Oblivion

NMM bug fix release and download hacking problems fixed

  • Comment
We’ve released a bug fix edition of NMM, taking us to version 0.44.4. Here’s the change log:

1. New Feature: The ReadMeManager now supports PDF files.
2. Bugfix: ReadMe Manager preventing .txt files from being installed in mod folders. (This fixes the installation of mods like Fores New Idles)
3. Bugfix: Rare crash while deleting a mod in CategoryView.
4. Bugfix: Omod script interpreter.
5. Bugfix: Users were able to set Mods and Install Info as the same folder.
6. Bugfix: NMM crashing with a corrupt ReadMeManager.xml file.
7. Bugfix: NMM using the wrong game path after a game rescan.
8. Bugfix: LoadOrder export using the wrong plugin list.

You can download the update through NMM or by downloading and installing manually through the NMM download page.

Unfortunately earlier today we found out that some of our file servers had been hacked, replacing manual (not NMM) downloads with a malicious installer that contained malware. This hack was targeted as the hacker deliberately named the file “Nexus_Downloader.exe” to try and snag as many people as possible. While I haven’t tried to run it myself it seems to be a scam malware that sends the user to a fake FBI page informing the user they must pay must in order to unlock their system. To make it worse only 4 of the 20 main anti-virus programs people use flagged this as a virus. It’s obviously a relatively new one that most haven’t caught up with, and this might have caught a few of you off guard.

As soon as we found out about the breach we had the servers down and patched up within minutes and we’ve been working today further hardening our servers and shutting down the method used by the hacker to gain access.

There’s a few things to take away from this. First of all I’m sorry that this has happened to some of you. You clearly trust us to provide you with a safe and secure modding experience and we got caught with our pants on our heads. While this won’t help you now, can I give you some advice? Don’t trust anything, any site, or any person fully on the internet. Be suspicious of everything. If you’ve tried to download a fluffy sheep mod that says it’s 50mb in size for Skyrim and instead been given a file called “Nexus_Downloader.exe” that’s 100kb in size...be suspicious. We’d never do something like that, especially without letting you know first. These sorts of things can happen to any site out there (just look at the past hacking’s of Sony, Valve/Steam...even Bethesda got hacked) and having an anti-virus, firewall and malware protection won’t keep you 100% safe. Nothing will. But try and be perceptive and don’t let your guard down.

We can’t guarantee your safety 100% when browsing and downloading from the Nexus. No other site can offer you that guarantee either. What I can guarantee you is that we work hard to try and make the experience as safe and secure as possible, and we work even harder when we know we’ve been breached, often without sleep.

Never be afraid to report suspicious activity either by others or by the sites themselves on the forums or to the staff.

336 comments

Comments locked

A moderator has closed this comment topic for the time being
  1. predetor336
    predetor336
    • supporter
    • 3 kudos
    aha ya i got that "virus" "malware" what ever you want to call it......but lucky i found a exploit with it to hide the display and gain access to the computer, (This was done on a Win 7 Ultimate 64bit) So hit Ctrl-Alt-Del hit shutdown then it should go back to desktop and it will say something along the lines, "Windows is shutting down, closing background programs." then hit cancel as soon as that shows up, if it does not and just shutsdown then boot back up and as soon as your on the desktop open as many programs as you can then the "virus" should come up, then try again. If this does not work I'm sorry i cant help further, well i can but I'm done now so....bye.

    edit: Oops almost forgot when the "wall" hiding your desktop is gone get some kind of anti-virus and run "full" scans, I got 4 of them and its gone now. I used Hijack-This, Malwarebytes, Spyhunter, and HitmanPro. So you can try any/all of them if you want too......i mean i can't stop you......can i?......no i cant....
  2. sunichi24
    sunichi24
    • member
    • 0 kudos
    took me a while to read all the comment

    no wonder the last few weeks the connection went full retard lol

    any ho, manage to update it to latest version, so far so good. The only thing is i lost all the previous mod i've download before i apply the update *GASP*

    but luckily oblivion ran as usual, with all the previous mod still intact, not sure why but i checked back OBMM and looks like all the Mod before update still there, just not showing up in Nexus Mod Manager in Mod's tab.

    lastly, thanks to the update, now no more readme screw up!!!
  3. WingdingsNiglet
    WingdingsNiglet
    • BANNED
    • 3 kudos
    Still having mod installation issues, when I try to uninstall some mods, (ERSO and Magic Duel) they just stay there.
  4. bben46
    bben46
    • premium
    • 781 kudos
    @Thorne67 look at the top of any of the game sites that use NMM - find the 'install NMM ' - click on that to be taken to the NMM download page. Scroll down and read the info on NMM. Look for the orange highlighted parts and click on them (These are called 'Links') to be taken to the various forums, bug report section, tutorials and other stuff relating to NMM.
     
     
     
     
    1. Thorne67
      Thorne67
      • member
      • 54 kudos
      I'll tell him when he gets back from the hospital. He's in for heart surgery and kidney removal (one) due to complications with his diabetes. He's a bit addled having had a few strokes so generally he only goes one link into a page.

      I'm actually surprised he learned how to upload files here. He hasn't done that since Morrowind.

      Jr.
  5. Subzero254
    Subzero254
    • premium
    • 0 kudos
    Hi everyone i didn't get a chance to fully read the post however I just removed the virus after losing control of my PC and not being able to boot in Safe Mode... i provided What i did in sort of a guide format on this post if anyone is interested, sorry if someone else posted something similar again i'm short on time so could not read the entire post
     
    http://forums.nexusmods.com/index.php?/topic/947923-somehow-got-the-fbi-moneypak-virus-after-downloading-a-mod/
     
    Have a nice day
  6. Shaeam
    Shaeam
    • member
    • 0 kudos
    Is this who fiasco over with yet? Can I go back to downloading mods or is it still not safe and risky? I realize it's probably not a threat to me so long as I don't run the .exe -- but i'm just so gosh darn paranoid and don't wanna take the chance.
    1. Thorne67
      Thorne67
      • member
      • 54 kudos
      Well...I'm here every day all day and haven't seen any reports on trouble with the last "hack" and have continued my downloading and tests so I could say "yes" to your question. Other than that unless you see it FLAGGED by users or especially a Site MODERATOR yer safe.
  7. sangimpur
    sangimpur
    • premium
    • 2 kudos
    Any updates on the virus front? Also, can you let us know what has been changed with the recent updates from 0.44.3 to 0.44.7? Thanks.
    1. Thorne67
      Thorne67
      • member
      • 54 kudos
      I've downloaded about 60 mods (tiny ones) just to check on the hack breach and all files were successfully qued and downloaded with utterly NO Nexus Downloader.exe or any other renamed or invalid file redirects.

      Blessings and many thanks to the nexus team for all the hard work in fighting the hack.

      44.3 if I remember correctly was the really BAD bug version that stripped the readme files from the mods and then installed them rather than leaving them intact.

      I am using version 44.5 of NMM and saw NMM jump from 44.6 to 7 in like LESS than a 72 hour period so I personally do NOT know what changes have been made as of 44.7

      Many people have complained about slow response times from the Skyrim server itself. My grandkids and great ones play dragonage, oblivion and a few of the other nexus supported games and report very quick responses from those servers so my opinion is that as skyrim is so HEAVILY modded at current time that there is always going to be network congestions. Oblivion and the rest ARE pretty much retired with skyrim after all

      Just be patient with your downloads. Don't click from one server to another. Just use ONE server and reclick until it responds. Very rarely have I encountered any ACTUAL slow or sluggish DL speeds. Just in queing it up. Then again I AM on 56k so I can't test that theory past v96 speeds.
    2. sangimpur
      sangimpur
      • premium
      • 2 kudos
      Thanks Thorne67. Only seeing the usual download issues (weekends = crunch time) but no real trouble there. Some downloading issues may be sourced elsewhere (DNS attacks slowing down the entire Net have grown recently)

      Glad you were able to DL a bunch without bugs... progress appears to have been made or you ducked the bullet. Am hoping for a status from Nexus if they have that period behind them. Haven't detected a virus since 4-2 so am hoping its behind them now. Also expunging a software gremlin (source unverified) so plan to reinstall Skyrim from the ground up including Nexus and am hoping the cleansing is now completed (such as that can be done)

      I'm using 44.1 now and spent a lot of time getting back to zero. Took Dark0ne's advice and decided to hold on upgrades until there is a good reason so hope we can get a list of the changes similar to that which was given on the open of this article.
    3. Thorne67
      Thorne67
      • member
      • 54 kudos
      Still using 44.5 and don't know if I should upgrade to 44.7 as I've seen no posts regarding the updates yet, especially why there was an immediate jump from 6 to 7. So far the only thing with 44.5 is a constant CTD after installing about 4 or 5 mods right after each other. Same thing with downloading. Immediate CTD when downloading large (at least 40mb) files. Even though they've successfully downloaded (close NMM or NOT message box. I close normally)
      Generally when i restart NMM and the "offensive" download shows up, I just redownload the same file and NMM doesn't crash. Dunno if the 44.7 update fixed that issue.

      Personally I think the NMM program itself should have its own download page with a BUG forum and a SUGGESTIONS forum attached. As we've gotten accustomed to THIS forum here I'd leave this one running as a general discussions/biaatching page.

      I'm sure it exists SOMEWHERE on Nexus here but...I can't find it so..on my earlier comment on NMM having it's own DL page like all the other mods I'd suggest the "main" info page contain all the info pertaining to the release (44.0, 44.3, 44.7...yadda yadda...) and on down the line and the download page contain JUST a few previous STABLE beta downloads.

      So.. how's THAT for some ideas?

      Gramps.
  8. awesonymous
    awesonymous
    • supporter
    • 1 kudos
    hmmm. i tried 8 different servers and they all say server is busy, try again later?
    1. Thorne67
      Thorne67
      • member
      • 54 kudos
      I'm on 56k using Internet Download Manager. They've ALL been saying server is busy...even though they aren't. Simple way for "ME" to bypass it is to click on the download server, IDM pops up with the "server busy" on top so I click on the "Download Later" then the server is "saved" in the IDM request set. I can either immediatley highlight the file to be DLed and resume of just do my batch file que 1 at a time for me. No biggie.

      Servers aren't actually "busy" I think links just aren't responding quick enough on the pages.

      Without IDM I just kept clicking on the SAME server link till it caught up and allowed the DL to start. On 56k it took about 5 tries each time. Still no biggie.

      Haven't had the virus flag here for about a week now and I've been download small texture packages all day.

      Hope this helps everyone.

      Gramps
  9. EnaiSiaion
    EnaiSiaion
    • premium
    • 9,568 kudos
    Just take the Nexus offline until you figure it out.
  10. xerox2k2
    xerox2k2
    • premium
    • 2 kudos
    what if authors posted md5s of their files on the website and the mod manager calculates and compares the md5 of the mod before installing. that would give some protecting against file being tampered with.

    i suppose a hacker could change the md5 on the website,so maybe put the md5s on all your servers and have the mod manager check all the servers (downloaded file matches server A,B and C so it must be legit).with the idea being 1 server might get hacked but it's unlikely ALL servers will get hacked.if the mod manager doesn't get 3 matches it sends a message back to you guys saying file abc.zip downloaded from server B is not validating then all you guys have to do is check the logs for these field reports to know what's affected