Schedule I

Schedule I

Statistieken weergeven:
Found a virus in Schedule I files
My Antivirus software Kaspersky detected a virus in Schedule 1 files

File - version.dll - HEUR:Trojan.Win64.DllHijack.gen
Location - C:\Program Files (86)\Steam\steamapps\common\Schedule I\
Origineel geplaatst door Aera:
Had the same issue and it does not come from mods itself but from the MelonLoader and seems to be a false positive when checking a VirusTotal. The file it flagged for you comes from installing the MelonLoader.
< >
16-30 van 55 reacties weergegeven
Origineel geplaatst door Banzai:
These mods are known to be infected:

🛑 Increased Stacklimit (contains malware!)
🛑 Backpack Mod – Reupload (also infected!)
I don't have any of those
Origineel geplaatst door Rudra_Jr:
Origineel geplaatst door Banzai:
These mods are known to be infected:

🛑 Increased Stacklimit (contains malware!)
🛑 Backpack Mod – Reupload (also infected!)
I don't have any of those

Which are you using?
Origineel geplaatst door Rudra_Jr:
Origineel geplaatst door Shaken_Widow:
considering you downloaded and installed something that contained that virus, (likely a mod that injected it,) that opinion is valid

kaspersky is in fact trash, it didn't catch it until after it likely had already done damage, you likely now have to redo all of your passwords on everything because that virus was actually able to be installed to begin with because it was likely activated upon the installation of whatever put it there, again likely a mod.
I've been using Nexus for a long time, never even considered it. But you're right it must be a mod, thanks for the help
everyone swears by nexus, but im am of an age that i have seen it filled with viruses for decades now.

i like modding, but i steer clear of nexus period because of crap like this, especially on games like this that are brand new in early access, that's just asking for trouble as there is no real security measures in place in the game itself, and you're rolling the dice with nexus.

i prefer being in contact with mod authors myself through things like github, and actually being versed on the actual efforts required to make such mods so i don't download something like that.

not everyone has my patience tho.

to be clear: it may be that nexus mods itself has been infested in some shape or form, and it may be the download mirrors themselves or the actual direct links that are affected, not specifically the mods.
Laatst bewerkt door Shaken_Widow; 17 apr om 7:45
Origineel geplaatst door Rudra_Jr:
Origineel geplaatst door Banzai:
These mods are known to be infected:

🛑 Increased Stacklimit (contains malware!)
🛑 Backpack Mod – Reupload (also infected!)
I don't have any of those

Then someone else snuck a virus in another mod, unless kaspersky quarantined because of similar traits.

Listing your mods, uploading the sample to virustotal, figuring out where that file came from, and reporting to Tyler and the modding discord would also be a good step.

Either way, you should be changing all your passwords from a clean PC and doing a thorough analysis of your computer to remove any infections and remnants.
Laatst bewerkt door Havok; 17 apr om 7:47
I don't have any version.dll and I do not run antivirus software (no, not even defender) so it being caught and quarantined/deleted is impossible.
Origineel geplaatst door Banzai:
Origineel geplaatst door Rudra_Jr:
I don't have any of those

Which are you using?
These are the mods I have

Always visible clock
Auto sow
Deal optimizer
Instant delivery
Reshelves
Trash life time
Wages manager
Wolfs business improvements
Origineel geplaatst door Havok:
Origineel geplaatst door Rudra_Jr:
I don't have any of those

Then someone else snuck a virus in another mod, unless kaspersky quarantined because of similar traits.

Listing your mods, uploading the sample to virustotal, figuring out where that file came from, and reporting to Tyler and the modding discord would also be a good step.

Either way, you should be changing all your passwords from a clean PC and doing a thorough analysis of your computer to remove any infections and remnants.
Could be a false positive but I'll do a cleanup to be safe
Origineel geplaatst door Echoz:
I don't have any version.dll and I do not run antivirus software (no, not even defender) so it being caught and quarantined/deleted is impossible.
You should atleast run the defender, everything is sus these days, never know where or what might contain a virus or malware
Origineel geplaatst door Rudra_Jr:
Origineel geplaatst door Havok:

Then someone else snuck a virus in another mod, unless kaspersky quarantined because of similar traits.

Listing your mods, uploading the sample to virustotal, figuring out where that file came from, and reporting to Tyler and the modding discord would also be a good step.

Either way, you should be changing all your passwords from a clean PC and doing a thorough analysis of your computer to remove any infections and remnants.
Could be a false positive but I'll do a cleanup to be safe
nuke the whole thing. format drive etc. once you've run malware you should assume everything it can touch is unsafe
Origineel geplaatst door Rudra_Jr:
Origineel geplaatst door Echoz:
I don't have any version.dll and I do not run antivirus software (no, not even defender) so it being caught and quarantined/deleted is impossible.
You should atleast run the defender, everything is sus these days, never know where or what might contain a virus or malware
i should not and i can not
Origineel geplaatst door Echoz:
Origineel geplaatst door Rudra_Jr:
Could be a false positive but I'll do a cleanup to be safe
nuke the whole thing. format drive etc. once you've run malware you should assume everything it can touch is unsafe
I will do a cleanup and reset the PC
Origineel geplaatst door Rudra_Jr:
Origineel geplaatst door Echoz:
I don't have any version.dll and I do not run antivirus software (no, not even defender) so it being caught and quarantined/deleted is impossible.
You should atleast run the defender, everything is sus these days, never know where or what might contain a virus or malware
many games have readmes that explicitly state to disable your antivirus when playing to stop it from crashing the game itself due to processes being stopped.

this is why many people just run their pcs without defender on at all, it is in fact perfectly safe as long as they practice their own prudence.

the first antivirus is to simply not just download any old file, do your research.
Origineel geplaatst door Rudra_Jr:
These are the mods I have

Always visible clock
Auto sow
Deal optimizer
Instant delivery
Reshelves
Trash life time
Wages manager
Wolfs business improvements

Always on Clock and Auto Sow both have comments about malicious traces.

Wages manager and Wolfs business improvements dont exist on nexus any more.

Im not downloading all of these to find which has the version.dll, but considering 2 of your mods have questionable traces, false positive or not, idk man..
I would wipe the drive, or apply an image if you have a backup, get rid of that data
De auteur van dit onderwerp heeft aangegeven dat dit bericht het oorspronkelijke onderwerp beantwoordt.
Had the same issue and it does not come from mods itself but from the MelonLoader and seems to be a false positive when checking a VirusTotal. The file it flagged for you comes from installing the MelonLoader.
< >
16-30 van 55 reacties weergegeven
Per pagina: 1530 50

Geplaatst op: 17 apr om 7:26
Aantal berichten: 55