Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
18,472
226,624
ok now after checking with Procmon, this seems to be super suspicious:
1) it force opens conhos.exe
2) it creates over 500k events (each 100k read/write) right after loading/starting a game

may someone who has a bit more knowledge on that topic verify this please?!

EDIT:
ad 2): cross-checked with other RenPy games, and it seems to be somewhat normal to have that much events...
View attachment 4877435
This looks like a crypto miner. BUT I just downloaded the game scanned it with a few programs and also used our custom scanner. I wasn't able to replicate it. Were did you get the game from?
Also the files that were shared back in December last year were directly from Patreon.
 

SonsOfLiberty

Discussion Dynamo
Compressor
Sep 3, 2022
27,882
247,225
This looks like a crypto miner. BUT I just downloaded the game scanned it with a few programs and also use our custom scanner. I wasn't able to replicate it. Were did you get the game from?
Also the files that were shared back in December last year were directly from Patreon.
It wasn't from the file here, as I know who shared the last 2 updates here and they came direct from the source.
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
18,472
226,624
They've had to get it from somewhere else, or maybe there they have a mod that is listed here on F95. Could be a memory leak but it's not running that SDK version and using v8.
Yeah either a mod or from somewhere else.
Looks exactly like a Bitcoin minor tho.
 

SonsOfLiberty

Discussion Dynamo
Compressor
Sep 3, 2022
27,882
247,225
Yeah either a mod or from somewhere else.
Looks exactly like a Bitcoin minor tho.
Something that would have been caught, as there is only one other post about high ram usage and that was months ago, and no one else has reported anything unusual.
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
18,472
226,624
Something that would have been caught, as there is only one other post about high ram usage and that was months ago, and no one else has reported anything unusual.
Yeah we would be flooded with reports. Time for him to either try to remove the miner (if its not the game itself that wasn't downloaded from here). Best probs would reinstall who know what else is there lol.
 

SonsOfLiberty

Discussion Dynamo
Compressor
Sep 3, 2022
27,882
247,225
Yeah we would be flooded with reports. Time for him to either try to remove the miner (if its not the game itself that wasn't downloaded from here). Best probs would reinstall who know what else is there lol.
Sounds like a format, or at least a virus scan. I would suggest getting a second opinion one since it sounds like it bypassed his main scanner.








4 I've used in the past and Emsisoft one I still have installed.
 
  • Like
Reactions: Bob69

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
18,472
226,624
Sounds like a format, or at least a virus scan. I would suggest getting a second opinion one since it sounds like it bypassed his main scanner.








4 I've used in the past and Emsisoft one I still have installed.
Oh I read foxi. post again. Looks like he caught something that attaches itself to Renpy games that are usually not very system heavy to mask itself. I'd just yeeeet win, and reinstall. While if its really only a Miner its unlike, but still would change PWs.
 

foxi.

Newbie
Apr 3, 2022
18
7
Oh I read foxi. post again. Looks like he caught something that attaches itself to Renpy games that are usually not very system heavy to mask itself. I'd just yeeeet win, and reinstall. While if its really only a Miner its unlike, but still would change PWs.
well I do have a (in my opinion quite good) security software set to advanced, and it didn't catch anything suspicious in any RenPy recently... and the super suspicious behaviour monitored ONLY happens on this game... I prolly wouldn't even have noticed if the fans didn't immediately ramp up...
I don't really remember which hoster I downloaded the game from; but it most likely was from gofile...

usually a miner works online and connects to an IP, but this behaviour also happens if I block its internet connection...

maybe someone can double check the number of events on procmon?

but thx eitherway for the hints/notes
 

Bob69

Uploading the World
Uploader
Donor
Compressor
Mar 2, 2019
18,472
226,624
well I do have a (in my opinion quite good) security software set to advanced, and it didn't catch anything suspicious in any RenPy recently... and the super suspicious behaviour monitored ONLY happens on this game... I prolly wouldn't even have noticed if the fans didn't immediately ramp up...
I don't really remember which hoster I downloaded the game from; but it most likely was from gofile...

usually a miner works online and connects to an IP, but this behaviour also happens if I block its internet connection...

maybe someone can double check the number of events on procmon?

but thx eitherway for the hints/notes
Oh when its only that game then its kinda weird if you downloaded it from here and didn't use any mods. Did you try just redownload?
Because I just downloaded it when I saw your report from Gofile and nothing for me. Also like I said all our Virus scans were fine.
 
  • Like
Reactions: foxi.

foxi.

Newbie
Apr 3, 2022
18
7
Oh when its only that game then its kinda weird if you downloaded it from here and didn't use any mods. Did you try just redownload?
Because I just downloaded it when I saw your report from Gofile and nothing for me. Also like I said all our Virus scans were fine.
yeah will try that too... nuke every game file and see what the fresh game does
 
  • Like
Reactions: Bob69
3.80 star(s) 88 Votes