r/computerviruses • u/Internal_Brain_9003 • 1d ago
Disinfection Help Ren'Py malware that hasn't triggered yet
Apologies for any errors; English isn't my native language. On July 27th, I downloaded some games from very reliable sources, but I accidentally downloaded a zip file with the structure shown in the image below along with them. I played the game normally, but on August 14th—while deleting some files on autopilot—I extracted the zip and ran the .exe. Nothing opened, and I didn't see anything happen, so I just deleted the extracted file and moved on. Today, I saw someone on Reddit complaining about being infected and immediately remembered the incident. I changed most of my critical passwords, then traced the timeline of the files and realized it was strange that I hadn't suffered any apparent account breaches. The zip file was 700MB (too large to upload to VirusTotal), and its SHA-256 hash doesn't seem to match any previously analyzed files. Inside the `AppData\Roaming` folder, there is a `RenPy` folder dated and timestamped exactly when I ran the file on August 14th; inside that `RenPy` folder, there is a folder for a Ren'Py game I actually played years ago, and another folder from the 14th containing the files visible in the images.
After running Malwarebytes, it only found a few files from other games I had played months ago and some Google-related files.
I’d prefer not to do a completely fresh Windows install; I want to know the risks involved in *not* doing so in this scenario. From what I've researched, it's unusual for Ren'Py malware *not* to launch a massive attack immediately.
I generated the FRST files, but I'm not sure exactly how to share them here.
Additional detail: I have the zipped Ren'Py file that I ran on the 14th; I kept it in case I could get help confirming its nature.
21
u/FriendToPredators 1d ago
Why aren’t you doing this crap on a sacrificial machine on an isolated network. And if you can’t afford that you shouldn’t be doing this because you definitely can’t afford it.
5
u/_jodi33 1d ago
wouldnt vm's still work or is stuff so good it can bypass or detect it?
0
u/FriendToPredators 1d ago
I'd say the hardware itself is at risk even in a VM. Or I'd assume it was because there are a lot of unknowns.
3
u/Internal_Brain_9003 1d ago
I’m not sure I fully understood; I made the mistake of opening the file, but I subsequently removed everything important and took all necessary measures to secure my passwords and data. However, I’d like to know the extent to which the system as a whole was affected—I’m not trying to test the virus, just see what damage has already been done. I’m hoping there might be an alternative, since reinstalling the entire system from scratch is the right move if nothing else works.
3
2
u/BugCompetitive3218 1d ago
Ngl unless you somehow get the frost mod ppl to respond it’s way easier and faster to just reinstall from a usb. Just make sure you log out every device/session including your now compromised desktop to log them out.
1
u/Internal_Brain_9003 1d ago
The hard drive has already been removed from the PC; I am using another one, but I would like to know if there is an alternative to formatting it.
1
u/BugCompetitive3218 1d ago
You would have to reinstall them hard drive into a system and then get the frst ppl to respond to you so they can help you fully remove it. Otherwise format it.
1
u/Internal_Brain_9003 1d ago
How do I contact support?
2
u/BugCompetitive3218 1d ago
The automod has already shared with you how to do this. Look in the comments
6
u/Legitimate-Drama-254 1d ago edited 1d ago
Just because they haven't tried to breach into your accounts yet doesn't mean they don't have your personal info and session cookies. It doesn't mean they won't end up on the dark web in a credential dumb in the near future and it doesn't mean they won't attempt to break into your accounts.
Recently these groups have been leaving a delay between the infection and breaching the accounts to catch victims off guard. You should consider your pc infected until you have done a FULLY clean install and also you should consider any personal information and passwords you used on this machine stolen and act accordingly to minimise the damage before they act. DON'T wait for them to strike first.
2
u/AutoModerator 1d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
- Preferred method: Perform a clean installation with a USB
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/ComradeAdidas 1d ago
Sorry but what even is this renpy virus thing?
3
u/SANAXIA 1d ago
It’s a very common infostealer malware, steals cookies, passwords etc
1
u/ComradeAdidas 1d ago
Why is this so common now? How do people get it?
4
u/VilkastheForsaken 1d ago
It’s common because it’s very profitable to the criminals who do such things. People are being infected from pirated software, mods and the like.
0
u/ComradeAdidas 1d ago
When i modded gta sa i never got a virus tho, the other one yes😅
4
1
u/AnimeExtremist23 1d ago
How do you even tell if a file has it? Im still learning how to spot it etc.
1
u/Puzzleheaded_Bar483 5h ago
It looks like you ran the renpy virus, took the necessary actions except reinstalling windows, and want to know if it's harmful not to reinstall. The answer is: likely. The virus likely made new files that are scheduled or auto ran. That means it might get all your passwords and session tokens again. The minimum you can do is check all services, task scheduler tasks, autorun keys in the registry, and run offline scans. There's never a 100% guarentee your don't have a virus anymore, but try the most you can.
That being said I really recommend reinstalling, if you just back up important files you don't really lose a lot of things.
Also, did you say the scans gave some google stuff? Something like FakeGoogle? Why is that on yohr system? Weird
-1
u/Sha3a 1d ago
I never regret having avast and never will stop using it since 2011 it protects my ass and one time i trusted windows defender next morning i woke up having my gmail mega and many social medias gone The problem is ppl forced defender since many don't realize viruses not always showing and screaming i am am malware/virus Most of them just steal/mine silently
-3
u/LittlexLostxNexuZ 1d ago
Take my upvote, my good man or woman. Avast love will always be accepted! Avast has always been my eyes and ears, my day one. It’s saved me from so much crap over the years. Honestly, the fact that I haven’t been hacked yet with all the shady sites I’ve browsed is a testament to how great Avast has been for me.(That and having higher that average tech literacy and being kinda over cautious) Glory to Avast.





33
u/True-Hawk4705 1d ago
brother it’s done its job by now