Jump to content

GTA V Mods infected with malware

Uwillparish

(Website is down, Original link:http://gtaforums.com/topic/794383-possibility-of-trojan-downloaderspyware-installed-via-gta-v-mod/Cached Version: http://webcache.googleusercontent.com/search?q=cache:9mYf0EgigG4J:gtaforums.com/topic/794383-possibility-of-trojan-downloaderspyware-installed-via-gta-v-mod/+&cd=1&hl=en&ct=clnk&gl=us 

So, The TLDR is 2 mods, Specifically the Angry Planes mod and the Noclip mod seem to install a program called "Fade.exe" into your temp files and your registry, If you did install the mod like i did, i would check your registry and run a malwarebytes scan

 

(originally posted here:http://www.reddit.com/r/pcmasterrace/comments/35xo8o/psa_gtav_modsalexander_blade_confirms_noclip_mod/ )

Link to comment
Share on other sites

Link to post
Share on other sites

FUCKING TWATS, completely put me off modding GTA now. In the proccess of chaning my passwords, 2 step verification will be saving my ass here .

CPU: Intel 3570 GPUs: Nvidia GTX 660Ti Case: Fractal design Define R4  Storage: 1TB WD Caviar Black & 240GB Hyper X 3k SSD Sound: Custom One Pros Keyboard: Ducky Shine 4 Mouse: Logitech G500

 

Link to comment
Share on other sites

Link to post
Share on other sites

Here we go. Some fu*ktards ruining it for everybody.

Glad im staying away from mods until they get applied on community servers (one day it will happen my friends).

Connection200mbps / 12mbps 5Ghz wifi

My baby: CPU - i7-4790, MB - Z97-A, RAM - Corsair Veng. LP 16gb, GPU - MSI GTX 1060, PSU - CXM 600, Storage - Evo 840 120gb, MX100 256gb, WD Blue 1TB, Cooler - Hyper Evo 212, Case - Corsair Carbide 200R, Monitor - Benq  XL2430T 144Hz, Mouse - FinalMouse, Keyboard -K70 RGB, OS - Win 10, Audio - DT990 Pro, Phone - iPhone SE

Link to comment
Share on other sites

Link to post
Share on other sites

FUCKING TWATS, completely put me off modding GTA now. In the proccess of chaning my passwords, 2 step verification will be saving my ass here .

I would be running malware bytes scans, checking regedit and looking for any trace of Fade.exe before doing it, no one is safe till you are sure you have it, and/or sure you dont anymore

 

Here we go. Some fu*ktards ruining it for everybody.

Glad im staying away from mods until they get applied on community servers (one day it will happen my friends).

Well, we had modding since before GTA 4, its been ~10 years man!

Link to comment
Share on other sites

Link to post
Share on other sites

I would be running malware bytes scans, checking regedit and looking for any trace of Fade.exe before doing it, no one is safe till you are sure you have it, and/or sure you dont anymore

 

Well, we had modding since before GTA 4, its been ~10 years man!

Malwarebytes doesn't detect it.

 

http://linustechtips.com/main/topic/366420-gta-5-mods-angry-planes-and-noclip-installing-keyloggers/

 Asus M5A99X Evo  - AMD FX-8350 - 16GB Corsair Vengeance 1866Mhz - Corsair 120mm Quiet Edition Fans BenQ XL2411Z- EVGA GTX 980 Superclocked Fractal Design Define R4 - Corsair H100i - 2 TB 7200rpm HDD - Samsung 840 Evo 120GB - Corsair RM750w PSU - Logitech G502 Proteus Core - Corsair K70 RGB MX Red - Audio Technica M50x + Modmic 4.0 - LG 23EA63V x2


Spinthat Spinthat Spinthat Spinthat

Link to comment
Share on other sites

Link to post
Share on other sites

Well, we had modding since before GTA 4, its been ~10 years man!

U had malware on a modded server before?

Because what i was implying is that servers will not have malware on them. Not that i never heard of mods before..

Connection200mbps / 12mbps 5Ghz wifi

My baby: CPU - i7-4790, MB - Z97-A, RAM - Corsair Veng. LP 16gb, GPU - MSI GTX 1060, PSU - CXM 600, Storage - Evo 840 120gb, MX100 256gb, WD Blue 1TB, Cooler - Hyper Evo 212, Case - Corsair Carbide 200R, Monitor - Benq  XL2430T 144Hz, Mouse - FinalMouse, Keyboard -K70 RGB, OS - Win 10, Audio - DT990 Pro, Phone - iPhone SE

Link to comment
Share on other sites

Link to post
Share on other sites

U had malware on a modded server before?

Because what i was implying is that servers will not have malware on them. Not that i never heard of mods before..

no, i thought you meant mods on steam community, I read it wrong

 

 
Too shay, i ran AVG and saw nothing, also nothing in regedit http://i.imgur.com/vzyM3ij.png
Link to comment
Share on other sites

Link to post
Share on other sites

Those douchebags. I hope someone catches their little punk asses

 

Someone needs to make a mod that increases the volume of the custom music channel. I've got my music in there, and it's all quiet as hell, I have to turn my system volume to max, and turn down everything else on GTA V just to be able to hear it.

 

Someone also needs to make a radio station that doesn't suck. Unlike previous GTA games, I've yet to find a single station I entirely like. Good songs here and there (lock and load, welcome to los santos, danger zone, etc) but the rest of it just annoys me.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

Mods are a great addition to any game, you can add giant cocks to Skyrim and have your computer hijacked in GTAV lol.

Link to comment
Share on other sites

Link to post
Share on other sites

I was quite worried about this with GTA IV, when I messed around trying to get the best mod results....there are just so much out there and a lot is not checked that much...

The Mistress: Case: Corsair 760t   CPU:  Intel Core i7-4790K 4GHz(stock speed at the moment) - GPU: MSI 970 - MOBO: MSI Z97 Gaming 5 - RAM: Crucial Ballistic Sport 1600MHZ CL9 - PSU: Corsair AX760  - STORAGE: 128Gb Samsung EVO SSD/ 1TB WD Blue/Several older WD blacks.

                                                                                        

Link to comment
Share on other sites

Link to post
Share on other sites

And this is why mod support and something like mod curation in something like... oh say... steam? would be really nice.

 

edit: i should say real mod support and guantees that mods work/are malware free. not shitty steam support like they had when they "launched" with no curation no ability to get money back, and no guantee that any of it would work.

Primary:

Intel i5 4670K (3.8 GHz) | ASRock Extreme 4 Z87 | 16GB Crucial Ballistix Tactical LP 2x8GB | Gigabyte GTX980ti | Mushkin Enhanced Chronos 240GB | Corsair RM 850W | Nanoxia Deep Silence 1| Ducky Shine 3 | Corsair m95 | 2x Monoprice 1440p IPS Displays | Altec Lansing VS2321 | Sennheiser HD558 | Antlion ModMic

HTPC:

Intel NUC i5 D54250WYK | 4GB Kingston 1600MHz DDR3L | 256GB Crucial M4 mSATA SSD | Logitech K400

NAS:

Thecus n4800 | WD White Label 8tb x4 in raid 5

Phones:

Oneplux 6t (Mint), Nexus 5x 8.1.0 (wifi only), Nexus 4 (wifi only)

Link to comment
Share on other sites

Link to post
Share on other sites

LOL this is a first for me.

  ﷲ   Muslim Member  ﷲ

KennyS and ScreaM are my role models in CSGO.

CPU: i3-4130 Motherboard: Gigabyte H81M-S2PH RAM: 8GB Kingston hyperx fury HDD: WD caviar black 1TB GPU: MSI 750TI twin frozr II Case: Aerocool Xpredator X3 PSU: Corsair RM650

Link to comment
Share on other sites

Link to post
Share on other sites

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

oh what assholes. I had a similar problem with puush, it got infected and had to change all my pasword as well, now using keepass  and it's fucking annoying.

Link to comment
Share on other sites

Link to post
Share on other sites

Gtaforums posted removal instructions for the malware

Instructions on virus removal:

If these files do not exist, do not assume you weren't affected. The virus could have deleted itself after grabbing what it needed to cover its tracks, or your anti-virus could have deleted it after it grabbed what it needed.

If you have used the mods Angry Planes and/or Noclip mod, then here is how to get rid of the virus, or check if it is still on your computer.

1. Press Ctrl+Shift+Esc, go to processes, and end the csc.exe process.

2. Go to your Temp folder at "C:\Users\*YOUR USER NAME*\AppData\Local\Temp"

3. Sort the files by date added, and find .z and init..exe and delete those. Some reports say that .z might be named differently, like .x.

4. Some people also reported an unnamed archive file (.zip or .rar) that could not be opened that looks like this: http://www.twitch.tv...thedanishviking

77.68.209.7

Further investigation revealed the following modules active:

Facebook spam/credential stealing module

Twitch spam/credential stealing module

Messenger.com spam/credential stealing module

A Steam spamming module

A Steam module that evaluates the items in your inventory and their value based on current market value

A Keylogger module that logs individual button presses in an XML like format, it also includes information about context switches (switching from one app/window to another)

A UDP flooding module

There were others I hadn't deciphered and didn't see in action.

All of the spam/credential stealing modules above will attempt to rip your session cookies for each of the above sites from IE/Chome/Firefox and use the credentials to do their thing.

It stores all this information in a Session#.bin file as described above and ships it to the RAT admin's server.

Now, here's the juciest and most useful bit.

The C&C server is apcrypt.duckdns.org which resolves to 45.58.121.105. It's a cheap windows VPS with a company called https://www.cloudieweb.com/which is utilizing dedicated server rented from Choopa.com

This server is running Remote Desktop on 3389 as well as a webserver, which I believe is acting as an endpoint/C&C server for the RAT. The RAT uses SSL to communicate with this server so I was unable to spy any of that activity in an meaningful way in the time I had available.

Tool used to investigate:

ProcessExplorer

WinDbg

Jetbrains DotPeek

Strings (https://technet.micr...s/bb897439.aspx)

Wireshark

IMPORTANT/TL;DR:

If you didn't read/understand all of the above the most important thing to take from this is that everything you typed while infected is in the malware admin's hands. Your active/logged in sessions to Facebook/Twitch/Youtube/Steam are in his hands. Change all your passwords, logout and log back in to every site mentioned above to invalidate the existing session.

p.s. I will include some strings from the modules referenced above in the following post.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

oh what assholes. I had a similar problem with puush, it got infected and had to change all my pasword as well, now using keepass  and it's fucking annoying.

Except puush wasn't blatantly trying to be malicious, it could happen to anyone.

CPU: Intel 3570 GPUs: Nvidia GTX 660Ti Case: Fractal design Define R4  Storage: 1TB WD Caviar Black & 240GB Hyper X 3k SSD Sound: Custom One Pros Keyboard: Ducky Shine 4 Mouse: Logitech G500

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×