Unity Nemurimouto [v0.09] [pachipoi]

4.60 star(s) 17 Votes

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
23,744
324,879
998
The Virus downloader only executed if your system time was 2025-08-14. If you started the game before the 14th you are most likely fine, but delete and redownload.
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
23,744
324,879
998
just downloaded this today from pixeldrain, is my system safe?
No (if you started it and when you started it was the 14th). Yes if you didn't, deleted it and redownloaded it now.
 

ELDuran2K4

Member
Sep 9, 2022
115
64
152
I DL'ed this morning. Scanned with my antivirus and came up with zero issues. said I had no infected files. Should I be worried still?
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
23,744
324,879
998
I DL'ed this morning. Scanned with my antivirus and came up with zero issues. said I had no infected files. Should I be worried still?
If you started it and it was the 14th yes. If not then no.

Also it contains a downloader that will download the malware. Scanning it before the actual malware is downloaded will do nothing.

Mega link in OP is safe?
Yes
 
  • Like
Reactions: JustForHentai00011

ELDuran2K4

Member
Sep 9, 2022
115
64
152
If you started it and it was the 14th yes. If not then no.

Also it contains a downloader that will download the malware. Scanning it before the actual malware is downloaded will do nothing.


Yes
I'm still on the 13th. won't be 14 until 7 more hours.
 

Tuberaku

Member
Jul 22, 2019
123
114
200
I downloaded it but didn’t open it, I just extracted it from the RAR after ı see this post then deleted it. Could a virus have gotten in?
 
  • Like
Reactions: RayBar

MisterBrickster

New Member
Jun 6, 2022
3
4
37
Downloaded the android version, ripped it out and cleaned some files up just to be safe.

From a tertiary glance it only affects windows yeah? Just wanna make sure that it didn't shove a file somewhere.
 
  • Like
Reactions: Bob69

vaporeon12211

Newbie
Apr 2, 2024
74
42
62
i played the 13th and been 2 h and 15 min of the 14 for me, i already deleted it what kind of scanner i use to see if i have something
 

abbydrago

New Member
Mar 30, 2020
12
9
146
I downloaded and played it probably in 14th, coz Windows defender caught this downloded in temp folder.
1755130526075.png

It was automatically quarantined, and I removed it from system.
Currently scanning system with Malwarebytes and Windows defender.
Can someone suggest me what should I do to keep myself safe?
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
23,744
324,879
998
i played the 13th and been 2 h and 15 min of the 14 for me, i already deleted it what kind of scanner i use to see if i have something
Just a Antivirus scan should be fine. Could be execute when it was running into the 14th.
I downloaded and played it probably in 14th, coz Windows defender caught this downloded in temp folder.
View attachment 5142753

It was automatically quarantined, and I removed it from system.
Currently scanning system with Malwarebytes and Windows defender.
Can someone suggest me what should I do to keep myself safe?
If it was quarantined and you deleted it its okay. Good to see WinDefender catches it. That makes the possible infections probably very rare.
 

SvenVlad

Engaged Member
Modder
Aug 11, 2017
2,089
9,999
768
Whew, good thing I didn't start the game. Although probably my AV would've blocked the download.

In any case, it's deleted. Thanks for letting us know.
 

Zeffuu

New Member
Jan 25, 2020
9
7
22
Just a Antivirus scan should be fine. Only if you started the game on the 14 its would have been executed.

If it was quarantined and you deleted it its okay. Good to see WinDefender catches it. That makes the possible infections probably very rare.
Curious the payload timing, so the game was running on my system when it hit 12AM, and noticed some firewall pings..

First was the game exe going to ethereum-sepolia.publicnode.com:443 (104.20.24.117) 12:00am
Then an AutoIt v3 Script kicking off going to destinyshatter.one:80 (109.107.168.8) 12:01am
Then Windows Defender quarantining the same Lumma that abbydrago got at 12:01am.

So I assume the AutoIt script pulls down the Lumma?

The AutoIt script that spawned was located at appdata\local\temp\730305\partners.pif
 
4.60 star(s) 17 Votes