1. There is no such thing as a "pending" ban or Steam admin. Anyone threatening your account is a scammer trying to scare you. Read more.

Steam Phishing Links, Help?

Discussion in 'SteamRep General Discussion' started by MnD, Jan 16, 2015.

  1. MnD

    MnD New User

    Messages:
    16
    Steam:
    STEAM_0:1:90716592
    So I opened a link from a phishing bot, and Chrome auto-downloaded this .scr file.
    Deleted it, and emptied recycling bin as soon as it downloaded, and didn't run it. Should I be worried?
    .scr/.exe files don't run automatically after they get downloaded do they?
    I'm not so worried about my Steam Inventory, because I have no valuables, but my account passwords for FB, credit card info etc...
    Any help would be great. Currently scanning my computer with Malwarebytes and Norton 360
  2. Horse

    Horse Administrator SteamRep Admin

    Messages:
    76,869
    SteamRep Admin:
    STEAM_0:1:34690691
  3. SilentReaper(SR)

    SilentReaper(SR) Retired Staff

    Messages:
    11,991
    SteamRep Admin:
    STEAM_0:0:89705646
    If you didn't execute the .scr file, you should be safe. Glad you didn't mistook it for ".screenshot" as image but for ".screensaver" (executable).
    A check would be a good idea. But if your anti-virus/anti-malware didn't go barking on the file, its not very effective. For multiple parties already publicized that they catch .scr files now.

    May I ask, which antivirus/antimalware you run, that it let that .scr file to be downloaded?

    The attack is mostly aimed at the steam account: run a code to trade items to a mule account. it consists of hijacking the steam logged in browser or copying some files from the steam client to the hijacker.

    As for your other accounts you named (FB, PP, e-mail etc), if you do not trust your computer currently, go to another computer that you trust more and change all those passwords from there, and don't log in to them from the untrusted computer until you are assured that it's clean.

    there are some guides that might interest you in our guides section (the hijack recovery thread is still being expanded and written, complex one):
    http://forums.steamrep.com/threads/suggestions-to-secure-your-computer-windows.82604/
    http://forums.steamrep.com/threads/how-to-recover-from-a-hijack.86363/
    http://forums.steamrep.com/threads/general-e-mail-security-considerations.17308/
  4. MnD

    MnD New User

    Messages:
    16
    Steam:
    STEAM_0:1:90716592
    I downloaded it because I visited the phishing site, which was probably a redirect to google drive, and chrome just auto downloaded the file. I'm scanning my computer with Malwarebytes and Norton 360. If all else fails and my account has been compromised, i'll probablu just reformat the whole computer with a new version of Windows.
  5. MnD

    MnD New User

    Messages:
    16
    Steam:
    STEAM_0:1:90716592
    Thanks for the replies by the way, they were very helpful, but i'm still unsure of whether my account could be compromised. I'm 100% sure I didn't run it, and as soon as I saw it downloading I tried to cancel but it downloaded pretty quickly, and then i just deleted ASAP. Hopefully the results of my AV scans come back soon
  6. SilentReaper(SR)

    SilentReaper(SR) Retired Staff

    Messages:
    11,991
    SteamRep Admin:
    STEAM_0:0:89705646
    You said Norton/Symantec.... bweurk... excuse me, I'm puking. (read my first linked topic for why)
  7. MnD

    MnD New User

    Messages:
    16
    Steam:
    STEAM_0:1:90716592
    I'm going to change over to Avast (Free) now haha. By the way, Malwarebytes + Norton called my computer clean, I didn't open the file or anything, so I should be good right?
  8. SilentReaper(SR)

    SilentReaper(SR) Retired Staff

    Messages:
    11,991
    SteamRep Admin:
    STEAM_0:0:89705646
    Well, have more confidence in Malwarebytes then "norton", but as I said above, if you never started it, then you should be good.

    I can't give you more surity, if you want more, you will have to go to my first linked thread again, at the bottom of my opening post is a bunch of links to various forums on the internet who help people to clean/check their computers if they suspect being hacked/infected/etc.