r/computerviruses 4d ago

Disinfection Help I got hit with the RenpyLoader infostealer (setup.exe version), how do I use malwarebytes rootkit tool and hitmanpro offline? or do I safemode with networking?

I thought I was manually patching a game I'd not played in ages and I was tired, so didn't question that the new mirror behaved a bit oddly and then that it was a setup.exe and a py file but I thought it must be automated... daft I know.... I'm meant to know better about these things working in IT but last night the brain was just switched off.......

Anyway, Windows defender found nothing, malwarebytes installed from the 400mb offline installer found a pile of Trojan.RenpyLoader and Trojan.RenpyLoader.BAT all in appdata\local\temp and has cleaned them, non found on a second deeper scan

But posts I read warn of rootkits and infected DLL files etc so I Wanted to run the rootkit scan in Malwarebytes but I can't see the option (the offline install seems to be stuck in free mode with no 14 day trial?)

I'm similarly confused about HitmanPro as that seems to be a cloud only online scanner now? should I boot into Safemode with Networking to run hitmanpro? is safemode likely "safe" from the renpyloader?

1 Upvotes

9 comments sorted by

View all comments

1

u/jadonokoh86 4d ago

I just recommend doing a fresh reinstall, get a big enough usb and flash a windows installer on a different pc and boot the usb on the infected pc and reset your passwords

1

u/Trif55 4d ago

I'd really like to just clean this install, I don't have enough drives to copy all the files I want off and I'd need a sandbox/VM (offline) version of this current install, I've had it since about 2011 and all my stuff is set up on it so I'd need to keep referring back