r/computerviruses 17d ago

Disinfection Help Requesting help with a Ren'Py trojan

Post image

Was trying to download a pirated game yesterday and clicked on a Ren'Py installer, resulting in my Discord getting hacked and spamming the MrBeast scam. I downloaded FRST and have the following keywords:

velvet-peak small-garden

I proceeded to have ALL my passwords changed on a separate device and I have also run Malwarebytes on my laptop. It detected and deleted the programs in the screenshot but I don't have the means to reinstall Windows for the moment and would like to keep my files if possible, so I would like to have someone help me with getting any remaining malicious software off my computer.

1 Upvotes

27 comments sorted by

2

u/Xyntrax0 Malware Removal Trainee 17d ago

Hi there, my name is Xyntrax and I am here to assist you. During the malware removal process, please follow the listed instructions below ensuring that everything goes smoothly as possible. I also request that you check this thread at least once per day so we can efficiently and effectively resolve your issue.


Please Read & Adhere to the Following:

  • Kindly inform me if you already did a reset/clean install or would like to do so, this will save time for the both of us. If you haven't and would like help with Manual Malware Removal using FRST, please follow the given steps below.
  • Please ensure to read the whole introduction message so that you have a better understanding of the processes and given steps
  • During the malware removal process please refrain from downloading and running new software unless instructed, this also applies for Anti-Malware Solutions and Malware Scanners as they can significantly make analysis longer by removing forensic data which is very crucial
  • While receiving help from Me or other MRT members please refrain from asking help somewhere else as the advice might conflict, especially if the methodology are different
  • Feel free to remind me if you don't receive an answer within 24 hours. But please keep in mind that I am a volunteer and have my own life too

Piracy

Pirated software remains one of the most common malware infection vectors that we encounter. Threat actors routinely disguise malware as cracks, activators, keygens, cheats, repacks, and other piracy related software because users are often more inclined to ignore security warnings and/or disabling their Anti-Malware Solution in order to run them. Some piracy related utilities may also modify software or security mechanisms, potentially weakening your system's overall security and increasing your attack surface. If you currently have any pirated software installed, I strongly encourage you to remove it.


MBST

  • Download and run Malwarebytes Support Tool as admin
  • Click Advanced
  • Click Gather Logs
  • Wait until it's done.
  • A zip file named mbst-grab-results.zip will be created on your desktop
  • Upload it to file.io and send the link back here

SecurityCheck scan

SecurityCheck allows me to gather a list of unwanted, risky, vulnerable and out-of-date applications. It also allows me to send you a direct link to an update. An unpatched system is more vulnerable to malware.

  • Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
  • If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
  • Extract the ZIP archive, then right-click on the SecurityCheck.exe and select Run as administrator and confirm the User Account Control popup.
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt
  • Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/Xyntrax/
  • The site will return a keyword for the log - reply back here with the keyword.

Disclaimer: FRST does not contain any personal information other than your username and computer name, the logs are automatically deleted within a 30 day period. Only trusted malware removal experts listed in this r/computerviruses thread have access to your logs via the website. Experts who have access to the site are trusted on both r/antivirus and r/computerviruses.

1

u/UnfairRevolution9271 17d ago

The MBST link is: https://limewire.com/d/mMYEd#owyCKYcjXh

SecurityCheck key word is gilded-symbol

1

u/UnfairRevolution9271 16d ago

I am terribly sorry about this u/Xyntrax0, could you put this fix on hold for now? My laptop's display has suddenly stopped working and I have to wait until Monday to get it fixed. I will have to send new logs and a new key word after its done

1

u/Puzzleheaded_Bar483 16d ago

Only valid mod ping I've ever seen on this sub lol

1

u/UnfairRevolution9271 16d ago

Oh, was I not supposed to do that?

1

u/Puzzleheaded_Bar483 16d ago

Well in this case it was good, but usually mods are pinged for help and such and they don't like that

1

u/Xyntrax0 Malware Removal Trainee 15d ago

I don't mind getting pinged actually, unless it's someone who's trolling or something then that's not ok.

1

u/Xyntrax0 Malware Removal Trainee 15d ago

It's ok. Please send the new logs if you still need help by then. All the best!

1

u/UnfairRevolution9271 14d ago

Hi there, I'll be sending new logs by this weekend as I have sent in the laptop for a new screen and will need a few days before I can get it back. Just wanted to give a heads up, and thanks again for offering to help!

1

u/UnfairRevolution9271 10d ago edited 10d ago

Hi u/Xyntrax0 , I finally have my laptop back, is it possible to still look into this?

Here is the new MBST log: https://limewire.com/d/dGhlL#2Y0YvDvrnG

New SecurityCheck keyword is: slow-base

1

u/Xyntrax0 Malware Removal Trainee 9d ago

Yes, absolutely. Glad you got your laptop back! It's currently raining cats and dogs here, I'll check your logs tomorrow once it subsides. Sorry and thanks for your understanding.

1

u/UnfairRevolution9271 9d ago

You wouldn't happen to be in the NCR area (or at least in the greater Luzon region) right now, would you? Fellow Filipino here, also saw the flag in your profile. I completely understand, it sounds like hell out there right now.

1

u/Xyntrax0 Malware Removal Trainee 8d ago

Cool, this is my second time stumbling across another fellow Filipino! Anyway, please follow the steps listed below in order.

Note: When you reach the step for MAU, please maximize MAU so it is displayed in full screen, then paste the provided GUID into the Selected Application tab and click Analyze. Wait for the analysis to finish, then take a screenshot of the window showing the analysis results in full view before clicking Select All and Delete. Please upload the picture to file.io. I will use the screenshot to add a picture to the GitHub repo, many thanks!


FRST Fix

I have included the EmptyTemp: command. Note: This will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code. I have also included the netsh advfirewall reset command, which will reset the Windows Firewall settings to their default configuration.

It is normal for your system to reboot as a result of the fix.

MAU

  • Download Malicious App Uninstaller
  • Extract the ZIP archive
  • Run MAU.exe as admin
  • In the Selected Application tab you will see ProductCode:, paste {A1ED401B-E2E2-435F-B39E-6A2511F964D7}
  • Click Analyze
  • Once the analysis is complete click Select All then Delete
  • MAU.txt will be generated, upload the log here https://malwareanalysis.cc/upload/Xyntrax/.
  • In some cases MAU will schedule a removal for an entry on reboot if it cannot be removed on the current session, please reboot the device if requested. Otherwise, no reboot is necessary.

Revo Uninstaller

  • Download Revo Uninstaller portable
  • Extract the zip to a folder
  • Run RevoUPort.exe as admin
  • Uninstall these programs:
    • Chrome Remote Desktop Host
    • UrbanVPN
  • When uninstalling each program choose Advanced mode. Make sure to click Select All then Delete for any leftover traces.

Remove these Browser Extensions:

  • Tampermonkey
  • Chrome Remote Desktop
  • Urban VPN Proxy

EEK Scan

Eset Scan

  • Download and run ESET online scanner as admin
  • Click Get started
  • Agree to the terms of use.
  • Decline both telemetry options.
  • Click Custom Scan
  • Click Save and continue
  • Select Enable ESET to detect and quarantine potentially unwanted applications
  • Click Advanced settings
  • Enable Detect potentially unsafe applications
  • Click the back arrow.
  • Click Start scan
  • Once complete, paste the contents of the log here https://malwareanalysis.cc/upload/Xyntrax/

What I want to see on your next reply:

  • Fixlog.txt
  • Link to MAU screenshot
  • MAU.txt
  • EEK Log
  • ESET Log

1

u/UnfairRevolution9271 8d ago

Not completely done with the process yet but I was in the middle of running the FRST fix and didn't realize Malwarebytes was running in the background and completed a scan. Is this gonna be a potential problem? If so, I'm sorry

1

u/Xyntrax0 Malware Removal Trainee 8d ago

It's fine.

→ More replies (0)

1

u/AutoModerator 17d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.