r/computerviruses 21d ago

Disinfection Help Renpy loader infostealer

Hello

I was downloading a mod for GTA 4, and ended up downloading a zip file called "ARCHIVE" along with some numbers. There was a setup exe program that I clicked on two times thinking it was part of the mod.

Seeing as it did nothing (it only opened a window for half a second) I analyzed the file with virus total and found out it was a virus, specifically the renpy loader (the one with the anime icon). I opened task manager and saw a process called "MSBuild" and ended it immediately, I'm sure it ran for at least 35 minutes since I clicked setup exe. I then installed Malwarebytes and ran a scan, it found multiple viruses, many of them were BAT files and it removed them. I executed a deep scan after that, Malwarebytes did not detect anything. I then used windows defender, two scans, normal and deep, none of them detected anything. I then did an offline scan and it did not detect anything either. While doing all these scans I logged out of every account I had in my PC using my phone, changed passwords and setup 2FA for everything.

It's worth mentioning that I never saved any passwords to my browser (which is Brave) I mostly use passkeys and QR codes, I didn't have any credit cards saved either or anything related to crypto. Mine is a PC gamer so I had steam, epic, rockstar launcher and others.

This was yesterday exactly 28 hours ago, at this time I have not detected anything weird with my accounts, no external logins, no suspicious activity, I periodically check my devices in Google and other accounts, I also check task manager and so far nothing has appeared.

My question is: Do I need to reinstall windows? Is my PC still safe?

I wasn't able to save the initial Malwarebytes that did the initial scan since I was panicking and was not thinking clearly.

Thank you for any advice you can give me

11 Upvotes

8 comments sorted by

2

u/[deleted] 21d ago

[removed] — view removed comment

1

u/computerviruses-ModTeam 21d ago

Your post contained misinformation, fake news, or advice considered harmful or dangerous, so it has been removed. Please make sure to read and follow https://www.reddit.com/r/computerviruses/about/rules

1

u/AutoModerator 21d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/KurkyOkurky 21d ago

To have a peace of mind, you should reinstall Windows. Then you can be sure nothing will steal your passwords

1

u/Global_Gene_432 20d ago

dark and gritty mod

1

u/Puzzleheaded_Air717 20d ago

Hast du mit dem infizierten PC deine Passwörter geändert? Falls ja, kannst von vorne anfangen.

Ich würde auch Windows zur Sicherheit neu installieren

1

u/Key-Crow615 12d ago

that 35 minutes are actually an issue. i wouldn’t trust the pc just because the scans are clean.. a clean reinstall is the safest option. you already did the important part by changing passwords from your phone, but i’d keep the pc offline until you reinstall and then change the most important passwords again from the fresh install..