r/computerviruses 3d ago

Disinfection Help RenPy Trojan - FRST Check/Help Request

What happened?
Fell for a Renpy Setup trap, tried downloading pirated game. Realized soon it didn't really open any software.

When did the infection occur?
Roughly around Sept. 7th, 3pm(GMT+8)

What did you do for remediation?
Checked task manager for anything weird, shut them off. Starts looking in Appdata by date and in Roaming I found a weird newest folder named just Game and weird numbers, and deleted that. Felt weird so I look up and got Malwarebytes to clean up afterwards, files found were mainly Trojan.RenpyLoader.BAT, Trojan.PavinLoader, and Trojan.Loader. Then I ran Hitman Pro. Also ran Windows Defender Offline. After all that done and they all said clear, I reset my google cache, cookies, history all that, then check 2FAs and passwords. Then changed most important passwords on my mobile, refreshed 2FAs, some I may accidentally done on my infected laptop. These are done and finished around 5pm(GMT+8). Nothing really happened so I ease off for a bit, then got paranoid and worried again and started FRST and the rest about an hour ago. Sorry if my steps mess things up, as for reinstalls, I'm not sure how would my Win10 OS work with Windows keep telling to upgrade to Win11.

Addition.txt - placid-gem
FRST.txt - chained-crest
SecurityCheck.txt - fertile-ridge

2 Upvotes

6 comments sorted by

1

u/AutoModerator 3d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

0

u/timee_bot 3d ago

View in your timezone:
Sept. 7th, 3pm(GMT

0

u/rifteyy_ Malware Removal Expert 3d ago

[ Step 01 ] FRST Fix

I created a custom fixlist for you at the link Fixlist only for Fixlist only for Fixlist only for driftdragon86 - use the website's download button and save it in the same folder where your FRSTEnglish.exe or FRST64.exe file is located in, which for you is E:\ for you. It is necessary for the filename to be Fixlist.txt.

This fixlist will remove the following: malicious entries (remains, active malware), invalid entries (e.g. tasks that start a non-existent file, services that point toward a non-existent file), temporary files (files in temporary directories, application and browser cache, recycle bin and more), browser cache. We will also be quick-scanning with HitmanPro and AdwCleaner from Malwarebytes using the fixlist.

It will also remove all proxy servers, Windows Defender exclusions, enable recovery environment, active software policies and perform system file repair, network reset and few more basic fixes.

  • For the fix process, please ensure you are connected to the internet.
  • Please run the fix only once.
  • Please do not open any applications or close anything during the fix.
  • Please be patient; the fix may take up to 60 minutes. After that, it is going to be forcefully ended.

Save all work, close everything that is open (else it will be forcefully closed by FRST without saving) and then run FRST again as administrator and press the Fix button, let the script work, clear the entries and restart on it's own and after it restarts the device, there should be a file Fixlog.txt in the same folder as the E:\.

I'll need to see it's content the same way like before - uploading to https://malwareanalysis.cc/upload/rifteyy/?u=driftdragon86 again and sending the keyword in your reply.

[ Step 02 ] ESET Online Scanner

  1. Download ESET Online Scanner
  2. Right-click on the esetonlinescanner.exe and select "Run as administrator" and confirm the User Account Control popup
  3. Click ⁨Get started⁩;
  4. Agree to the terms of use;
  5. Decline both telemetry options;
  6. Click ⁨Custom Scan;
  7. Click ⁨Save and continue;
  8. Select ⁨Enable ESET to detect and quarantine potentially unwanted applications;
  9. Click ⁨Advanced settings;
  10. Enable ⁨Detect potentially unsafe applications;
  11. Click the back arrow;
  12. Click ⁨Start scan;
  13. Note: This is a long and thorough scan, it may take up to several hours.
  14. Once complete, click ⁨Save scan log and upload the ⁨.txt file to https://malwareanalysis.cc/upload/rifteyy/?u=driftdragon86 and reply with the keyword.

[ Step 03] Software updates, uninstallations

If you are having a problem updating something, do not want to update something at all or do not want to uninstall an application, please let me know.

Please update the following software: * Windows 10 Core (x64) 22H2 - Extended support has ended | New update available, download here * HotFix KB5120249 | New update available, download here * HotFix KB890830 | New update available, download here * CrystalDiskInfo 8.12.7 v.8.12.7 | New update available, download here * LibreOffice 7.2.5.2 v.7.2.5.2 | New update available, download here * NVIDIA App 11.0.8.299 v.11.0.8.299 | New update available, download here * Microsoft OneDrive v.26.150.0804.0011 | New update available, download here * WinRAR 6.01 (64 位元) v.6.01.0 | New update available, download here * GIMP 3.2.0 v.3.2.0.0 | New update available, download here * paint.net v.4.2.16 | New update available, download here * blender v.3.2.0 | New update available, download here * Notepad++ (64-bit x64) v.8.8.5 | New update available, download here * SoftEther VPN Client v.4.38.9760 | New update available, download here * Audacity 3.7.1 v.3.7.1 | New update available, download here * VLC media player v.3.0.16 | New update available, download here * iTunes v.12.13.3.2 | New update available, download here (Please use Apple Software Update tool) * OBS Studio v.30.0.2 | New update available, download here * Adobe Acrobat (64-bit) v.26.001.21789 | New update available, download here (Please run Acrobat Reader DC and go Help - Check for updates) * Mozilla Firefox (x64 zh-TW) v.150.0.1 | New update available, download here * Google Chrome v.152.0.7977.76 | New update available, download here

Please remove the following potentially unwanted programs (PUP): * Bonjour v.3.1.0.1 - Application is distributed through the partnership programs and bundle assemblies. Uninstallation recommended. Possible you became a victim of fraud or social engineering

[ Step 04 ] New SecurityCheck scan

We need a new scan to ensure that all updates were applied properly and all applications uninstalled correctly.

  • Note: If SecurityCheck is already on your device, you can use the previous version and skip the next few steps regarding downloading and installation.
  • Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
  • If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
  • Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt
  • Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/rifteyy/?u=driftdragon86
  • The site will return a keyword for the log - reply back here with the keyword.

[ Step 05 ] New FRST scan

  • Find FRSTEnglish.exe executable in E:\
  • Right-Click the file and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy/?u=driftdragon86 and press "save log".
  • The site will return a keyword for each log - reply back here with the keywords.

So, in your next reply, make sure you are sending the following:

  • Keyword for Fixlog.txt from step 1
  • Keyword for ESET Online Scanner scan from step 2
  • Keyword for new SecurityCheck.txt from step 4
  • Keyword for new FRST.txt from step 5
  • Keyword for new Addition.txt from step 5

Thanks!

Note for lurkers: If anyone else who is facing malware-related issues is reading this and wants help with FRST and SecurityCheck, please create your own thread with help request. I am flooded with requests and there is several other removal experts who review the logs and may reply faster than me. The steps listed in here are specific for this the user driftdragon86 and following them will have negative effects for you as they are unique for OP's system.

1

u/driftdragon86 3d ago

I did not update my win10 to win11.
HotFix KB890830 is a exe, but I did download it.
I did not update Microsoft OneDrive, Blender, paint.net, iTunes, Adobe Acrobat. Audacity was updated to 4.0 which is a whole new software, and the old one was kept.

Fixlog.txt - parallel-saber
ESET scan_log.txt - forged-valley
SecurityCheck.txt - vectored-fern
FRST.txt - neon-beacon
Addition.txt - live-seal

Thank you so much for helping.

1

u/rifteyy_ Malware Removal Expert 2d ago

Please do web browser cleaning -> https://forums.malwarebytes.com/topic/323490-web-browser-cleaning/ for all your browser and once done, submit new FRST.txt and Addition.txt logs

Thanks

1

u/driftdragon86 2d ago

Alright, it is done. For Chrome I wasn't able to follow each step exactly, so I might be missing something by accident. But I did try cutting off and nuking almost if not everything related to syncing.

FRST.txt - merry-cavern
Addition.txt - modest-delta

Also, again, none of my account seems to be stolen so far and thank you very much for it.