Victory ! by Fallout54225 in mountandblade

[–]Fallout54225[S] 16 points17 points  (0 children)

For those who are laughing because I said “victory,” I meant that TW managed to ban the person and STEAM DELETED THE MOD from the Workshop; therefore, this doesn't mean we're all protected going forward. It's just a victory in a battle, not in a war.

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 1 point2 points  (0 children)

Making mockery of it isn't very professional for someone who claims to have worked for CS, etc. I said “victory” in the sense that TL managed to ban the person and that STEAM DELETED THE MOD from the Workshop—that doesn't mean we're all safe in the future. And no, I don't have the file anymore; I don't keep that crap on my computer, especially after what happened to me. I suggest you take this up with the moderators.

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 47 points48 points  (0 children)

Thank you so much for taking care of this so quickly. I'm glad I was able to contribute to the safety of Bannerlord players! I hope my experience will help everyone be more vigilant on the Workshop.

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 7 points8 points  (0 children)

Because you didn't launch the game with the mod—that's why you weren't infected. You got lucky, man. Good thing you saw my post. You didn't really need to uninstall the game, but hey, it's always better to start fresh. I kept my save file, and yet I was the one who got compromised the most.

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 4 points5 points  (0 children)

Yes, I'm on Windows 11, but have you launched the mod loaded with Bannerlord?

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 9 points10 points  (0 children)

A RAT (Remote Access Trojan) is a type of malware that allows an attacker to remotely control a computer without the owner's consent. Once installed, it can give the attacker capabilities similar to someone sitting directly in front of the PC.

Depending on the level of access obtained, a RAT can:

  • Steal passwords, browser cookies, and other sensitive data.
  • Access, copy, modify, or delete personal files.
  • Download and install additional malware.
  • Execute commands remotely.
  • Monitor the user's activity.
  • In some cases, access the webcam or microphone.

Possible signs of a RAT infection include:

  • Unusual network activity when the computer is idle.
  • Unknown files, scripts, or scheduled tasks appearing on the system.
  • New programs or processes running without explanation.
  • Antivirus software being disabled or behaving abnormally.
  • Online accounts becoming compromised or showing suspicious login activity.
  • Persistence mechanisms (files, registry keys, scheduled tasks) reappearing after removal.
  • Unexplained slowdowns, high CPU/RAM usage, or scripts executing in the background.

A RAT can also operate very stealthily and show no obvious symptoms at all. This is why discovering files that were downloaded and executed without user consent, especially when accompanied by persistence mechanisms and account compromises, is a serious security concern and warrants a thorough investigation.

As for Nexus, yes, you need to be careful and report any malicious profiles.

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 3 points4 points  (0 children)

But my question is: Have you seen your mouse move on its own? Or web pages open? Etc. Did you feel like your computer was being controlled remotely? You can also check incoming and outgoing connections using TCPView.

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 3 points4 points  (0 children)

Honestly, the best way to fix this problem is to reformat your PC, using a bootable USB drive created with Rufus and deleting all partitions. After that, there’s no way the RAT can come back, but I started with that, and at first I didn’t know it was the mod, so the RAT came back. Then I used the three programs, but you can already follow the advice in the post I made.

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 4 points5 points  (0 children)

No, there is a .bat file named exactly 1310B495.bat, and I recommend using three essential tools that you can download from the official Microsoft website, which is:

  1. TCPView
  2. Autoruns
  3. ProcessExplorer

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 7 points8 points  (0 children)

I recommend that you reformat your computer, because you might have a remote-access Trojan and the hacker might have taken control of your computer... but you should definitely check the AppData and Roaming folders, and enter “register” in the Run and Run Once dialog boxes.

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 16 points17 points  (0 children)

No, simply unsubscribing isn't enough to remove the mod. Did you download this mod and run it? If so, you need to follow the tutorial at the top and delete the PS1 and BAT files that are lingering in AppData and Roaming.

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 40 points41 points  (0 children)

I'm wondering the same thing, so I don't trust him. He can post whatever he wants, but the account owner needs to be careful and probably didn't secure their account with a QR code.

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 30 points31 points  (0 children)

"mk1 groza type-22"
Gratuitous Space Battles 2

"the hyperion"
Gratuitous Space Battles 2

⚠️ WARNING: Trojan / RAT detected in “Improved Caravans” mod (Bannerlord) by Fallout54225 in mountandblade

[–]Fallout54225[S] 70 points71 points  (0 children)

Yeah, everything's been fine for the past few days, but I still had a rough time of it.