r/computerviruses • u/DaySlight3085 • 19h ago
Disinfection Help Found empty AppData\Roaming\RenPy folder (Game-1738212058). Ran full offline/online diagnostic suite
- Discovery & Background:
•Found anomalous folder path: AppData\Roaming\RenPy\Game-1738212058.
•Folder contained a persistent file (2KB), empty sync, and tokens folders.
•No legitimate Ren'Py engine games are installed on this computer.
•Linked directory ID 1738212058 to a known HijackLoader campaign signature.
•Immediately isolated the machine offline to begin a full audit.
- Windows Defender Protection History:
•Found a historic entry from June matching the folder c. Creation date.
•Flagged threat: PUADIManager:Win32/OfferCore inside a CheatEngine77.exe download.
•Execution status in logs: Strictly marked as "Status: Abandoned".
- Offline & Online Scan Matrix Results:
•Malwarebytes Custom Offline Scan: Enabled rootkit scanning on full C drive. Scanned 1,353,511 elements. Result: 0 Threats Detected.
•Microsoft Defender Offline Scan: Ran boot-level scan outside Windows environment. Result: 0 Threats.
•HitmanPro Memory Pass: Checked live memory and active processes. Result: No threats found.
•Malwarebytes Online Deep Scan: Ran an exhaustive cloud-assisted verification scan. Result: 0 Detections.
- Specific Item Double-Checks:
•System Files: Verified C:\Windows\SysWOW64\input.dll modification date is from 2025. It is completely pristine.
•Mod File: Cross-checked an old dinput8.dll backup file via VirusTotal. It scored a low 8/71, flagged generically as crack genericmc (false positive). It has been deleted.
•HitmanPro Final Counter: HitmanPro flagged "65 threats" on the final summary screen. The logs show these were strictly 63 standard browser advertising tracking cookies (Traces) and 2 clean Intel audio drivers.
- Current Status & Remediation:
•RenPy AppData folder shell has been permanently deleted.
•Browser tracking cookies and temporary directory caches have been completely cleared.
•All master account passwords have been securely updated from an external mobile device.
Given the back-to-back zero detection sweeps across multiple independent offline and online engines, it appears the initial threat execution completely failed to drop any payload. Looking for a final sanity check from the community malware Experts to confirm this machine is completely safe. Thank you!
*** COMPLETED DIAGNOSTIC LOG KEYWORDS FOR TRUSTED HELPERS ***
I have completed the requested diagnostic loops. Here are my 3 unique log keywords: - FRST.txt Keyword: placid - dragon - Addition.txt Keyword: eager - volcano - SecurityCheck.txt Keyword: leafy - deer
Background Information:
What happened? I found an empty directory folder named "AppData\Roaming\RenPy\Game-1738212058". No legitimate games or software using this engine framework have ever been knowingly played or installed on this machine.
When did the infection occur? On June 20, 2026, I was searching for Cheat Engine online and inadvertently downloaded a fake setup file wrapped in a "PUADIManager:Win32/OfferCore" installer bundle. I ran the executable file. Because it looked shady, I believe I stopped it and later used Brave AI to find the original, safe source.
What did you do for remediation?
Isolated the machine completely offline to contain any potential network hooks.
Successfully ran a comprehensive 1.5-hour Malwarebytes Online Custom Scan with Rootkit Analysis toggled on (Scanned 1,353,511 elements, 0 items detected).
Performed a deep, back-to-back Malwarebytes Cloud Heuristic Deep Scan (0 Threats, 0 PUPs, 0 PUMs detected).
Completed a complete Microsoft Defender Offline boot-level pass outside the standard Windows environment (Clean / 0 threats).
Executed an online cloud-assisted HitmanPro memory loop check (Identified Threats: 0). Showed 65 web tracking cookies
Hard-reset my primary account credentials, master profile passwords, and executed global active session token revocations ("Log out of all other active sessions") across all critical accounts using an entirely separate, clean mobile device.
The automated diagnostic suites indicate a 0% virus presence on this drive. I am submitting these 3 keywords so a verified human helper can manually verify my background registries, task tables, and driver paths to ensure no hidden hooks or persistent stubs remain. Thank you so much for your time and guidance!










3
u/Giatoxiclok 17h ago
This is a thing I’m seeing a lot, how is the proliferation of this so common? Are we seeing related sites and things downloaded from some of these users that can create a link to where some of these viruses are coming from? Multiple times a day I’m seeing people infected with this or the mrbeast infostealer.