Cities: Skylines

Cities: Skylines

View Stats:
This topic has been locked
J_1111 Jul 14, 2018 @ 2:52am
Trojan malware found recently
My malware program found the following trojan in the game recently:
Trojan.Win32.Kryptik.vb!n
It is found in:
C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Mono\lib\mono\2.0\Ic.exe
I advise people to run malware programs to get rid of it.
< >
Showing 1-15 of 31 comments
MarkJohnson Jul 14, 2018 @ 3:21am 
What program found it as malware?

Malwarebytes shows good. Windows Defender reports safe as well.
CyberVibes Jul 14, 2018 @ 3:24am 
What Anti Virus are you using ?

It's probably a false positive, i have two seperate scanners and that file comes back clean for me.
CyberVibes Jul 14, 2018 @ 3:31am 
Ok it's not a false positive, it is a trojan.

See the info here for removal, https://forums.malwarebytes.com/topic/157179-removal-instructions-for-trojanagent-kryptik/

The question now is how did it get there, there's no way it's come from updates from Paradox or Colossal Order.

Edit: How did Trojan.Agent Kryptik get on my computer?

Trojans use many ways to infect your computer. This particular one was spread by using Silverlight and Adobe Flash exploits following this flowchart:

https://blog.malwarebytes.com/threat-analysis/2014/08/shining-some-light-on-the-unknown-exploit-kit/

Always make sure your flash is updated or better still stay away from it and silverlight, they have been vunerable from day one and failing to keep them updated results in infections like this.

Last edited by CyberVibes; Jul 14, 2018 @ 3:37am
J_1111 Jul 14, 2018 @ 5:16am 
The program I used to detect the trojan is GridinSoft Anti-Malware.
Tankfriend Jul 14, 2018 @ 7:05am 
Originally posted by CyberVibes:
Ok it's not a false positive, it is a trojan.
False positive doesn't mean that what your AV system thinks it has found doesn't exist. It means that what your system thinks is a trojan etc. is not actually one, but just a harmless file. Especially the commercial AV systems tend to produce a large number of false positives, either to be on the safe side of things, or to be alarmist and make you pay for the software.

Whatever is the case for you, though, it's a good idea to take the necessary precautions - just in case.
Last edited by Tankfriend; Jul 14, 2018 @ 7:05am
Meesmoth Jul 14, 2018 @ 8:26am 
Okay what is this? I have played Cities: Skylines like only a couple of hours ago.

#RIPCSUsers
Streeto Jul 14, 2018 @ 9:09am 
Originally posted by Meesmoth:
Okay what is this? I have played Cities: Skylines like only a couple of hours ago.

#RIPCSUsers

Lol it's just some guy who's probably watched some questionable videos on the internet, and a virus has spread into a random folder, just happened to be his CS folder I guess.

Edit: I also have this file LOL, no virus though, seems the trojan is being an imposter.
Last edited by Streeto; Jul 14, 2018 @ 9:12am
MarkJohnson Jul 14, 2018 @ 10:29am 
Originally posted by CyberVibes:
Ok it's not a false positive, it is a trojan.

See the info here for removal, https://forums.malwarebytes.com/topic/157179-removal-instructions-for-trojanagent-kryptik/

The question now is how did it get there, there's no way it's come from updates from Paradox or Colossal Order.

Edit: How did Trojan.Agent Kryptik get on my computer?

Trojans use many ways to infect your computer. This particular one was spread by using Silverlight and Adobe Flash exploits following this flowchart:

https://blog.malwarebytes.com/threat-analysis/2014/08/shining-some-light-on-the-unknown-exploit-kit/

Always make sure your flash is updated or better still stay away from it and silverlight, they have been vunerable from day one and failing to keep them updated results in infections like this.

What A/V caught it?

If it was Malwarebytes, then it is likely coming from a mod.

If Adobe is updated properly and not a new version of an old virus, the virus is harmless and can't infect you.

But let this be a good lesson on downloading stuff off the workshop. Make sure the author has the source code available. If the Authors are hiding the source code, you risk getting a virus as you won't know what extra code is in the mod and allowing a virus into your system.
MarkJohnson Jul 14, 2018 @ 10:35am 
Originally posted by Neb:
What about Shockwave flash ?

Always keep all of your software up to date or you have a higher risk of infection.
ephil4705 Jul 14, 2018 @ 10:59am 
I don't know if this is relevant but a few days ago malwarebytes detected a trojan on an asset page, but I didn't click to subscibe and had no probiens since
Last edited by ephil4705; Jul 14, 2018 @ 11:01am
Meesmoth Jul 14, 2018 @ 11:13am 
okay seriously is this a widespread issue? I don't want to uninstall CS from my machine just because some random virus got into the game files for unknown reasons.
Ualdriver Jul 14, 2018 @ 11:31am 
Yeah, do I actually have to go through all of this? What does the virus do anyway?
shponglefan Jul 14, 2018 @ 11:37am 
Ran Malwarebytes; nothing detected on my system.
Last edited by shponglefan; Jul 14, 2018 @ 11:40am
Metacritical Jul 14, 2018 @ 11:57am 
best thread ever
Meesmoth Jul 14, 2018 @ 12:00pm 
Originally posted by Metacritical:
best thread ever
Seriously this is not a joke thread, it is a serious problem and there is no confirmation if this is widespread, I DON'T WANT TO UNINSTALL CITIES: SKYLINES FROM MY PC just because of this random virus that entered the game files for unknown reasons.
< >
Showing 1-15 of 31 comments
Per page: 1530 50

Date Posted: Jul 14, 2018 @ 2:52am
Posts: 30