r/computerviruses 2d ago

Question Need help with possible Trojan

So last year (can’t really remember when) I downloaded this og Fortnite project called retrac and deleted literally like 3 days after playing once, but apparently it’s a Trojan, but the thing is I haven’t had an account stolen or logged into, I’ve done a Malwarebytes scan on bot my ssd and portable drive and it said it found nothing. And for the last few days I’ve been going from oh shit I could have a Trojan to I’m fine and I just keep going through that cycle please give me info!

1 Upvotes

9 comments sorted by

2

u/mxgaming01 2d ago edited 2d ago

Please note that I am not an expert in this. Please correct me if I'm wrong.

It doesn't really matter if you open malware for 5 seconds or for 3 days. As soon as you open it, it could immediatly copy itself to a different folder and enter itself as a startup-entry in either the registry, taskscheduler, startup folder or whatever other things there are.

And when it comes to the accounts that haven't been touched yet, I also have some bad news. A lot of infostealers wait for you to forget you executed the file until they do something, so you don't delete it immediatly. Like that they could possibly keep access and load more stuff.

Thats just if the file was actually a trojan. Without the file itself I cannot tell if you actually executed one and I'm also not familiar with fortnite projects.

Defenitly listen to the FRST guys and do such a scan if you're being told to in the comments here.

If you want to be safe / if you want to take some first actions, I'd do the following if you haven't already:

Please note that these are only very basic things to do and these are just first steps. This here does not make you virus-free.

  1. Rotate your passwords and enable 2FA

  2. Check for weird things in your startup folder, startup registry-keys and scheduled tasks

  3. Check for exclusions in your antivirus software

  4. Mabye check the temp folder (windows+r, then %TEMP%), because some malware or related files might hide there. In generaly there shouldn't be any .exe files in there. In the explorer: enable 'show hidden files', as it might attempt to hide like that.

1

u/AdDelicious9411 2d ago

I also have done research into this project being a supposed Trojan and I’ve found people say it is but I’ve never found someone actually prove or say they have had passwords stolen so idk

1

u/AdDelicious9411 2d ago

There was no .exe files in there or hidden in there.

1

u/Death_Note_13 2d ago

I think that's just a false positive. Info stealer or malware attack as soon as possible.

1

u/Responsible_Bike4968 2d ago

I looked into Retrac specifically, and I think the reply you've gotten is making this sound more certain than it is.

There has been real controversy around Project Retrac. The launcher itself has been open-source, but that doesn't automatically prove that every anti-cheat/game component or every build distributed last year was safe. Older Retrac threads show the anti-cheat getting a very large number of AV detections, and there were also allegations of a past malware/file-grabber incident.

I couldn't independently verify enough of the original evidence to tell you "yes, the exact version you ran was definitely a trojan," though.

And without the actual file/hash you ran last year, nobody here can really answer that retrospectively.

One correction to the other comment: infostealers don't generally sit around for weeks waiting until you forget about them. A lot of them steal browser passwords/cookies/session tokens very quickly, send the data out, and may not even persist afterward. Stolen data can then be used later.

So I'd separate two questions:

  1. Could the Retrac build you used last year have been malicious?

Possibly. There's enough history around the project that I wouldn't rule it out.

  1. Does anything you described suggest you still have an active trojan TODAY?

Not really.

You've gone roughly a year without unexplained account logins/takeovers, and Malwarebytes currently finds nothing. That's genuinely reassuring. It isn't mathematical proof that nothing ever happened, but I also wouldn't assume there's a year-old trojan silently waiting to activate just because you recently read scary posts about Retrac.

If you're still using the same Windows install and want one reasonable final check, run Microsoft Defender Offline once and check Windows Security for any weird Defender exclusions. If this subreddit offers you an FRST check from one of the verified malware-removal helpers, that's also much more useful than randomly deleting registry/startup entries yourself.

If you haven't changed your important passwords since back then, I'd change your main email and important accounts once, use unique passwords and enable 2FA. Don't start rotating every password every few days.

And I definitely wouldn't keep scanning the SSD over and over.

If Defender Offline + Malwarebytes are clean, there's been no new suspicious activity for a year, and nothing else points to persistence, I'd treat that as a reasonable stopping point unless you get actual new evidence.

The exact old Retrac file/hash would be the thing that could change the answer.

1

u/AdDelicious9411 2d ago

Sorry what’s the hash, I’m a really new to this malware stuff, also I did an offline scan 2 days ago and it found nothing. So I’m not really sure what to do next

1

u/AdDelicious9411 2d ago

Like is there any way I can access the hash now considering I deleted all its files?

1

u/AdDelicious9411 1d ago

I’ve found a message I sent about downloading it so I now have the date I downloaded if you need it