Vor einigen Stunden stellte sich heraus, dass es bei den Mods "Angry Planes" und "No Clip" nicht nur um GTA V Erweiterungen handelt, sondern gleichzeit auch um Malware! Die schadhafte Teil der Software war sehr gut versteckt, so dass dies erst heute Morgen aufgefallen ist. (Weitere Infos @ GTAForums)
Diese Mods wurden aber nicht nur auf GTAinside vorgestellt, sondern auch auf zahlreichen anderen Webseiten und großen Portalen (PCgamer, IGN etc.). So etwas ist in den letzten 14 Jahren, in denen es GTAinside gibt, bisher noch nicht vorgekommen und ist umso ärgerlicher für all diejenigen unter euch, die mit ihren ehrlichen Mods anderen einfach nur eine Freude machen wollen. Selbstverständlich haben wir die beiden betroffenen Mods sofort aus unserer Datenbank entfernt!
Um genau zu sein, handelt es sich bei der Malware um einen Keylogger. Die Schadsoftware läuft unter dem Dateinamen "The Fade.exe". Um den Keylogger wieder zu entfernen, löscht zunächst die beiden GTA V Erweiterungen und startet einen Virus Scanner. Weitere Hinweise findet ihr im entsprechenden Thread auf GTAForums.com: Possibility of Trojan Downloader/Spyware installed via GTA V Mod?.
Wichtig: Ändert bitte unbedingt all eure Passwörter!
In Zukunft werden die Mods vor Freischaltung noch genauer geprüft! Falls du trotzdem noch verunsichert bist, empfehlen wir zudem, nur noch *.lua und *.cs Script-Mods zu installieren: Diese Dateien sind OpenSource und Trojaner lassen sich daher wesentlich leichter entdecken. All diejenigen Modifikationen, die mit Hilfe von OpenIV installiert werden, sind ebenfalls zu 100% sicher.
Quote: Mr. Raspberry Jam
maybe the author of this mod is from a rival company who trying to ruin the gta?
maybe the author of this mod is from a rival company who trying to ruin the gta?
I've implemented the VirusTotal API v2. This gives you some more safety!
More information here:
http://www.gtainside.com/en/news.php?do=kommentare&id=5775
@rizqan7:
Clearly it's for money (and lulz). By using keylogger, they can gather data such as credit card information, login information (email and passwords), private documents (doxx), and other valuable info from recorded keystrokes which they can sell for $$$, Bitcoin, or other crypto-currency. Basically, it's a profitable form of trolling.
Good job that you've deleted those mods, because maybe you've saved many GTA V PC gamers around here, by the way I pretty confused why the modder put that malware in their mods, maybe that they want to find sensation or just to amuse .
Schwer zu sagen. Kann gut sein. Änder auf jeden Fall trotzdem deine Passwörter und lass einen Virenscanner laufen.
Ich habe diese beiden Mods benutzt Ohne Internetverbindung, bringt das was?
Quote: FeisalAR
Could this be one of Rockstar's evil anti-modding scheme? It seems that Rockstar is trying to stop V's modding progress in its early stage.
Is it possible that the malware scare is used to spread paranoia among the mod user base, and ultimately diminishing the user base completely?
A rumor stated that Rockstar gained small cut of profit from increased anti-virus sales.
Oooh the conspiracy.
The problem is that some mods (especially Trainer files) are considered malicious but actually they are fine. This false positive results have to do with how these files work.
When I download those files, 3 of 6 antivirus in my laptop sign an alert for malware in the file that's why the download always stop at 99% with IDM or basic browser downloader, those 2 files are suspicious from their release, because that I said something, that I will download GTA V mods later, other mods are fine though, never receive any malware on this site anyway except for the noclip and angry planes mod
Those are professional work.
I wonder if all people from other site will know about it?
All the people won't have bastards spreading vice wantonly!
@FeisalAR: Rockstar no longer prevent modding in GTA V Singleplayer, it's the user itself that include the malware in its files.
Could this be one of Rockstar's evil anti-modding scheme? It seems that Rockstar is trying to stop V's modding progress in its early stage.
Is it possible that the malware scare is used to spread paranoia among the mod user base, and ultimately diminishing the user base completely?
A rumor stated that Rockstar gained small cut of profit from increased anti-virus sales.
Oooh the conspiracy.
@jpbuquid:
In no way! We just have to be more careful when using *.asi and *.dll mods.
Everything else is safe! There is absolutely no reason to flip out.
Modding community is ruined
even though my anti virus actualy detected no clip but i ignored it !! i had problems on my game so i removed it like 3 mintues installed !
Quote: Megalow
people who do all this should be at least expelled from the page, and if possible; locate and send them to the afterlife (kill)
I don't believe this too. The second time happens again that a mod has virus! (After 2007 mod GTA Hood Life for GTA San Andreas)
Quote: Jonathan6506
Alex, just block the modder for infinite amount of time on this website.
Reason: Sending malware
Quote: Alex
Of course we already did, Jonathan6506! Those people don't belong to the GTA scene.
Of course we already did, Jonathan6506! Those people don't belong to the GTA scene.
Alex, just block the modder for infinite amount of time on this website.
Reason: Sending malware
Pathetic.
As GTA IV/SA use ASI mods too, I'm worrying incase IV/SA will be hit with similar attacks. :|
@Siriox:
Natürlich prüfen wir die Mods vor Veröffentlichung. Das bedeutet aber nicht, dass sowas nicht passieren kann. Die beiden betroffenen Mods waren zudem auf nahezu jeder spielebezogenen Webseite. Darunter sowohl die ganz ganz Großen wie Gamestar, Gameswelt, PCgamer, IGN als auch jede einzelne GTA Fanpage oder GTAForums ... und es ist trotzdem bis heute Morgen niemandem aufgefallen. Das hat auch damit zu tun, dass *.asi und *.dll Dateien kompiliert sind und der Quelltext somit unbekannt ist. Bei *.lua und *.cs Skripts ist dies nicht der Fall: Der Quellcode ist OpenSource und somit frei einsehbar.
Im Prinzip kann dies bei wirklich JEDER aus dem Internet heruntergeladener Datei passieren. Es gibt immer ein Restrisiko.
####################################
English:
@Siriox:
Of course we check every single mod before publication. But this does not mean that something like this cannot happen. The two affected mods were also on almost every game-related website. From the big players like GameStar, Gameswelt, PCgamer and IGN to every GTA fan page or big communities like GTAForums ... And nevertheless nobody noticed it. This has to do with the fact that *.asi and *.dll files are compiled and the source code is thus unknown. On the other hand, *.lua and *.cs scripts are open source and the source code is visible.
In principle, this can happen with every file you download from the Internet. There is always a residual risk.
Wie ist sowas möglich ? Ich bin davon ausgegangen, dass ihr das prüft, bevor es öffentlich gemacht wird.
Ist ja nen Witz.
Wieso sollte ich jetzt noch weiterhin Mods downloaden, wenn sie Viren enthalten KÖNNEN ? Mein Vertrauen ist angeschlagen.
Quote: Alex
You're completely right, Szthomas: We have to be more carefully, but there is absolutely no reason to flip out.
But anyway, it's a very sad moment for GTA modding.
@Andryvision09:
Right. We have to carry the responsibility to inform those people who have installed this malicious mods.
Quote: IForgotPassword
So, the .asi mods may be dangerous?
people who do all this should be at least expelled from the page, and if possible; locate and send them to the afterlife (kill)
- Texture, Handling and other mods which have to be installed with OpenIV are 100% safe.
- *.lua and *.cs mods are pretty safe because malicious software can not be hidden easily.
- *.asi and *.dll mods are POTENTIALLY dangerous, because malicious software COULD be hidden. I'm sure that 99.9% of ASI and DLL mods are safe but there is a risk.
So, the .asi mods may be dangerous?
I don't want to offense any modder or author with my comment, I am just worried now. Because - funny thing- this morning my anti vir software said that the Mod "Car Controls" (I downloaded v2, got updated to v3 over time) could be a virus. It contains "Hacktool.Win64.Agent.p". Is that normal? I use "Kaspersky Internet Security". Car Controls is a ScriptHook mod and comes as an .asi data.
You're completely right, Szthomas: We have to be more carefully, but there is absolutely no reason to flip out.
But anyway, it's a very sad moment for GTA modding.
@Andryvision09:
Right. We have to carry the responsibility to inform those people who have installed this malicious mods.
Most of the mod makers are still "clean" and they are playing nice, so i don't think this event will cause great troubles in the future, but we need to be more careful from now on, that's for sure. It is kinda sad that people are willing to use even mods to spread those shity things...
== [ENG] ==
I can't believe this can happen in a community that only makes extra content for users.
This kind of things scare the shit out of me, cause you never expect one day, an asshole could do anything like this. Great.
Well... now, all the GTA V MODs' places will try to find new malware to prevent another disaster like this.
Despite the situation is hard, is great to see all the people taking care of this problems.
Greetings.
== [ESP] ==
No puedo creer que esto ocurra en una comunidad que solo hace contenido extra para los usuarios.
Este tipo de cosas me ponen los pelos de punta, porque nunca esperas que un día, un capullo pueda hacer algo como esto. Genial.
Bueno... por ahora, todas las comunidades de MODs de GTA V están intentando encontrar nuevos malwares para prevenir otro desastre como este. Y a pesar de que la situación sea dura, me parece genial ver a todo el mundo moverse por esta clase de problemas.
Saludos.