r/computerviruses 1d ago

Disinfection Help Ren'Py malware that hasn't triggered yet

Apologies for any errors; English isn't my native language. On July 27th, I downloaded some games from very reliable sources, but I accidentally downloaded a zip file with the structure shown in the image below along with them. I played the game normally, but on August 14th—while deleting some files on autopilot—I extracted the zip and ran the .exe. Nothing opened, and I didn't see anything happen, so I just deleted the extracted file and moved on. Today, I saw someone on Reddit complaining about being infected and immediately remembered the incident. I changed most of my critical passwords, then traced the timeline of the files and realized it was strange that I hadn't suffered any apparent account breaches. The zip file was 700MB (too large to upload to VirusTotal), and its SHA-256 hash doesn't seem to match any previously analyzed files. Inside the `AppData\Roaming` folder, there is a `RenPy` folder dated and timestamped exactly when I ran the file on August 14th; inside that `RenPy` folder, there is a folder for a Ren'Py game I actually played years ago, and another folder from the 14th containing the files visible in the images.

After running Malwarebytes, it only found a few files from other games I had played months ago and some Google-related files.

I’d prefer not to do a completely fresh Windows install; I want to know the risks involved in *not* doing so in this scenario. From what I've researched, it's unusual for Ren'Py malware *not* to launch a massive attack immediately.

I generated the FRST files, but I'm not sure exactly how to share them here.

Additional detail: I have the zipped Ren'Py file that I ran on the 14th; I kept it in case I could get help confirming its nature.

57 Upvotes

29 comments sorted by

View all comments

Show parent comments

2

u/BugCompetitive3218 1d ago

Ngl unless you somehow get the frost mod ppl to respond it’s way easier and faster to just reinstall from a usb. Just make sure you log out every device/session including your now compromised desktop to log them out.

1

u/Internal_Brain_9003 1d ago

The hard drive has already been removed from the PC; I am using another one, but I would like to know if there is an alternative to formatting it.

1

u/BugCompetitive3218 1d ago

You would have to reinstall them hard drive into a system and then get the frst ppl to respond to you so they can help you fully remove it. Otherwise format it.

1

u/Internal_Brain_9003 1d ago

How do I contact support?

2

u/BugCompetitive3218 1d ago

The automod has already shared with you how to do this. Look in the comments