Anatta Feb 7, 2021 @ 8:32am
Fake Steam Malware Notification
Hi, as title suggest seem like i got a malware which appear as a "weirdy bootleg" steam notification ScreenShot [ibb.co]. As exposed in the pic the "notification use a similar, but not so much, style as steam, use one of my most played game as title followed up to some clickbait CS message.

I'm pretty sure i got it through "BattleField 3" on Origin, since is the first time i play it, and this malware appeared for the first time too, alongside is since the 2012/2013 a lot of BF/origin players mention it in various forum. I still post here since the mal is obviously steam aimed (off course i never clicked it, but i suppose it will harm my steam account).

Already tried to get rid of it with avg, malwarebytes or similar, but of course they failed to do so.

I hope someone here can help better than this programs, and hopeful warn other people about such thing.
Originally posted by Dr.Shadowds 🐉:
Originally posted by SIlver:
The problem alongside this Malicious notification pop-up randomly and annoying (loud not. sound) and i fear to click it accidentaly since appear in the same place as other notification appear on the monitor, so i wonder if there is a way to get rid of it in a definitive ways.
I have to metion the notification is NOT FROM steam, even closing it or turning internet off it still made appear the Notification (even if still randomly).
If you're getting a pop that not from Steam, that you're claiming to be getting despite steam being not active, and not connected to the internet, then yes that would point to meaning your system has been compromise, either you installed something on your system that you shouldn't have, such as pirating software, or unkown software you have no idea what it was you downloaded, and installed from the internet, things like that either you want to do the rooting yourself, or nuke your PC by doing a full system wipe. IDK what kind of malware/virus you have on your system but I would recommend nuking it.

If you do the nuke.
1. You be using your OS installer via disk, or usb thumb drive you have. Do not make OS IOS copy on infected PC, if you need to download a copy of your OS, and make IOS, do it on a clean PC.

2. Giving you two option how far you wanna go if you wanna ease your paranoia.

A) On infected PC make sure it off, unplug power for minute, then plug back in, plug in your USB thumb drive, power on PC, and then smash boot key, until you get boot option, If using CD put in disk wait few seconds, now boot from your USB thumb drive / CD drive, and erase everything, if you see partitions delete them, and should be left with one drive, then follow the steps to installing your OS.

B) If you wanna go extra mile, you want a 2nd USB thumb drive basically, and install something like Parted Magic OS on it, or other type of linux OS, something like it to do secure erase for your system HDD / SSD, and you want to do secure erase for the HDD/SSD, do check to ensure you done correctly, basically want all the 1's to be force to 0's and this will be the extra mile, for SSD it be done in seconds, for HDD may take time please note you do not want to format SSD/HDD to anything but the NTFS format if so don't mess with the format it need to be in. Then after finish doing it, time to install your OS like normally.

3. Once you have OS installed, fully updated, drivers all done, you will need to start chaging your passwords on all your things because again no idea what type of malware / virus you gotten, and keep your eye on your stuff overtime such as banking, or whatever. Again I have no idea what malware / virus you gotten yourself on your system.


If you want to try root out the malware / virus, and don't want to nuke.
You want to use few types of scanning softwares.
1. Download Malwarebytes, and Hitman Pro, and install them.

2. You want to restart PC in Safe mode, launch Malwarebytes enable root kit scan from the settings, yes you really want that enable, this will take a really long time for it to fully scan system with root kit enable but it gets the job done, so ensure that is enable then do a full system scan. Once finish restart, and do another scan with Hitman Pro, the reason want to use more than one anti virus scanner, is that you want to cover much ground as possible for any possible malware, trojan, and virus signatures, once you fully scan system with both anti virus scanner, then you can go back to Windows normally. I will recommend recording what files been found, and check the area in case it missed anything that shouldn't exist, or not suppose to be there, be warn if it finds things in system32, be aware what you're doing, or else you have to do Windows repair, or worse having to reinstall OS if repair not able to work out.
< >
Showing 1-7 of 7 comments
Dr.Shadowds 🐉 Feb 7, 2021 @ 8:37am 
That chat notification, also looks like the person trying to scam you with false lie of you winning anything to try get you to login to their phishing site.

Most common reason people get accounts hijack for any service really are as followed.
- Sharing account infomation with others. <--- Very common with impersonators, pretending to be Steam admin / support.
- Logging in on phishing sites. <--- Very common scam.
- Downloading / Installing Virus / Keylogger on your system.
- Using public devices that has keyloggers, such as cyber cafe, school computers, and etc...
- Storing your login credentials on a unsecured service that others has access to view.
- Using same login credentials for all your things, or using same login credentials on another service that had a data leak. Yes it does matter because even if it not related to Steam, if using same login credentials, hijackers will try to use those credentials to see what services you use with those credentials. https://haveibeenpwned.com/

https://youtu.be/9TRR6lHviQc
Last edited by Dr.Shadowds 🐉; Feb 7, 2021 @ 8:38am
John CS Feb 7, 2021 @ 9:59am 
okay
Anatta Feb 7, 2021 @ 10:38am 
The problem alongside this Malicious notification pop-up randomly and annoying (loud not. sound) and i fear to click it accidentaly since appear in the same place as other notification appear on the monitor, so i wonder if there is a way to get rid of it in a definitive ways.
I have to metion the notification is NOT FROM steam, even closing it or turning internet off it still made appear the Notification (even if still randomly).

Originally posted by Dr.Shadowds 🐉:
That chat notification, also looks like the person trying to scam you with false lie of you winning anything to try get you to login to their phishing site.

Most common reason people get accounts hijack for any service really are as followed.
- Sharing account infomation with others. <--- Very common with impersonators, pretending to be Steam admin / support.
- Logging in on phishing sites. <--- Very common scam.
- Downloading / Installing Virus / Keylogger on your system.
- Using public devices that has keyloggers, such as cyber cafe, school computers, and etc...
- Storing your login credentials on a unsecured service that others has access to view.
- Using same login credentials for all your things, or using same login credentials on another service that had a data leak. Yes it does matter because even if it not related to Steam, if using same login credentials, hijackers will try to use those credentials to see what services you use with those credentials. https://haveibeenpwned.com/

https://youtu.be/9TRR6lHviQc
Last edited by Anatta; Feb 7, 2021 @ 10:38am
The author of this thread has indicated that this post answers the original topic.
Dr.Shadowds 🐉 Feb 7, 2021 @ 11:42am 
Originally posted by SIlver:
The problem alongside this Malicious notification pop-up randomly and annoying (loud not. sound) and i fear to click it accidentaly since appear in the same place as other notification appear on the monitor, so i wonder if there is a way to get rid of it in a definitive ways.
I have to metion the notification is NOT FROM steam, even closing it or turning internet off it still made appear the Notification (even if still randomly).
If you're getting a pop that not from Steam, that you're claiming to be getting despite steam being not active, and not connected to the internet, then yes that would point to meaning your system has been compromise, either you installed something on your system that you shouldn't have, such as pirating software, or unkown software you have no idea what it was you downloaded, and installed from the internet, things like that either you want to do the rooting yourself, or nuke your PC by doing a full system wipe. IDK what kind of malware/virus you have on your system but I would recommend nuking it.

If you do the nuke.
1. You be using your OS installer via disk, or usb thumb drive you have. Do not make OS IOS copy on infected PC, if you need to download a copy of your OS, and make IOS, do it on a clean PC.

2. Giving you two option how far you wanna go if you wanna ease your paranoia.

A) On infected PC make sure it off, unplug power for minute, then plug back in, plug in your USB thumb drive, power on PC, and then smash boot key, until you get boot option, If using CD put in disk wait few seconds, now boot from your USB thumb drive / CD drive, and erase everything, if you see partitions delete them, and should be left with one drive, then follow the steps to installing your OS.

B) If you wanna go extra mile, you want a 2nd USB thumb drive basically, and install something like Parted Magic OS on it, or other type of linux OS, something like it to do secure erase for your system HDD / SSD, and you want to do secure erase for the HDD/SSD, do check to ensure you done correctly, basically want all the 1's to be force to 0's and this will be the extra mile, for SSD it be done in seconds, for HDD may take time please note you do not want to format SSD/HDD to anything but the NTFS format if so don't mess with the format it need to be in. Then after finish doing it, time to install your OS like normally.

3. Once you have OS installed, fully updated, drivers all done, you will need to start chaging your passwords on all your things because again no idea what type of malware / virus you gotten, and keep your eye on your stuff overtime such as banking, or whatever. Again I have no idea what malware / virus you gotten yourself on your system.


If you want to try root out the malware / virus, and don't want to nuke.
You want to use few types of scanning softwares.
1. Download Malwarebytes, and Hitman Pro, and install them.

2. You want to restart PC in Safe mode, launch Malwarebytes enable root kit scan from the settings, yes you really want that enable, this will take a really long time for it to fully scan system with root kit enable but it gets the job done, so ensure that is enable then do a full system scan. Once finish restart, and do another scan with Hitman Pro, the reason want to use more than one anti virus scanner, is that you want to cover much ground as possible for any possible malware, trojan, and virus signatures, once you fully scan system with both anti virus scanner, then you can go back to Windows normally. I will recommend recording what files been found, and check the area in case it missed anything that shouldn't exist, or not suppose to be there, be warn if it finds things in system32, be aware what you're doing, or else you have to do Windows repair, or worse having to reinstall OS if repair not able to work out.
Originally posted by SIlver:
I'm pretty sure i got it through "BattleField 3" on Origin, since is the first time i play it, and this malware appeared for the first time too, alongside is since the 2012/2013 a lot of BF/origin players mention it in various forum.
Someone creates a big game, to put a weak notification malware on peoples computers...... Did you think that through?
Anatta Feb 8, 2021 @ 5:51am 
Originally posted by Muppet among Puppets:
Originally posted by SIlver:
I'm pretty sure i got it through "BattleField 3" on Origin, since is the first time i play it, and this malware appeared for the first time too, alongside is since the 2012/2013 a lot of BF/origin players mention it in various forum.
Someone creates a big game, to put a weak notification malware on peoples computers...... Did you think that through?

Off course to put the virus wasn't the EA, this would be silly to think by you.
Is not a new think to external people to put malicious file in big one, just look what happened to CCleaner time ago, and with an online game, even more a most abbandoned one like bf3 is easier.

Anyway the Hitman Pro suggested by Dr.Shadowds seem have solved the problem without doing the "nuke".
Last edited by Anatta; Feb 8, 2021 @ 5:53am
Dr.Shadowds 🐉 Feb 8, 2021 @ 6:07am 
Make sure to use both anti virus type of scans.
< >
Showing 1-7 of 7 comments
Per page: 1530 50

Date Posted: Feb 7, 2021 @ 8:32am
Posts: 7