Jump to content

Installed a modding program for GTA5 (OpenIV) from two different sources and now not sure how to properly scrub windows in case there’s a virus

TheSilverKing

Here are the links I used (I used the first one first with the offline installer, then reinstalled windows as I wasn’t sure it was legit (the official site for the OpenIV program is down and has been for three months) and installed from the second one. My recent experience with Minecraft mods getting viruses made me a bit worried about this program so I then:

 

reinstalled windows 11 from a clean bootable usb

deleted all the partitions on my C drive and let the windows installer make a new one

deleted all the partitions on my storage drives and remade them in windows

 

a couple days later I realized I should probably reflash my BIOS just to be safe, so I used a clean laptop to make a BIOS flashing usb as well.

 

links

 

https://gta5mod.net/gta-5-mods/tools/openiv-3-1/

 

https://archive.org/details/openiv_202304
 

What made me so paranoid was this VirusTotal scan https://www.virustotal.com/gui/file/bb476bef066592e17b65ac5d12306ee55fc33065402bd3be3591cf5f04cdf6e6

 

did I do things backwards by reflashing the bios second?

 

mods, I’m unsure what forum this should go to, so please feel free to move it if I have put it in the wrong place.

Link to comment
Share on other sites

Link to post
Share on other sites

The standard “it’s infected! Scrub it!” Is to wipe everything that was connected.  Sometimes there are apps that can save parts, sometimes not.

Not a pro, not even very good.  I’m just old and have time currently.  Assuming I know a lot about computers can be a mistake.

 

Life is like a bowl of chocolates: there are all these little crinkly paper cups everywhere.

Link to comment
Share on other sites

Link to post
Share on other sites

Its worth noting that particular detection method seems prone to false positives, so there may be no infection at all.

Router:  Intel N100 (pfSense) WiFi6: Zyxel NWA210AX (1.7Gbit peak at 160Mhz)
WiFi5: Ubiquiti NanoHD OpenWRT (~500Mbit at 80Mhz) Switches: Netgear MS510TXUP, MS510TXPP, GS110EMX
ISPs: Zen Full Fibre 900 (~930Mbit down, 115Mbit up) + Three 5G (~800Mbit down, 115Mbit up)
Upgrading Laptop/Desktop CNVIo WiFi 5 cards to PCIe WiFi6e/7

Link to comment
Share on other sites

Link to post
Share on other sites

if you deleted all the partitions on the drive and made new ones, 99%+ you're safe.

 

very very very few viruses can live through that, and/or infect the bios.  

Link to comment
Share on other sites

Link to post
Share on other sites

In the future you can use shadow copy feature and restore points in Windows so you could roll back your games and the system if something goes wrong with mods.

This post has been ninja-edited while you weren't looking.

 

I'm a used parts bottom feeder.  Your loss is my gain.

 

I like people who tell good RGB jokes.

Link to comment
Share on other sites

Link to post
Share on other sites

53 minutes ago, TheSilverKing said:

Here are the links I used (I used the first one first with the offline installer, then reinstalled windows as I wasn’t sure it was legit (the official site for the OpenIV program is down and has been for three months) and installed from the second one. My recent experience with Minecraft mods getting viruses made me a bit worried about this program so I then:

 

reinstalled windows 11 from a clean bootable usb

deleted all the partitions on my C drive and let the windows installer make a new one

deleted all the partitions on my storage drives and remade them in windows

 

a couple days later I realized I should probably reflash my BIOS just to be safe, so I used a clean laptop to make a BIOS flashing usb as well.

 

links

 

https://gta5mod.net/gta-5-mods/tools/openiv-3-1/

 

https://archive.org/details/openiv_202304
 

What made me so paranoid was this VirusTotal scan https://www.virustotal.com/gui/file/bb476bef066592e17b65ac5d12306ee55fc33065402bd3be3591cf5f04cdf6e6

 

did I do things backwards by reflashing the bios second?

 

mods, I’m unsure what forum this should go to, so please feel free to move it if I have put it in the wrong place.

Looks like useless panic ... Most modding programs must look like "viruses" to work, and only one out of 20 antivirus gave a positive, one I've never heard of, so won't trust it...

System : AMD R9 5900X / Gigabyte X570 AORUS PRO/ 2x16GB Corsair Vengeance 3600CL18 ASUS TUF Gaming AMD Radeon RX 7900 XTX OC Edition GPU/ Phanteks P600S case /  Eisbaer 280mm AIO (with 2xArctic P14 fans) / 2TB Crucial T500  NVme + 2TB WD SN850 NVme + 4TB Toshiba X300 HDD drives/ Corsair RM850x PSU/  Alienware AW3420DW 34" 120Hz 3440x1440p monitor / Logitech G915TKL keyboard (wireless) / Logitech G PRO X Superlight mouse / Audeze Maxwell headphones

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, PDifolco said:

Looks like useless panic ... Most modding programs must look like "viruses" to work, and only one out of 20 antivirus gave a positive, one I've never heard of, so won't trust it...

A point. There is such a thing as a fake malware trojan where they inject the package with the repair system instead of the thing being called malware.  These things usually trip every time though.  There are also fake “you have been infected” pop ups where there wasn’t even anything to trip.  1of 20 is a low number.  Malware is actually fairly rare.  Most people don’t have enough money to steal.  Some do though.

Not a pro, not even very good.  I’m just old and have time currently.  Assuming I know a lot about computers can be a mistake.

 

Life is like a bowl of chocolates: there are all these little crinkly paper cups everywhere.

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, r00tb33r said:

In the future you can use shadow copy feature and restore points in Windows so you could roll back your games and the system if something goes wrong with mods.

Yeah but trusting System Restore for an actual trojan infection is a bad idea, its only for a corrupt OS.

Router:  Intel N100 (pfSense) WiFi6: Zyxel NWA210AX (1.7Gbit peak at 160Mhz)
WiFi5: Ubiquiti NanoHD OpenWRT (~500Mbit at 80Mhz) Switches: Netgear MS510TXUP, MS510TXPP, GS110EMX
ISPs: Zen Full Fibre 900 (~930Mbit down, 115Mbit up) + Three 5G (~800Mbit down, 115Mbit up)
Upgrading Laptop/Desktop CNVIo WiFi 5 cards to PCIe WiFi6e/7

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, Alex Atkin UK said:

Yeah but trusting System Restore for an actual trojan infection is a bad idea, its only for a corrupt OS.

I dunno.  Save points change everything don’t they?  If they don’t you’re totally right though.

Not a pro, not even very good.  I’m just old and have time currently.  Assuming I know a lot about computers can be a mistake.

 

Life is like a bowl of chocolates: there are all these little crinkly paper cups everywhere.

Link to comment
Share on other sites

Link to post
Share on other sites

22 minutes ago, Alex Atkin UK said:

Yeah but trusting System Restore for an actual trojan infection is a bad idea, its only for a corrupt OS.

My ex-fiancee wanted me to wear two.

 

And she was right, one full-on ripped.

This post has been ninja-edited while you weren't looking.

 

I'm a used parts bottom feeder.  Your loss is my gain.

 

I like people who tell good RGB jokes.

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, r00tb33r said:

My ex-fiancee wanted me to wear two.

 

And she was right, one full-on ripped.

? (There needs to be an emoji for something sailing over your head)

Not a pro, not even very good.  I’m just old and have time currently.  Assuming I know a lot about computers can be a mistake.

 

Life is like a bowl of chocolates: there are all these little crinkly paper cups everywhere.

Link to comment
Share on other sites

Link to post
Share on other sites

18 hours ago, PDifolco said:

Looks like useless panic ... Most modding programs must look like "viruses" to work, and only one out of 20 antivirus gave a positive, one I've never heard of, so won't trust it...


Unless I’m missing something, 2/67 gave a positive. “Bkav Pro W32.AIDetectMalware” and “Trapmine Malicious.high.ml.score”

 

I’m not sure what these things mean and couldn’t find much about them when I looked. Malwarebytes and Windows Defender both didn’t find anything though.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, TheSilverKing said:


Unless I’m missing something, 2/67 gave a positive. “Bkav Pro W32.AIDetectMalware” and “Trapmine Malicious.high.ml.score”

 

I’m not sure what these things mean and couldn’t find much about them when I looked. Malwarebytes and Windows Defender both didn’t find anything though.

My feeling is that there's nothing dangerous here, only some byte sequences that may resemble some virus signature

I don't trust at all those unknown antiviruses, the guys are paid to detect stuff, so...

 

System : AMD R9 5900X / Gigabyte X570 AORUS PRO/ 2x16GB Corsair Vengeance 3600CL18 ASUS TUF Gaming AMD Radeon RX 7900 XTX OC Edition GPU/ Phanteks P600S case /  Eisbaer 280mm AIO (with 2xArctic P14 fans) / 2TB Crucial T500  NVme + 2TB WD SN850 NVme + 4TB Toshiba X300 HDD drives/ Corsair RM850x PSU/  Alienware AW3420DW 34" 120Hz 3440x1440p monitor / Logitech G915TKL keyboard (wireless) / Logitech G PRO X Superlight mouse / Audeze Maxwell headphones

Link to comment
Share on other sites

Link to post
Share on other sites

The moral of this thread is celibacy is the answer for those who are afraid of STIs.

 

In other words, if you're afraid then don't download things off the Internet.

This post has been ninja-edited while you weren't looking.

 

I'm a used parts bottom feeder.  Your loss is my gain.

 

I like people who tell good RGB jokes.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×