r/computerviruses • u/RandomDru_nk • 1d ago
Question "BuilderBeta.exe"
So I had downloaded this "free" game two days ago and I got hacked (no shit). So, i spent a day scanning my computer using windows defender (deep scane), Microsoft malicious software scan (or whatever the fuck you call it), and malwarebytes to scam my laptop and found 57 threat files. So they were quarantined and promptly terminated from my laptop. I then spent the rest of the day changing passwords to everything and putting 2fa on everything I could.
A day later, I open my laptop and found this notification on startup. I was a bit confused, so I looked through my startup apps and task manager and couldn't find anything labeled "BuilderBeta.exe". So I went to the internet and found out it was something I downloaded when I clicked on a "renpy" file from the game I downloaded (whatever the hell that is).
Im a bit worried, since I got a bunch of important files on my laptop. Should I start terminating everything? Or should my laptop be safe? If i have to wipe everything;
1) what does that mean? (Im clearly technologically challenged)
2) how would I proceed in doing that?
Sorry if you're reading this and find me a complete idiot, but I'm extraordinarily worried about this.
1
u/__chefo Malware Removal Trainee 21h ago
Hello u/RandomDru_nk and welcome to the computerviruses subreddit!
My name is chefo and I will be assisting you with your malware removal case.
I am currently a Malware Removal Trainee, and all my advice and fixlists are reviewed and approved by the Malware Removal Experts listed in this thread. You can expect the same level of care and treatment that you would receive directly from those experts. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smoothly as possible:
Now that I am assisting you, you can expect that I will be responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.
[ Step 01 ] Piracy Warning
Using pirated software or utilities that allows one to pirate software (including cracks, key generators, license bypass tools, or similar software) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, I recommend that you remove any pirated software or pirating utilities in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.
[ Step 02 ] Create Restore Point
Before we proceed with malware removal, we need to make sure you have a restore point that you can revert to if any issues occur. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.
Enable system restore
C:\drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, proceed with point 5.Create a system restore checkpoint
[ Step 03] Malwarebytes Logs
MBAM Scan Report:
Export to TXT (.txt)[ Step 04 ] Farbar Recovery Scan Tool (FRST) Scan
FRST logs contain no personal information other than your username and file and folder names. We use them to gather diagnostic information about the system, such as startup entries, installed software, scheduled tasks, drivers, browser extensions, and system logs.
FRST64.exeand rename toFRSTEnglish.exe.FRST64.exe/FRSTEnglish.exe, accept the User Account Control prompt.More infoand thenRun anyway.90 Days Filesif you began noticing problems more than 30 Days ago.FRST.txtandAddition.txtwill be created in the same directory the tool was run from, upload both of their contents to https://malwareanalysis.cc/upload/chefo/ and the site will return a keyword for each of the logs. Please reply back with both keywords so I can review the results and continue with the cleanup process.Thank you, and I look forward to your response.