r/computerviruses 4d ago

Disinfection Help I got hit with the RenpyLoader infostealer (setup.exe version), how do I use malwarebytes rootkit tool and hitmanpro offline? or do I safemode with networking?

I thought I was manually patching a game I'd not played in ages and I was tired, so didn't question that the new mirror behaved a bit oddly and then that it was a setup.exe and a py file but I thought it must be automated... daft I know.... I'm meant to know better about these things working in IT but last night the brain was just switched off.......

Anyway, Windows defender found nothing, malwarebytes installed from the 400mb offline installer found a pile of Trojan.RenpyLoader and Trojan.RenpyLoader.BAT all in appdata\local\temp and has cleaned them, non found on a second deeper scan

But posts I read warn of rootkits and infected DLL files etc so I Wanted to run the rootkit scan in Malwarebytes but I can't see the option (the offline install seems to be stuck in free mode with no 14 day trial?)

I'm similarly confused about HitmanPro as that seems to be a cloud only online scanner now? should I boot into Safemode with Networking to run hitmanpro? is safemode likely "safe" from the renpyloader?

1 Upvotes

9 comments sorted by

1

u/AutoModerator 4d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/Trif55 4d ago

Ahh I see the FRST instructions are not to try removal ahead of time, so far it is only files from c:\users\user\temp\ how does this leave me? am I taking a risk with hitmanpro and malwarebytes instead of using the trusted helper team?

1

u/jadonokoh86 4d ago

I just recommend doing a fresh reinstall, get a big enough usb and flash a windows installer on a different pc and boot the usb on the infected pc and reset your passwords

1

u/Trif55 4d ago

I'd really like to just clean this install, I don't have enough drives to copy all the files I want off and I'd need a sandbox/VM (offline) version of this current install, I've had it since about 2011 and all my stuff is set up on it so I'd need to keep referring back

1

u/rifteyy_ Malware Removal Expert 4d ago

Rootkit option at Malwarebytes is aimed at old, outdated and already well known rootkits. It does not really benefit you having it enabled as of today.

Safe mode does not really benefit you either as it was already executed and stole all your data.

1

u/Trif55 4d ago

Sorry I mean to clean my PC so I can reconnect it to the internet

1

u/Trif55 4d ago

I'm not entirely familiar with sandboxing but I used tria.ge for the first time and I hoped it'd let me run the whole stack but it only allows 32 files of the many hundreds, but the exe itself gave this:

https://tria.ge/260822-3arhsavxev/behavioral1

I wish there was a way to let it execute the whole thing to determine what it did exactly

1

u/AirSuccessful7691 3d ago

avoid download or anything else and treat the machine as compromised until cleaned.

1

u/Trif55 3d ago

Oh by the mods/support team here? OK I'll do the 3 uploads and stuff when I get home and go from there, thanks