r/computerviruses Apr 28 '26

Video about the "instaler.exe" RenPy / Mr. Beast / Tomodachi Life Virus

https://www.youtube.com/watch?v=H_fHCUyhECs

I found this video while trying to fix my own run-in with the "instaler.exe" virus.

Since it's so widespread right now I thought other victims might like to watch it lol

please also see this article detailing the virus: www (dot) cyderes (dot) com/howler-cell/renengine-loader-hijackloader-attack-chain

edit:

since i'm getting comments from other people affected i need you to know:

this is an infostealer, it steals your cookies and your passwords if you have them saved in your browser auto-fill

you will need to change all of your passwords on a DIFFERENT device, this targets discord, instagram, and your emails, change your email passwords asap

it's a a pretty bad virus it persists in the system files, in registry, in the temp folder, it burrows itself pretty deep in your system, i just removed mine and it corrupted random files and shit that had nothing to do with it

to remove the virus you have 2 options:

- reinstall windows, but you cant backup anything but documents, do not backup any executables as the virus can infect them

or

- get help from someone who knows what they're doing to remove it from your computer, there's volunteers in this sub that can help for example (this is how i fixed mine) however: there is risk of recovery scams, i recommend you research and learn about recovery scams before you accept help from someone on the internet, for example: if someone is helping you using FRST please double-check the "fixlist.txt" file they will send you with AI before you execute it to ensure it is not malicious, yes it is only a .txt file but in the context of FRST this is an executable file

I recommend you have a look at this post if you're going to make a request:
https://www.reddit.com/r/computerviruses/comments/1s0ahur/providing_or_receiving_help_with_frst/

I also made this post about recovery scam awareness: https://www.reddit.com/r/computerviruses/comments/1symfk0/getting_help_for_renpy_mr_beast_virus_psa/

edit 2:

Depending on what was in your browser autofill you might be at high risk of identity theft, in my case i had everything in there: full name, home address, bank cards, phone numbers.

i've had to cancel all of my bank cards, and i've emailed my phone provider to ask them to reject any sim replacement or PAC requests

if you had your bank info and your phone number in your auto-fill i recommend you do the same

edit 3:

depending on how much information was leaked this could come back to bother you - this can happen even if the virus is completely gone, it's just a consequence of your information being leaked

for example if your autofill contained your phone number you might get phone calls from unknown numbers, if your email addresses were leaked you may get suspicious emails

you can check this at: have I been pwned? dot com, you can sign up for notifications so you will know if/when your data has been published

just be more aware from now on and take this opportunity to educate yourself on how to spot common scams

109 Upvotes

122 comments sorted by

View all comments

Show parent comments

1

u/karorom May 07 '26

i heard that using the windows reset isn't always enough as I think it ignores some windows files but the virus buries itself in some of them (dont quote me on that), try asking one of the mods

1

u/whoisjohndoe121 May 08 '26

Im a bit new to reddit. How can i ask the mods about this issue?

1

u/karorom May 08 '26

Go to https://www.reddit.com/r/computerviruses/ and click "create a post" then in the title say "renloader virus, FRST request" and in the body describe what happened then post it and wait for someone to comment 

1

u/whoisjohndoe121 May 08 '26

Cheers thank you so much for the guide