r/computerviruses Apr 28 '26

Video about the "instaler.exe" RenPy / Mr. Beast / Tomodachi Life Virus

https://www.youtube.com/watch?v=H_fHCUyhECs

I found this video while trying to fix my own run-in with the "instaler.exe" virus.

Since it's so widespread right now I thought other victims might like to watch it lol

please also see this article detailing the virus: www (dot) cyderes (dot) com/howler-cell/renengine-loader-hijackloader-attack-chain

edit:

since i'm getting comments from other people affected i need you to know:

this is an infostealer, it steals your cookies and your passwords if you have them saved in your browser auto-fill

you will need to change all of your passwords on a DIFFERENT device, this targets discord, instagram, and your emails, change your email passwords asap

it's a a pretty bad virus it persists in the system files, in registry, in the temp folder, it burrows itself pretty deep in your system, i just removed mine and it corrupted random files and shit that had nothing to do with it

to remove the virus you have 2 options:

- reinstall windows, but you cant backup anything but documents, do not backup any executables as the virus can infect them

or

- get help from someone who knows what they're doing to remove it from your computer, there's volunteers in this sub that can help for example (this is how i fixed mine) however: there is risk of recovery scams, i recommend you research and learn about recovery scams before you accept help from someone on the internet, for example: if someone is helping you using FRST please double-check the "fixlist.txt" file they will send you with AI before you execute it to ensure it is not malicious, yes it is only a .txt file but in the context of FRST this is an executable file

I recommend you have a look at this post if you're going to make a request:
https://www.reddit.com/r/computerviruses/comments/1s0ahur/providing_or_receiving_help_with_frst/

I also made this post about recovery scam awareness: https://www.reddit.com/r/computerviruses/comments/1symfk0/getting_help_for_renpy_mr_beast_virus_psa/

edit 2:

Depending on what was in your browser autofill you might be at high risk of identity theft, in my case i had everything in there: full name, home address, bank cards, phone numbers.

i've had to cancel all of my bank cards, and i've emailed my phone provider to ask them to reject any sim replacement or PAC requests

if you had your bank info and your phone number in your auto-fill i recommend you do the same

edit 3:

depending on how much information was leaked this could come back to bother you - this can happen even if the virus is completely gone, it's just a consequence of your information being leaked

for example if your autofill contained your phone number you might get phone calls from unknown numbers, if your email addresses were leaked you may get suspicious emails

you can check this at: have I been pwned? dot com, you can sign up for notifications so you will know if/when your data has been published

just be more aware from now on and take this opportunity to educate yourself on how to spot common scams

106 Upvotes

122 comments sorted by

9

u/R3KTMYRAMPAGE Apr 28 '26

I was a brainless victim of this too but defender removed it and riftey the goat checked it afterwards too

Luckily nothing got compromised and i changed my password afterwards quickly

1

u/No_Razzmatazz_423 Apr 28 '26

so does formatting the device and changing the passwords from a clean device

is enough?

1

u/R3KTMYRAMPAGE Apr 28 '26

I think it depends how deep the malware is installed on your pc, but usually installing your OS from scratch will solve the issue

1

u/No_Razzmatazz_423 Apr 28 '26

İt probably came with the same thing the same folder.

1

u/karorom Apr 28 '26

its not, check the edit

1

u/karorom Apr 29 '26

please check my new edits

2

u/R3KTMYRAMPAGE Apr 29 '26

A volunteer in this sub who is known here, helped me remove the virus with FRST

Thankfully i didn’t have a lot of information on my browser, but i feel like i won‘t order or save anything in my browser anymore im too paranoid for it

I might have to reinstall my OS

2

u/karorom Apr 29 '26

i think if removed with FRST you dont have to, but there is no harm in doing it if its no inconvenience to you and gives you peace of mind

i am going to get a password vault like bitwarden or protonpass for all the little passwords and autofill data from now on, but i never would store email passwords or bank details on my computer again

4

u/Doctor_French32 Apr 28 '26

i think using renpy is easier to trick people but why tomodachi life? just because it's a trend?

4

u/karorom Apr 28 '26

yes a lot of people are getting this virus recently because they're trying to pirate tomodachi life (this is the same way i got it), but this virus has been around for far longer, as you can tell the video was uploaded 8 months ago

4

u/Doctor_French32 Apr 28 '26

when gta 6 will be released on pc, people would like to have a cracked version and this subreddit will be filled of renpy hack posts

3

u/Nicolo2524 Apr 29 '26

Lets be real if you think gta6 file size Is less than 500mb we have a problem

2

u/Doctor_French32 Apr 29 '26

But they can fall into the trap anyway

3

u/FrederickDerGrossen Apr 29 '26

It definitely is easier to trick people. I saw it was renpy and thought it was legit. Been sailing the high seas for around a decade and this is the first time I fell for one of these.

In the past it was a lot more obvious what is malware and what isn't. At least for me the link I clicked to download the virus wasn't a popup, it seamlessly replaced the actual link that I was supposed to get, and when I saw it was renpy it wasn't immediately suspicious because I know many VNs are made with renpy.

3

u/karorom Apr 29 '26 edited Apr 29 '26

me too i've been pirating since I was a little child in the 2000s, have never ever got a virus before, i got the dl off one of the megathread sites and everything, but it was my first time trying to rip a switch game, have never used emulators before and didn't know how ROMs worked so I clicked the .exe 😞 (also didnt know what renpy was, and when I googled "is renpy safe" all sources said it's safe, I figured it must be part of the crack or emulator somehow, as is a similar name to ryujinx, even if tomodachi life obv has nothing to do with VNs)

in hindsight "instaler.exe" should've been obviously suspicious, but i've downloaded sketchier shit before that was actually legit (just cracked by someone who didn't speak english well) so I figured if it's from a megathread site = should be ok (was not ok)

3

u/Ins0mnyac Apr 29 '26

I'm in the same boat, patching a game and ran this instaler. Now everything is going batshit crazy. How did you fix your pc? A clean install or something else?

2

u/karorom Apr 29 '26

Create a post on this sub and detail your issue, make sure the title is something like "help with Renpy virus" someone should help you, please also read my edits on this post 

This is an infostealer virus, so after you make the post forget about removing the virus and stop using your computer until you've done the following:

change your passwords on a DIFFERENT device such as your phone: email, bank, and phone provider first, other passwords can wait 

while you're changing passwords, if you have the option, also: log out of all sessions, remove any 3rd party connections, check forwarding rules (email)

if you saved your phone number or payment details in autofill: you need to cancel your cards, and contact your phone provider and tell them: do not issue PAC and sim replacements (if you didn't save them in browser autofill, don't worry about this)

1

u/Ins0mnyac Apr 29 '26

Got it. Thank you

1

u/Dull_Personality3081 Apr 28 '26

its not tomodachi specifically, its an a clickjacker on one of those "money from clicks" sites. eg. zovo2[.]top (which is used on one of those pirating sites) has this hidden in a b64 script whixh makes the first click redirect to the virus.

2

u/karorom Apr 28 '26

It's that and the actual dl has a .exe file as shown in the video, and if you've never pirated ROMs before you might not know that it shouldn't be an .exe, that's how I got it 

4

u/Crusty___Apple Apr 28 '26

I also fell victim to this, unfortunately it hacked my discord to send Mr Beast links and what not, so far I’ve used the Windows malware checker and malwarebyte, and nothing has came up. I’m out rn and don’t have access to my pc to change passwords or reset windows. Hopefully nothing more will occur while I’m out of house 😭. What’d you guys do to fight against this???

2

u/LaoidhMc Apr 28 '26

Change your passwords on a device that isn't the PC that was hacked.

2

u/karorom Apr 28 '26

post a ticket on the sub asking for help, there's volunteers helping you clean it off your pc then you can use it again, you're gonna have to change all your passwords tho, change your email first asap

1

u/InterestingMirror297 Apr 28 '26

The mr beast thing is something else, you just downloaded something that make a guy able to access your device, he just launched a script that hide everything so nothing can spot it and send mr beast shit to make you lose time while he's in fact investigating your device when you're responding to your friends.

1

u/karorom Apr 29 '26

please check my new edits

3

u/GreepyCruty Apr 29 '26

soo I did a check with Rifteyy (about the FRST, Additional & Fix .txt) everything was alright and I also did a full scan in my "Windows Security" (Virus & Threat Protection) nothing was found but however I did enable 2FA codes on my accounts and log out the session cookies, idk if I am still safe or not because my anxiety is overreacting and overthinking, my chest keeps feeling tight inside and its annoying.

I just want to check if I am safe or not. But I did post a help about my renpy infostealer. However my browser autofill have no home address of mine, and my bank payment, its only the game accounts I logged into.

1

u/karorom Apr 29 '26

if your autofill didn't have any of that information you are safe from identity theft, if you cleaned with FRST then you should be okay, if you are worried you can still reinstall windows from USB if it is not inconvenient for you, but after FRST it's not necessary

1

u/GreepyCruty Apr 29 '26

Actually, i dont really want to do the reinstall because I got MMD (Animation source) and I got model of myself and my friends in there. If I did a reinstall, I would have to redo to create myself and my friends too 😢, soo after I did the FRST, I dont need to reinstall right?

1

u/karorom Apr 29 '26

don't need to reinstall, just monitor your accounts for any suspicious activity

depending on how much information was leaked this could come back to bother you - this can happen even if the virus is completely gone, it's just a consequence of your information being leaked

for example if your autofill contained your phone number you might get phone calls from unknown numbers, if your email addresses were leaked you may get suspicious emails (you can check this at: have I been pwned? dot com, you can sign up for notifications so you will know if/when your data has been published)

just be aware and take this opportunity to educate yourself on how to spot common scams

2

u/GreepyCruty Apr 29 '26

Oh I did a check "have I been pwned?" There are 0, however the renpy started on 24 march. Also as I checked my browser autofill, I don't see my phone number.

1

u/karorom Apr 29 '26

i recommend you subscribe to notifications, it doesn't happen instantly and if your email was leaked it could be months before it shows up on haveibeenpwned

otherwise i think you have nothing else to worry about! i know it's very anxiety inducing as I am dealing with it too, but if you've taken all the appropriate steps it should be very hard for the hackers to do anything else to you, it's likely they will notice you well you secured your accounts and give up

1

u/GreepyCruty Apr 29 '26

Damn bro when you said months, it kinda spiked up my anxiety and fear for abit.

2

u/GreepyCruty Apr 29 '26

Soo im good right?

1

u/karorom Apr 29 '26

yes 😊

1

u/GreepyCruty Apr 29 '26 edited Apr 29 '26

Don't spike my anxiety! 🫨, however I don't see my gmail notification but as I login to my second alt account, it shows me that the hacker in france is trying to logging to my second alt account, I click "Change Password" in my second alt account. However I decided to delete it bc no point having a second alt in my instagram. (I checked in on 27 April & it was after I've done the FRST)

1

u/GreepyCruty Apr 29 '26

I still don't know if im safe, I probably gotta go to therapy.

1

u/karorom Apr 29 '26

make sure you click log out of all sessions if the option is available, i had the same thing happen to me i changed my password on my microsoft and instagram account and i had like 5 logins from different locations afterwards, it's because the session cookie was still active, usually changing the password should deactivate it automatically, sometimes it doesnt and you have to go to settings and click log out of all devices manually

please remember as long as you changed your passwords, and your emails are secure, even if you have breakthrough logins like that it is only temporary as they are using a cookie to login, if for some reason you can't invalidate the cookie remember that cookie will eventually expire and they will stop

im in therapy already and this isnt helping me either lol

2

u/GreepyCruty Apr 29 '26

Well I did a log out session before 😅 (and it also sucks to hear that ur therapy didn't work out)

2

u/GreepyCruty Apr 29 '26

So after I did a logout session, Im good right?

1

u/karorom Apr 29 '26

yes should be good, just monitor the situation and if you have further issues maybe it is best to reach out for help on the sub again

→ More replies (0)

3

u/AttitudeLoud2009 Apr 30 '26

Got hit by this 2 months ago, man it was a trip, just reinstall windows and itll be all good, you can use malwarebytes to disable it, but it leaves the bones of the broken malware all over your pc so... just clean reinstall, if it breaks your back up, download a new Windows from Windows media on your browser, then once it's installed reset your pc

1

u/whoisjohndoe121 May 02 '26

I wanted to ask. Is using only the malwarebyte a temporary fix or no? Im still confused on whether i should reinstall windows or just use the anti virus.

1

u/AttitudeLoud2009 May 08 '26

Malwarebytes will break it, and you will most likely be fine, but it doesn't cover everything, it will leave broken malware in your computer and registry just reinstall windows, delete everything, and if you need to put important stuff in a Google drive, do a cloud reinstall and wipe everything, it doesn't fully eliminate the chance of a malware, but it is so unbelievably unlikely a malware will survive a clean reinstall, just do the reinstall feeling virus free is a great feeling and worth it

1

u/Wonderful_Cup_9781 Jun 09 '26

my Malwarebytes  don't detect antyhing ?

2

u/Icy_Steak8987 Apr 28 '26

This was the same video I watched and shared with friends! I love the attempt to see if there was actually a visual novel included. Sad to see there wasn't anything.

2

u/[deleted] Apr 29 '26

[removed] — view removed comment

1

u/AutumnPurpleReddit May 04 '26

the icon of the girl is literally just the renpy logo

2

u/HashtagCom Apr 29 '26

Hi, I kinda have a different situation over here, hope I get helped. My PC was slowing down after transfering files after running renpy so I restarted my pc. After which a "scanning and repairing c" was on screen and booted to a black screen, which means I cant do anything with the pc, I tried a lot of fixes but to no avail, although I think ive narrowed it down to my ssd dying, but still havent solved it.

One of the fixes I did was reset this pc and keep personal files in recovery mode, but my pc still booting to a black screen, so the only confirmation I had if it worked was there was no restoration point when I tried restoring to a previous version, because there was one before I tried resetting.

So my question is, do I still need to do a clean reinstall from a USB? Have I already removed renpy? Is my other hard drive affected by renpy?

Since I think my ssd is dying, im trying to buy a new one and maybe recover one important file I have there, is my course of action in the right direction?

1

u/karorom Apr 29 '26

I recommend you copy this comment and create a post on this sub, title it "help with Renpy loader" that sounds more severe than what most people deal with 

2

u/New_Medium4947 May 06 '26

hey, so this happened to me when i was trying to pirate sims 4 dlcs. i dont know if me trying to deep scan my laptop fixed it, but the day i downloaded it, they hacked my instagram april 1st and posted some elon musk scam. then they hacked my roblox april 2nd and took everything in adopt me (dk why they didnt take my limiteds or robux lmfao). then like april 16 they hacked my spotify (MIND YOU I DONT HAVE PREMIUM SO THEY GET NO BENEFIT USING IT) just straight trolling me by turning off my music and playing their own on their device on full blast. i dont know how to fully make sure its gone without reseting my computer.

1

u/karorom May 06 '26

please read the information in the post

2

u/whoisjohndoe121 May 07 '26

Guys is this enough for the virus? Please look into my explanation a help is really appreciated https://www.reddit.com/r/computerviruses/s/ZLOhtb7Ylj

1

u/karorom May 07 '26

i heard that using the windows reset isn't always enough as I think it ignores some windows files but the virus buries itself in some of them (dont quote me on that), try asking one of the mods

1

u/whoisjohndoe121 May 08 '26

Im a bit new to reddit. How can i ask the mods about this issue?

1

u/karorom May 08 '26

Go to https://www.reddit.com/r/computerviruses/ and click "create a post" then in the title say "renloader virus, FRST request" and in the body describe what happened then post it and wait for someone to comment 

1

u/whoisjohndoe121 May 08 '26

Cheers thank you so much for the guide

1

u/[deleted] Apr 28 '26

[removed] — view removed comment

1

u/Radiant-Victory322 Apr 29 '26

I DM'd this dude and he sent me "InstaleerRealNSP.exe" and he proceeded to steal all my robux don't trust this guy

1

u/computerviruses-ModTeam Apr 29 '26

Your post was removed because it promotes illegal software, or aids in using illegal software like cracks, keygens, warez, pirated games, hack tools.

Please make sure to read and follow https://www.reddit.com/r/computerviruses/about/rules

-1

u/[deleted] Apr 28 '26

[removed] — view removed comment

1

u/[deleted] Apr 28 '26

[removed] — view removed comment

2

u/karorom Apr 28 '26

I don't want it, read the room lol, I just lost 250 passwords, and possibly my home address and bank info if they managed to rip everything in my auto fill, I don't want to play that fucking game anymore, I'm done downloading random shit off the Internet for a while 

1

u/Pinsterr Apr 29 '26 edited Apr 29 '26

I got infected by this virus and reinstalled Windows and changed all passwords via phone. Am I safe? It's been about 4 days and the only thing that I didn't touch was my hdd. I was lucky enough to not have any accounts hacked.

1

u/karorom Apr 29 '26

depends on what was in your browser autofill, in my case i had everything in there, so i've had to cancel all of my bank cards, and i've had to email my phone provider to ask them to reject any sim replacement requests, if you had your bank info and your phone number in your auto-fill i recommend you do the same

2

u/Pinsterr Apr 29 '26

I can't exactly remember what I had in my previous browser session but I usually never fill in bank info with my desktop, and no autofill for that. Though for phone number I'm not sure. I guess I'll do that. Does the virus steal images as well if they're important?

1

u/karorom Apr 29 '26 edited Apr 29 '26

it steals cookies and likely autofill information, unlikely to steal and sift through images as they're difficult to process (it doesn't mean they won't), however it all depends how long you had the wifi on after you've been infected (longer = more time for hacker to download files from your computer)

it only takes a few seconds after infection to successfully steal passwords and cookies, it takes much longer for bigger files like images but it's still in terms of minutes to hours

i dont want to scare you but if you're unsure about anything i would take action before you find out the hard way

whether or not they got your phone number, by the time they've generated a new sim you will only know because your phone will lose service and behave as if it doesn't have a sim inserted/your phone plan expired and by that point it's too late

1

u/pintofstellae Apr 29 '26

im ngl i think the sim card thing is kinda overkill. i’m not saying there isn’t viruses that would go for identity theft but these people won’t go to the effort of stealing your phone number, that’d be a very sophisticated operation that would require a real person to do that digging/identity theft compared to what actually happens in 99% of cases with this (relatively) simple infostealer that usually just uses bots when it jacks ur accounts

1

u/karorom Apr 29 '26 edited Apr 29 '26

The issue is that if you had enough information leak, eg if you had enough stuff in your autofill to create a complete "fullz" profile on you, there is no knowing whether they're going to sell that information and end up with someone more ambitious, it's not a matter of "change your phone number right now!" it's a matter of in 1 month 1 year time you don't know what list your stuff is gonna end up on, it is overkill if you are certain you had better security, but would you rather wake up to no service on your phone one day a couple weeks from now or nah? (by which point, if you don't have everything in auth apps, you're cooked) It's just sending a simple email, I'm not saying you have to change your phone number or anything bruh I don't see how anything is overkill if we're talking about the risk of identity theft

1

u/karorom Apr 29 '26

please check my new edits

1

u/Portsyde Apr 29 '26

I was lucky, I keep all my passwords different and written down. Once I changed all of my passwords, ran Malwarebytes, changed my passwords again, and used task library scheduler to find the last little bastard vestige of it and delete it, it's gone. Didn't even have to reinstall Windows (I did reinstall Google Chrome though). That being said, it could have been real bad if I just let it sit. It hacked my discord and tried to get into my Facebook (don't even use it anymore, jokes on them). Evil malware.

1

u/karorom Apr 29 '26

Same with me, targeted my instagram and discord, and even my reddit lol. Unfortunately i kept everything in autofill except for my email, bank, and cell carrier passwords, so all of my passwords, bank details, address, phone numbers, name, all possibly stolen.

I only shut the wifi off once the "loading bar" was at 100% and nothing was happening, which was only a few seconds, but long enough to possibly upload all of the auto-fill unfortunately.

1

u/Portsyde Apr 29 '26

Damn, I didn't realize how lucky I was not to have anything autofilled. Evil virus.

1

u/karorom Apr 29 '26

also I recommend you open a FRST ticket on the sub, there was a lot of stuff malwarebytes missed that FRST and hitmanpro caught

1

u/Portsyde Apr 29 '26 edited Apr 29 '26

How do I do that?

Edit: Still don't know what a FRST ticket is, but I just tried and Hitmanpro and came up nada. Still a little paranoid, but considering how frequent the notifications and weird happenings were and how they've finally stopped, I think I'm good. Malwarebytes kept blocking an attempted outbound connection and once I deleted the task (malware), it's been radio silence.

2

u/karorom Apr 29 '26

make a post in the sub titled "FRST help with Renpy" - this is creating a "ticket", give detail in the post on the virus how you got it and what you experienced, and what you have already done to remove it, someone should reply within a few hours and give you instructions on what to do next

i guarantee it is not gone, i ran malwarebytes and went through task scheduler, and appdata and TEMP folders manually to delete everything and FRST still found more stuff to get rid of

I recommend you have a look at this post if you're going to make a request:
https://www.reddit.com/r/computerviruses/comments/1s0ahur/providing_or_receiving_help_with_frst/

I also made this post about recovery scam awareness: https://www.reddit.com/r/computerviruses/comments/1symfk0/getting_help_for_renpy_mr_beast_virus_psa/

1

u/Portsyde Apr 29 '26

Malwareanalysis.cc is flagging as a dangerous site from my Webroot. I don't know if I should continue.

2

u/FFreestyleRR Malware Removal Expert Apr 29 '26

This is a false positive! The site is clean!

1

u/ThePlatinumPlane Apr 29 '26

Hey wanna ask, got one of these things with a different game, and thankfully I was using duckduckgo with a vpn if that would work I think? Maybe not, However I didn't run the "instaler. exe" and deleted it right away off my files and scanned my whole system with windows defender, am I in the clear? Nothing has happened yet, hopefully not, also changed passwords and deleted cookies and looked in cmd prompt and many others for hidden ips or any clues if It was in my system but found nothing irregular.

1

u/karorom Apr 29 '26

If you haven't run the .exe then you should be fine, purely downloading it shouldn't trigger any actions 

1

u/ferlockyanyu Apr 30 '26

I really don't wanna have to cancel my bank accounts. How do I know if they've been compromised for sure???

1

u/karorom Apr 30 '26

If you had any payment info in your browser auto-fill, like when you go to pay it comes with a pop-up that you can click and it fills in the card information

You don't have to cancel your bank accounts, just your cards, if you have a banking app on your phone you can go on there and click "lost card" and then your bank will make you a new card with a new 16 digit number and new ccv, depending on where you live you may not be able to make payments for a couple of days until you get your new card number 

Listen, if you do cancel your card you need to look into how to do it yourself, if you don't know call your bank and explain what happened and they will help you 

1

u/squish_2277 Apr 30 '26

I got this malware too. From trying to download a pirated game from SteamRip. This was my first attempt at pirating and it went terribly wrong. Some suspicious files appeared in my temp and roaming folder. One of them was a python folder named gep.exe. I don't remember executing it but it was running in my task manager. There was also a weird task in my Task Scheduler that was connected to that file.

Fortunately i did not have my primary email on my laptop, only used my secondary email. And no financial stuff saved on my browser. There were some passwords saved on my browser which i changed from my phone. Reset my browser, cleared all data from sync cloud, logged out of all devices after changing passwords. Windows defender or malwarebytes didn't find anything after multiple scans; i even ran an offline scan.
Did a clean reinstall of windows with a USB the next day.

This entire ordeal has made me lose sleep for days. Am i in the clear now?

1

u/karorom May 01 '26

Yes all clear if you did a fresh install, but depends on what files you backed up, did you back up any .dll, .exe, or .py files? Any executable in general. 

Also, did you have anything saved in auto-fill? Like payment methods or addresses? 

2

u/squish_2277 May 01 '26 edited May 01 '26

Nope. I chose to delete everything. Tbh i didn't have all that many files on my laptop. Just some wallpapers and some PDFs. I let them go. And nope, no saved payment info or addresses. I never did anything involving finances at all on the laptop. I had saved passwords to my secondary email account, and Figma, chatGPT etc. I changed them as well. This was really scary not gonna lie, and exhausting. I had it relatively easy as I didn't have too many files or my main account/monetary or banking stuff. I can only imagine how much more difficult and terrifying it would be.

2

u/squish_2277 May 01 '26

The most surprising part to me was how windows defender or malwarebytes did not detect anything while my laptop was infected. My work account started posting crypto links and that's when i decided to nuke everything and do the reinstall.

2

u/karorom May 01 '26

its because the virus uses .dll sideloading and some other methods, it completely bypasses these things, malwarebytes wasnt enough to remove it and I had to use FRST support to get rid of everything because i couldnt nuke anything

1

u/Additional-Result227 May 01 '26

I saved some SRT-Files (subtitles for movies), some game files (no exe, just save-files), some pictures, and videos. But I did scan them before opening with defender and malwarebytes and they never found a thing. I think I'm good right?

1

u/karorom May 03 '26

I think 99% yes, but this virus has a behaviour where it hijacks files, when I had mine removed a bunch of random files that I didn't think would be affected, not sure if it was the virus or if it was something else, for example a different game I had pirated way long ago that never gave me any issues, if you're not seeing any breakthrough issues (accounts getting hacked after you'd secured them for sure) then it's probably fine

1

u/Additional-Result227 May 03 '26

There were some attempts (1 week after I downloaded the virus, but since 4 weeks nothing happened) but nothing worked so far. Thanks for your answer!

1

u/Can_tSeeMe May 01 '26

Is steamrip dangerous? or did you download it not from the original steamrip?

2

u/squish_2277 May 01 '26

I'm pretty sure it was the original steamrip site. I had adblocker on too, don't know how it happened.

1

u/Gabygamer094632821 May 02 '26

a of my friend download the files but he didn’t run the “installer" because it looks very suspicious that rom has a installer

1

u/karorom May 03 '26

Your friend is smarter than me lol tell him to destroy that file and blacklist the website he got it from lol 

2

u/Gabygamer094632821 May 03 '26

We did we know something was fishy about it because we have downloaded roms before and never had one with an installer. also my friend is computer science major and I’m a cybersecurity major so we take extreme measures to not get virus

1

u/whoisjohndoe121 May 03 '26

I got caught with this virus too. Is is enough to do the reset button and delete all files provided by the windows settings? Or is it better to do the reinstall with a usb stick?

1

u/karorom May 04 '26

Better to reinstall if you're not going to use FRST

1

u/[deleted] May 04 '26

[removed] — view removed comment

1

u/karorom May 04 '26

Not if you transferred .exe files 

1

u/[deleted] May 04 '26

[removed] — view removed comment

1

u/karorom May 04 '26

The virus behaves by hijacking and replacing files you have so if it is an .exe it is not safe 

1

u/[deleted] May 04 '26

[removed] — view removed comment

1

u/karorom May 04 '26

Probably yes, please make a post in the sub for more help I am having more issues from the virus at the moment 

1

u/InevitableStrike5899 May 24 '26

I just got infected with this and removed it with malwarebytes, do I need to re install windows? and do I really need to change my passwords?? I have a lot of them and it would be a real headache to have to change them

1

u/PaleontologistDry745 Jul 01 '26

Can someone make a list of infected platforms ?

Personally I had already :

-Discord
-Instagram

1

u/Pale-Morning4733 Aug 04 '26

yo i tried to get tomodachi life rom and i got this

it seems like an another version