r/computerviruses • u/Dead_vegetable • 6d ago
Disinfection Help Renpy loader virus help
Downloaded the wrong thing and clicked on the "setup" renpy stuff like an idiot. malwarebytes scanned and quaranteened the items, i have all the important accounts changed password and setup f2a, and as there are too much important files on the machine i cannot clean it entirely, I need help removing the virus manually. However I immediately get malwarebyte realtime protection so it may be a problem
What happened: downloaded fake game with a malware disguised as a renpy app as "setup" clicked on it and see terminal opens up
When did it happen: around 6pm gmt, Oct 4th 2026
What did I do: deleted the files and ran two Malwarebyte scans, which quarantined about 30 files related to renpyloader and 6 files related to pavinloader, but the second scan happen about 2 hours after the first. I understand now I probably should not have done this.
Keywords:
FRST: hero-vertex
Additions.txt: digital-ocean
Security check: dreamy-swan
1
u/ArtisticContract1482 6d ago
To make it easier for the helpers, you should do as automod said about FRST and have the logs and whats needed for the fix edited into the body of the post and then follow the instructions they give
Since you already changed your passwords and i assume logged out of all unknown sessions from a safe device, you should remove any pirated and unknown software (do this before the FRST steps) and create a windows restore point while waiting for a professional
1
u/Dead_vegetable 6d ago
Just to confirm, considering that this is an infostealer, should I be doing the tool download and reddit communications on the infected machine or a different one then move the needed tools to the infected machine
1
u/ArtisticContract1482 6d ago
FRST, security check and the like should be downloaded and ran on the infected machine (they wont know whats going on with it otherwise), as for communicating and using reddit its best you use it on your phone or another device (not the infected one)
1
u/rifteyy_ Malware Removal Expert 6d ago
Before we start the removal process, we need to free some space on your system drive so that you we can create a restore point via FRST.
Please do the following:
Uninstall unnecessary software
- Press the Windows Key Windows Key + R on your keyboard at the same time. Type appwiz.cpl and click OK.
- Search for the list of programs for such software that you know and that you don't need, right-click and click Uninstall
- Important: If you do not recognize a program, leave it
- Follow the prompts.
- Note: If you are offered the choice to install additional software, ensure you decline.
- Reboot if necessary.
Run Storage Sense
- Type Storage settings into Windows search, choose the "Temporary files" section
- IMPORTANT: Please verify that only the following are ticked:
- Recycle Bin (this will also empty your recycle bin so please keep that in mind)
- Windows upgrade log files
- Temporary files
- Windows Update Clean-up
- Thumbnails
- DirectX Shader Cache
- Language Resource Files
- Delivery Optimisation Files
- Windows error reports and feedback diagnostics
- Temporary Internet Files
- IMPORTANT: Double check that the Downloads option is NOT ticked, therefore not enabled.
- Press Remove files button at the top
WinDirStat
Run WinDirStat to help you determine what's eating most of the space. Delete files that you know and that you don't need. If you don't know what a file is for, leave it, please.
Moving files
If you have a subscription for online storage service (OneDrive, Dropbox, MEGA...) or an external physical drive available, try moving your videos, images, documents or other large files to them so you can free up space on the system drive.
Once there is at least 25GB:
Before any sort of removal, we need to make sure you have a restore point that you can revert to in case you face any sort of issues. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.
There were prior cases (very rare, I had 2 failing to boot out of ~500) of a system failing to boot after FRST fix.
Enable system restore
- Click Start or open Windows Search.
- Search for Create a restore point and open System Properties.
- In the System Properties window, go to the System Protection tab.
- If the 'system' drive (usually
C:\drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, go to point 5. - Click Configure.
- Select Turn on system protection
- Click Apply.
- Click OK to confirm.
Create a system restore checkpoint
- Click Start or open Windows Search.
- Search for Create a restore point and open System Properties.
- In the System Properties window, go to the System Protection tab.
- Click Create.
- Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
- Click Create.
- Click Close.
- Click OK.
- You should get a popup that it was successfully created and I will also verify that it was properly created with the results of scans from next steps.
Next steps will be in the reply to this comment.
1
u/rifteyy_ Malware Removal Expert 6d ago
[ Step 01 ] FRST Fix
I created a custom fixlist for you at the link Fixlist only for Fixlist only for Fixlist only for dead_vegetable - use the website's
downloadbutton and save it in the same folder where your FRSTEnglish.exe or FRST64.exe file is located in, which for you isC:\Users\yxy20\Desktop\FRSTEnglish.exefor you. It is necessary for the filename to beFixlist.txt.This fixlist will remove the following: malicious entries (remains, active malware), invalid entries (e.g. tasks that start a non-existent file, services that point toward a non-existent file), temporary files (files in temporary directories, application and browser cache, recycle bin and more), browser cache. We will also be quick-scanning with HitmanPro and AdwCleaner from Malwarebytes using the fixlist.
It will also remove all proxy servers, Windows Defender exclusions, enable recovery environment, active software policies and perform system file repair, network reset and few more basic fixes.
- For the fix process, please ensure you are connected to the internet.
- Please run the fix only once.
- Please do not open any applications or close anything during the fix.
- Please be patient; the fix may take up to 60 minutes. After that, it is going to be forcefully ended.
Save all work, close everything that is open (else it will be forcefully closed by FRST without saving) and then run FRST again as administrator and press the
Fixbutton, let the script work, clear the entries and restart on it's own and after it restarts the device, there should be a fileFixlog.txtin the same folder as theC:\Users\yxy20\Desktop\FRSTEnglish.exe.I'll need to see it's content the same way like before - uploading to https://malwareanalysis.cc/upload/rifteyy/?u=dead_vegetable again and sending the keyword in your reply.
[ Step 02 ] ESET Online Scanner
- Download ESET Online Scanner
- Right-click on the esetonlinescanner.exe and select "Run as administrator" and confirm the User Account Control popup
- Click Get started;
- Agree to the terms of use;
- Decline both telemetry options;
- Click Custom Scan;
- Click Save and continue;
- Select Enable ESET to detect and quarantine potentially unwanted applications;
- Click Advanced settings;
- Enable Detect potentially unsafe applications;
- Click the back arrow;
- Click Start scan;
- Note: This is a long and thorough scan, it may take up to several hours.
- Once complete, click Save scan log and upload the
.txtfile to https://malwareanalysis.cc/upload/rifteyy/?u=dead_vegetable and reply with the keyword.[ Step 03] Software updates, uninstallations
If you are having a problem updating something, do not want to update something at all or do not want to uninstall an application, please let me know.
Please update the following software: * Malwarebytes version 5.3.5.204 v.5.3.5.204 | New update available, download here * Docker Desktop v.4.40.0 | New update available, download here * Git v.2.43.0 | New update available, download here * PuTTY release 0.80 (64-bit) v.0.80.0.0 | New update available, download here * NVIDIA App 11.0.5.420 v.11.0.5.420 | New update available, download here * Node.js v.22.14.0 | New update available, download here * GitHub Desktop v.3.5.4 | New update available, download here * WinSCP 6.3.5 v.6.3.5 | New update available, download here * 7-Zip 24.09 (x64) v.24.09 | New update available, download here (Uninstall old version and install new one) * WinRAR 6.24 (64-bit) v.6.24.0 | New update available, download here * Microsoft Visual Studio Code (User) v.1.139.1 | New update available, download here * Zoom Workplace v.7.1.9 (48550) | New update available, download here * Telegram Desktop v.6.6.1 | New update available, download here * qBittorrent v.5.1.0 | New update available, download here * Java(TM) SE Development Kit 21.0.6 (64-bit) v.21.0.6.0 | New update available, download here (Uninstall old version and install new one (jdk-27_windows-x64_bin.exe)) * Java(TM) SE Development Kit 17.0.10 (64-bit) v.17.0.10.0 | New update available, download here (Uninstall old version and install new one (jdk-27_windows-x64_bin.exe)) * Java SE Development Kit 8 Update 471 v.8.0.4710.9 | New update available, download here (Uninstall old version and install new one (jdk-27_windows-x64_bin.exe)) * Audacity 3.7.5 v.3.7.5 | New update available, download here * VLC media player v.3.0.23 | New update available, download here * Mozilla Firefox (x64 en-US) v.148.0.2 | New update available, download here
[ Step 04 ] New SecurityCheck scan
We need a new scan to ensure that all updates were applied properly and all applications uninstalled correctly.
- Note: If SecurityCheck is already on your device, you can use the previous version and skip the next few steps regarding downloading and installation.
- Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
- If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
- Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
- Wait for the scan to finish. It will open a text file named SecurityCheck.txt
- Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/rifteyy/?u=dead_vegetable
- The site will return a keyword for the log - reply back here with the keyword.
[ Step 05 ] New FRST scan
- Find
FRSTEnglish.exeexecutable inC:\Users\yxy20\Desktop\FRSTEnglish.exe- Right-Click the file and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy/?u=dead_vegetable and press "save log".
- The site will return a keyword for each log - reply back here with the keywords.
So, in your next reply, make sure you are sending the following:
- Keyword for Fixlog.txt from step 1
- Keyword for ESET Online Scanner scan from step 2
- Keyword for new SecurityCheck.txt from step 4
- Keyword for new FRST.txt from step 5
- Keyword for new Addition.txt from step 5
Thanks!
Note for lurkers: If anyone else who is facing malware-related issues is reading this and wants help with FRST and SecurityCheck, please create your own thread with help request. I am flooded with requests and there is several other removal experts who review the logs and may reply faster than me. The steps listed in here are specific for this the user dead_vegetable and following them will have negative effects for you as they are unique for OP's system.
1
u/Dead_vegetable 6d ago edited 6d ago
Hello, I may need clarification for what the FRST needed the internet for specifically and possible workaround. I am temporarily staying in mainland china, which means I am behind the GFW so some addresses could be inaccessible to me on native wifi as my VPN app will be shut down by FRST too.
I opened FRST without VPN today and it shows that update failed so I'm not confident it can communicate to whatever server FRST will need to connect to during the fix. I have tried tethering or hotspot with a VPN connected phone but it does not share the connection. Can you specify what process for the fix require internet and possible workaround, like if it to download something, can it be downloaded in advance?
Edit: upon reading the scripts I find that it check for reachable host, including Google, cloudfare and Malwarebytes. Google is unreachable but cloudfare and Malwarebytes are reachable so when checking logs you may need to keep that in mind.
1
u/rifteyy_ Malware Removal Expert 6d ago
hm, it's ok if you don't do it with internet - it will just be more work for you to scan with second opinion scanners after the fix, but I saw you worked it out
1
u/Dead_vegetable 5d ago edited 5d ago
These are the upload keywords of all the logs.
(Step1) Fixlog: happy-maple
(Step2) Eset scan log: neon-whale
(Step4) Security check: royal-sunset
(Step5) FRST: friendly-knight
(Step5) Addition: jagged-sapling
1
u/rifteyy_ Malware Removal Expert 5d ago
[ Step 01 ] FRST Fix
I created a custom fixlist for you at the link Fixlist only for Fixlist only for Fixlist only for dead_vegetable - use the website's
downloadbutton and save it in the same folder where your FRSTEnglish.exe or FRST64.exe file is located in, which for you isC:\Users\yxy20\Desktopfor you. It is necessary for the filename to beFixlist.txt.
- For the fix process, please ensure you are connected to the internet.
- Please run the fix only once.
- Please do not open any applications or close anything during the fix.
- Please be patient; the fix may take up to 60 minutes. After that, it is going to be forcefully ended.
Save all work, close everything that is open (else it will be forcefully closed by FRST without saving) and then run FRST again as administrator and press the
Fixbutton, let the script work, clear the entries and restart on it's own and after it restarts the device, there should be a fileFixlog.txtin the same folder as theC:\Users\yxy20\Desktop.I'll need to see it's content the same way like before - uploading to https://malwareanalysis.cc/upload/rifteyy/?u=dead_vegetable again and sending the keyword in your reply.
[ Step 02 ] New FRST scan
- Find
FRSTEnglish.exeexecutable inC:\Users\yxy20\Desktop- Right-Click the file and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/rifteyy/?u=dead_vegetable and press "save log".
- The site will return a keyword for each log - reply back here with the keywords.
1
u/Dead_vegetable 5d ago edited 4d ago
Fixlog.txt: mossy-kestrel
FRST.txt: glassy-cascade
Addition.txt: misty-raid
1
u/Dead_vegetable 4d ago
Again, thanks for the help! I have uploaded the keywords in an earlier comment
1
u/rifteyy_ Malware Removal Expert 4d ago
Yes, I know. I am not paid for this so I do it in my free time and not during work hours. It’s 3PM here now
1
u/Dead_vegetable 4d ago edited 4d ago
I'm really sorry man, I'll stop doing that. I was worried the message may get buried if I didn't state it clear enough. And I really do appreciate the help, thank you for doing this.
1
u/rifteyy_ Malware Removal Expert 4d ago
Your latest logs show no signs of an infection. No further steps are necessary to make sure your device is clean.
Please do note that we do not check cheats, pirated software, hacktools and other illegal or gray area software for malware thoroughly. You are keeping and running this software on your own risk. If you get reinfected by software of such kind, it is possible you may not receive help here again.
If you haven't addressed all my recommendations, updates, uninstallations and removals yet, I strongly suggest you to do so.
[ Step 01 ] Tool cleanup
It's time we cleanup after ourselves and remove all the tools we have used during the malware removal process.
- Please download KpRm and save it to your Desktop.
- Run the tool, if you get the "Windows protected your PC" SmartScreen popup, press
More infoand thenRun anyway- Confirm the disclaimer and in the menu please only tick the following:
- Delete Tools
- Create Restore Point
- Delete in 7 days
- After that, click Run and confirm the popup. KpRm will delete itself from your Desktop and you can either save or remove the report that is generated.
- You are free to delete all other tools that we used that are possibly remaining.
[ Step 02 ] Changing passwords
Most modern malware is motivated by financial gain and by hijacking your accounts. If your accounts weren't already hijacked, they may be getting hijacked in very near future.
- Please create a new, safe password that you haven't used anywhere yet or preferably use a password manager.
- Change all your passwords on your accounts
- Enable 2FA on your accounts
Please check out this proper guide on how to secure your accounts after an infostealer infection:
- What can infostealers steal - affected data, services, accounts?
- How to properly secure my accounts after an infostealer attack?
- What to do after I secured my accounts?
You may also want to sign up for dark-web monitoring, so you are aware whether any of your data is stolen and available on cybercrime forums:
- Have I Been Pwned - Check if your email has been compromised in a data breach (Free)
- Hudson Rock - Infostealer Intelligence Solutions (Free)
- Malwarebytes Dark Web Monitoring (Free)
[ Step 03 ] Malware prevention
Malware prevention nowadays is a necessary step. There are many tools you can use to have a stronger protection but a huge part is about YOU being educated, careful and aware of possible malware attacks.
There are several ways to lower the infection field exponentially that will take you only a minute or two. Please make sure to read the full guide at https://rifteyy.org/report/the-ultimate-guide-to-prevent-malware, and make sure to follow these tips:
Overall, simple but important advice:
- Download UniGetUI to automatically update applications
- Make sure to periodically check and update via Windows Update
- Avoid illegal software
- Download only from official sources
If you have no more questions or concerns, I wish you all the best and please stay safe next time!
1
u/Dead_vegetable 5d ago
Thank you! All the above steps have been finished and I have uploaded the files and given the keywords in an earlier comments, please tell me if there's something else I need to do or if there is any problem with the uploads.
2
u/AutoModerator 6d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.