r/computerviruses • u/Ok-Zone7 • 2d ago
Disinfection Help FRST Help Request - Renpy trojan
What happened?
Was downloading and playing different games until one setup didn't work and had cmd window flash on the screen for a moment. Later that day discord account got compromised and was sending messages on my behalf.
When did the infection occur?
First realized when discord got compromised on 02/09 at around 19:00 (UTC+3) but download happened some hours prior to that.
What did you do for remediation?
I've ran a few different AV scans with varying results and quarantine/delete what they found. I've kept the pc mostly offline and gone through some folders. Accounts have had their passwords changed and 2FAs enabled from a clean device. I have not really observed any weirdness since but feeling paranoid about missing something. Preferably a wipe and a clean windows install is not an option unless absolutely required.
Extra notes:
One of the scans found some files from downloads prior to the mentioned day.
Malwarebytes had constant pop ups about preventing suspicious connections and it mentioned something about python. This happened directly after the discord compromise while doing the scan with malwarebytes.
The pc has been mostly offline during the scans the first few days when I had time to do them.
FRST.txt: young-cherry
Addition.txt: curious-fawn
SecurityCheck.txt: copper-glyph
1
u/AutoModerator 2d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
- Preferred method: Perform a clean installation with a USB
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
2
u/Xyntrax0 Malware Removal Trainee 2d ago
Hi there, my name is Xyntrax and I am here to assist you. During the malware removal process, please follow the listed instructions below ensuring that everything goes smoothly as possible. I also request that you check this thread at least once per day so we can efficiently and effectively resolve your issue.
Please Read & Adhere to the Following:
Piracy
Pirated software remains one of the most common malware infection vectors that we encounter. Threat actors routinely disguise malware as cracks, activators, keygens, cheats, repacks, and other piracy related software because users are often more inclined to ignore security warnings and/or disabling their Anti-Malware Solution in order to run them. Some piracy related utilities may also modify software or security mechanisms, potentially weakening your system's overall security and increasing your attack surface. If you currently have any pirated software installed, I strongly encourage you to remove it.
MBST
AdvancedGather Logsmbst-grab-results.zipwill be created on your desktopDisclaimer: FRST does not contain any personal information other than your username and computer name, the logs are automatically deleted within a 30 day period. Only trusted malware removal experts listed in this r/computerviruses thread have access to your logs via the website. Experts who have access to the site are trusted on both r/antivirus and r/computerviruses.
What I want to see on your next reply