Unity True Facials [v0.53a Pro] [HenryTaiwan]

3.70 star(s) 51 Votes

MavisFeatherlight

Active Member
Mar 17, 2019
532
648
Temp files can't really do anything in your computer (look it up). They are created depending how many times you use a program, at times, it's sort of a way they purge their stuff and some may access them at times to function properly (like Fallout mod managers, but you can still delete the files, the program may create them again, some may have a few glitches). But that folder can be safely deleted at any moment and nothing will happen, heck, Windows won't even stop you from deleting it. Do you think a malware just installs itself in there and starts to operate from there, when anyone can just delete the folder?

I literally checked the game files with Malwarebytes and it shows zero issues, so i really don't know what to say or what happened to you other than all popular AV programs are malware to me themselves, they probably can look everything in your computer and other stuff, slowing Windows down and having rights over any other program, from an external company. All i can say is that your BitDefender just decided to shit on itself for no reason, making a mess. If you believe anything that a popular "antivirus" (which is just another form of massive bloatware) says (which are popular indeed for false positives) and now you are convinced you must reinstall Windows, i really don't know what to say.

Defender, having common sense and informing yourself on how malware truly works and manually working to remove it's what everyone should do.

Operaupdate.exe it's just what Opera browser uses for updates. Now idea what it may generate in Temp folder or for what reason it got formed in your files if you don't have it installed, but i'd check for other stuff and not blame this game's files only.
Do you work in IT or cyber security?
 

gghhoosstt123

Member
Oct 9, 2022
264
266
The .exe file does NOTHING of what this guy believes only because a website simulates its "behavior". To begin with, the game has zero connection to the internet, you can check the reports in Task Manager and you could also check the current connections on your computer with a CMD command:

Secondly, the game's .exe doesn't "spawn" any extra services lmao, the guy just posts that idiotic BS, but provides no real info on that. I am always very aware of what runs on my computer, what services are running, background stuff, start up programs and such, i keep my system tweaked and i ALWAYS know what is running and what shouldn't be running, i use stuff such as Process Explorer for example. I can guarantee this game and none of its files are malicious or malware.

Don't trust someone that is literally pasting screenshots from a website that simulates malware behavior based on a false positive, if he knew what he was talking about, he'd run the files on a Virtual Machine and show us the amount of "bad" behavior the game would create in Windows. Then he tells people to wipe Windows :FacePalm:.
Yea i just extracted the game and it opens up normally just like version 42b used to, the game files also look really normal too so i don't think there is any malware to it. And i never use AV anyways once you yourself understand what to look for or what to not look for, just enough knowledge and experience is need with these kind of things. AV just slows the pc down and always being a nusance to anything that is installed into pc so i don't bother with AVs.
 
  • Like
Reactions: rev_10

JamCrumpet

Newbie
Apr 28, 2018
49
174
Ive ran the game before all of this drama kicked off and it seems fine, Ill do more digging but im pretty sure this is all just false positive fear posting
 
  • Like
Reactions: rev_10

Blacktearss

Newbie
Feb 18, 2020
42
33
I will only speak from my experience and without much computer knowledge. Last year I downloaded this game. Since that time some time passed and my PC stopped being the same. Even in the short period of time they withdrew 140 dollars from my bank account in my country through Paypal without authorizing or checking anything at the bank.

They added and removed my card like it was nothing. As if they knew all my details. In my experience I DO NOT RECOMMEND DOWNLOADING THIS GAME. Everyone is free to do as they please. It's a great game, really. But it's not worth the price xD

Luckily my bank recognized that it was an "attack" on my bank account and refunded me the money.

I am an active user and I try many games on this forum. This is the first time something similar has happened to me. True Facials has something very strange and dangerous in my opinion. Thank you for reading.
 

JamCrumpet

Newbie
Apr 28, 2018
49
174
I will only speak from my experience and without much computer knowledge. Last year I downloaded this game. Since that time some time passed and my PC stopped being the same. Even in the short period of time they withdrew 140 dollars from my bank account in my country through Paypal without authorizing or checking anything at the bank.

They added and removed my card like it was nothing. As if they knew all my details. In my experience I DO NOT RECOMMEND DOWNLOADING THIS GAME.
How have you linked the two though? What direct evidence do you have?
Otherwise it seems like coincidental superstition, like, "hey I want to the bakers on the same day I got hacked I bet the bakers stole my card info when I paid for my buns!"
The mods always check the files, and the comment specifically calls it a "false positive"
Ive since checked some of the listed folders people mentioned here and... nada, they dont even exist.

Sounds like people are getting viruses from other sources, or just THINKING they have a virus and attributing to a false positive from the game. FYI, I didnt get any warning.
Though I have deleted the game because they removed all the fucking characters.
 
  • Like
Reactions: Xddrekt and rev_10

anzug

Member
Oct 30, 2019
181
407
man, this update was a roller coaster of emotion:
Seeing that it exists at all and Henry is alive: :D
Seeing the absolutely horrible framerate and briefly wondering if my PC is busted: :oops:
Seeing that dickgirls are now an option: :D
Seeing that almost all the other options, including characters, are gone: :cry:
Seeing that it's just a demo, so there's hope: :D
 

Blacktearss

Newbie
Feb 18, 2020
42
33
I run the 0.5 version one time.
I'm doomed?
Which antimalware to use?
In my experience I couldn't do anything once installed. Maybe change the passwords on your computer and your accounts. But do it from another device. I have not formatted my PC because I have many important jobs... But I say again that installing this game was a before and after. Something really changed for the worse. And I don't care if they believe me or those who know a lot about computers give me shit. I'm just talking about my experience.
 

Blacktearss

Newbie
Feb 18, 2020
42
33
How have you linked the two though? What direct evidence do you have?
Otherwise it seems like coincidental superstition, like, "hey I want to the bakers on the same day I got hacked I bet the bakers stole my card info when I paid for my buns!"
The mods always check the files, and the comment specifically calls it a "false positive"
Ive since checked some of the listed folders people mentioned here and... nada, they dont even exist.

Sounds like people are getting viruses from other sources, or just THINKING they have a virus and attributing to a false positive from the game. FYI, I didnt get any warning.
Though I have deleted the game because they removed all the fucking characters.
Look, you are very right. What happened is when I installed the game my PC alarmed not one but many viruses in quarantine. I was never able to eliminate the alert or apparently the virus. Even every time I do a check on my PC it still shows the same thing. Let me look in my email for the evidence of paypal.

The truth is, as I mentioned many times before, I don't know if it was a coincidence or not, but what it is is that installing this game produced changes in my computer for the worse. And that was instantly.
 

gghhoosstt123

Member
Oct 9, 2022
264
266
man, this update was a roller coaster of emotion:
Seeing that it exists at all and Henry is alive: :D
Seeing the absolutely horrible framerate and briefly wondering if my PC is busted: :oops:
Seeing that dickgirls are now an option: :D
Seeing that almost all the other options, including characters, are gone: :cry:
Seeing that it's just a demo, so there's hope: :D
My main rollar coaster ride is see the battle of either the game is malware or not XD, i am on non malware side tho :p
 

Eldoween

Newbie
Jan 1, 2023
68
121
Can an administrator come by and tell us if the site has done everything necessary to be 100% safe with the download?
 

zbunk

Member
Jul 7, 2021
136
587
I will only speak from my experience and without much computer knowledge. Last year I downloaded this game. Since that time some time passed and my PC stopped being the same. Even in the short period of time they withdrew 140 dollars from my bank account in my country through Paypal without authorizing or checking anything at the bank.

They added and removed my card like it was nothing. As if they knew all my details. In my experience I DO NOT RECOMMEND DOWNLOADING THIS GAME. Everyone is free to do as they please. It's a great game, really. But it's not worth the price xD

Luckily my bank recognized that it was an "attack" on my bank account and refunded me the money.

I am an active user and I try many games on this forum. This is the first time something similar has happened to me. True Facials has something very strange and dangerous in my opinion. Thank you for reading.
the amount of tech illiterate people on this site is scary, there is nothing and never was anything wrong with the game, your opsec is just garbage and someone got into your account. reading this thread is actual torture, shit i've been using linux for 3 years now and i know more about windows than 90% of people here.

1695807623056859.jpg
 

MavisFeatherlight

Active Member
Mar 17, 2019
532
648
the amount of tech illiterate people on this site is scary, there is nothing and never was anything wrong with the game, your opsec is just garbage and someone got into your account. reading this thread is actual torture, shit i've been using linux for 3 years now and i know more about windows than 90% of people here.

View attachment 3766001
and another Linux user who tells you that he is a Linux user and therefore knows everything better.
that doesn't really help to get rid of the reputation that all Linux users are "arrogant toxic assholes".

as I said, I won't touch the game until a specialist can assure me that I won't ruin my PC.

I'm also surprised that no admin has said anything about it yet.
 

Blacktearss

Newbie
Feb 18, 2020
42
33
It was not my intention to put on a drama, I do declare myself ignorant of computers. Chances are there are plenty of people here who know more than me. I am only telling my personal experience and my recommendation from my discretion. Everyone is free to do whatever you want! If someone is doing great and hasn't had a virus alarm go off, please comment here :)
the amount of tech illiterate people on this site is scary, there is nothing and never was anything wrong with the game, your opsec is just garbage and someone got into your account. reading this thread is actual torture, shit i've been using linux for 3 years now and i know more about windows than 90% of people here.

View attachment 3766001
 

punhetas

Active Member
Nov 2, 2016
632
1,305
It was not my intention to put on a drama, I do declare myself ignorant of computers. Chances are there are plenty of people here who know more than me. I am only telling my personal experience and my recommendation from my discretion. Everyone is free to do whatever you want! If someone is doing great and hasn't had a virus alarm go off, please comment here :)
To be clear, you're talking about version .42 and not the new 0.5 that some are complaining.

The previous has been amply discussed before in the thread since they used a system translator because the programer is corean ( if I'm not mistaken).
The "trojan" was a script to run the translator on the .exe that most antivírus flagged as a generic trojan.

This new "situation" might be something of the sort, don't know.
 

olie

Newbie
Feb 23, 2022
37
50
Personally I'm not tech literate enough to really know what half the stuff ya'll are talkin about means, but if this program has a chance of containing a virus, it should be re-checked to be virus free.

First of all, was it 0.5 or 0.4.2 that had the virus? Was it both? If it was 0.4.2, was it the 0.4.2 that was originally on the main page of this or was it the one that was posted by someone after 0.4.2 was removed from the main page? From what I can see, it seems like different people are seeing different things, which I think (as a non-tech expert mind you) it could just be that if the virus exists, it may only exist on one version.
 

scoobydoo86

New Member
Mar 6, 2021
5
2
DO NOT RUN THIS GAME

UNTIL THE DEVELOPER / OP CAN EXPLAIN THESE DETECTIONS, AND FILE OPERATIONS.








Both do the same, both have different anti virus results.


The virus one, injects into C:\Program Files (x86)\Google1608_1329478733\bin\updater.exe

View attachment 3764914


Does this really look like something this forum shouldn't look into?

Do I need to manually reverse engineer this executable to prove the developer (OR ORIGINAL POSTER !! ! ) is doing something fishy.

View attachment 3764915

Related parents, aka shared file hashes. Why is it affiliated with keygens, and random zips???

It establishes connections to multiple external IP addresses. These connections are potentially command-and-control (C2) servers, indicating the malware's attempt to communicate with an external source for instructions or data exfiltration.

Spawns new processes and services, indicating the execution of its payload and attempts to maintain control over the infected system.

It modifies registry entries in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run to ensure it runs every time the system starts.

Changes in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services to manipulate system services, often to disable security-related services or to create new malicious services.

Modifies the key HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE, potentially to affect browser behavior and user credential handling.

View attachment 3764941 View attachment 3764942

The malware creates numerous .tmp files in the user's temporary directory (AppData\Local\Temp). These files are likely used as intermediate stages in the malware's execution process.

The malware uses cmd.exe to execute batch files (.bat) located in the temporary directory. These batch files are used to execute the primary malicious payload.

The malware masquerades as the Google updater to blend in with legitimate processes. This is indicated by paths like C:\Program Files (x86)\Google\Update\.

By creating and executing multiple batch files, the malware ensures persistence and continuous execution, making it harder to remove.
Downloaded via Gofile. (Original link on 22.06.24 before 12:32)
Kaspersky AV has nothing to complain about.
No files are generated in the TEMP folder when the exe file is executed. Cannot reproduce or confirm the behaviour described here. ‍♀
 

anzug

Member
Oct 30, 2019
181
407
For whatever it's worth, Malwarebytes didn't seem to have an issue with it, at least not for me.
 
3.70 star(s) 51 Votes