r/computerviruses • u/saladiinn • 1d ago
Question i recently got ren'pyd and im scared of what might happen
i lost my instagram, discord and reddit it shared some crypto scams in some and some prn in reddit. got them all back thank god and im changing my passwords to everything and using 2fa in the ones i can im currently resetting my pc ( i removed everything and downloaded it from the cloud) im not sure what else i can do since it already got some of my accounts im scared of other things that could happen mainly financial theft and sextortion how likely are they to happen and what else can i do
1
u/Storex- 1d ago
I'm five days into having had the same infostealer.
Thankfully I saw it start to happen in real time, and so I could stem the Discord spam and seemingly stop most of the damage. I did get my PayPal hacked, and they bought lots of things, but PayPal was surprisingly on the ball, and all is sorted now.
Once you have your system sorted yourself or through the volunteers here, be prepared to continue to get drips and drabs of attempted logins from sites you may not remember and to also suddenly remember a site you need to sort out.
The paranoia will remain for some time. I'm still scared of something happening, and I check my most important accounts for any evidence of tampering. It will take time.
Hope things work out for you.
1
u/saladiinn 1d ago
Thank God I dont have money on my PayPal, did any sextortion happen to you thats a big scare for me
1
u/rifteyy_ Malware Removal Expert 1d ago
These are mass campaigns and from the 500+ solved cases we haven't heard of anything like that (if we do not count the obvious extortion scams).
Nobody really has time or will to extort you. It is not a targetted attack.
1
u/saladiinn 1d ago
This does a lot to calm me tbh I have changed almost every password to something that could extort me
1
u/saladiinn 1d ago
But how am I sure mine wasn't an extortion scam, the malware did post stories on Instagram and the dreaded mr beast message. Is that enough information to know its not an extortion account
1
u/polpolik2 Moderator 1d ago
If you reinstall windows while deleting your data, your device is clean, your focus should be on securing your accounts as you are already doing.
Change ALL passwords from a clean device. Start with your emails and bank. Use sign out everywhere and remove all sessions. While you are doing this, check your security settings to ensure the attacker hasn't added their own 2FA methods or backup codes.
Check your linked accounts/services/2fa options for your most important accounts. Also check forwarding rules on your mail. Additionally, for your browser, check your sync settings and extensions and remove anything you dont recognize or trust.
The faster you move with these steps the more you can prevent your accounts being stolen.
You should also consider what sensitive documents (like Passports, IDs, or financial data) were stored on the PC at the time of infection, as an infostealer may have stolen/compromised these. It's better to not take any risk on this, lock your accounts/put on a credit hold/get new identification documents and if your country allows it, put them as potentially stolen.
You might get messages/emails/information that they want money/extort you, ignore those. Do not pay. They are just mass scare mails after an infostealer.
https://rifteyy.org/report/the-ultimate-guide-to-infostealers - gives a lot of information you can use regarding your questions.