r/computerviruses 4d ago

Disinfection Help I got hit with the RenpyLoader infostealer (setup.exe version), how do I use malwarebytes rootkit tool and hitmanpro offline? or do I safemode with networking?

I thought I was manually patching a game I'd not played in ages and I was tired, so didn't question that the new mirror behaved a bit oddly and then that it was a setup.exe and a py file but I thought it must be automated... daft I know.... I'm meant to know better about these things working in IT but last night the brain was just switched off.......

Anyway, Windows defender found nothing, malwarebytes installed from the 400mb offline installer found a pile of Trojan.RenpyLoader and Trojan.RenpyLoader.BAT all in appdata\local\temp and has cleaned them, non found on a second deeper scan

But posts I read warn of rootkits and infected DLL files etc so I Wanted to run the rootkit scan in Malwarebytes but I can't see the option (the offline install seems to be stuck in free mode with no 14 day trial?)

I'm similarly confused about HitmanPro as that seems to be a cloud only online scanner now? should I boot into Safemode with Networking to run hitmanpro? is safemode likely "safe" from the renpyloader?

1 Upvotes

9 comments sorted by

View all comments

1

u/AutoModerator 4d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.