Cities: Skylines II
CS2 VIRUS .DLL Traffic Mod ⚠️
Be warned, As per Cities Skylines Discord & Steam News:

https://steamcommunity.com/games/949230/announcements/detail/4490744894194712654?snr=2___

"@everyone

Important update for all Cities: Skylines II Players:

There is a potential security issue that has affected the “Traffic” mod for Cities: Skylines II. Late Monday evening, an outside actor pushed an update to the mod, which includes a .dll file which we believe is malicious. We have already removed it and the current version as of <t:1730385300:F> is safe to download and use, but if your mod synced and you played the game using the mod between Monday and then, there is a possibility that you may have the malicious file.

We are working to determine the nature of this .dll, and we will update you as soon as possible. In the meantime, please take the following steps as soon as possible to secure your system:
- If you have not played with the Traffic mod and have not subscribed nor downloaded it, there should be no risk to your system and nothing you need to do.
- If you have the Traffic mod and have not played Cities: Skylines 2 between Monday and today, let the mod sync as normal, and the malicious file should be deleted automatically. Please still scan your system with an anti-malware program like Windows Defender.
- If you have played using the affected version, please check your local files. If you have any malicious files installed, you will find them here; %AppData%\LocalLow\Colossal Order\Cities Skylines II\.cache\Mods\mods_subscribed\80095_13.
- Note that it is **only specifically the 80095_13 folder** that will contain malicious files; if you do not see this folder, you do not have the compromised version of the mod.
- If you do locate this folder, use an antivirus or antimalware program to quarantine it and/or remove it from your system, and run a thorough scan of your drives.
- As a precaution, we recommend changing your passwords.

We are working on the following steps to ensure you can enjoy our mods safely and securely:

- We will be going through all files uploaded to Paradox Mods and see if any other mods have had unexpected updates.
- We have contacted the modder whose mod was compromised and discussed our recommended steps to secure their account. They have updated Traffic to a safe version, so anyone playing with version v.0.2.4 is playing with a safe version.
- Paradox Mods will receive an update that notifies modders when their mods have been updated so that creators are quickly alerted to changes they have not personally made.

**Sharing creative game content is at the heart of our community at Paradox, and we will continue to ensure you can explore mods safely.**

As an important reminder, do not share your account information or passwords with anyone; we will never directly ask for your password or personal information."
Отредактировано Noob; 31 окт. 2024 г. в 11:47
< >
Сообщения 4660 из 76
Автор сообщения: Cosmic Sea
Автор сообщения: Xamurai
in august i was playing CSII with that mod. Suddenly my PC started to act weird. crashing programs, disappearing viruscanner etc.... even after a factory reset things could not be installed properly. Like windows update, Nvdea driver. Never had something like this before. After sending to a manufacturer. they didn't find any problems. now everything works normal, but i am afraid something linger around.
maybe It's from another problem, but still i am afraid something lingers around.

Was the mod save in august & before?
Yes. The mod was fine before Oct 28th. Your issues had nothing to do with a mod, nor the game.

ok thank you.
Автор сообщения: LMB_123_space
Автор сообщения: Carson
Do you know the sheer scale of users who have compromised systems as a result of this? This is a staggering issue. What the hell.
I'm wondering if there is some kind of scan before files and updates are made public or after. If it's the latter, no more mods for me. Mods should be seen as malicious unless proven otherwise imo.

im just deleting the game all together ive seen our gameplay dont mean anything to them the quality of this game is a joke for what we was promised and now this bs is my last straw i as well wunna know the pos. effected systems as well and told how this was allowed to happen
This game and studio are a joke. Back to the ugly looking CS1, CS2 will never be redownloaded on my PC again.
well, guess playing without mods has its advantages.
Автор сообщения: Merlinium
well, guess playing without mods has its advantages.
For half of this year, it was impossible to play without some mod or another because of game-breakings bugs (dogs, homeless...).
Upping again this thread as PDX think it doesn't deserve an official thread, not even a unpinned one like on the official forum.
Another fine execution by Paradox. Oh hey, we're going to create our own mod store, require you to sign away your rights to the mods you create, and then package them later as a DLC -- contrary to what every single fan said they wanted. And now it comes with virus.

This is genuinely the last Paradox game I'm going to buy and I own several.
Still no new info from PDX, so...
If the game was in a decent state to start with we wouldn't have needed a traffic mod. how come a modder can add functionality that CO hasn't even a year after release.
Автор сообщения: BoraBora
Still no new info from PDX, so...
Right now it seems to be mostly coming from third parties doing their own investigations. From what these folks have found it seems that they have decided to dub the malware Ecotickler.

This link will give you an idea of what they have discovered.
https://website.locknessko.com/blog/cs2_malware

And that on VirusTotal 29 AV engines know about it now. And that at least Windows Defender has had their signature files updated to scan for this new malware which Microsoft have called (Trojan:Win32/Shelood).

The interesting thing is that it seems to be similar to one that was in a mod for GTA5.

Now we just have to wait from CO / PDX on what they found.
Автор сообщения: BoraBora
Автор сообщения: Merlinium
well, guess playing without mods has its advantages.
For half of this year, it was impossible to play without some mod or another because of game-breakings bugs (dogs, homeless...).
Really?
Guess all those videos I made without mods over the last 8 months were faked then right?
I only have a thought about this, how would one upload on someone else's account? unless said account holder published or used a rather stupid and easy to guess password. So while PDX should have something in place to catch this, the modder's should also be responsible by using a secure password and keeping up to date with their security on their own PC. But sure, lets blame PDX for it all. (I am not happy with how PDX is doing business, but I am not gonna be blind and just go along with the other lemmings saying its all PDX's fault)
Автор сообщения: Major Kudos™
So much for the "stronger" security PDX Mods VS Steam.

One word, Amateurs.


Yeah, most people shouldn't have believed that honestly, but it was an excuse people who were "pro" Paradox Mods, wanted to use.



However mods are to be used at your own risk, and no system is infallible.

Personally i don't think auto-update should be a thing unless you choose it, it should be off by default, and updated/additional files could be shown, so if there any added exe's or dll's you'll know about it.
Отредактировано Apples; 3 ноя. 2024 г. в 10:10
Yeah Whack GTFO while you can


:scum_knuckles:
Автор сообщения: Merlinium
Really?
Guess all those videos I made without mods over the last 8 months were faked then right?
You mean you were the only player not blocked at one point or another by the homeless bug? Lucky you.
Автор сообщения: BoraBora
Upping this thread as PDX think it does'nt deserve an official thread, not even a unpinned one like on the official forum.
bumping thread because its strangely quiet in term of how huge this breach is and how little any platform is talking about it, and its been 3 days.
< >
Сообщения 4660 из 76
Показывать на странице: 1530 50

Дата создания: 31 окт. 2024 г. в 11:45
Сообщений: 76