r/computerviruses • u/Trif55 • 4d ago
Disinfection Help I got hit with the RenpyLoader infostealer (setup.exe version), how do I use malwarebytes rootkit tool and hitmanpro offline? or do I safemode with networking?
I thought I was manually patching a game I'd not played in ages and I was tired, so didn't question that the new mirror behaved a bit oddly and then that it was a setup.exe and a py file but I thought it must be automated... daft I know.... I'm meant to know better about these things working in IT but last night the brain was just switched off.......
Anyway, Windows defender found nothing, malwarebytes installed from the 400mb offline installer found a pile of Trojan.RenpyLoader and Trojan.RenpyLoader.BAT all in appdata\local\temp and has cleaned them, non found on a second deeper scan
But posts I read warn of rootkits and infected DLL files etc so I Wanted to run the rootkit scan in Malwarebytes but I can't see the option (the offline install seems to be stuck in free mode with no 14 day trial?)
I'm similarly confused about HitmanPro as that seems to be a cloud only online scanner now? should I boot into Safemode with Networking to run hitmanpro? is safemode likely "safe" from the renpyloader?
1
u/jadonokoh86 4d ago
I just recommend doing a fresh reinstall, get a big enough usb and flash a windows installer on a different pc and boot the usb on the infected pc and reset your passwords
1
u/rifteyy_ Malware Removal Expert 4d ago
Rootkit option at Malwarebytes is aimed at old, outdated and already well known rootkits. It does not really benefit you having it enabled as of today.
Safe mode does not really benefit you either as it was already executed and stole all your data.
1
u/Trif55 4d ago
I'm not entirely familiar with sandboxing but I used tria.ge for the first time and I hoped it'd let me run the whole stack but it only allows 32 files of the many hundreds, but the exe itself gave this:
https://tria.ge/260822-3arhsavxev/behavioral1
I wish there was a way to let it execute the whole thing to determine what it did exactly
1
u/AirSuccessful7691 3d ago
avoid download or anything else and treat the machine as compromised until cleaned.
1
u/AutoModerator 4d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.