此主題已被鎖定
azwethinkweiz 2017 年 4 月 15 日 下午 5:39
Just lost < $500 to a scammer using a TeamSpeak server + an error message.
Title pretty much sums up my grief.
I thought something seemed off, but my trustworthy inner dumbass allowed myself to install this patch for "teamspeak."

User added me to invite me to competitive play, which I don't even play but whatever.
Wants me to use teamspeak so we can play efficiently, whatever.
I dont use it personally, so I was ignorant, and listened to the scammer.

My steam account dropped offline, and was completely replaced with a fake steam, a trojan at that. 14 different threats detected in the file system so far. (scanning as I type)

[Trojan.FakeSteam.Gen] x14

Next my steam guard was completely useless, the phone authentication didn't do anything to help me, nor did my email. Both of those would not let me sign in.

Now that I've spent 15 minutes with the wonderful steam support, all of my items in TF2 are just plain gone. Wiped from existence.

Now I also have to reinstall steam, and hope the damage doesn't continue, or is any more severe.

And to hell with you Valve, you don't have control over the hackers.

I thought the phone authentication made it harder for scammers.
Instead it just wasted MORE of my time.

I think I'm done.

User's name was - at the time.
最後修改者:Spawn of Totoro; 2017 年 4 月 15 日 下午 8:40
< >
目前顯示第 46-60 則留言,共 151
azwethinkweiz 2017 年 4 月 16 日 上午 10:21 
No emulator, I promise. Really wouldn't even know how to use it.
Now unless they installed one with the software and I don't know it...
I'm not sure how the email and trade timing is that significant.
His bot account sent me a trade request, and the program allowed him to accept it for me.
Muppet among Puppets 2017 年 4 月 16 日 上午 10:23 
The timing is significant because it tells us what happened first.

By the expectation it should be impossible that the trade happened right after removal.
If we have a proven time stamp point of something that is definitely not supposed to happen, thats the first clue that there is a hole.

Its important to know the relation
azwethinkweiz 2017 年 4 月 16 日 上午 10:25 
recovery for steam guard mobile started at 7:06PM, April 15th.
at 7:08, all of my stranges and unusuals were traded to bot account.
Then at 7:09, every other tradeable item was traded to bot account.
I regained control around 7:16.
Muppet among Puppets 2017 年 4 月 16 日 上午 10:27 
You have an email that shows steam auth removed at
7:06pm

and the trade happened at 7:08pm?

Thats evidence of a hole in the system. That should be absolutely impossible to happen.
azwethinkweiz 2017 年 4 月 16 日 上午 10:29 
correction: recovery started at 7:06, the authenicator removal email is at 7:16
followed by emails at 8pm for access from a new computer (me reinstalling steam)
Muppet among Puppets 2017 年 4 月 16 日 上午 10:29 
Revovery started? What exactly does that mean?
PsydeFX 2017 年 4 月 16 日 上午 10:30 
That's crazy man. Then valve should have info of the email generated, and would prove that there is a vulnerability in their sma. That should not have been possible at all. If they themselves can see when the email went out and match it to when the trades happened, then it's clear the system is flawed, and they need to work on it.

This is exactly why I didn't want SMA to be mandatory, it would prove to be a useless hurdle for users who don't get compromised.

Very sorry that this happened to you, and thanks for providing the info.
azwethinkweiz 2017 年 4 月 16 日 上午 10:30 
"An SMS code has been sent to your phone to remove or replace the Steam Guard Mobile Authenticator on your account.

If this is you, enter the SMS code into the Steam dialog or mobile device that is requesting it."

And this was me.
Muppet among Puppets 2017 年 4 月 16 日 上午 10:32 
引用自 Prick
"An SMS code has been sent to your phone to remove or replace the Steam Guard Mobile Authenticator on your account.

If this is you, enter the SMS code into the Steam dialog or mobile device that is requesting it."

And this was me.
That is confusing.
Could you sort the things in the right order? Whatdo you mean with "and this was me"?
azwethinkweiz 2017 年 4 月 16 日 上午 10:34 
I will need a minute to compile all of that information into a decent structure.
And by it was me...
After trying to login, the code on my mobile app did not work 2-3 times.
So then it sent me a text message with a new code, which also did not work.
Again, I didn't know this wasn't steam though. So I might have been sending him all the codes he needed without my knowledge.
Muppet among Puppets 2017 年 4 月 16 日 上午 10:35 
Thanks for your cooperation. It could benefit many people.
azwethinkweiz 2017 年 4 月 16 日 上午 10:44 
conversation with scammer around 6:50-7:00
installation of fake steam around 7:05ish
panic ensues when steam crashes out, prompting me to login
7:06 is when the first email for steam guard recovery was received (An SMS code)
This was me trying to log back in to the fake steam
The next email was at 7:07 for "steam guard mobile device changed"
"You are now getting Steam Guard Mobile Authenticator codes on a new device.
If you did not perform this action, please follow the link below to lock your account and submit a request for assistance."
I must have not been paying attention to my emails.
But I'm also uncertain if this was me trying to remove it or not.
7:08 and 7:09 is when the trades occured without my knowledge.
At 7:15 I was regaining my account by changing my password through steam website via email.
After I had control I scanned my system and quarantined the 14 files and rebooted.
Then I had to reinstall steam and make a backup of my steam app files.
It wasn't until around 8pm that it was all over.
Muppet among Puppets 2017 年 4 月 16 日 上午 10:50 
This states an impossible event. But it happens regulary by criminals lately.

Changed device, no matter who did it at 7:07
And TWO trades from 7:08 and 7:09.

You have the evidence in your hand.

Changing of device should always activate 15 days trade block.

Contact support, tell them just when the guard was removed and when the trades happened.
It does not fit the specification of auth app.
azwethinkweiz 2017 年 4 月 16 日 上午 10:52 
Do you know the best way to contact support? I dont want to dig through their website again
Muppet among Puppets 2017 年 4 月 16 日 上午 10:53 
Reply to your initial ticket.

Tell them they should check their time stamps as well.
< >
目前顯示第 46-60 則留言,共 151
每頁顯示: 1530 50

張貼日期: 2017 年 4 月 15 日 下午 5:39
回覆: 151