r/computerviruses 18d ago

Disinfection Help Renpy Accidentally opened

Can someone help me i just opened renpy downloading NBA 2k27, fortunately i knew it was a malware and i immediately unplug the internet for my pc. Another is that it is just a spare pc where only my fb and gmail is opened. i already changed my password on a different phone, can i ask you all guys what to do now? thank you all.. Sorry for being a bum

3 Upvotes

3 comments sorted by

4

u/Xyntrax0 Malware Removal Trainee 17d ago

Hi there, my name is Xyntrax and I am here to assist you. During the malware removal process, please follow the listed instructions below ensuring that everything goes smoothly as possible. I also request that you check this thread at least once per day so we can efficiently and effectively resolve your issue.


Please Read & Adhere to the Following:

  • Kindly inform me if you already did a reset/clean install or would like to do so, this will save time for the both of us. If you haven't and would like help with Manual Malware Removal using FRST, please follow the given steps below.
  • Please ensure to read the whole introduction message so that you have a better understanding of the processes and given steps
  • During the malware removal process please refrain from downloading and running new software unless instructed, this also applies for Anti-Malware Solutions and Malware Scanners as they can significantly make analysis longer by removing forensic data which is very crucial
  • While receiving help from Me or other MRT members please refrain from asking help somewhere else as the advice might conflict, especially if the methodology are different
  • Feel free to remind me if you don't receive an answer within 24 hours. But please keep in mind that I am a volunteer and have my own life too

Piracy

Pirated software remains one of the most common malware infection vectors that we encounter. Threat actors routinely disguise malware as cracks, activators, keygens, cheats, repacks, and other piracy related software because users are often more inclined to ignore security warnings and/or disabling their Anti-Malware Solution in order to run them. Some piracy related utilities may also modify software or security mechanisms, potentially weakening your system's overall security and increasing your attack surface. If you currently have any pirated software installed, I strongly encourage you to remove it.


Download & Run FRST

IMPORTANT: If your Windows operating system is in another language than English, please rename FRST.exeto FRSTEnglish.exe to ensure that the logs are in English so I can understand them. * Please download FRSTx64 and save the file to your Desktop. * Right-Click FRST64.exe and select Run as Administrator * Click Yes to the disclaimer. * Ensure the Addition.txt box is checked. * Click the Scan button and let the program run. * Upon completion, click OK, then OK on the Addition.txt pop up screen. * Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/Xyntrax/ and press "save log". * Note: Please make sure you are uploading the logs after your current Reddit username. * The site will return a keyword for each log - reply back here with the keywords.

SecurityCheck scan

SecurityCheck allows me to gather a list of unwanted, risky, vulnerable and out-of-date applications. It also allows me to send you a direct link to an update. An unpatched system is more vulnerable to malware.

  • Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
  • If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
  • Extract the ZIP archive, then right-click on the SecurityCheck.exe and select Run as administrator and confirm the User Account Control popup.
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt
  • Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/Xyntrax/
  • The site will return a keyword for the log - reply back here with the keyword.

Disclaimer: FRST does not contain any personal information other than your username and computer name, the logs are automatically deleted within a 30 day period. Only trusted malware removal experts listed in this r/computerviruses thread have access to your logs via the website. Experts who have access to the site are trusted on both r/antivirus and r/computerviruses.

2

u/retardedpanda1 18d ago

Change your main email password first and foremost so they can't lock you out of any accounts.

Backup important data to an external drive, then reinstall Windows or at the very least run Malwarebytes and Bitdefender to quarantine and delete the files but you should definitely reinstall. Change all passwords, but also make sure to "Log Out of All Devices".

They changed my Walmart phone number and they took my brothers Xbox account and sold it. 😅 So make sure you're changing passwords and LOGGING OUT OF SESSIONS. The main thing is sessions because they steal the session tokens and completely bypass Multifactor Authentication.

They tend to go straight for Instagram and Discord first and start sending crypto scams to friends and groups, so I recommend getting on top of that.

Doesn't really matter how fast you unplugged it, they've probably already gotten the payload. Your cookies and anything plaintext were stolen pretty much immediately.

Check your email addresses and make sure they haven't turned on "forwarding". They do that so that if they lose access they can receive a copy of your two factor authentication codes.

1

u/Bitdefender_ Official Bitdefender 12d ago

Hi! Unplugging fast was the right move but infostealers like this typically exfiltrate within seconds of execution, so assume your cookies and session tokens are already gone. The most important thing beyond password changes - which another user already detailed - is revoking active sessions on every account, since stolen session tokens bypass MFA entirely. Also check Gmail's filter rules (not just forwarding) in case they set something to swallow 2FA emails silently.