Schedule I

Schedule I

Lihat Statistik:
(URGENT)confirmed viruses found in increase stack size mod and backpack mod reupload
https://www.reddit.com/r/Schedule_I/comments/1jx6vl8/urgent_psa_malware_found_in_2_popular_schedule_1/
^^^^^^^^^^^ post on reddit from moderator
the post says that as long as you havent installed or updated it after april 11th at 10pm (EST i assume) that you should be safe but i would get rid of it anyways just to be safe (talking about the stack size limit mod)
please change yalls passwords n ♥♥♥♥, and check for any suspicious activity on your accounts
STAY SAFE AND INFORMED YALL
Terakhir diedit oleh Rix; 12 Apr @ 12:22pm
< >
Menampilkan 1-15 dari 18 komentar
Rix 12 Apr @ 12:02pm 
please share this with anyone you know is using these mods.
Rix 12 Apr @ 12:10pm 
you can install malwarebytes free and run a scan, which i would recommend
Yeah I was using the increased stack size I downloaded the mod on the 4th but even if it doesn't have anything I'm not taking that risk I don't want to lose a computer so I got an alternative mod until that gets sorted out if it does if it doesn't it's whatever.
Terakhir diedit oleh TheRebelGreaser; 12 Apr @ 12:17pm
Rix 12 Apr @ 12:21pm 
yeah the reddit post says you should be okay as long as you didnt install it after april 11th after 10 pm (id assume EST)
Havok 12 Apr @ 12:24pm 
Look, I’m normally one to advise against unproven, untested and low endorsed mods, but on this one I simply have to ask..

How did it get proven? Are the samples uploaded on VirusTotal? Were they tested using dynamic analysis on one of the major sandbox vendors? Were they unpacked and reverse engineered to discover malicious code fragments and behaviors?

Where is the proof? I’m not discrediting that they are malicious, but I would like to know exactly what they did to determine it in case other mods try the same.

Edit: looks like this is all the modding discord finding out. Looks like they are decompiling the dlls and performing static analysis on the code and finding obfuscation techniques commonly used in malicious packages to get payloads.
https://youtu.be/T-OhKIWBA-I?si=eHoAmvUNrffA8_7H
Terakhir diedit oleh Havok; 12 Apr @ 12:31pm
Diposting pertama kali oleh Rix:
yeah the reddit post says you should be okay as long as you didnt install it after april 11th after 10 pm (id assume EST)
True but I would rather be safe than sorry I mean I got bigstackz which is basically the same thing plus I do have Malwarebytes so it's not like it would notice if something was there but I would prefer to be on more the safe side to be honest.

I already gone through a couple computers for various reasons and I have been trying to be very careful with this one so any slight indication of a problem especially when it comes to that mainly I'll be cleaning whatever could have a virus in it or whatever the case may be.
Diposting pertama kali oleh Havok:
Look, I’m normally one to advise against unproven, untested and low endorsed mods, but on this one I simply have to ask..

How did it get proven? Are the samples uploaded on VirusTotal? Were they tested using dynamic analysis on one of the major sandbox vendors? Were they unpacked and reverse engineered to discover malicious code fragments and behaviors?

Where is the proof? I’m not discrediting that they are malicious, but I would like to know exactly what they did to determine it in case other mods try the same.
Well I would assume probably someone downloaded the mod after the profile transfer and the new owner updated the file to add a virus in it and someone downloaded that updated file and something was picked up by one of the antiviruses.

So the person must have immediately got rid of the file and reported it to Nexus.

Technically the file is still in Nexus but they're monitoring it until further notice cuz they didn't delete it they're just watching it if that makes any sense so you can't download the file as of right now but it won't come up as deleted if that makes any sense to you. Plus if you downloaded the file before the 11th you should be fine like in my case but I'm not even taking the risk and I don't think anyone else should.

Until Nexus can confirm that it's okay now so I would suggest alternative mods that do the same thing for a while.

Also when it comes to the backpack I think that reupload got deleted immediately cuz I didn't even know it was an reupload cuz I still have the original before it was deleted from the Creator.
Terakhir diedit oleh TheRebelGreaser; 12 Apr @ 12:31pm
Havok 12 Apr @ 12:35pm 
Diposting pertama kali oleh TheRebelGreaser:
Diposting pertama kali oleh Havok:
Look, I’m normally one to advise against unproven, untested and low endorsed mods, but on this one I simply have to ask..

How did it get proven? Are the samples uploaded on VirusTotal? Were they tested using dynamic analysis on one of the major sandbox vendors? Were they unpacked and reverse engineered to discover malicious code fragments and behaviors?

Where is the proof? I’m not discrediting that they are malicious, but I would like to know exactly what they did to determine it in case other mods try the same.
Well I would assume probably someone downloaded the mod after the profile transfer and the new owner updated the file to add a virus in it and someone downloaded that updated file and something was picked up by one of the antiviruses.

So the person must have immediately got rid of the file and reported it to Nexus.

Technically the file is still in Nexus but they're monitoring it until further notice cuz they didn't delete it they're just watching it if that makes any sense so you can't download the file as of right now but it won't come up as deleted if that makes any sense to you. Plus if you downloaded the file before the 11th you should be fine like in my case but I'm not even taking the risk and I don't think anyone else should.

Until Nexus can confirm that it's okay now so I would suggest alternative mods that do the same thing for a while.

Also when it comes to the backpack I think that reupload got deleted immediately cuz I didn't even know it was an reupload cuz I still have the original before it was deleted from the Creator.

Yea I edited my original. Mod author sold their account and the new owner injected obfuscation and payload targets on the new version.

This is really a damn shame. It’s going to scare so many people off modding and that really shouldn’t happen. But, this is the internet, and someone always has to be edgy and hurt people.. so yea..
Diposting pertama kali oleh Havok:
Diposting pertama kali oleh TheRebelGreaser:
Well I would assume probably someone downloaded the mod after the profile transfer and the new owner updated the file to add a virus in it and someone downloaded that updated file and something was picked up by one of the antiviruses.

So the person must have immediately got rid of the file and reported it to Nexus.

Technically the file is still in Nexus but they're monitoring it until further notice cuz they didn't delete it they're just watching it if that makes any sense so you can't download the file as of right now but it won't come up as deleted if that makes any sense to you. Plus if you downloaded the file before the 11th you should be fine like in my case but I'm not even taking the risk and I don't think anyone else should.

Until Nexus can confirm that it's okay now so I would suggest alternative mods that do the same thing for a while.

Also when it comes to the backpack I think that reupload got deleted immediately cuz I didn't even know it was an reupload cuz I still have the original before it was deleted from the Creator.

Yea I edited my original. Mod author sold their account and the new owner injected obfuscation and payload targets on the new version.

This is really a damn shame. It’s going to scare so many people off modding and that really shouldn’t happen. But, this is the internet, and someone always has to be edgy and hurt people.. so yea..
Yeah I can definitely see why people would be nervous but at least it was detected very quickly cuz sometimes it's always the case and at least there are alternatives so it's not too bad.

Not even just that but even though I download the mod on the 4th I'm still going to run a full scan next time I have my computer run just on the off chance
Terakhir diedit oleh TheRebelGreaser; 12 Apr @ 12:42pm
Rix 12 Apr @ 12:58pm 
yeah, i have no idea how they detected it but the account (froggyp1) has been banned and the file was deleted by nexusmods...
again no idea how they detected it but rather be safe then sorry, soon as i saw the reddit post i alt f4 without even saving the game lol
Diposting pertama kali oleh Rix:
yeah, i have no idea how they detected it but the account (froggyp1) has been banned and the file was deleted by nexusmods...
again no idea how they detected it but rather be safe then sorry, soon as i saw the reddit post i alt f4 without even saving the game lol

There are tools out there for free that allow you to decompile or view the calls that something will make.

My hunch is they were made aware the same way most people are. Someone updated, noticed something fishy or was caught by an AV heuristics, reported to the modding discord, and given they make mods and share resources to do so, they can probably just as easily pull a packed mod apart, found some code and reported to nexus. (Is normally how these things go, unfortunately)

Bigger communities are a bigger target, especially in this case, so the more people who immediately jump to update, the more people the Trojan will catch. Thankfully, most modders are super lazy and only update if something breaks, check for updates when game updates, or in some cases never update.

Fingers crossed the damage and people infected are minimal, and it’s not a nasty one that digs and tries to actively fight against removal
Terakhir diedit oleh Havok; 12 Apr @ 1:09pm
Rix 12 Apr @ 1:14pm 
fr
Diposting pertama kali oleh Havok:
Diposting pertama kali oleh Rix:
yeah, i have no idea how they detected it but the account (froggyp1) has been banned and the file was deleted by nexusmods...
again no idea how they detected it but rather be safe then sorry, soon as i saw the reddit post i alt f4 without even saving the game lol

There are tools out there for free that allow you to decompile or view the calls that something will make.

My hunch is they were made aware the same way most people are. Someone updated, noticed something fishy or was caught by an AV heuristics, reported to the modding discord, and given they make mods and share resources to do so, they can probably just as easily pull a packed mod apart, found some code and reported to nexus. (Is normally how these things go, unfortunately)

Bigger communities are a bigger target, especially in this case, so the more people who immediately jump to update, the more people the Trojan will catch. Thankfully, most modders are super lazy and only update if something breaks, check for updates when game updates, or in some cases never update.

Fingers crossed the damage and people infected are minimal, and it’s not a nasty one that digs and tries to actively fight against removal

Hey, so I'm pretty sure i downloaded this mod prior to all the BS, but I'm still concerned...

Do you know what application i would need to use to open up the dll file and see if it contains the malicious code? I've done multiple scans on my system with various methods, malwarebytes, bitdefender, microsoft defender, all come back clean but I'm worried they aren't able to detect the threats.
Diposting pertama kali oleh MightyMonte88:
Diposting pertama kali oleh Havok:

There are tools out there for free that allow you to decompile or view the calls that something will make.

My hunch is they were made aware the same way most people are. Someone updated, noticed something fishy or was caught by an AV heuristics, reported to the modding discord, and given they make mods and share resources to do so, they can probably just as easily pull a packed mod apart, found some code and reported to nexus. (Is normally how these things go, unfortunately)

Bigger communities are a bigger target, especially in this case, so the more people who immediately jump to update, the more people the Trojan will catch. Thankfully, most modders are super lazy and only update if something breaks, check for updates when game updates, or in some cases never update.

Fingers crossed the damage and people infected are minimal, and it’s not a nasty one that digs and tries to actively fight against removal

Hey, so I'm pretty sure i downloaded this mod prior to all the BS, but I'm still concerned...

Do you know what application i would need to use to open up the dll file and see if it contains the malicious code? I've done multiple scans on my system with various methods, malwarebytes, bitdefender, microsoft defender, all come back clean but I'm worried they aren't able to detect the threats.

Step 1 is to upload the DLL to virus total.

If you know for a fact that you downloaded it before the specified date in the Reddit thread, then you are safe. It’s only if you updated it after that date that you are at risk. You can’t get the Trojan if you didn’t upgrade the mod to the version that runs it thankfully. Check your downloads. If the download is BEFORE April 11, you’re good. The rest of this is optional

If you legitimately feel that you are at risk…
Disconnect the internet from your computer. On another clean computer, download the following and move to infected pc via usb. If that isn’t an option, check your etc/hosts for dns manipulation, delete any records that 0.0.0.0 virus removal stuff and download these in your computer to begin.

1. https://www.bleepingcomputer.com/download/rkill/

RKill will attempt to stop known malware processes and allow your AV to run and remove it. RKill does not remove viruses.

2. Use https://www.malwarebytes.com/mwb-download or https://www.hitmanpro.com/en-us to remove it if RKill does stop something.

https://www.eset.com/us/home/online-scanner/?srsltid=AfmBOoqtMcii5STLWH7XP6ftu29nOgPsg3A5I_CAjFBwb_jBnHX50xu3 And https://learn.microsoft.com/en-us/defender-endpoint/safety-scanner-download are also great tools.

https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer and https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns are great for viewing if you have a potential active infection as well. Be forewarned, some of the AV vendors do flag legitimate processes as malicious sometimes. Go into the options and enable submissions to VirusTotal. If it is a 1/70 and people are saying it’s safe and legitimate, it’s a false positive by the vendor and will be cleaned up in a few days. We are mainly looking for anomalies outside of system functions, and these are normally at the bottom of PE where threads like your browser will spawn.

As for inspecting dlls.. you can use https://www.jetbrains.com/decompiler/
https://www.dll-decompiler.com/
https://github.com/icsharpcode/ILSpy
https://binary.ninja/

To decompile it, but it’s not going to cleanly tell you exactly what the code does, since you have to do more to make it readable, and in many cases, de-obfuscate it.

Since this also happened in Cities Skyline 2 with a rogue DLL malware, this would be a good watch:
https://youtu.be/bvyklJ5Wie0?si=OH_Z4pSnU-775NnI
Terakhir diedit oleh Havok; 13 Apr @ 7:41am
Rix 13 Apr @ 7:35am 
Diposting pertama kali oleh Havok:
Diposting pertama kali oleh MightyMonte88:

Hey, so I'm pretty sure i downloaded this mod prior to all the BS, but I'm still concerned...

Do you know what application i would need to use to open up the dll file and see if it contains the malicious code? I've done multiple scans on my system with various methods, malwarebytes, bitdefender, microsoft defender, all come back clean but I'm worried they aren't able to detect the threats.

Step 1 is to upload the DLL to virus total.

If you know for a fact that you downloaded it before the specified date in the Reddit thread, then you are safe. It’s only if you updated it after that date that you are at risk. You can’t get the Trojan if you didn’t upgrade the mod to the version that runs it thankfully. Check your downloads. If the download is BEFORE April 11, you’re good. The rest of this is optional

If you legitimately feel that you are at risk…
Disconnect the internet from your computer. On another clean computer, download the following and move to infected pc via usb. If that isn’t an option, check your etc/hosts for dns manipulation, delete any records that 0.0.0.0 virus removal stuff and download these in your computer to begin.

1. https://www.bleepingcomputer.com/download/rkill/

RKill will attempt to stop known malware processes and allow your AV to run and remove it. RKill does not remove viruses.

2. Use Mbam, or https://www.hitmanpro.com/en-us to remove it if RKill does stop something.

https://www.eset.com/us/home/online-scanner/?srsltid=AfmBOoqtMcii5STLWH7XP6ftu29nOgPsg3A5I_CAjFBwb_jBnHX50xu3 And https://learn.microsoft.com/en-us/defender-endpoint/safety-scanner-download are also great tools.

https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer and https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns are great for viewing if you have a potential active infection as well. Be forewarned, some of the AV vendors do flag legitimate processes as malicious sometimes. Go into the options and enable submissions to VirusTotal. If it is a 1/70 and people are saying it’s safe and legitimate, it’s a false positive by the vendor and will be cleaned up in a few days. We are mainly looking for anomalies outside of system functions, and these are normally at the bottom of PE where threads like your browser will spawn.

As for inspecting dlls.. you can use https://www.jetbrains.com/decompiler/
https://www.dll-decompiler.com/
https://github.com/icsharpcode/ILSpy
https://binary.ninja/

To decompile it, but it’s not going to cleanly tell you exactly what the code does, since you have to do more to make it readable, and in many cases, de-obfuscate it.

Since this also happened in Cities Skyline 2 with a rogue DLL malware, this would be a good watch:
https://youtu.be/bvyklJ5Wie0?si=OH_Z4pSnU-775NnI


dont forget about that malwarebytes free trial
< >
Menampilkan 1-15 dari 18 komentar
Per halaman: 1530 50

Tanggal Diposting: 12 Apr @ 11:55am
Postingan: 18