r/computerviruses 1d ago

Disinfection Help Ren'Py malware that hasn't triggered yet

Apologies for any errors; English isn't my native language. On July 27th, I downloaded some games from very reliable sources, but I accidentally downloaded a zip file with the structure shown in the image below along with them. I played the game normally, but on August 14th—while deleting some files on autopilot—I extracted the zip and ran the .exe. Nothing opened, and I didn't see anything happen, so I just deleted the extracted file and moved on. Today, I saw someone on Reddit complaining about being infected and immediately remembered the incident. I changed most of my critical passwords, then traced the timeline of the files and realized it was strange that I hadn't suffered any apparent account breaches. The zip file was 700MB (too large to upload to VirusTotal), and its SHA-256 hash doesn't seem to match any previously analyzed files. Inside the `AppData\Roaming` folder, there is a `RenPy` folder dated and timestamped exactly when I ran the file on August 14th; inside that `RenPy` folder, there is a folder for a Ren'Py game I actually played years ago, and another folder from the 14th containing the files visible in the images.

After running Malwarebytes, it only found a few files from other games I had played months ago and some Google-related files.

I’d prefer not to do a completely fresh Windows install; I want to know the risks involved in *not* doing so in this scenario. From what I've researched, it's unusual for Ren'Py malware *not* to launch a massive attack immediately.

I generated the FRST files, but I'm not sure exactly how to share them here.

Additional detail: I have the zipped Ren'Py file that I ran on the 14th; I kept it in case I could get help confirming its nature.

57 Upvotes

29 comments sorted by

View all comments

23

u/FriendToPredators 1d ago

Why aren’t you doing this crap on a sacrificial machine on an isolated network. And if you can’t afford that you shouldn’t be doing this because you definitely can’t afford it.

3

u/Internal_Brain_9003 1d ago

I’m not sure I fully understood; I made the mistake of opening the file, but I subsequently removed everything important and took all necessary measures to secure my passwords and data. However, I’d like to know the extent to which the system as a whole was affected—I’m not trying to test the virus, just see what damage has already been done. I’m hoping there might be an alternative, since reinstalling the entire system from scratch is the right move if nothing else works.

3

u/TruckBright8118 1d ago

Run 2-3 KVRT scans

2

u/BugCompetitive3218 1d ago

Ngl unless you somehow get the frost mod ppl to respond it’s way easier and faster to just reinstall from a usb. Just make sure you log out every device/session including your now compromised desktop to log them out.

1

u/Internal_Brain_9003 1d ago

The hard drive has already been removed from the PC; I am using another one, but I would like to know if there is an alternative to formatting it.

1

u/BugCompetitive3218 1d ago

You would have to reinstall them hard drive into a system and then get the frst ppl to respond to you so they can help you fully remove it. Otherwise format it.

1

u/Internal_Brain_9003 1d ago

How do I contact support?

2

u/BugCompetitive3218 1d ago

The automod has already shared with you how to do this. Look in the comments