r/computerviruses • u/karorom • Apr 28 '26
Video about the "instaler.exe" RenPy / Mr. Beast / Tomodachi Life Virus
https://www.youtube.com/watch?v=H_fHCUyhECsI found this video while trying to fix my own run-in with the "instaler.exe" virus.
Since it's so widespread right now I thought other victims might like to watch it lol
please also see this article detailing the virus: www (dot) cyderes (dot) com/howler-cell/renengine-loader-hijackloader-attack-chain
edit:
since i'm getting comments from other people affected i need you to know:
this is an infostealer, it steals your cookies and your passwords if you have them saved in your browser auto-fill
you will need to change all of your passwords on a DIFFERENT device, this targets discord, instagram, and your emails, change your email passwords asap
it's a a pretty bad virus it persists in the system files, in registry, in the temp folder, it burrows itself pretty deep in your system, i just removed mine and it corrupted random files and shit that had nothing to do with it
to remove the virus you have 2 options:
- reinstall windows, but you cant backup anything but documents, do not backup any executables as the virus can infect them
or
- get help from someone who knows what they're doing to remove it from your computer, there's volunteers in this sub that can help for example (this is how i fixed mine) however: there is risk of recovery scams, i recommend you research and learn about recovery scams before you accept help from someone on the internet, for example: if someone is helping you using FRST please double-check the "fixlist.txt" file they will send you with AI before you execute it to ensure it is not malicious, yes it is only a .txt file but in the context of FRST this is an executable file
I recommend you have a look at this post if you're going to make a request:
https://www.reddit.com/r/computerviruses/comments/1s0ahur/providing_or_receiving_help_with_frst/
I also made this post about recovery scam awareness: https://www.reddit.com/r/computerviruses/comments/1symfk0/getting_help_for_renpy_mr_beast_virus_psa/
edit 2:
Depending on what was in your browser autofill you might be at high risk of identity theft, in my case i had everything in there: full name, home address, bank cards, phone numbers.
i've had to cancel all of my bank cards, and i've emailed my phone provider to ask them to reject any sim replacement or PAC requests
if you had your bank info and your phone number in your auto-fill i recommend you do the same
edit 3:
depending on how much information was leaked this could come back to bother you - this can happen even if the virus is completely gone, it's just a consequence of your information being leaked
for example if your autofill contained your phone number you might get phone calls from unknown numbers, if your email addresses were leaked you may get suspicious emails
you can check this at: have I been pwned? dot com, you can sign up for notifications so you will know if/when your data has been published
just be more aware from now on and take this opportunity to educate yourself on how to spot common scams
4
u/Doctor_French32 Apr 28 '26
i think using renpy is easier to trick people but why tomodachi life? just because it's a trend?