Aug 21, 2022
18
45
127
I'm confused on how to clean my computer, I had the infected file, I had the directory My super game in appdata, I deleted all that, no weird .exe file though.

I ran a complete scan from multiple antivirus and they didn't detect anything. how can I know if I have bad files to remove?
I saw that someone had some weird folders with infected files on their computer, I don't have those.

Fortunately, i don't have any password stored on my computer, and i hadn't to log in anywhere since I launched the game, but I would like to be sure the computer is safe before doing anything.
If you found the "mysupergame" folder it means that the malware was installed. Best advice, reinstall windows from an external device.
 

Bixter05

New Member
Jun 22, 2020
5
2
126
How long it's run for doesn't matter. Because the moment you run it, it executes the bad exe. What matters is when you ran it. If it was after the 20th (your time), the virus did its job.

This isn't the 5 second rule when you drop a fucking french fry on the floor and it's still good because the germs didn't get to it yet my guy lol
So i got the game on 20th on my time and immediately play on that date and finish it, i do get the mysupergame folder and other sus folder when i check this thread on 21st, but didnt open the game again and deleted all the game, download, and the sus folders, and my windows security give me warning about the mysupergame folder, did i need to do more action to remove the threat or im kinda save for now?
 

flannan

Engaged Member
Dec 15, 2022
3,449
3,659
377
So i got the game on 20th on my time and immediately play on that date and finish it, i do get the mysupergame folder and other sus folder when i check this thread on 21st, but didnt open the game again and deleted all the game, download, and the sus folders, and my windows security give me warning about the mysupergame folder, did i need to do more action to remove the threat or im kinda save for now?
Most likely, windows security has stopped the virus from activating when it gave warning. It is rather aggressive like that.
It might be worth it to get a one-time use antivirus (I usually get them from Dr. Web) and have it scan your computer.
From what I understand of other people's comments, it might be worth it to log out of all the sites you're logged in, and then log back in again. Fortunately, most sites don't keep you logged in for too long.
 
  • Like
Reactions: Bixter05

chizome123akaguro

New Member
May 4, 2024
9
5
38
i ran the game and it detects trojans. luckily my pc detected it immediately, it triggers when you open the game and spend a bit of time on it. Even if u deleted "mysupergame" in the appdata, once u launch the game again the trojan will activate again. Is any link even safe on this game? I downloaded in the main f95zone, are links in this thread different?
 
  • Like
Reactions: Armistal3

MiKaEl90

Member
Jun 25, 2017
253
342
181
Word of advice, install a firewall. It doesn't have to be a paid one. I use Windows Firewall Control for example but there are others as well. I'm not sure if I downloaded the infected version or not but most of the games you download will try to connect to the internet, be it renpy, rpg or even unity. I always block those requests using the firewall so even if you do get infected, if said virus can't send any data from your PC it's just a resoursce hog at that point but not an actual threat to your security. Since most of them act as gateways for other malicious code to run if you stop that execution it will also be a lot easier to clean later on.
 

Glastware

New Member
Dec 17, 2024
2
0
44
I'm confused on how to clean my computer, I had the infected file, I had the directory My super game in appdata, I deleted all that, no weird .exe file though.

I ran a complete scan from multiple antivirus and they didn't detect anything. how can I know if I have bad files to remove?
I saw that someone had some weird folders with infected files on their computer, I don't have those.

Fortunately, i don't have any password stored on my computer, and i hadn't to log in anywhere since I launched the game, but I would like to be sure the computer is safe before doing anything.
IMO if you are paranoid, the safest way is to just reinstall window from external USB drive. You can delete drive partition from there and reset from zero.
 

Mrezo

New Member
Oct 1, 2018
6
3
80
EDIT: 2028-08-20 MALWARE ADVISORY -
If you downloaded the game from F95, or from someone who shared the same source, the game (ZIP SHA256: 10AFACB6CB6BBC7ADA46D70DFB91EB9555238D52B5E5F7EA73DC998486B05923) is equipped with the Lumma Stealer malware thats doing the rounds right now. Check this thread's OP for up-to-date information.
I know you're coming here because you either searched for a walkthrough or someone linked you here, but be careful, as it was also spotted in other RPG Maker and python/Ren'py games shared on F95.
OK, but is the game segure to download? or not?
Should be okay now. I've downloaded a couple of days ago (once during malware, and once right after), and the one after was clean (didn't have the JS lines). If you know how to get SHA256, I would compare it with the above first quote. If it matches, it has the malware.
 

draxy

Newbie
Dec 12, 2019
42
23
193
Shit. Yeah. I downloaded the infected file, played for 5 or so hours, went to bed, booted it up again today and Eset caught a weird thing being sent through powershell (windows' file explorer or edge, I guess). Thought it was weird but whatever. Then, I checked this thread for the walkthrough cuz I like 100%ing games, only to find this out. Checked my SHA and my stomach dropped. Checked Eset's logs, and sure as shit, the interception linked back to (and was cleaned by Eset) the aforementioned "C:\Users\<username>\AppData\Local\MySupergame" file.

It seems like it also installed a fake file in "C:\Users\<username>\AppData\Local\Breeding City Welcomes You!" and in that folder's default folder(shown below), it just lists all the shit it was collecting in an unknown file format. I can't remember which, but one folder had some ini that seemed to look like the game's. In addition to deleting MySupergame, you should probably check for this file and delete it too, because it might still be logging your shit regardless of which version you download after the fact.


View attachment 5168528
Maybe it only runs the send-off of what it collects on the second time you play the game? Eset hasn't really ever not caught something like this before for me, especially for what I think is an unfortunately fairly common virus nowadays. Perhaps the first time you open the game is when it installs the above fake files and opening it a second time runs the ini in them? Hopefully? Either way, that's insidious as fuck.

Regardless, I just deleted those folders and am scanning through anything in appdata that doesn't seem kosher, and resetting my important passwords, but the cached ones that are saved in my browser or like steam that I didn't manually access should be fine, right? I'm kinda freaking out about that rn tbh. Anyone here know how that virus actually functions?

I just wanted to play my stupid little porn game, man.

EDIT: Found another file with basically the same stuff in it: "C:\Users\<username>\AppData\Local\User Data".
EDIT 2: AND ANOTHER TWO. "C:\Users\<username>\AppData\Local\w8i225jz" and "C:\Users\<username>\AppData\Local\zfefsooa".
Man, whoever wrote this was persistent. I've only just gone through local so far, I'm getting somehow even more annoyed.
miniedit: Nothing in AppData\LocalLow so far. Will update again after I go through roaming.
Final Edit: Nothing in Appdata\Roaming either. Looks like these were limited to Local. Still frustrating. Good luck out there. Really hoping that the only time it sent out what it logged was after running the game a second time.
I decided to look into that as i did have similar folders in my appdata and considering the amount of file you had i thought it had to be a false positive, from what i was able to gather with other game who showed the same behavior and people thinking it was a virus too :

"NW.js is an app runtime based on Chromium and node.js"

1. The game is launched through the built-in web browser.
2. The web browser creates a new profile, where it later writes game saves.

so the files here should be remnant of the game built-in web browser and not the data from your own browser (info gotten from
Paradise Overlap thread which isn't infected ( at least i think so ) )
 
  • Like
Reactions: Cherev

Annontail

New Member
Mar 26, 2023
1
0
60
Shit. Yeah. I downloaded the infected file, played for 5 or so hours, went to bed, booted it up again today and Eset caught a weird thing being sent through powershell (windows' file explorer or edge, I guess). Thought it was weird but whatever. Then, I checked this thread for the walkthrough cuz I like 100%ing games, only to find this out. Checked my SHA and my stomach dropped. Checked Eset's logs, and sure as shit, the interception linked back to (and was cleaned by Eset) the aforementioned "C:\Users\<username>\AppData\Local\MySupergame" file.

It seems like it also installed a fake file in "C:\Users\<username>\AppData\Local\Breeding City Welcomes You!" and in that folder's default folder(shown below), it just lists all the shit it was collecting in an unknown file format. I can't remember which, but one folder had some ini that seemed to look like the game's. In addition to deleting MySupergame, you should probably check for this file and delete it too, because it might still be logging your shit regardless of which version you download after the fact.


View attachment 5168528
Maybe it only runs the send-off of what it collects on the second time you play the game? Eset hasn't really ever not caught something like this before for me, especially for what I think is an unfortunately fairly common virus nowadays. Perhaps the first time you open the game is when it installs the above fake files and opening it a second time runs the ini in them? Hopefully? Either way, that's insidious as fuck.

Regardless, I just deleted those folders and am scanning through anything in appdata that doesn't seem kosher, and resetting my important passwords, but the cached ones that are saved in my browser or like steam that I didn't manually access should be fine, right? I'm kinda freaking out about that rn tbh. Anyone here know how that virus actually functions?

I just wanted to play my stupid little porn game, man.

EDIT: Found another file with basically the same stuff in it: "C:\Users\<username>\AppData\Local\User Data".
EDIT 2: AND ANOTHER TWO. "C:\Users\<username>\AppData\Local\w8i225jz" and "C:\Users\<username>\AppData\Local\zfefsooa".
Man, whoever wrote this was persistent. I've only just gone through local so far, I'm getting somehow even more annoyed.
miniedit: Nothing in AppData\LocalLow so far. Will update again after I go through roaming.
Final Edit: Nothing in Appdata\Roaming either. Looks like these were limited to Local. Still frustrating. Good luck out there. Really hoping that the only time it sent out what it logged was after running the game a second time.


I am sitting here at 4 am and thinking do I have the virus or not?
Saw a lot of folders like that but no files that jump out as wrong. the strangest folder is one called mygame but I think its from a legit game, at least thumbnail reminds me of smth. Also did not download any of the known infected games, my AV is defender and free malwarebytes (I cannot purchase premium no matter how much I want to).
Whats the strange file? Name? extension?
 

Cherev

New Member
Sep 1, 2023
2
9
57
I decided to look into that as i did have similar folders in my appdata and considering the amount of file you had i thought it had to be a false positive, from what i was able to gather with other game who showed the same behavior and people thinking it was a virus too :

"NW.js is an app runtime based on Chromium and node.js"

1. The game is launched through the built-in web browser.
2. The web browser creates a new profile, where it later writes game saves.

so the files here should be remnant of the game built-in web browser and not the data from your own browser (info gotten from
Paradise Overlap thread which isn't infected ( at least i think so ) )
To add on to the conversation, I also read up about this to figure out why there are so many folders like this.

Like the person in the other thread mentioned, rpgmaker is made with NW.js, which is based on Chromium and Node.js. Chromium in particular has a User Data folder where it stores info that would be useful for a web browser, which is mentioned in the Chromium documentation:

Also since Chrome obviously uses Chromium it has its own User Data and Default folders (which the docs mention is also located in Appdata/Local), and have a ton of files and folders, some of which are the same files seen in the other User Data folders that many people are worried about.

Also in the NW.js documentation it mentions where the data path for an NW.js app is located:

Just like Chromium, it's also located in Appdata/Local which likely means this was inherited from it. However, it has a <name> variable in the file path, which the docs say is located in a package.json manifest. If you look in any rpgmaker game folder where the exe for the game is, there is also a package.json file, and when opened with any text editor, a web browser, or even Notepad, it lists a few name/value pairs. The first in the list is almost always "name", and whatever value it has is what NW.js uses to name the data path.

For example, in some rpgmaker games that I've installed, the "name" value is "rmmz-game", which is probably a default name for rpgmaker MZ projects and explains why I have a rmmz-game folder in my Appdata/Local file path. Most games have empty quotations, which defaults to the file path Appdata/Local/User Data, some have random text which creates the Appdata/Local/<random-text> folder, and some actually have the name of the game, which also explains why game titles are in Appdata/Local.

This is why I don't think the existence of these folders is anything to be worried about, it's just files and folders that are made from rpgmaker games (unless the game was tampered with to include malicious files, like this game was during that time period). Also people worrying about the User Data folder seems to occur every now and then, since this was also brought up in the Daily Lives of My Countryside thread over a year ago.

Also feel free to correct me on any of this, I'm just trying to give myself and others some form of peace regarding these folders.
 
  • Like
Reactions: Dretel and shmurfer

UDoTT

Newbie
Aug 30, 2023
29
16
89
In addition to deleting MySupergame, you should probably check for this file and delete it too, because it might still be logging your shit regardless of which version you download after the fact.


1755768717593.png



Which files exactly?
 

draxy

Newbie
Dec 12, 2019
42
23
193
To add on to the conversation, I also read up about this to figure out why there are so many folders like this.

Like the person in the other thread mentioned, rpgmaker is made with NW.js, which is based on Chromium and Node.js. Chromium in particular has a User Data folder where it stores info that would be useful for a web browser, which is mentioned in the Chromium documentation:

Also since Chrome obviously uses Chromium it has its own User Data and Default folders (which the docs mention is also located in Appdata/Local), and have a ton of files and folders, some of which are the same files seen in the other User Data folders that many people are worried about.

Also in the NW.js documentation it mentions where the data path for an NW.js app is located:

Just like Chromium, it's also located in Appdata/Local which likely means this was inherited from it. However, it has a <name> variable in the file path, which the docs say is located in a package.json manifest. If you look in any rpgmaker game folder where the exe for the game is, there is also a package.json file, and when opened with any text editor, a web browser, or even Notepad, it lists a few name/value pairs. The first in the list is almost always "name", and whatever value it has is what NW.js uses to name the data path.

For example, in some rpgmaker games that I've installed, the "name" value is "rmmz-game", which is probably a default name for rpgmaker MZ projects and explains why I have a rmmz-game folder in my Appdata/Local file path. Most games have empty quotations, which defaults to the file path Appdata/Local/User Data, some have random text which creates the Appdata/Local/<random-text> folder, and some actually have the name of the game, which also explains why game titles are in Appdata/Local.

This is why I don't think the existence of these folders is anything to be worried about, it's just files and folders that are made from rpgmaker games (unless the game was tampered with to include malicious files, like this game was during that time period). Also people worrying about the User Data folder seems to occur every now and then, since this was also brought up in the Daily Lives of My Countryside thread over a year ago.

Also feel free to correct me on any of this, I'm just trying to give myself and others some form of peace regarding these folders.
Well you explained it was better than me lmao
 
3.80 star(s) 33 Votes