Post: Possibility of Trojan Downloader/Spyware installed via GTA V Mod?
05-14-2015, 04:19 PM #1
Passion
League Champion
(adsbygoogle = window.adsbygoogle || []).push({}); AboutSeven wrote this:

Hey all, first time posting here.

Please excuse my ignorance on this subject, as I could be over reacting about something I simply have no knowledge of, but this has definitely raised some red flags.

I came across something pretty startling today after reviewing my processes that were running on my computer. I tend to do this a lot out of paranoia, just checking that I don't have stuff running in the background that I don't want running, or if I ever possibly run into something that is out of the ordinary that could possibly be malware. I happened to notice that the Windows C# compiler running the background as csc.exe. I have never noticed noticed this running in the background, and there really is no reason for a C# compiler to be running in the background because I've never even programmed in C#. This is a normal system file, but I decided to pop open Process Explorer and took a look at the process in detail. First thing I noticed is that it was sending and receiving some data across the internet. That was the first red flag, as why would a compiler be accessing the internet? (Again ignorant on this subject, maybe compilers do connect to the internet for specific reasons that I do no know of). Second, not only was the normal system file of the .exe in the path url, but also an .exe located in my Temp folder called Fade.exe. I went to the location of this, and found the .exe with another folder called Data. Within that folder was another called Logs, and then two folders with recent dates, and within those were files called Session1.bin, Session2.bin, and so on.

Here are some images of the folder hierarchy and the files in question:
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.

So sure enough, I'm freaking out at this point. The Fade.exe had hijacked an official system file, the C# Compiler, and was accessing the internet while keeping what seems to be logs of my system in the hidden temp directory. I then did a Malwarebytes scan and it reported that Fade.exe had also hijacked a part of the registry to force this program to start up on windows logon, as can be seen here: You must login or register to view this content.
Also, two other files were created in the temp directory with the names .z and init..exe which can be seen here: You must login or register to view this content.

I did more research on this Fade.exe program, but couldn't find anything except for this single instance here which seems to fit the description perfectly: [url]https://vms.drweb-av....irus/?i=4337630[/url]
For some reason, directly scanning the file with Malwarebytes reports that it is not malware, and only 3 out of 56 virus scanners found Fade.exe to be malicious: [url]https://www.virustot...a9336/analysis/[/url]

Now where does GTA V modding come into this? Well, I compared the date of when the Fade.exe instance was created to whatever I had in my download folder. I don't go around downloading random programs from non-trusted sources, so I couldn't believe that I had gotten a virus from a program. Well sure enough, I noticed all the mods that I had downloaded for GTA V had matched the date when this folder was created. I decided to experiment. I first deleted all instances of the Fade.exe folder, the files in the temp folder, and the registry hijack. I then ran GTA V with the mods installed. Fade.exe had returned after the game had loaded up (not to the menu screen, to the game itself), along with everything else. Again I removed the Fade.exe and all the other stuff, and I then removed all mods but ScriptHook V and its Native Trainer and relaunched the game. The first thing I noticed is that GTA V started up fullscreen when I did this, when it started windowed with the mods installed. Also, with the mods installed, I always noticed a flashing window right before the game finished loading which was gone after removing the mods. After starting up GTA V without the mods and only ScriptHook V, there was no Fade.exe or any other files.

Please note that all mods are .asi and .lua type mods. It's not like I ran some random program or something.

This brings me to you guys, because due to my ignorance, I have no idea if this is normal behavior or not. It sure doesn't look like normal behavior, especially considering that it hijacks the registry for windows startup, runs in the background without GTA V running, and seems to be contacting a server. Have mods ever been vulnerable to things like this before? I'm going to post this right now so people can go ahead and read it, but I'm going to try and update this with more information after I do some more testing to see which mod is causing this.

Update: The first mod that I found to be the culprit was Angry Planes, which can be found here: [url]https://www.gta5-mod...ts/angry-planes[/url]
I tested it twice, I would remove the Fade.exe and all of the other files, load up GTA V with only Angry Planes installed, and the Fade.exe would appear with the registry hijacks and other files. Loading up GTA V without Angry Planes does not add any files, so I can only assume that this mod is the one causing it.


SOURCE :

You must login or register to view this content.
(adsbygoogle = window.adsbygoogle || []).push({});
05-14-2015, 06:52 PM #2
PS3 ITA DEX <3
Are you high?
Yes, the .ASI can install malware on your computer. Its a bit harder to detect considering it is encrypted. NoClip and Angry planes both cause this. The Fade.exe is a password stealer / Keylogger. Clean the computer delete the mods and all the sources of fade. Then CHANGE EVERY PASSWORD. Virus scan everything.. The file might not be "Fade.exe" but Angry Planes or noclip I forget likes to make a init file with Malwarebytes blocks so check your history for that as well.
05-14-2015, 09:45 PM #3
I don't have install Angry-Planes and i don't have this virus.

I have No-Clip, Endeavour Mod Menu, Dev-C trainer, and my personnal trainer for online.
All work perfectly.
05-14-2015, 09:49 PM #4
PS3 ITA DEX <3
Are you high?
Originally posted by Kaotic13 View Post
I don't have install Angry-Planes and i don't have this virus.

I have No-Clip, Endeavour Mod Menu, Dev-C trainer, and my personnal trainer for online.
All work perfectly.


No-Clip may not install Fade.exe but it could install init Winky Winky just because it works for you and you don't look doesn't mean its not there. Get malwarebytes and a do scan.
06-08-2015, 06:43 AM #5
LV2
I defeated!
Originally posted by Passion View Post
AboutSeven wrote this:

Hey all, first time posting here.

Please excuse my ignorance on this subject, as I could be over reacting about something I simply have no knowledge of, but this has definitely raised some red flags.

I came across something pretty startling today after reviewing my processes that were running on my computer. I tend to do this a lot out of paranoia, just checking that I don't have stuff running in the background that I don't want running, or if I ever possibly run into something that is out of the ordinary that could possibly be malware. I happened to notice that the Windows C# compiler running the background as csc.exe. I have never noticed noticed this running in the background, and there really is no reason for a C# compiler to be running in the background because I've never even programmed in C#. This is a normal system file, but I decided to pop open Process Explorer and took a look at the process in detail. First thing I noticed is that it was sending and receiving some data across the internet. That was the first red flag, as why would a compiler be accessing the internet? (Again ignorant on this subject, maybe compilers do connect to the internet for specific reasons that I do no know of). Second, not only was the normal system file of the .exe in the path url, but also an .exe located in my Temp folder called Fade.exe. I went to the location of this, and found the .exe with another folder called Data. Within that folder was another called Logs, and then two folders with recent dates, and within those were files called Session1.bin, Session2.bin, and so on.

Here are some images of the folder hierarchy and the files in question:
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.

So sure enough, I'm freaking out at this point. The Fade.exe had hijacked an official system file, the C# Compiler, and was accessing the internet while keeping what seems to be logs of my system in the hidden temp directory. I then did a Malwarebytes scan and it reported that Fade.exe had also hijacked a part of the registry to force this program to start up on windows logon, as can be seen here: You must login or register to view this content.
Also, two other files were created in the temp directory with the names .z and init..exe which can be seen here: You must login or register to view this content.

I did more research on this Fade.exe program, but couldn't find anything except for this single instance here which seems to fit the description perfectly: [url]https://vms.drweb-av....irus/?i=4337630[/url]
For some reason, directly scanning the file with Malwarebytes reports that it is not malware, and only 3 out of 56 virus scanners found Fade.exe to be malicious: [url]https://www.virustot...a9336/analysis/[/url]

Now where does GTA V modding come into this? Well, I compared the date of when the Fade.exe instance was created to whatever I had in my download folder. I don't go around downloading random programs from non-trusted sources, so I couldn't believe that I had gotten a virus from a program. Well sure enough, I noticed all the mods that I had downloaded for GTA V had matched the date when this folder was created. I decided to experiment. I first deleted all instances of the Fade.exe folder, the files in the temp folder, and the registry hijack. I then ran GTA V with the mods installed. Fade.exe had returned after the game had loaded up (not to the menu screen, to the game itself), along with everything else. Again I removed the Fade.exe and all the other stuff, and I then removed all mods but ScriptHook V and its Native Trainer and relaunched the game. The first thing I noticed is that GTA V started up fullscreen when I did this, when it started windowed with the mods installed. Also, with the mods installed, I always noticed a flashing window right before the game finished loading which was gone after removing the mods. After starting up GTA V without the mods and only ScriptHook V, there was no Fade.exe or any other files.

Please note that all mods are .asi and .lua type mods. It's not like I ran some random program or something.

This brings me to you guys, because due to my ignorance, I have no idea if this is normal behavior or not. It sure doesn't look like normal behavior, especially considering that it hijacks the registry for windows startup, runs in the background without GTA V running, and seems to be contacting a server. Have mods ever been vulnerable to things like this before? I'm going to post this right now so people can go ahead and read it, but I'm going to try and update this with more information after I do some more testing to see which mod is causing this.

Update: The first mod that I found to be the culprit was Angry Planes, which can be found here: [url]https://www.gta5-mod...ts/angry-planes[/url]
I tested it twice, I would remove the Fade.exe and all of the other files, load up GTA V with only Angry Planes installed, and the Fade.exe would appear with the registry hijacks and other files. Loading up GTA V without Angry Planes does not add any files, so I can only assume that this mod is the one causing it.


SOURCE :

You must login or register to view this content.


Did some1 say Trojan ? Cool Troll
06-09-2015, 07:46 AM #6
Default Avatar
Bch
Guest
Originally posted by Passion View Post
AboutSeven wrote this:

Hey all, first time posting here.

Please excuse my ignorance on this subject, as I could be over reacting about something I simply have no knowledge of, but this has definitely raised some red flags.

I came across something pretty startling today after reviewing my processes that were running on my computer. I tend to do this a lot out of paranoia, just checking that I don't have stuff running in the background that I don't want running, or if I ever possibly run into something that is out of the ordinary that could possibly be malware. I happened to notice that the Windows C# compiler running the background as csc.exe. I have never noticed noticed this running in the background, and there really is no reason for a C# compiler to be running in the background because I've never even programmed in C#. This is a normal system file, but I decided to pop open Process Explorer and took a look at the process in detail. First thing I noticed is that it was sending and receiving some data across the internet. That was the first red flag, as why would a compiler be accessing the internet? (Again ignorant on this subject, maybe compilers do connect to the internet for specific reasons that I do no know of). Second, not only was the normal system file of the .exe in the path url, but also an .exe located in my Temp folder called Fade.exe. I went to the location of this, and found the .exe with another folder called Data. Within that folder was another called Logs, and then two folders with recent dates, and within those were files called Session1.bin, Session2.bin, and so on.

Here are some images of the folder hierarchy and the files in question:
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.

So sure enough, I'm freaking out at this point. The Fade.exe had hijacked an official system file, the C# Compiler, and was accessing the internet while keeping what seems to be logs of my system in the hidden temp directory. I then did a Malwarebytes scan and it reported that Fade.exe had also hijacked a part of the registry to force this program to start up on windows logon, as can be seen here: You must login or register to view this content.
Also, two other files were created in the temp directory with the names .z and init..exe which can be seen here: You must login or register to view this content.

I did more research on this Fade.exe program, but couldn't find anything except for this single instance here which seems to fit the description perfectly: [url]https://vms.drweb-av....irus/?i=4337630[/url]
For some reason, directly scanning the file with Malwarebytes reports that it is not malware, and only 3 out of 56 virus scanners found Fade.exe to be malicious: [url]https://www.virustot...a9336/analysis/[/url]

Now where does GTA V modding come into this? Well, I compared the date of when the Fade.exe instance was created to whatever I had in my download folder. I don't go around downloading random programs from non-trusted sources, so I couldn't believe that I had gotten a virus from a program. Well sure enough, I noticed all the mods that I had downloaded for GTA V had matched the date when this folder was created. I decided to experiment. I first deleted all instances of the Fade.exe folder, the files in the temp folder, and the registry hijack. I then ran GTA V with the mods installed. Fade.exe had returned after the game had loaded up (not to the menu screen, to the game itself), along with everything else. Again I removed the Fade.exe and all the other stuff, and I then removed all mods but ScriptHook V and its Native Trainer and relaunched the game. The first thing I noticed is that GTA V started up fullscreen when I did this, when it started windowed with the mods installed. Also, with the mods installed, I always noticed a flashing window right before the game finished loading which was gone after removing the mods. After starting up GTA V without the mods and only ScriptHook V, there was no Fade.exe or any other files.

Please note that all mods are .asi and .lua type mods. It's not like I ran some random program or something.

This brings me to you guys, because due to my ignorance, I have no idea if this is normal behavior or not. It sure doesn't look like normal behavior, especially considering that it hijacks the registry for windows startup, runs in the background without GTA V running, and seems to be contacting a server. Have mods ever been vulnerable to things like this before? I'm going to post this right now so people can go ahead and read it, but I'm going to try and update this with more information after I do some more testing to see which mod is causing this.

Update: The first mod that I found to be the culprit was Angry Planes, which can be found here: [url]https://www.gta5-mod...ts/angry-planes[/url]
I tested it twice, I would remove the Fade.exe and all of the other files, load up GTA V with only Angry Planes installed, and the Fade.exe would appear with the registry hijacks and other files. Loading up GTA V without Angry Planes does not add any files, so I can only assume that this mod is the one causing it.


SOURCE :

You must login or register to view this content.


A .ASI file is the same as a .dll, which is essentially a program library used by other programs, therefore have the full capability as a normal EXE. And yes there has been reports of quite a few recently

The following user thanked Bch for this useful post:

Passion

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo