u/Callme_Kon

Hello there again! For context, I was hit with the infamous renpy installer infostealer on April 23. I since then reset my laptop keeping no files (2 times now), kept it disconnecred from the internet , and nothing weird has happened after securing my accounts. Today, I checked my laptop again and checked if my windows,old folder is empty and found this file named drupdate,dll inside.

So yeah really sorry if it's a stupid question but, what is it? Is it normal to be in windows,old folder or should I be concerned? From what I know, the infostealer can't survive a reset that keeps no files, but I can't really tell if this is normal 🥲 Any answers are appreciated!

u/Callme_Kon — 12 days ago

Last week, my discord spammed the Mr Beast crypto spam to 10 of my friends. Somehow it didn't send to any servers. It managed to get one of my alt accounts too (thankfully I had no friends there since it was just a backup account). I immediately reset my laptop and kept no files. I have my laptop disconnected from our wifi until I get to reinstall with a USB (I'm going to get help from my uncle). I still got suspicious logins 5 minutes or so after resetting my laptop, but I'm pretty sure that's because I hadn't reset my passwords yet. I reset the passwords, enabled 2fa, took off my phone number from my gmails of all my gmails and important accounts and hadn't gotten affected other than some failed logins that google managed to identify as suspicious and managed to block.

It's been a week now, and I keep agonizing over the worst possible scenarios that can happen even after all that. So now I am here to ask some (kinda stupid) questions that I have stuck in my head :')

-Is having my laptop disconnected from the internet and reset (I didn't keep any files) safe enough for now? I haven't touched my laptop since then other than running a windows defender scan. It was clean, but I'm too scared to connect it to the internet again. I'm still going to do the USB reinstall but I'd rather get help from my uncle to be safe. I'm scared that the virus will crawl out of my laptop and jump into our wifi, or something, but that's just my weird imagination I guess...

-Is it possible for it to infect other devices that were connected to the same internet when it happened? I found that the malware I got in my laptop was from a renpy exe installer. I saw another post saying that those contain themselves in the infected device, but I'm really worried that it'll affect my other devices or my mother's devices.

-Does the Mr Beast spam only happen in discord and instagram? This is mostly just a curious question but I haven't seen it do the same thing to Facebook or something. I've seen people have it log into their Facebook, but not the spam message thing specifically. My Discord and Instagram are pretty small, but my Facebook is friends with literally everyone since I was in elementary. I'd die of embarrassment if my past teachers received a Mr Beast scam message from me. I've changed the Gmail, password, and 2fa of my Facebook alot thanks to this.

Thankfully, I don't have any banking or financial information in any of my devices. I also don't really use autofill. The only other thing I'm worried about is the possibility of sim swapping since I put my phone number as a 2fa and recovery option on my gmails, but I took it out after I got hacked and replaced it with an authenticator app.

I check the devices in my gmail every hour religiously now and man I just want to be able to sleep properly again. I have OCD so I'm constantly paranoid about everything even more now after getting my accounts compromised. It's really one of my biggest fears come true.

Thank you a ton to anyone who can answer these, sorry if the post is so long :') So far, nothing weird has happened, but man I'm scared. I'm even going to get a new laptop now since it has spooked me out by that much...

reddit.com
u/Callme_Kon — 15 days ago