Jump to content

Malware inside Angry Planes & Noclip Mod


aboutseven

Recommended Posts

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Link to comment
Share on other sites

Alexander Blade

asi shows clean because antivirus has no signature match , so it goes into dynamic analysis i.e. emulating library execution and finds still nothing because this stuff is called only when script starts ingame (no proper environment for antivirus) , so there will be signatures in av bases soon for the downloader function inside asi , signatures for logger which it is downloading are already in 1/4 of antiviruses

  • Like 3
Link to comment
Share on other sites

MagikarpIsOP

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

 

Same here.

 

This is exactly my point.

Link to comment
Share on other sites

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Did you run the game with the mod installed?

Link to comment
Share on other sites

 

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Did you run the game with the mod installed?

 

Yeah, a while back though.. maybe it deleted its self.. Why the f*ck would people do this, seriously.

Link to comment
Share on other sites

 

 

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Did you run the game with the mod installed?

 

Yeah, a while back though.. maybe it deleted its self.. Why the f*ck would people do this, seriously.

 

Possibly, or your anti-virus picked it up. Check your anti-virus history and see what files it picked up as malware over the past week or so.

Link to comment
Share on other sites

MagikarpIsOP

 

 

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Did you run the game with the mod installed?

 

Yeah, a while back though.. maybe it deleted its self.. Why the f*ck would people do this, seriously.

 

Heisenberg is exactly saying what i wanna say. (Good words!)

 

Im also worried it deleted itself, anyone that used this mod should change passwords anyway.

Link to comment
Share on other sites

 

 

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Did you run the game with the mod installed?

 

Yeah, a while back though.. maybe it deleted its self.. Why the f*ck would people do this, seriously.

 

 

Check your anti-virus history?

 

y5vb.png

Link to comment
Share on other sites

MarshallRawR

Oh f*ck.. http://prntscr.com/753boo

 

What do? WAT DO? Am I okay if the antivirus picked it up? Has it ceased to go furhter? Are my passwords safe?

 

There's some cleanup to do (regedit.exe, then search "Winlogon" and remove the extra it added

 

bBtk8HM.png

 

 

Delete all of it traces and change password I my guess.

Link to comment
Share on other sites

MagikarpIsOP

Oh f*ck.. http://prntscr.com/753boo

 

What do? WAT DO? Am I okay if the antivirus picked it up? Has it ceased to go furhter? Are my passwords safe?

 

Change them asap. (Also, which software detected that?)

Link to comment
Share on other sites

 

Oh f*ck.. http://prntscr.com/753boo

 

What do? WAT DO? Am I okay if the antivirus picked it up? Has it ceased to go furhter? Are my passwords safe?

 

Change them asap. (Also, which software detected that?)

 

My antivirus is Avast. That detected it.

 

 

Oh f*ck.. http://prntscr.com/753boo

 

What do? WAT DO? Am I okay if the antivirus picked it up? Has it ceased to go furhter? Are my passwords safe?

 

There's some cleanup to do (regedit.exe, then search "Winlogon" and remove the extra it added

 

bBtk8HM.png

 

 

Delete all of it traces and change password I my guess.

 

That file isn't there. Shell wasn't there, it seemed clean. Ill give it another look over and start changing my passwords for maximum safety.

Link to comment
Share on other sites

MagikarpIsOP

Is it possible that Kaspersky might stopped this? Im genuinely confused since im yet to find any of this files. Will keep scanning etc.

Link to comment
Share on other sites

shiiiiit I got Fade.exe

 

am I f*cked????? My computer has OS password too sh*t

Edited by Cyberzone2
Link to comment
Share on other sites

Im So HM02

Hmm... I installed NoClip the day it came out and used it for about an hour all up. I have MBAM but don't have the active protection on. Nothing suspicious in my registry and no files in my temp folder (although I do a regular clean up of these). Is it possible it deleted its own registry keys?

Edited by Im So HM02
Link to comment
Share on other sites

GtaGamer2222

WTF.. Thanks for the Post OP. guys i deleted init.exe and fade.exe also i cleared the registry as MarshallRawR said is there anything i need to do ? I'm really worried right now

Edited by GtaGamer2222
Link to comment
Share on other sites

WTF.. Thanks for the Post OP. guys i deleted init.exe and fade.exe also i cleared the registry as MarshallRawR said is there anything i need to do ? I'm really worried right now

Change all your passwords.

Link to comment
Share on other sites

MagikarpIsOP

Is it possible that Kaspersky might stopped this? Im genuinely confused since im yet to find any of this files. Will keep scanning etc.

Nothing from a full scan of malwarebytes and also nothing from a scan in the appdata folder.

 

I seem to be the only here that is "safe".. And i don't like that.

Edited by MagikarpIsOP
Link to comment
Share on other sites

Grichka Bogdanoff

Damn... Steam's asking my password does not recognise it... :|

 

I just changed my Steam Guard setting btw. Now it send me an email if someone wants to log in.

Edited by m3tal z_DKI
Link to comment
Share on other sites

And that's why i refuse to use .asi whatsoever for anything else than mandatory tools like OpenIV.

 

If you want to do a menu or some easy script use .lua. There's no need to clutter everything with .asi files.

Edited by Drkz
Link to comment
Share on other sites

Damn... Steam's asking my password does not recognise it... :|

Wait sh*t have they stolen your steam account? Check your emails for ANY changes to your account. Saame goes with everything else.

Link to comment
Share on other sites

use virustotal because this malware is one sneaky bastard

Edited by Cyberzone2
Link to comment
Share on other sites

And that's why i refuse to use .asi whatsoever for anything else than mandatory tools like OpenIV.

 

If you want to do a menu or some easy script use .lua. There's no need to clutter everything with .asi files.

You realize .lua's are loaded by an .asi, right?

Link to comment
Share on other sites

I wonder what happen with the other people especially GTASeries video and IGN since they used this mod too

Link to comment
Share on other sites

 

And that's why i refuse to use .asi whatsoever for anything else than mandatory tools like OpenIV.

 

If you want to do a menu or some easy script use .lua. There's no need to clutter everything with .asi files.

You realize .lua's are loaded by an .asi, right?

 

 

You realize you can't avoid .asi in GTA modding scene but you can atleast alleviate your exposition to it, right ? Use the necessary tools and then stick to .lua.

Edited by Drkz
Link to comment
Share on other sites

Damn... Steam's asking my password does not recognise it... :|

 

I just changed my Steam Guard setting btw. Now it send me an email if someone wants to log in.

Best thing you could have done. I always set these guards up the moment they offer them. Same for gmail same for Origin.If anyone attempts to log in to my accounts i get a text message passcode sent to my mobile or email

  • Like 1
Link to comment
Share on other sites

You realize you can't avoid .asi in GTA modding scene but you can atleast alleviate your exposition to it, right ?

Of course I do, since I develop them myself. But I'm not that f*cked up in the head to include malware in them ;)

  • Like 2
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • 1 User Currently Viewing
    0 members, 0 Anonymous, 1 Guest

×
×
  • Create New...

Important Information

By using GTAForums.com, you agree to our Terms of Use and Privacy Policy.