Jump to content

Malware inside Angry Planes & Noclip Mod


Recommended Posts

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Alexander Blade

asi shows clean because antivirus has no signature match , so it goes into dynamic analysis i.e. emulating library execution and finds still nothing because this stuff is called only when script starts ingame (no proper environment for antivirus) , so there will be signatures in av bases soon for the downloader function inside asi , signatures for logger which it is downloading are already in 1/4 of antiviruses

  • Like 3
MagikarpIsOP

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

 

Same here.

 

This is exactly my point.

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Did you run the game with the mod installed?

 

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Did you run the game with the mod installed?

 

Yeah, a while back though.. maybe it deleted its self.. Why the f*ck would people do this, seriously.

 

 

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Did you run the game with the mod installed?

 

Yeah, a while back though.. maybe it deleted its self.. Why the f*ck would people do this, seriously.

 

Possibly, or your anti-virus picked it up. Check your anti-virus history and see what files it picked up as malware over the past week or so.

MagikarpIsOP

 

 

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Did you run the game with the mod installed?

 

Yeah, a while back though.. maybe it deleted its self.. Why the f*ck would people do this, seriously.

 

Heisenberg is exactly saying what i wanna say. (Good words!)

 

Im also worried it deleted itself, anyone that used this mod should change passwords anyway.

 

 

Ive looked into my temp directories, scanned the asi and everything else, but i cant find any trace of the file doing what you are saying its done.. i cant see csc.exe, i cant see fade.exe anywhere either.. am I just blind or am I clean? Do I need the mod installed for it to do any harm? Ive had it installed once, but now its just sitting in my mod manager..

Did you run the game with the mod installed?

 

Yeah, a while back though.. maybe it deleted its self.. Why the f*ck would people do this, seriously.

 

 

Check your anti-virus history?

 

y5vb.png

MarshallRawR

Oh f*ck.. http://prntscr.com/753boo

 

What do? WAT DO? Am I okay if the antivirus picked it up? Has it ceased to go furhter? Are my passwords safe?

 

There's some cleanup to do (regedit.exe, then search "Winlogon" and remove the extra it added

 

bBtk8HM.png

 

 

Delete all of it traces and change password I my guess.

 

Oh f*ck.. http://prntscr.com/753boo

 

What do? WAT DO? Am I okay if the antivirus picked it up? Has it ceased to go furhter? Are my passwords safe?

 

Change them asap. (Also, which software detected that?)

 

My antivirus is Avast. That detected it.

 

 

Oh f*ck.. http://prntscr.com/753boo

 

What do? WAT DO? Am I okay if the antivirus picked it up? Has it ceased to go furhter? Are my passwords safe?

 

There's some cleanup to do (regedit.exe, then search "Winlogon" and remove the extra it added

 

bBtk8HM.png

 

 

Delete all of it traces and change password I my guess.

 

That file isn't there. Shell wasn't there, it seemed clean. Ill give it another look over and start changing my passwords for maximum safety.

Im So HM02

Hmm... I installed NoClip the day it came out and used it for about an hour all up. I have MBAM but don't have the active protection on. Nothing suspicious in my registry and no files in my temp folder (although I do a regular clean up of these). Is it possible it deleted its own registry keys?

Edited by Im So HM02
MagikarpIsOP

Is it possible that Kaspersky might stopped this? Im genuinely confused since im yet to find any of this files. Will keep scanning etc.

Nothing from a full scan of malwarebytes and also nothing from a scan in the appdata folder.

 

I seem to be the only here that is "safe".. And i don't like that.

Edited by MagikarpIsOP

And that's why i refuse to use .asi whatsoever for anything else than mandatory tools like OpenIV.

 

If you want to do a menu or some easy script use .lua. There's no need to clutter everything with .asi files.

You realize .lua's are loaded by an .asi, right?

 

And that's why i refuse to use .asi whatsoever for anything else than mandatory tools like OpenIV.

 

If you want to do a menu or some easy script use .lua. There's no need to clutter everything with .asi files.

You realize .lua's are loaded by an .asi, right?

 

 

You realize you can't avoid .asi in GTA modding scene but you can atleast alleviate your exposition to it, right ? Use the necessary tools and then stick to .lua.

Edited by Drkz

Damn... Steam's asking my password does not recognise it... :|

 

I just changed my Steam Guard setting btw. Now it send me an email if someone wants to log in.

Best thing you could have done. I always set these guards up the moment they offer them. Same for gmail same for Origin.If anyone attempts to log in to my accounts i get a text message passcode sent to my mobile or email

  • Like 1

You realize you can't avoid .asi in GTA modding scene but you can atleast alleviate your exposition to it, right ?

Of course I do, since I develop them myself. But I'm not that f*cked up in the head to include malware in them ;)

  • Like 2
Guest
This topic is now closed to further replies.
  • 0 User Currently Viewing
    0 members, 0 Anonymous, 0 Guests

×
×
  • Create New...

Important Information

By using GTAForums.com, you agree to our Terms of Use and Privacy Policy.