-ShetlandPony- Posted May 14, 2015 Share Posted May 14, 2015 Damn You still need to clean the registry. Can we update the first post in order to help people solve this issue? What do you do to clean the registry? I was reading through this thread and related to like everything you were saying. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465674 Share on other sites More sharing options...
404UserNotFound Posted May 14, 2015 Share Posted May 14, 2015 Lol hi snowshoe, shouldn't you be working on TF2C? I'm not sure actually, mainly because I don't mess around with GTA mods. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465679 Share on other sites More sharing options...
Snowshoe Posted May 14, 2015 Share Posted May 14, 2015 (edited) Lol hi snowshoe, shouldn't you be working on TF2C? I'm not sure actually, mainly because I don't mess around with GTA mods. I edited my post. It's more probable something like that could be done with CLEO/SCM stuff (definitely not for V though). But ASI is just too complicated for that. They are essentially DLLs, EXEs (I'm going with the former), or whatever, but renamed. Edited May 14, 2015 by Snowshoe Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465685 Share on other sites More sharing options...
Maniakus Posted May 14, 2015 Share Posted May 14, 2015 i use my Nod on this and only one virus "init.exe" deleted no fade but anyway thanks Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465693 Share on other sites More sharing options...
Sergeeeek Posted May 14, 2015 Share Posted May 14, 2015 I saw this being discussed somewhat on the first page, but I'm from the AlliedModders community and on our forums when you add a .sp file as a post attachment, it comes up with two options: Get Plugin Get Source Get Plugin gets you the compiled .smx file and Get Sourcr gets you the uncompiled .sp file. The forum runs the attached .sp file through the sourcepawn compiler at the time of download and counts every download. It's also against our T&C to upload compiled plugins without the source. The .sp files are completely readable in any notepad program. Our forun also has a New Plugin section and users who are designated as Plugin Approvers. These users know how to spot malicious code and approve good plugins which moves the new plugins thread into the Approved Plugins section. Plugjns that reproduce things in existing plugins, or plugins that no longer work (due to game updates) are usually moved to the Unapproved Plugins section. That setup sounds like what this community needs to prevent the spread of malicious mods. Pawn scripts =/= entire C++ projects/DLLs with numerous source files and dependencies How would this even work? server-side MSVC? It would make sense with CLEO mods possibly but not this. Maybe require c++ asi mods to have public github repos with build servers set up (https://travis-ci.org/ for example) so what moderators on modding websites could check if md5 hashes are the same with the build server's version. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465698 Share on other sites More sharing options...
Silent Posted May 14, 2015 Share Posted May 14, 2015 gtaall noclip malware version attempts to download GTA5.exe from xttp://stenagergaard nu/tmp/GTA5 exe obv it's http but I wanted to obfuscate the link a bit Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465706 Share on other sites More sharing options...
iOnlyEatCops Posted May 14, 2015 Share Posted May 14, 2015 Damn You still need to clean the registry. Can we update the first post in order to help people solve this issue? How do you clean it? Just delete the Shell? Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465707 Share on other sites More sharing options...
gamesguru Posted May 14, 2015 Share Posted May 14, 2015 (edited) Thanks for the heads-up. I had a few restore points, including a manual one I made just before using the Angry Planes script. I had both Fade.exe and init.exe in my temp folder. Which both went after restoring (but the data folder was left over). Unlike the OP, instead of having a .Z file I had a .yz file instead (date created matched the exe). I had to delete that one manually. I didn't have anything after the explorer.exe in my registry's string. So I don't know if that means, I was safe to begin with (at least password wise). But I restored to just before I used the mod and changed all the passwords on the sites I was active on in between that time, just to be secure (Steam, Social Club, here, etc). Edited May 14, 2015 by gamesguru Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465709 Share on other sites More sharing options...
GhostStorm Posted May 14, 2015 Share Posted May 14, 2015 No shell in my winlogon part of regedit. Also no fade.exe or init.exe showing up via malware bytes. I'm clean? Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465718 Share on other sites More sharing options...
ZombiePyroNinja Posted May 14, 2015 Share Posted May 14, 2015 I had the shell written. What exactly do we do to get rid of this? I deleted the folder within temp that had the logs fade used but what else can I do? Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465727 Share on other sites More sharing options...
Lozo222 Posted May 14, 2015 Share Posted May 14, 2015 (edited) I think im ok, i did install the planes mod but ive checked temp and nothing in there (i deleted it all just to be sure), no detections from malware bytes, i checked both registry locations and nothing out of the ordinary there, no password emails so im pretty sure im ok and i also checked to see if i had an extra GTAV.exe and i did not Edited May 14, 2015 by Lozo222 Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465728 Share on other sites More sharing options...
lipskamafia Posted May 14, 2015 Share Posted May 14, 2015 No shell in my winlogon part of regedit. Also no fade.exe or init.exe showing up via malware bytes. I'm clean? me too, so all is good ? thanks you Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465737 Share on other sites More sharing options...
-ShetlandPony- Posted May 14, 2015 Share Posted May 14, 2015 I have shell but it points to expstart.exe Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465742 Share on other sites More sharing options...
aboutseven Posted May 14, 2015 Author Share Posted May 14, 2015 I've updated the OP on virus removal, if anyone has more information on anything else that could have been affected, please tell me. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465744 Share on other sites More sharing options...
Sergeeeek Posted May 14, 2015 Share Posted May 14, 2015 gtaall noclip malware version attempts to download GTA5.exe from xttp://stenagergaard nu/tmp/GTA5 exe obv it's http but I wanted to obfuscate the link a bit Whois doesn't give any useful information on domain. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465747 Share on other sites More sharing options...
Drkz Posted May 14, 2015 Share Posted May 14, 2015 I saw this being discussed somewhat on the first page, but I'm from the AlliedModders community and on our forums when you add a .sp file as a post attachment, it comes up with two options: Get Plugin Get Source Get Plugin gets you the compiled .smx file and Get Sourcr gets you the uncompiled .sp file. The forum runs the attached .sp file through the sourcepawn compiler at the time of download and counts every download. It's also against our T&C to upload compiled plugins without the source. The .sp files are completely readable in any notepad program. Our forun also has a New Plugin section and users who are designated as Plugin Approvers. These users know how to spot malicious code and approve good plugins which moves the new plugins thread into the Approved Plugins section. Plugjns that reproduce things in existing plugins, or plugins that no longer work (due to game updates) are usually moved to the Unapproved Plugins section. That setup sounds like what this community needs to prevent the spread of malicious mods. Interesting. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465754 Share on other sites More sharing options...
Bencici Posted May 14, 2015 Share Posted May 14, 2015 I've updated the OP on virus removal, if anyone has more information on anything else that could have been affected, please tell me.I don't think removing Shell is safe, you probably just have to delete the part who begin after the comma Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465755 Share on other sites More sharing options...
Silent Posted May 14, 2015 Share Posted May 14, 2015 I've updated the OP on virus removal, if anyone has more information on anything else that could have been affected, please tell me. Could you append info about x64/GTA5.exe malware and maybe link to this analysis too? http://gtaforums.com/topic/794383-possibility-of-trojan-downloaderspyware-installed-via-gta-v-mod/?p=1067465309 Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465758 Share on other sites More sharing options...
Snowshoe Posted May 14, 2015 Share Posted May 14, 2015 I saw this being discussed somewhat on the first page, but I'm from the AlliedModders community and on our forums when you add a .sp file as a post attachment, it comes up with two options: Get Plugin Get Source Get Plugin gets you the compiled .smx file and Get Sourcr gets you the uncompiled .sp file. The forum runs the attached .sp file through the sourcepawn compiler at the time of download and counts every download. It's also against our T&C to upload compiled plugins without the source. The .sp files are completely readable in any notepad program. Our forun also has a New Plugin section and users who are designated as Plugin Approvers. These users know how to spot malicious code and approve good plugins which moves the new plugins thread into the Approved Plugins section. Plugjns that reproduce things in existing plugins, or plugins that no longer work (due to game updates) are usually moved to the Unapproved Plugins section. That setup sounds like what this community needs to prevent the spread of malicious mods. Pawn scripts =/= entire C++ projects/DLLs with numerous source files and dependencies How would this even work? server-side MSVC? It would make sense with CLEO mods possibly but not this. Maybe require c++ asi mods to have public github repos with build servers set up (https://travis-ci.org/ for example) so what moderators on modding websites could check if md5 hashes are the same with the build server's version. Like Silent said, md5 could possibly differ depending on the compiler. Maybe file size would be a better way but probably has the same pitfalls. Really, the only way to be sure is to analyze the source code and compile it yourself, which I don't think a lot of people have the time or programs necessary to do this sadly. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465763 Share on other sites More sharing options...
aboutseven Posted May 14, 2015 Author Share Posted May 14, 2015 I've updated the OP on virus removal, if anyone has more information on anything else that could have been affected, please tell me. I don't think removing Shell is safe, you probably just have to delete the part who begin after the comma Are you sure? I read that the Shell key was just for custom shells and that by default Windows uses explorer.exe anyways. I could be wrong though. I'll restart my computer to see if any problems persist after removing Shell. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465766 Share on other sites More sharing options...
AngryGamer94 Posted May 14, 2015 Share Posted May 14, 2015 hmmm i re formatted my PC yesterday due to an unrelated issue(had problems with win10 preview) I used angry planes once and then deleted it,should i be worried? Changing all my passwords would be a massive chore.I have a hard time remembering things so i use the same 2-3 passwords on everything except steam. Not going to install any more random .asi mods from now on,i'll stick to .lua scripts. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465771 Share on other sites More sharing options...
iCeDMeTaL Posted May 14, 2015 Share Posted May 14, 2015 It's really simple, guys. I see so many people asking the same questions over and over... Am I infected? If my antivirus caught it, am I good to go? The answer is, no one really knows. Imagine if a badly sick person sneezes in your face, but you manage to quickly wipe it off. Are you infected? We don't know, but it's a good idea to take precautions. So if you have any sign of infection, I recommend you treat it as a full infection and change all your passwords and protect yourself. A keylogger is a program that relays anything you type directly to the hacker, so even your flirty chats on facebook are logged and recorded, not just passwords. No one is going to give you a definitive answer and tell you that you are SAFE, because no one wants to be responsible when your bank account gets cleaned out. Everyone is still trying to figure out the extent of the damage, no one knows for sure which antivirus can detect and clean it prior to infection. If you downloaded and used the mods in question, treat it as a full infection. Stay safe and happy modding. Fraizer 1 Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465772 Share on other sites More sharing options...
Bencici Posted May 14, 2015 Share Posted May 14, 2015 (edited) I've updated the OP on virus removal, if anyone has more information on anything else that could have been affected, please tell me. I don't think removing Shell is safe, you probably just have to delete the part who begin after the comma Are you sure? I read that the Shell key was just for custom shells and that by default Windows uses explorer.exe anyways. I could be wrong though. I'll restart my computer to see if any problems persist after removing Shell. Well, you probably know more than me Edited May 14, 2015 by Bencici Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465773 Share on other sites More sharing options...
Sergeeeek Posted May 14, 2015 Share Posted May 14, 2015 (edited) Like Silent said, md5 could possibly differ depending on the compiler. Maybe file size would be a better way but probably has the same pitfalls. Really, the only way to be sure is to analyze the source code and compile it yourself, which I don't think a lot of people have the time or programs necessary to do this sadly. Again, if file's md5 differs from build server version just don't allow the mod. It's a lot harder for modders but that ensures safety for users so why not? Edited May 14, 2015 by Sergeeeek Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465780 Share on other sites More sharing options...
vithepunisher Posted May 14, 2015 Share Posted May 14, 2015 I heard the so called modder was apparently a R* games employee trying to shut everyone down on modding the game by making an epic plane mod that had everyone fooled including myself, this incident is to propose a huge impact to warn people modding there game and most importantly turn people away from modding there game completely, now i don't know if i should believe this but looking back at the way R* acted towards the modding community i wouldn't be surprised if this is there retaliation. they'd make something more epic this was a simple simple simple simple script mod Thats true i appreciate your reply im a big fan i just thought id share that conspiracy slash lie that's going around in order that'd shed some light on the subject i dont belive it myself only sharing it lol i dont want people getting mad Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465783 Share on other sites More sharing options...
deathzkid17 Posted May 14, 2015 Share Posted May 14, 2015 I'm glad I didn't download those 2 mods that contains malware. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465789 Share on other sites More sharing options...
FlyingAce Posted May 14, 2015 Share Posted May 14, 2015 welp I dont remembering deleting the userinit.exe from the registry but I dont have one.. will I not be able to login past the user screen now? Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465790 Share on other sites More sharing options...
aboutseven Posted May 14, 2015 Author Share Posted May 14, 2015 I've updated the OP on virus removal, if anyone has more information on anything else that could have been affected, please tell me. Could you append info about x64/GTA5.exe malware and maybe link to this analysis too? http://gtaforums.com/topic/794383-possibility-of-trojan-downloaderspyware-installed-via-gta-v-mod/?p=1067465309 Do you happen to have a link to the information about x64/GTA5.exe? I couldn't find anything like that in my case, so I believe this might have been a different mod (NoClip?) that has done this. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465792 Share on other sites More sharing options...
Igor Bogdanoff Posted May 14, 2015 Share Posted May 14, 2015 Why don't just report him to right authorities? Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465794 Share on other sites More sharing options...
Silent Posted May 14, 2015 Share Posted May 14, 2015 I've updated the OP on virus removal, if anyone has more information on anything else that could have been affected, please tell me. Could you append info about x64/GTA5.exe malware and maybe link to this analysis too? http://gtaforums.com/topic/794383-possibility-of-trojan-downloaderspyware-installed-via-gta-v-mod/?p=1067465309 Do you happen to have a link to the information about x64/GTA5.exe? I couldn't find anything like that in my case, so I believe this might have been a different mod (NoClip?) that has done this. gtaall noclip malware version attempts to download GTA5.exe from xttp://stenagergaard nu/tmp/GTA5 exe And yes, it's NoClip. Though the other NoClip I got has Fade in. Guess it comes in multiple flavours. Beyond f*cked up. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/10/#findComment-1067465799 Share on other sites More sharing options...
Recommended Posts