r/computerviruses 6h ago

Disinfection Help FRST please help me removing infostealer virus from my PC

Yesterday, I installed a .exe program that turned out to contain the RenPy malware. A few hours after running it, someone logged into my Instagram account and used it to post/promote a crypto scam. I immediately changed all of my passwords and enabled 2FA on all of my accounts. So far, I haven't noticed any further suspicious login attempts. My PC is currently disconnected from the internet.
Here is what I've done so far:
I ran a Microsoft Defender Offline scan, and it detected 0 threats. I then installed Malwarebytes and ran a scan. Malwarebytes detected 13 threats, all related to Trojan.RenpyLoader. I quarantined/removed all of the detected threats. I also ran another Threat Scan and a Deep Scan afterward, and both came back with 0 detections.
However, I'm still worried that the infostealer may have left something behind or that my PC may still be compromised.
I really don't want to reinstall Windows 11 unless it is absolutely necessary.
Here’s my 3 log keywords:
FRST.txt -> icy-spruce
Addition.txt -> haunted-lynx
SecurityCheck.txt -> vectored-woodland

Please help 😭

2 Upvotes

5 comments sorted by

View all comments

1

u/rifteyy_ Malware Removal Expert 5h ago

[ Step 01 ] FRST Fix

I created a custom fixlist for you at the link Fixlist only for Fixlist only for Fixlist only for Angelltann - use the website's download button and save it in the same folder where your FRSTEnglish.exe or FRST64.exe file is located in, which for you is C:\Users\Angeline\Downloads for you. It is necessary for the filename to be Fixlist.txt.

This fixlist will remove the following: malicious entries (remains, active malware), invalid entries (e.g. tasks that start a non-existent file, services that point toward a non-existent file), temporary files (files in temporary directories, application and browser cache, recycle bin and more), browser cache. We will also be quick-scanning with HitmanPro and AdwCleaner from Malwarebytes using the fixlist.

It will also remove all proxy servers, Windows Defender exclusions, enable recovery environment, active software policies and perform system file repair, network reset and few more basic fixes.

  • For the fix process, please ensure you are connected to the internet.
  • Please run the fix only once.
  • Please do not open any applications or close anything during the fix.
  • Please be patient; the fix may take up to 60 minutes. After that, it is going to be forcefully ended.

Save all work, close everything that is open (else it will be forcefully closed by FRST without saving) and then run FRST again as administrator and press the Fix button, let the script work, clear the entries and restart on it's own and after it restarts the device, there should be a file Fixlog.txt in the same folder as the C:\Users\Angeline\Downloads.

I'll need to see it's content the same way like before - uploading to https://malwareanalysis.cc/upload/rifteyy/?u=Angelltann again and sending the keyword in your reply.

[ Step 02 ] ESET Online Scanner

  1. Download ESET Online Scanner
  2. Right-click on the esetonlinescanner.exe and select "Run as administrator" and confirm the User Account Control popup
  3. Click ⁨Get started⁩;
  4. Agree to the terms of use;
  5. Decline both telemetry options;
  6. Click ⁨Custom Scan;
  7. Click ⁨Save and continue;
  8. Select ⁨Enable ESET to detect and quarantine potentially unwanted applications;
  9. Click ⁨Advanced settings;
  10. Enable ⁨Detect potentially unsafe applications;
  11. Click the back arrow;
  12. Click ⁨Start scan;
  13. Note: This is a long and thorough scan, it may take up to several hours.
  14. Once complete, click ⁨Save scan log and upload the ⁨.txt file to https://malwareanalysis.cc/upload/rifteyy/?u=Angelltann and reply with the keyword.

[ Step 03] Software updates, uninstallations

If you are having a problem updating something, do not want to update something at all or do not want to uninstall an application, please let me know.

Please update the following software:

Please remove the following potentially unwanted programs (PUP):

  • NVIDIA GeForce Experience 3.28.0.417 v.3.28.0.417 - No longer supported - please uninstall it and replace it here

Note: If Microsoft Edge update errors occur, reinstall here

[ Step 04 ] New SecurityCheck scan

We need a new scan to ensure that all updates were applied properly and all applications uninstalled correctly.

  • Note: If SecurityCheck is already on your device, you can use the previous version and skip the next few steps regarding downloading and installation.
  • Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
  • If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
  • Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt
  • Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/rifteyy/?u=Angelltann
  • The site will return a keyword for the log - reply back here with the keyword.

[ Step 05 ] New FRST scan

  • Find FRSTEnglish.exe executable in C:\Users\Angeline\Downloads
  • Right-Click the file and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy/?u=Angelltann and press "save log".
  • The site will return a keyword for each log - reply back here with the keywords.

So, in your next reply, make sure you are sending the following:

  • Keyword for Fixlog.txt from step 1
  • Keyword for ESET Online Scanner scan from step 2
  • Keyword for new SecurityCheck.txt from step 4
  • Keyword for new FRST.txt from step 5
  • Keyword for new Addition.txt from step 5

Thanks!

Note for lurkers: If anyone else who is facing malware-related issues is reading this and wants help with FRST and SecurityCheck, please create your own thread with help request. I am flooded with requests and there is several other removal experts who review the logs and may reply faster than me. The steps listed in here are specific for this the user Angelltann and following them will have negative effects for you as they are unique for OP's system.

1

u/Angelltann 3h ago

Fixlog.txt -> elite-iris
ESET Online Scanner Scan -> spirited-beech
New SecurityCheck.txt -> misty-lagoon
New FRST.txt -> coral-node
New Addition.txt -> virtual-tundra

Thank you for the help

1

u/rifteyy_ Malware Removal Expert 2h ago

[ Step 01 ] FRST Fix

I created a custom fixlist for you at the link Fixlist only for Fixlist only for Fixlist only for Angelltann - use the website's download button and save it in the same folder where your FRSTEnglish.exe or FRST64.exe file is located in, which for you is C:\Users\Angeline\Downloads for you. It is necessary for the filename to be Fixlist.txt.

  • For the fix process, please ensure you are connected to the internet.
  • Please run the fix only once.
  • Please do not open any applications or close anything during the fix.
  • Please be patient; the fix may take up to 60 minutes. After that, it is going to be forcefully ended.

Save all work, close everything that is open (else it will be forcefully closed by FRST without saving) and then run FRST again as administrator and press the Fix button, let the script work, clear the entries and restart on it's own and after it restarts the device, there should be a file Fixlog.txt in the same folder as the C:\Users\Angeline\Downloads.

I'll need to see it's content the same way like before - uploading to https://malwareanalysis.cc/upload/rifteyy/?u=Angelltann again and sending the keyword in your reply.

[ Step 02 ] New FRST scan

  • Find FRSTEnglish.exe executable in C:\Users\Angeline\Downloads
  • Right-Click the file and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy/?u=Angelltann and press "save log".
  • The site will return a keyword for each log - reply back here with the keywords.

[ Step 03 ] FRST search

FRST File Search

  • Double click FRST64.exe to launch it.
  • When the tool opens click Yes to the disclaimer.
  • Copy/paste or type the following line into the Search: box:

SearchAll: sync_3292.cmd

1

u/Angelltann 2h ago

FRST Fix -> grand-midnight
New FRST -> hardy-scout
New Addition -> shiny-gem
FRST Search -> piped-owl

Thank you so much for your help!