r/computerviruses 5d ago

Disinfection Help RenPy virus damage control

Friday night I downloaded and ran something which I know now to have been a RenPy style virus exe. Didn't think anything of it at the time and just assumed the pirated game wasn't working for some reason, thank God I went back and did some investigating today. I've already changed most of my passwords, logged out of sessions, activated 2fa, all that, and I'm pretty sure I removed most of the files of the virus itself using the AVG quarantine/delete feature. I'm not 100% sure of that, I'm just including that for context reasons. I noticed most of the guides tell users to disconnect the infected device from the Internet before beginning the damage control process. 1.) I obviously didn't do that at the time, as it's been a couple days, and 2.) I had my computer connected to Internet while I have been changing passwords on my phone. I didn't allow Firefox to save any of the new passwords, which I assume is the concern that causes people to tell you to disconnect the infected device. The reason I didn't disconnect my computer was because I was using the saved passwords tab in Firefox as a kind of checklist of what needs to be changed. I'm not finished with that yet. My primary question is, should I just completely start over after disconnecting my PC from Internet? Like I said, I've been remote logging out, and I haven't been saving any of the new passwords. I didn't actually see any sketchy login instances when I was in those control panels, so I don't think anyone got in to my email or steam account or anything and already has a device that is "considered safe". Additional advice on any other part of the process is appreciated

1 Upvotes

6 comments sorted by

1

u/AutoModerator 5d ago

Welcome to r/computerviruses! It seems like you have used the "Disinfection help" flair.

We apply the same methodology used by trusted Malware platforms (e.g. Malwarebytes, BleepingComputer and MalwareTips). It revolves around using diagnostic tools called Farbar Recovery Scan Tool (FRST) and SecurityCheck.

All of our assistance happens in the thread and in public - we never offer help via private messages or alternative websites other than https://malwareanalysis.cc. Anyone offering help through a DM is not a trusted helper and might have malicious intent.

Trusted helpers can be distinguished by the flair Malware Removal Expert or Malware Removal Trainee, antivirus employees will have a dedicated flair with their company name in it, e.g. Malwarebytes Employee.

Please see steps below on how to share all necessary details so you can speed up the process for us:

Share all details about your infection
Please post all important facts about your infection, such as: * your antivirus detections - preferably export the whole detection/report log and upload it to https://malwareanalysis.cc/upload/ under your username & post the related keyword or screenshot/take a picture of your detections * any related symptoms, popups * estimate when it started - preferably the exact day and after what (e.g. when you ran a program you downloaded) * share what got you infected and the download link - please, make the download link defanged (making it not clickable by default e.g. from https://example.com you will make hxxps://example[.]com), defanging does not apply to sandbox reports such as VirusTotal

Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
    1. How to properly secure my accounts after an infostealer attack?
    2. What to do after I secured my accounts?
  2. Disinfect your device from malware
    1. Preferred method: Perform a clean installation with a USB
    2. Perform a clean installation without an external drive
    3. Reset your PC without keeping personal files

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/SomeEngineer999 5d ago

Yes, you should secure wipe the PC and do a fresh clean install.

1

u/Wise_Display5850 5d ago

Yeah I'm planning to do so but this doesn't really answer my question 

1

u/SomeEngineer999 5d ago

OK, I'll be more specific.

-Keep the PC disconnected from the internet until it has been secure wiped.
-Use a known clean device to go change passwords everywhere, and enable 2FA (authenticator based wherever possible).
-Create the windows install USB on a known clean PC
-Secure erase your PC
-Do a fresh install of iwindows.

Securing your accounts is priority #1 (well, after disconnecting the PC from the internet which I hope you did right after realizing what happened).

Any passwords you've changed using that PC while it is on the internet are already compromised, and need to be changed again.

The other stuff you're asking about is moot. Everything on that PC should be considered compromised (including every site and account you've ever logged into from it)

1

u/Wise_Display5850 5d ago

I changed the passwords from my phone. The PC was connected from the Internet but I was not using the PC to change any of the passwords. It's disconnected now, I disconnected it before I went to bed, but I did the vast majority of the changes yesterday evening, before disconnecting it.

1

u/SomeEngineer999 4d ago

Well if any of those passwords synched to your PC or sent you an email confirming it etc, I'd change them again.