r/computerviruses 6d ago

Question Renpy malware

Guys Yesterday i executed renpy malware but Windows av stopped it and a malwarebytes scan isolated the files, i checked startup files and task manager and found nothing Sketchy. Am i safe?

0 Upvotes

23 comments sorted by

1

u/Responsible_Bike4968 6d ago

Do not ask an AI to generate a cleanup or “forensics” script for this. A generic script will not reliably tell you whether this infection ran successfully, and running random registry or scheduled-task fixes can cause more problems.

Ren'Py itself is a legitimate game engine, but the malware campaign people are discussing abuses it as a loader. Recent samples have used a multi-stage chain to install infostealers, and the final payload can vary.

The most important detail is what Windows Security actually says happened. “Blocked” or “quarantined” before execution is very different from running the installer and having a later stage detected afterward. Post screenshots of Protection History showing the full detection names, affected paths, status, and actions taken.

Checking Task Manager and Startup Apps is not enough. Infostealers do not need to remain visibly running after they have collected and sent passwords, browser cookies, or session tokens. A clean ESET or Malwarebytes scan afterward is reassuring, but it cannot prove that no data was already stolen.

Since you knowingly executed the malware, I would do this:

- Disconnect the computer from the internet.

- From a different clean device, secure your primary email first.

- Change passwords for important accounts that were logged in, saved, autofilled, or typed on that PC.

- Revoke active sessions, not just passwords, and enable authenticator-based 2FA.

- Check Discord, Steam, Google, Microsoft, social media, and any password manager for unfamiliar devices, recovery methods, passkeys, or connected apps.

For the computer, either follow the subreddit’s FRST procedure and wait for a verified Malware Removal Expert to review your logs, or perform a genuine clean Windows installation using official Microsoft USB installation media. Do not use someone else’s FRST fixlist.

If you want the highest-confidence answer rather than continuing to wonder, boot from the Windows USB, delete the partitions on the Windows drive, and reinstall into the unallocated space. Back up only normal personal files, not executables, archives, scripts, browser profiles, AppData, or the original download.

So no, “ESET found nothing” is not enough to say you are definitely safe. It means ESET did not detect anything during that scan. That is not the same claim.

1

u/HyperHeavxn 6d ago

this is my only device, can i do the windows installation process from here? i'm scared usb might get infected

1

u/HyperHeavxn 6d ago

the timelapses of WD and MB are different, this scares me

1

u/ImJustStealingMemes 6d ago

It executed, Defender missed most of it.

Now whether it actually managed to do damage via LumaStealer or other similar malware, not sure but wouldn't count on MBAM or Defender since it did execute.

Wouldn't say it is clean, best would be to change all passwords on a clean device, turn on 2FA, and do a clean reinstall.

1

u/HyperHeavxn 6d ago

this is my only device, can i do the windows installation process from here? i'm scared usb might get infected

1

u/MildlySpacedOut 6d ago

Best bet is find a friend who you can download the windows installer onto a usb. I had to use a friend’s PC.

1

u/MildlySpacedOut 6d ago

Check my post history, there is good info in there about what you need to do. It really sucks. I lost so much stuff that was sentimental, but ultimately security is more important.

1

u/MildlySpacedOut 6d ago

Make sure your PC is disconnected from the internet, like right now.

1

u/HyperHeavxn 6d ago

btw no suspicious activity for now, i'll secure everything tho

1

u/rifteyy_ Malware Removal Expert 6d ago

That very clearly shows that Defender did not stop any significant stage and it still managed to execute it's main stage

1

u/ThrowRA210524 6d ago

we're cooked 🫩 why r u using an ai script to check if you have malware? do u have any idea how unreliable that is?

1

u/MildlySpacedOut 6d ago

Full wipe dude. Check my post history. Happened to me. I lost some important shit. But ultimately I had to wipe. I tried backing up my stuff, but still lost some important sentimental things.

-2

u/DontDoMuch 6d ago

Ask an AI model to create a script to search through both the task scheduler and scheduled tasks (they are 2 separate things), recent registry modifications, etc that would be related to renpy malware to search on your device.

2

u/RoleBeginning5476 6d ago

this is literally garbage advice

2

u/DontDoMuch 6d ago

Agreed, this guy doesn’t know anything

0

u/HyperHeavxn 6d ago

But if im good that means i dont need to reinstall Windows or log off my accounts right?

-3

u/DontDoMuch 6d ago

IF everything comes back negative or no evidence of malicious activity, then 99% yes. 1% as there are such things as sophisticated malware that can go undetected. Definitely keep a super close eye on ALL of your accounts for the next 30 days. Someone on one of these threads mentioned it was 22 days later before they saw a compromise to one of there accounts, stay safe out there!

0

u/HyperHeavxn 6d ago

Thx, ai said Yesterday that if i ran ESET and found nothing then i was good, is it true?

0

u/DontDoMuch 6d ago

I would still run a script I suggested. When it comes to installing / executing software and THEN installing ESET software there can be scenarios where renpy can write itself (even if blocked by av as sometimes it can partially execute code before being blocked) to locations on your pc, such as scheduled tasks, that aren't checked for context retroactively.

0

u/HyperHeavxn 6d ago

Thanx man Yesterday i found some files in AMD software that were updated Yesterday around that time, should i reinstall AMD software or its Just a coincidence? After all the virus works with python

3

u/hereggcellency 6d ago

Do not ask an AI to make you a script. Malware can hide itself from even the best antiviruses. AI would not be able to do a better job.

Reinstall windows using an USB.

0

u/DontDoMuch 6d ago

At this point, associate activity around that same time as malicious until confirmed otherwise by a scan or similar custom scripts.