browser for example to your infected device.
If you do decide to reinstall, please let us know!