juaao Posted May 14, 2015 Share Posted May 14, 2015 My Malwarebytes Anti-Malware doesn’t dectec the Fade.exe What anti-virus I should use? vithepunisher 1 Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465800 Share on other sites More sharing options...
MHVuze Posted May 14, 2015 Share Posted May 14, 2015 Do you happen to have a link to the information about x64/GTA5.exe? I couldn't find anything like that in my case, so I believe this might have been a different mod (NoClip?) that has done this. Might be a noclip thing. I never had the plane mod installed and found the gta5.exe. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465805 Share on other sites More sharing options...
MarshallRawR Posted May 14, 2015 Share Posted May 14, 2015 As said, it seems everything is hosted on a server to which we have the freaking address. No way to take it down? Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465806 Share on other sites More sharing options...
Drkz Posted May 14, 2015 Share Posted May 14, 2015 Why don't just report him to right authorities? Because it would make the same effect as throwing a small rock in the sea. TheUnit 1 Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465807 Share on other sites More sharing options...
Sergeeeek Posted May 14, 2015 Share Posted May 14, 2015 (edited) And yes, it's NoClip. Though the other NoClip I got has Fade in. Guess it comes in multiple flavours. Beyond f*cked up. Where does Fade come from? Edited May 14, 2015 by Sergeeeek Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465811 Share on other sites More sharing options...
Nico Posted May 14, 2015 Share Posted May 14, 2015 So, there isn't any safe way to run this mod? I still don't have V, but I really wanted to try this once I got the game. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465814 Share on other sites More sharing options...
jihadijohn Posted May 14, 2015 Share Posted May 14, 2015 okay, so i had the fade.exe in my registry and deleted it, along with the temp files and any known infected mods right. then suddenly init,exe appeared in my temp folder so i deleted it and now im seeing Leep.exe in my registry.. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465822 Share on other sites More sharing options...
james_uk Posted May 14, 2015 Share Posted May 14, 2015 I got caught out by this one. In my case, it came from the Angry Planes mod. AVG flagged up the fade.exe and the init.exe files within temp when I started my computer the next day. Interestingly enough, the registry entries referred to in this thread weren't present in my registry so I don't know if the malware fully executed or not... I've changed my critical passwords just to play it safe. Can't believe these bastards would target the GTA V modding community in such an early stage of growth. All it serves to do is create distrust amongst others Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465823 Share on other sites More sharing options...
Sergeeeek Posted May 14, 2015 Share Posted May 14, 2015 So, there isn't any safe way to run this mod? I still don't have V, but I really wanted to try this once I got the game. Maybe if someone recreates it. But I doubt it will be as popular as the previous one. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465825 Share on other sites More sharing options...
Igor Bogdanoff Posted May 14, 2015 Share Posted May 14, 2015 Why don't just report him to right authorities? Because it would make the same effect as throwing a small rock in the sea. come on police cannot be that useless. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465826 Share on other sites More sharing options...
Silent Posted May 14, 2015 Share Posted May 14, 2015 Where does Fade come from? Angry Planes and one of NoClip flavours. ie. the original reason OP posted. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465827 Share on other sites More sharing options...
Snowshoe Posted May 14, 2015 Share Posted May 14, 2015 (edited) I see so many people asking the same questions over and over... Am I infected? If my antivirus caught it, am I good to go? These are the things you need to look out for to see if you're infected, from my observation: NoClip or Angry Planes ASI mods installed, and you ran the game at least once with these mods. A process named "csc.exe" (Visual C# Compiler) running in Task Manager. This is a legit file but is being used/hijacked by the malware. Suspicious files in AppData temp folder such as: Fade.exe, init..exe (also with nonsensical icons, such as the HTML5 logo ) File in GTAV's x64 folder named GTAV.exe Registry entries pointing to a Fade.exe file You might also see .bin files with the malware, basically logs that are being sent to the server every few days. They are encrypted so don't bother trying to read with a regular text editor. Edited May 14, 2015 by Snowshoe Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465838 Share on other sites More sharing options...
Drkz Posted May 14, 2015 Share Posted May 14, 2015 So, there isn't any safe way to run this mod? I still don't have V, but I really wanted to try this once I got the game. No. I'm sure someone will recreate it sooner or later. But for now stay away from this garbage like the plague. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465843 Share on other sites More sharing options...
Sergeeeek Posted May 14, 2015 Share Posted May 14, 2015 Where does Fade come from? Angry Planes and one of NoClip flavours. ie. the original reason OP posted. I mean web address (if it's being downloaded like GTA5.exe) Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465848 Share on other sites More sharing options...
Michael5074 Posted May 14, 2015 Share Posted May 14, 2015 (edited) I knew it would be too good to be true to actually get mods so soon.And i avoided downloading any kind of modification for the game till now and i am proud i did so.Hopefully they will make The GTA modding community as good as it was when SA was a mainstream modding project Edited May 15, 2015 by Michael5074 Ss4gogeta0 1 Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465859 Share on other sites More sharing options...
Silent Posted May 14, 2015 Share Posted May 14, 2015 I mean web address (if it's being downloaded like GTA5.exe) Probably embedded inside init.exe or so. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465860 Share on other sites More sharing options...
Snowshoe Posted May 14, 2015 Share Posted May 14, 2015 It's trying to mimic GTA V, but didn't even get it all right Silent and RoachKiller_416 2 Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465866 Share on other sites More sharing options...
Naean Posted May 14, 2015 Share Posted May 14, 2015 (edited) It's trying to mimic GTA V, but didn't even get it all right *Images snip.* The most glaring warning signs, even before opening the Details tab, is the incorrect file icon and the very apparent lack of a Digital Signatures tab. Edited May 14, 2015 by Nez Man Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465880 Share on other sites More sharing options...
MarshallRawR Posted May 14, 2015 Share Posted May 14, 2015 Well f*ck it I went for it. Not much was given, looks like cloudieweb are the one to contact. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465885 Share on other sites More sharing options...
Prof_Farnsworth Posted May 14, 2015 Share Posted May 14, 2015 Im just going to format, f*ck it. at this moment i wish i had a dvd drive lol only time i actually need one why can't windows release on usb sticks or be cloud downloaded with settings and everything OT but it is easy to install windows from usb, anything 7 and below that is. Haven't tried myself with 8 or 10 yet. PM me if you need a link. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465887 Share on other sites More sharing options...
jihadijohn Posted May 14, 2015 Share Posted May 14, 2015 i just found 2 folders in my registry labeled "Fade" and "Leep" lol Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465915 Share on other sites More sharing options...
bilago Posted May 14, 2015 Share Posted May 14, 2015 Do you have to actively enable the mod in game for it to execute or just starting the game with the mod loaded by scripthook will do it? I cannot find any symptoms listed in the first post, but I used a mod folder from a user of my manager as a test to troubleshoot an issue and noclip.asi is one of the mods. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465917 Share on other sites More sharing options...
Ezuu Posted May 14, 2015 Share Posted May 14, 2015 Maybe it was only me but my ".z" file didn't had a name (when I tried to open it, an error message appeared telling me that there was a problem opening .z) and it was a WinRar file Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465920 Share on other sites More sharing options...
Silent Posted May 14, 2015 Share Posted May 14, 2015 Do you have to actively enable the mod in game for it to execute or just starting the game with the mod loaded by scripthook will do it? I cannot find any symptoms listed in the first post, but I used a mod folder from a user of my manager as a test to troubleshoot an issue and noclip.asi is one of the mods. Apparently you have to launch the game, ie. new game/load a save. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465922 Share on other sites More sharing options...
cp1dell Posted May 14, 2015 Share Posted May 14, 2015 (edited) I knew it would be too good to be true to actually get mods so soon.And i avoided downloading any kind of modification for the game tillnow and i am proud i did so.Hopefully they will make The GTA modding community as good as it was when SA was a minstream modding project It's not "too good to be true." We still got mods and scripts working within a few weeks of release. This is just a case of one asshole taking advantage of the trust modders are given when download scripts and such. Has this ever happened before with GTA mods? First time I've heard of someone putting malware inside a script. Anything that can be done to prevent this from happening again? Edited May 14, 2015 by cp1dell Shaunr 1 Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465929 Share on other sites More sharing options...
aboutseven Posted May 14, 2015 Author Share Posted May 14, 2015 Do you have to actively enable the mod in game for it to execute or just starting the game with the mod loaded by scripthook will do it? I cannot find any symptoms listed in the first post, but I used a mod folder from a user of my manager as a test to troubleshoot an issue and noclip.asi is one of the mods. From my experience, it wasn't until you were actually in the game. Going to the menu didn't seem to execute anything. I assume ScriptHook V works by waiting until you are in the game and then executing whatever scripts you have installed. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465933 Share on other sites More sharing options...
Sergeeeek Posted May 14, 2015 Share Posted May 14, 2015 (edited) Do you have to actively enable the mod in game for it to execute or just starting the game with the mod loaded by scripthook will do it? I cannot find any symptoms listed in the first post, but I used a mod folder from a user of my manager as a test to troubleshoot an issue and noclip.asi is one of the mods. Apparently you have to launch the game, ie. new game/load a save. Looks the idiot has put it into the script logic so it executes only when you actually get into the game, not when asi loads, if I understand correctly. Edited May 14, 2015 by Sergeeeek Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465934 Share on other sites More sharing options...
Silent Posted May 14, 2015 Share Posted May 14, 2015 Looks the idiot has put it into the script logic so it executes only when you actually get into the game, not when asi loads, if I understand correctly. Yes, it's inside one of the defined functions or whatever. ScriptHook related stuff. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465939 Share on other sites More sharing options...
DxY Posted May 14, 2015 Share Posted May 14, 2015 Maybe it was only me but my ".z" file didn't had a name (when I tried to open it, an error message appeared telling me that there was a problem opening .z) and it was a WinRar file This needs to be shown in the orignal post by OP Mine was like a winrar file too with no name. Also, do I have to delete csc.exe? Or is that a safe windows file? I managed to remove everything OP said to remove, and for now my gta will remain unmodded and will be changing all passwords ASAP. Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465941 Share on other sites More sharing options...
ZZCOOL Posted May 14, 2015 Share Posted May 14, 2015 Im just going to format, f*ck it. at this moment i wish i had a dvd drive lol only time i actually need one why can't windows release on usb sticks or be cloud downloaded with settings and everything OT but it is easy to install windows from usb, anything 7 and below that is. Haven't tried myself with 8 or 10 yet. PM me if you need a link. problem is my disc is somewhere stuck in some dvd drive somewhere in my room disconnected but sure i'll send a pm also i loved your iv mods they were amazing hope to see you come back for v Link to comment https://gtaforums.com/topic/794383-malware-inside-angry-planes-noclip-mod/page/11/#findComment-1067465950 Share on other sites More sharing options...
Recommended Posts