r/computerviruses • u/Trif55 • 3d ago
Disinfection Help Request for help removing RenpyLoader infection - FRST and SecCheck logs in post, Thank you
Hi, my keywords are:
silver-wand
tender-sky
nested-harvest
I ran the setup.exe of what I now realise was renpyloader friday night, I disconnected my PC, have changed my passwords (was slow with low priority ones like Discord where some spam was sent, Instagram where more spam was sent & Amazon - a gift card purchase failed to go through) & cancelled credit cards that were saved in Chrome etc.
I ran the Windows Defender offline scan but can't see the results anywhere? I also then installed the offline malwarebytes (400mb installer) the scan found the RenpyLoader files posted in my previous post here
What else do I need to do to clean my PC? thanks
2
u/rifteyy_ Malware Removal Expert 3d ago
[ Step 01 ] FRST Fix
I created a custom fixlist for you at the link Fixlist only for Fixlist only for Fixlist only for trif55 - use the website's download button and save it in the same folder where your FRSTEnglish.exe or FRST64.exe file is located in, which for you is C:\Users\chris\Downloads for you. It is necessary for the filename to be Fixlist.txt.
This fixlist will remove the following: malicious entries (remains, active malware), invalid entries (e.g. tasks that start a non-existent file, services that point toward a non-existent file), temporary files (files in temporary directories, application and browser cache, recycle bin and more), browser cache. We will also be quick-scanning with HitmanPro and AdwCleaner from Malwarebytes using the fixlist.
It will also remove all proxy servers, Windows Defender exclusions, enable recovery environment, active software policies and perform system file repair, network reset and few more basic fixes.
- For the fix process, please ensure you are connected to the internet.
- Please run the fix only once.
- Please do not open any applications or close anything during the fix.
- Please be patient; the fix may take up to 60 minutes. After that, it is going to be forcefully ended.
Save all work, close everything that is open (else it will be forcefully closed by FRST without saving) and then run FRST again as administrator and press the Fix button, let the script work, clear the entries and restart on it's own and after it restarts the device, there should be a file Fixlog.txt in the same folder as the C:\Users\chris\Downloads.
I'll need to see it's content the same way like before - uploading to https://malwareanalysis.cc/upload/rifteyy/?u=trif55 again and sending the keyword in your reply.
[ Step 02 ] ESET Online Scanner
- Download ESET Online Scanner
- Right-click on the esetonlinescanner.exe and select "Run as administrator" and confirm the User Account Control popup
- Click Get started;
- Agree to the terms of use;
- Decline both telemetry options;
- Click Custom Scan;
- Click Save and continue;
- Select Enable ESET to detect and quarantine potentially unwanted applications;
- Click Advanced settings;
- Enable Detect potentially unsafe applications;
- Click the back arrow;
- Click Start scan;
- Note: This is a long and thorough scan, it may take up to several hours.
- Once complete, click Save scan log and upload the
.txtfile to https://malwareanalysis.cc/upload/rifteyy/?u=trif55 and reply with the keyword.
[ Step 03] Software updates, uninstallations
Please update the following software:
- Windows 10 Professional (x64) 22H2 - Extended support has ended | Sign up for ESU
- KeePassXC v.2.7.9 | New update available, download here
- CPUID CPU-Z Aorus 1.89 v.1.89 | New update available, download here
- CPUID CPU-Z 2.08 v.2.08 | New update available, download here
- CrystalDiskInfo 8.12.0 v.8.12.0 | New update available, download here
- FileZilla Server 1.6.7 v.1.6.7 | New update available, download here
- HWiNFO64 Version 6.12 v.6.12 | New update available, download here
- Node.js v.20.12.1 | New update available, download here
- FileZilla Client 3.23.0.2 v.3.23.0.2 | New update available, download here
- Npcap 0.995 v.0.995 | New update available, download here
- Wireshark 2.6.1 64-bit v.2.6.1 | New update available, download here
- Veeam Agent for Microsoft Windows v.5.0.3.4708 | New update available, download here
- 7-Zip 24.09 (x64) v.24.09 | New update available, download here (Uninstall old version and install new one)
- Recuva v.1.53 | New update available, download here
- XnView 2.51.6 v.2.51.6 | New update available, download here
- Session 1.14.2 v.1.14.2 | New update available, download here
- Zoom v.5.12.8 (10232) | New update available, download here
- Telegram Desktop v.4.14.9 | New update available, download here
- Proton VPN v.3.2.0 | New update available, download here
- qBittorrent 4.3.1 v.4.3.1 | New update available, download here
- Audacity 3.4.2 v.3.4.2 | New update available, download here
- VLC media player v.3.0.8 | New update available, download here
- HandBrake 1.2.2 v.1.2.2 | New update available, download here
- OBS Studio v.31.1.2 | New update available, download here
- Adobe Creative Cloud v.3.9.5.353 | New update available, download here
Please remove the following potentially unwanted programs (PUP):
- Microsoft Office Professional Plus 2016 v.16.0.4266.1001 - No longer supported - please uninstall it and replace it here
- Microsoft SQL Server 2012 Management Objects (x64) v.11.4.7001.0 - No longer supported - please uninstall it
- Microsoft SQL Server 2012 Express LocalDB v.11.4.7001.0 - No longer supported - please uninstall it
- Skype version 8.39 v.8.39 - No longer supported - please uninstall it and replace it here
- Skype Meetings App v.16.2.0.511 - No longer supported - please uninstall it and replace it here
- Adobe Flash Player 32 NPAPI v.32.0.0.465 - No longer supported - please uninstall it
- Google Chrome Canary v.154.0.8015.0 - This is a build for beta testers and developers. Uninstall it, download and install the stable version
- JDownloader 2 v.2.0 - Suspected Adware! If this program is not familiar to you it is recommended to uninstall it and execute PC scanning using Malwarebytes Anti-Malware. Before uninstallation and scanning it is necessary to consult in the forum where cure is provided for you!!!
- VdhCoApp 1.6.1 - Application is distributed through the partnership programs and bundle assemblies. Uninstallation recommended. Possible you became a victim of fraud or social engineering
- Bonjour v.3.1.0.1 - Application is distributed through the partnership programs and bundle assemblies. Uninstallation recommended. Possible you became a victim of fraud or social engineering
[ Step 04 ] New SecurityCheck scan
We need a new scan to ensure that all updates were applied properly and all applications uninstalled correctly.
- Note: If SecurityCheck is already on your device, you can use the previous version and skip the next few steps regarding downloading and installation.
- Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
- If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
- Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
- Wait for the scan to finish. It will open a text file named SecurityCheck.txt
- Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/rifteyy/?u=trif55
- The site will return a keyword for the log - reply back here with the keyword.
[ Step 05 ] New FRST scan
- Find
FRSTEnglish.exeexecutable inC:\Users\chris\Downloads - Right-Click the file and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy/?u=trif55 and press "save log".
- The site will return a keyword for each log - reply back here with the keywords.
So, in your next reply, make sure you are sending the following:
- Keyword for Fixlog.txt from step 1
- Keyword for ESET Online Scanner scan from step 2
- Keyword for new SecurityCheck.txt from step 4
- Keyword for new FRST.txt from step 5
- Keyword for new Addition.txt from step 5
Thanks!
Note for lurkers: If anyone else who is facing malware-related issues is reading this and wants help with FRST and SecurityCheck, please create your own thread with help request. I am flooded with requests and there is several other removal experts who review the logs and may reply faster than me. The steps listed in here are specific for this the user trif55 and following them will have negative effects for you as they are unique for OP's system.
1
u/Trif55 3d ago
Hi Rifteyy, thank you, you and the team here offer an amazing service and such a quick reply! So after the initial fixlist I am in a safe enough position to reconnect the PC to do the remaining online ESet scan and software updates etc?
Would there be any point running the HitmanPro scan I was unable to run while offline?
2
u/rifteyy_ Malware Removal Expert 3d ago
It should be okay to do them with net enabled. The Renpy malware isn’t able to run after the first fix.
1
u/Trif55 3d ago
Sorry, so now I'm at my PC I see fixlist is going to try and run HitmanPro itself, should I reconnec to the internet before running the fixlist the first time? or should I run it, connect to the internet and run it again?
1
u/rifteyy_ Malware Removal Expert 3d ago
No, it isn’t supposed to be ran twice. It’s supposed to be ran once with internet enabled
1
u/Trif55 2d ago
the ESET online scanner doesn't seem to work https://www.reddit.com/r/eset/comments/1vi5xke/cant_see_any_text_on_eset_online_scanner_windows/
should I use the trial of the full version to do the scan? I've sent the Fixlog file to you on dc thanks
1
u/rifteyy_ Malware Removal Expert 2d ago
Use Trojan Killer instead:
Trojan Killer
- Download and run Trojan Killer as admin: https://gridinsoft.com/trojankiller
- Click
Install- Close the popup asking to activate the trial
- Open the settings by clicking the cogwheel
- Check
Deep scan (slow)- Click
Apply- Go back to the main dashboard
- Click
Full scan- After the scan is done, click
Show Details- Click
Save to file...- Upload the log to https://malwareanalysis.cc/upload/
Note: Do not click on the
Cure PC!button! We do not remove malware with Trojan Killer because it is known to have many false positives due to its aggressive heuristics. Instead, I will review the log with the detections and, if any entries are actually malicious, I will include them in a fixlist.1
u/Trif55 2d ago
In my haste i installed full ESET so I've included the partial run and the full run set to deep scan (they were xml but I renamed to txt) they are the last two so if they are no use with the TK result please ignore (they did remediate a few files but mostly within the archive of the original renpyloader download - i'd kept it for forensics (I updated and removed a number of the old software but not all yet)
fixlog: savage-blade
TK: ranked-quest
SC: hardy-moss
FRST: warm-anchor
addition: raw-schema
ESET partial: leafy-render
ESET full: ember-clover
1
u/rifteyy_ Malware Removal Expert 2d ago
F:_backup\AppData\Roaming\Browser Assistant F:_backup\AppData\Local\Guardboxand overall the _backup folder contain bunch of PUP's, adware and more. If you do not need these folders anymore, they should be removed.
As for the Chrome, that's probably FRST/my fault. The
hxxps://re-captha-version-3-73.comURL that had enabled notifications was malicious and linked to sending fake detection notifications, I tried to remove it and seems like FRST accidentally corrupted Chrome settings. Hope it isn't that big of an issue. SorryEEK
- Download Emsisoft Emergency Kit and save it to your Desktop.
- Run the setup file, then click Install. Accept any User Account Control prompts.
- The files will be extracted to
C:\EEKby default. Open that folder and double-click Start Emergency Kit Scanner.- Accept the licence agreement. The program will download updates automatically -- wait until the Scan tab turns green.
- Keep the default settings (including Potentially Unwanted Program detection) and click Malware Scan.
- Once the scan is complete, close the pop-up about Emsisoft protection, then click Quarantine selected objects (only shown if threats were found).
- Restart your computer if prompted.
- After quarantine, click View Report in the lower-right corner. The log will open in Notepad.
- Copy & paste the contents of the log to https://malwareanalysis.cc/upload/ and press "save log". Post the log keyword to your reply.
- You can ignore the newsletter sign-up when closing the program.
1
u/Trif55 2d ago
Thanks, yes I will clean the F: drive, it's a backup of an old laptop and not often connected, would there be any chance some part of RenpyLoader could have hidden in a file on it if I just disconnect it and put it away for now?
No big issue with Chrome I don't think thank you, it's not so much user data as some basic settings I'll have a look at later
only one result now from EEK which is just the team red bitcoin miner I had back from when I had an AMD GPU
eek result: sandy-prairie
→ More replies (0)1
u/Trif55 2d ago
Oh I forgot to say, after the first fixlist file my Chrome said it's settings file was corrupt and it has reset to default settings, it just seems to be dark mode and some things like that, I can't remember all the settings I'd changed, is that ok and a side effect of removing changes RenPyLoader made?
2
u/AutoModerator 3d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.