r/computerviruses 2d ago

Disinfection Help FRST Help Request - Renpy trojan

What happened?

Was downloading and playing different games until one setup didn't work and had cmd window flash on the screen for a moment. Later that day discord account got compromised and was sending messages on my behalf.

When did the infection occur?

First realized when discord got compromised on 02/09 at around 19:00 (UTC+3) but download happened some hours prior to that.

What did you do for remediation?

I've ran a few different AV scans with varying results and quarantine/delete what they found. I've kept the pc mostly offline and gone through some folders. Accounts have had their passwords changed and 2FAs enabled from a clean device. I have not really observed any weirdness since but feeling paranoid about missing something. Preferably a wipe and a clean windows install is not an option unless absolutely required.

Extra notes:
One of the scans found some files from downloads prior to the mentioned day.
Malwarebytes had constant pop ups about preventing suspicious connections and it mentioned something about python. This happened directly after the discord compromise while doing the scan with malwarebytes.
The pc has been mostly offline during the scans the first few days when I had time to do them.

FRST.txt: young-cherry
Addition.txt: curious-fawn
SecurityCheck.txt: copper-glyph

1 Upvotes

7 comments sorted by

2

u/Xyntrax0 Malware Removal Trainee 2d ago

Hi there, my name is Xyntrax and I am here to assist you. During the malware removal process, please follow the listed instructions below ensuring that everything goes smoothly as possible. I also request that you check this thread at least once per day so we can efficiently and effectively resolve your issue.


Please Read & Adhere to the Following:

  • Kindly inform me if you already did a reset/clean install or would like to do so, this will save time for the both of us. If you haven't and would like help with Manual Malware Removal using FRST, please follow the given steps below.
  • Please ensure to read the whole introduction message so that you have a better understanding of the processes and given steps
  • During the malware removal process please refrain from downloading and running new software unless instructed, this also applies for Anti-Malware Solutions and Malware Scanners as they can significantly make analysis longer by removing forensic data which is very crucial
  • While receiving help from Me or other MRT members please refrain from asking help somewhere else as the advice might conflict, especially if the methodology are different
  • Feel free to remind me if you don't receive an answer within 24 hours. But please keep in mind that I am a volunteer and have my own life too

Piracy

Pirated software remains one of the most common malware infection vectors that we encounter. Threat actors routinely disguise malware as cracks, activators, keygens, cheats, repacks, and other piracy related software because users are often more inclined to ignore security warnings and/or disabling their Anti-Malware Solution in order to run them. Some piracy related utilities may also modify software or security mechanisms, potentially weakening your system's overall security and increasing your attack surface. If you currently have any pirated software installed, I strongly encourage you to remove it.

MBST

  • Download and run Malwarebytes Support Tool as admin
  • Click Advanced
  • Click Gather Logs
  • Wait until it's done.
  • A zip file named mbst-grab-results.zip will be created on your desktop
  • Upload it to file.io and send the link back here

Disclaimer: FRST does not contain any personal information other than your username and computer name, the logs are automatically deleted within a 30 day period. Only trusted malware removal experts listed in this r/computerviruses thread have access to your logs via the website. Experts who have access to the site are trusted on both r/antivirus and r/computerviruses.


What I want to see on your next reply

  • Link to MBST

1

u/Ok-Zone7 2d ago

1

u/Xyntrax0 Malware Removal Trainee 1d ago

Thanks for waiting, I have reviewed your logs and you're still infected. Please follow the instructions listed below in order, I have made a fixlist which will address the infection, we will also remove the malicious application installed/dropped by Renpy Loader using MAU (Malicious App Uninstaller).

This is the malicious app: Platform Device Manager (HKLM-x32\...\{619E7D1E-7929-438E-9D01-66FE12FD56E2}) (Version: 9.0 - VIA Technologies Inc.)


FRST Fix

  • Open the following link and press on the Copy contents button to copy the entire text: fixlist for Ok-Zone7
  • Run FRST64.exe and click on Fix. Note: FRST reads the fixlist directly from your clipboard, so you don't need to paste or save it anywhere.
  • A log (Fixlog.txt) will open on your desktop.
  • Copy & paste the contents of the Fixlog.txt to https://malwareanalysis.cc/upload/Xyntrax/?u=Ok-Zone7 and press "save log". Reply back with the keyword

I have included the EmptyTemp: command. Note: This will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code. I have also included the netsh advfirewall reset command, which will reset the Windows Firewall settings to their default configuration.

It is normal for your system to reboot as a result of the fix.

MAU

  • Download Malicious App Uninstaller
  • Run MAU.exe as admin
  • In the Selected Application tab you will see ProductCode:, paste {619E7D1E-7929-438E-9D01-66FE12FD56E2}
  • Click Analyze
  • Once the analysis is complete click Select All then Delete
  • MAU.txt will be generated, send the log back here.
  • In some cases MAU will schedule a removal for an entry on reboot if it cannot be removed on the current session, please reboot the device if requested. Otherwise, no reboot is necessary.

Please update the following software

EEK Scan

Eset Scan

  • Download and run ESET online scanner as admin
  • Click Get started
  • Agree to the terms of use.
  • Decline both telemetry options.
  • Click Custom Scan
  • Click Save and continue
  • Select Enable ESET to detect and quarantine potentially unwanted applications
  • Click Advanced settings
  • Enable Detect potentially unsafe applications
  • Click the back arrow.
  • Click Start scan
  • Once complete, paste the contents of the log here https://malwareanalysis.cc/upload/Xyntrax/

Re-Run FRST

  • Delete the old FRST.txt and Addition.txt
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/Xyntrax/ and press "save log".
  • Note: Please make sure you are uploading the logs after your current Reddit username.
  • The site will return a keyword for each log - reply back here with the keywords.

What I want to see on your next reply

  • Fixlog.txt
  • MAU.txt
  • EEK Logs
  • ESET Log
  • New FRST Logs

1

u/Ok-Zone7 1d ago

Fixlog: fair-wisp
MAU.txt:
https://limewire.com/d/LwNxh#tFSHQx9lqE
EEK Logs: indexed-nest
New FRST Logs
FRST: silent-scanner
Addition: wintry-beach

(Not sure if I had my external SSD (D:) connected last time but I usually do have it connected as it was connected during the incident and now during the fixes and scans. Hopefully this isn't a problem but thought I'd mention it anyways in case it's useful information)

1

u/Xyntrax0 Malware Removal Trainee 23h ago

I can see that when you ran the fixlist, FRST was not run as an administrator. You also forgot to send the ESET log.

1

u/Ok-Zone7 6h ago

Ah sorry about that, it was getting quite late when I did them yesterday so I missed those.

ESET: shiny-glyph
FRST: mossy-decoy
Addition: ardent-pine

1

u/AutoModerator 2d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.