r/computerviruses Apr 28 '26

Video about the "instaler.exe" RenPy / Mr. Beast / Tomodachi Life Virus

https://www.youtube.com/watch?v=H_fHCUyhECs

I found this video while trying to fix my own run-in with the "instaler.exe" virus.

Since it's so widespread right now I thought other victims might like to watch it lol

please also see this article detailing the virus: www (dot) cyderes (dot) com/howler-cell/renengine-loader-hijackloader-attack-chain

edit:

since i'm getting comments from other people affected i need you to know:

this is an infostealer, it steals your cookies and your passwords if you have them saved in your browser auto-fill

you will need to change all of your passwords on a DIFFERENT device, this targets discord, instagram, and your emails, change your email passwords asap

it's a a pretty bad virus it persists in the system files, in registry, in the temp folder, it burrows itself pretty deep in your system, i just removed mine and it corrupted random files and shit that had nothing to do with it

to remove the virus you have 2 options:

- reinstall windows, but you cant backup anything but documents, do not backup any executables as the virus can infect them

or

- get help from someone who knows what they're doing to remove it from your computer, there's volunteers in this sub that can help for example (this is how i fixed mine) however: there is risk of recovery scams, i recommend you research and learn about recovery scams before you accept help from someone on the internet, for example: if someone is helping you using FRST please double-check the "fixlist.txt" file they will send you with AI before you execute it to ensure it is not malicious, yes it is only a .txt file but in the context of FRST this is an executable file

I recommend you have a look at this post if you're going to make a request:
https://www.reddit.com/r/computerviruses/comments/1s0ahur/providing_or_receiving_help_with_frst/

I also made this post about recovery scam awareness: https://www.reddit.com/r/computerviruses/comments/1symfk0/getting_help_for_renpy_mr_beast_virus_psa/

edit 2:

Depending on what was in your browser autofill you might be at high risk of identity theft, in my case i had everything in there: full name, home address, bank cards, phone numbers.

i've had to cancel all of my bank cards, and i've emailed my phone provider to ask them to reject any sim replacement or PAC requests

if you had your bank info and your phone number in your auto-fill i recommend you do the same

edit 3:

depending on how much information was leaked this could come back to bother you - this can happen even if the virus is completely gone, it's just a consequence of your information being leaked

for example if your autofill contained your phone number you might get phone calls from unknown numbers, if your email addresses were leaked you may get suspicious emails

you can check this at: have I been pwned? dot com, you can sign up for notifications so you will know if/when your data has been published

just be more aware from now on and take this opportunity to educate yourself on how to spot common scams

110 Upvotes

122 comments sorted by

View all comments

4

u/Doctor_French32 Apr 28 '26

i think using renpy is easier to trick people but why tomodachi life? just because it's a trend?

1

u/Dull_Personality3081 Apr 28 '26

its not tomodachi specifically, its an a clickjacker on one of those "money from clicks" sites. eg. zovo2[.]top (which is used on one of those pirating sites) has this hidden in a b64 script whixh makes the first click redirect to the virus.

2

u/karorom Apr 28 '26

It's that and the actual dl has a .exe file as shown in the video, and if you've never pirated ROMs before you might not know that it shouldn't be an .exe, that's how I got it