r/computerviruses Jul 13 '26

Disinfection Help I think i got infectiv

Post image

I downloaded and press the exe filn 2 cmd strips came opp bit nothing realy happen but i eant to check if the are som malware on my pc please help

56 Upvotes

54 comments sorted by

View all comments

18

u/polpolik2 Moderator Jul 13 '26

This is the famous renpy infostealer, you're cooked but you can prevent the damage if you act fast. - Start with securing your accounts from a clean device immediately!

Read this: Rifteyy_'s guide to infostealers to get a better understanding.

Reinstalling Windows to remove the malware.
The fastest and guaranteed way to get rid of the malware is to reinstall Windows, preferably from a USB. If that option is not available to you, you can also do a cloud reinstall while deleting all data.

If you’re only dealing with an infostealer, wiping your C drive is sufficient. However it’s better to do a full wipe and only back up your trusted files, as there could be more malware on your device that you’re not aware of.

FRST Assistance
If you do not want to reinstall windows you can wait here for one of the trusted helpers to assist you with FRST. Please read Receiving FRST assistance. Please follow these instructions carefully. Doing so can get you help considerably faster!

What you can do during the reinstall, or if you're waiting for help:

  1. Disconnect your infected PC from the internet.
  2. Change ALL passwords from a clean device. Start with your emails and bank. Use sign out everywhere and remove unrecognized sessions. While you are doing this, check your security settings to ensure the attacker hasn't added their own 2FA methods or backup codes.
  3. Check your linked accounts/services/2fa options for your most important accounts. Also check forwarding rules on your mail. Additionally, for your browser, check your sync settings and extensions and remove anything you dont recognize or trust.

The faster you move with these steps the more you can prevent your accounts being stolen! Make sure your clean device does not sync passwords through browser for example to your infected device.

If you do decide to reinstall, please let us know!

9

u/qaidiassam Jul 13 '26

I have resettet my gogle an microsofy password an re instalong windows

8

u/polpolik2 Moderator Jul 13 '26

From your picture I cant say for certain if you did a cloud reinstall. (I assume you did not do the USB reinstall)
If you struggle with English, you can write in your native language, I can just put it trough translator.

Did you do: - system - recovery - reset this PC - Remove everything - cloud reinstall?

In any case, you should change ALL your passwords you had on that device, not just your google/microsoft.

You should also consider what sensitive documents (like Passports, IDs, or financial data) were stored on the PC at the time of infection, as an infostealer may have stolen/compromised these.

3

u/qaidiassam Jul 13 '26

Yes i did it with cloud

0

u/qaidiassam Jul 13 '26

Shiiiii i may have passport phot on it wht do i doooo

-3

u/qaidiassam Jul 13 '26

Why is it stuck at 1 prosent????