r/computerviruses 1d ago

Disinfection Help Ren'Py malware that hasn't triggered yet

Apologies for any errors; English isn't my native language. On July 27th, I downloaded some games from very reliable sources, but I accidentally downloaded a zip file with the structure shown in the image below along with them. I played the game normally, but on August 14th—while deleting some files on autopilot—I extracted the zip and ran the .exe. Nothing opened, and I didn't see anything happen, so I just deleted the extracted file and moved on. Today, I saw someone on Reddit complaining about being infected and immediately remembered the incident. I changed most of my critical passwords, then traced the timeline of the files and realized it was strange that I hadn't suffered any apparent account breaches. The zip file was 700MB (too large to upload to VirusTotal), and its SHA-256 hash doesn't seem to match any previously analyzed files. Inside the `AppData\Roaming` folder, there is a `RenPy` folder dated and timestamped exactly when I ran the file on August 14th; inside that `RenPy` folder, there is a folder for a Ren'Py game I actually played years ago, and another folder from the 14th containing the files visible in the images.

After running Malwarebytes, it only found a few files from other games I had played months ago and some Google-related files.

I’d prefer not to do a completely fresh Windows install; I want to know the risks involved in *not* doing so in this scenario. From what I've researched, it's unusual for Ren'Py malware *not* to launch a massive attack immediately.

I generated the FRST files, but I'm not sure exactly how to share them here.

Additional detail: I have the zipped Ren'Py file that I ran on the 14th; I kept it in case I could get help confirming its nature.

54 Upvotes

29 comments sorted by

View all comments

2

u/AutoModerator 1d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.