RPGM Completed Paizuri Slave Training Program [v1.05] [Aeba no Mori]

4.40 star(s) 36 Votes
Jan 25, 2022
51
22
it was used with a program called "Bat To Exe Converter", you can google that.
basically, someone made the malware in this batch file (probably dev themselves), then ran the program on it with the option to encrypt the original batch file, giving you 2 files as output, one being the binary .exe and the other being this batch file with encrypted contents, with the non-malware unencrypted part appended at the end to run the game.
since it seems to be a coin miner, dev probably got it somewhere to make an extra buck and simply added 2 extra lines at the end to run his game and pretend that's how you're supposed to run it.
it worse then just a bitcoin miner it hijack edge and webview likely to see passwords and credit card info it create lot of stuff like "program" auto start and trustedinstaller processes that kill/remove themselves when you find out about them (of course they get installed back either when you're idle or you restart) and lot more stuff that aren't as scary then the fact it mines bitcoins (at least tries since it would take millions of years to get one on my gpu) also all anti-viruses that i have tested can't remove it but that isn't as scary as losing some performance when idle and away from the computer that the worse thing this virus does
 
Jan 25, 2022
51
22
anyway someone still got the virus (the batc- i mean exe file that is totally not just a batch file) i want to upload it to every antivirus that don't detect it
 

Estronix

Member
Jan 21, 2022
109
66
Bro if the game has an actual virus then delete this whole thread lol, why is the page still online? If Aeba really did put a malware then we better told it even on DL Site/Ci En and confront him
 

thoox22

Newbie
Jun 25, 2021
23
43
Are you talking about this section?

::[Bat To Exe Converter]
::
::YAwzoRdxOk+EWAjk
::fBw5plQjdCuDJNxsIsbt1CfXrPQB3rk55WmfCyh4Dxu7KofC0hfG+20JWVdSHGPzGsADrxPHLfm6afcFDxRWMBuoYW8=
::YAwzuBVtJxjWCl3EqQJgSA==
::ZR4luwNxJguZRRnk
::Yhs/ulQjdF+5
::cxAkpRVqdFKZSzk=
::cBs/ulQjdF+5
::ZR41oxFsdFKZSDk=
::eBoioBt6dFKZSDk=
::cRo6pxp7LAbNWATEpCI=
::egkzugNsPRvcWATEpCI=
::dAsiuh18IRvcCxnZtBJQ
::cRYluBh/LU+EWAnk
::YxY4rhs+aU+JeA==
::cxY6rQJ7JhzQF1fEqQJQ
::ZQ05rAF9IBncCkqN+0xwdVs0
::ZQ05rAF9IAHYFVzEqQJQ
::eg0/rx1wNQPfEVWB+kM9LVsJDGQ=
::fBEirQZwNQPfEVWB+kM9LVsJDGQ=
::cRolqwZ3JBvQF1fEqQJQ
::dhA7uBVwLU+EWDk=
::YQ03rBFzNR3SWATElA==
::dhAmsQZ3MwfNWATElA==
::ZQ0/vhVqMQ3MEVWAtB9wSA==
::Zg8zqx1/OA3MEVWAtB9wSA==
::dhA7pRFwIByZRRnk
::Zh4grVQjdCuDJNxsIsbt1CfXrPQB3rk55WmfCyh4Dxu7KofC0hfG+20JWVdSHGPzGsADrxPHLfm6afc4HhpRcDWqYwp6rHZH1g==
::YB416Ek+ZG8=
::
::
::978f952a14a936cc963da21a135fa983


The :: implies that they are comments. But I don't know what it's saying since it's encrypted. But I'd assume since they are comment they aren't running anything.

Only thing that is running should be this part

cd GameData
start Game.exe
Looks encoded rather than encrypted so if you know the character set and encoding you could probably read it
 

opopi123

Member
Aug 1, 2022
180
182
Looks encoded rather than encrypted so if you know the character set and encoding you could probably read it
Yeah I thought so to so i did attempt to run it through a decoder using well known character sets but didn't get anything. Yeah I remembered to remove the :: comment on each line
 

clax

Newbie
May 5, 2020
46
18
I ran the game awhile back and it was caught by a anti maleware application, any way to find out if my pc is infected or is thing slippery and hard to find?
 

954107033

Newbie
Dec 11, 2022
21
25
Can we get a confirmation on the virus situation. I just loaded up the game today, found no problems, and ran my basic windows defender scan found no threats. This was all before I read the thread unfortunately, so I'm not entirely sure.
 

opopi123

Member
Aug 1, 2022
180
182
Can we get a confirmation on the virus situation. I just loaded up the game today, found no problems, and ran my basic windows defender scan found no threats. This was all before I read the thread unfortunately, so I'm not entirely sure.
There is no update to be said. The people that were talking about it never showed any time of evidence to show that it's the case. At least a screenshot of what they are seeing would help at least for other users to collaborate and figure out what is going on but they haven't.
 

Hmeh

New Member
Feb 27, 2019
10
3
Can we get a confirmation on the virus situation. I just loaded up the game today, found no problems, and ran my basic windows defender scan found no threats. This was all before I read the thread unfortunately, so I'm not entirely sure.
I have paid kaspersky and everything came out clean on my end. I used dl link from the start of the thread, the archive itself was fine, it was fine when i unzipped it, i had no issues or pop ups when running the game.
 

clax

Newbie
May 5, 2020
46
18
I have paid kaspersky and everything came out clean on my end. I used dl link from the start of the thread, the archive itself was fine, it was fine when i unzipped it, i had no issues or pop ups when running the game.
I know what I saw and read, it was def infected, maybe the version I downloaded was infected, I believe I downloaded the mega folder but it was awhile ago, which website did you download from?
 

Yukariin

Active Member
Oct 16, 2020
548
1,132
I have paid kaspersky and everything came out clean on my end. I used dl link from the start of the thread, the archive itself was fine, it was fine when i unzipped it, i had no issues or pop ups when running the game.
the actual game is in the "game" folder, don't run the .exe outside of it (you can delete it).
 

Hmeh

New Member
Feb 27, 2019
10
3
I know what I saw and read, it was def infected, maybe the version I downloaded was infected, I believe I downloaded the mega folder but it was awhile ago, which website did you download from?
This thread, the zip from Mega.
the actual game is in the "game" folder, don't run the .exe outside of it (you can delete it).
What exe outside of the game folder? In the zip i downloaded there's nothing outside of it.
Screenshot 2024-09-20 135408.png
 

Yukariin

Active Member
Oct 16, 2020
548
1,132
This thread, the zip from Mega.

What exe outside of the game folder? In the zip i downloaded there's nothing outside of it.
View attachment 4053287
this is not the game folder. this is the folder that's inside the .zip.
the .exe in it is not the game, it's the malware. there's another folder in there that has the actual RPGM game, and you can run that .exe instead.
 
4.40 star(s) 36 Votes