bhudii Mar 21, 2016 @ 3:39pm
VIRUS POP-UPS ON STEAM BROWSER
over the last couple of days, I have started to get adverts on my steam browser and my CS:GO news wire. I never use the steam browser apart from a rare occasion where I may use Youtube or Twitter. Also when playing surf or bhop maps, I hear an audio message saying that my PC has a virus and when I tab out, I get a message box titled JavaScript Confirm with a random message inside! I then go to my volume mixer and see that an extra steam program has opened called Steam Client Webhelper and that is where the audio is coming from. I have tried Norton Anti-Virus and reinstalling Steam but to no avail.

PLEASE HELP - reply here or on twitter - @bhudiigfx

https://t.co/tNsnDIxIvN
https://pbs.twimg.com/media/CeFVrGsWAAEFRCc.jpg
https://pbs.twimg.com/media/CeFV4iaXIAAb_Ir.jpg

Something went wrong while displaying this content. Refresh

Error Reference: Community_9734361_
Loading CSS chunk 7561 failed.
(error: https://community.fastly.steamstatic.com/public/css/applications/community/communityawardsapp.css?contenthash=789dd1fbdb6c6b5c773d)
< 1 2 >
Showing 1-15 of 21 comments
Mr. G Mar 21, 2016 @ 3:41pm 
Have you used AVG and did a full computer scan? Any fishy software installed?
bhudii Mar 21, 2016 @ 3:43pm 
Originally posted by Ricardo Shillyshally:
https://support.steampowered.com/kb_article.php?ref=6057-YLBN-1660
already read this article but didnt work
bhudii Mar 21, 2016 @ 3:44pm 
Originally posted by Captain Price:
Have you used AVG and did a full computer scan? Any fishy software installed?
I did a full computer scan yesterday and I found one steam file that was fishy. I then removed that folder but it is still here
Mr. G Mar 21, 2016 @ 3:45pm 
Originally posted by add -> bhudiismurf:
Originally posted by Captain Price:
Have you used AVG and did a full computer scan? Any fishy software installed?
I did a full computer scan yesterday and I found one steam file that was fishy. I then removed that folder but it is still here

I'd maybe do a fresh Windows install if there is no other solution by the end of the day.
bhudii Mar 21, 2016 @ 3:45pm 
Originally posted by Captain Price:
Originally posted by add -> bhudiismurf:
I did a full computer scan yesterday and I found one steam file that was fishy. I then removed that folder but it is still here

I'd maybe do a fresh Windows install if there is no other solution by the end of the day.
that would maybe be my last resort if nothing else works, don't want to get to that point though
try a program like malwarebytes it's MUCH better at finding malware and adware
bhudii Mar 21, 2016 @ 3:47pm 
Originally posted by Alexalmighty502 Sup Acc:
try a program like malwarebytes it's MUCH better at finding malware and adware
ok i'll give it a try!
Azza ☠ Mar 21, 2016 @ 3:47pm 
Avoid downloading that anti-virus scanner suggested under the Javascript box. It will be a fake and cause actually more infection or demand for payments.

Reboot your PC into Safemode, as this will help prevent the adware from running while you clean.

Ensure you DNS isn't spoofed.

DNS = Domain Name System. It's the web server which looks up that URL typed in your Address Bar and converts it to an IP Address. If it's been replaced, it means that URL can be redirected to a malicious IP Address instead of the real one.

Under your Control Panel > Network and Sharing Center > Click on your Connection (whatever it might be you use for the internet), listed under "Connections".

This will bring up a "Status", under activity click "Properties".

Find "Internet Protocol Version 4 (TCP /IPv4)" and click "Properties" on that selected.

You will find under this, "Obtain DNS server address automatically" and "Use the following DNS server addresses". If one is manually entered there, note it down and remove it.

If you wish to force a valid trusted DNS, you can manually set it to one, for example:

Perferred DNS server: 8.8.8.8
Alternate DNS server: 8.8.4.4

(Those are the Google DNS servers, trusted, secure and free to use - else you could find and use your ISP DNS servers or another open public DNS, so long you trust it and it performs fast, while being secure enough not to be spoofed)

Validate settings upon exit and "OK" back out.

Clean the web-browser hi-jacker

Download and use the Free Edition of Spybot (or similar anti-malware):
https://www.safer-networking.org/mirrors/

Malwarebytes is another very good one, but Spybot specializes more in web-browser hi-jack cleaning and future prevention.

Note: Ensure when you go webpages, that it's valid and not changed/injected on you. Specially on downloads. Do NOT download the adware fake scanners. If you are concerned, download via another PC (not infected), then WRITE PROTECT it on a thumb stick or similar, to transfer over to the infected. If doing this, just ensure the virus can't jump onto the thumb stick and respread.

If using Spybot to clean, update it's definations first, then run a full scan, wait and show results. It will find a lot, even minor privacy risks and cookies. Look for the high threat levels and clean, or just clean all.

Afterwards optionally apply it's immunization tool. This will add a block list to your web-browser(s) of known adware/malware websites, helping prevent this issue occuring again in the future.

Under your web-browser(s): Remove all plugins/extentions, reset the browsers default settings and clear out all the cache / temporary internet files.

Reboot back to normal and recheck it's clean.
Last edited by Azza ☠; Mar 21, 2016 @ 3:50pm
bhudii Mar 21, 2016 @ 3:54pm 
Originally posted by Azza ☠:
Avoid downloading that anti-virus scanner suggested under the Javascript box. It will be a fake and cause actually more infection or demand for payments.

Reboot your PC into Safemode, as this will help prevent the adware from running while you clean.

Ensure you DNS isn't spoofed.

DNS = Domain Name System. It's the web server which looks up that URL typed in your Address Bar and converts it to an IP Address. If it's been replaced, it means that URL can be redirected to a malicious IP Address instead of the real one.

Under your Control Panel > Network and Sharing Center > Click on your Connection (whatever it might be you use for the internet), listed under "Connections".

This will bring up a "Status", under activity click "Properties".

Find "Internet Protocol Version 4 (TCP /IPv4)" and click "Properties" on that selected.

You will find under this, "Obtain DNS server address automatically" and "Use the following DNS server addresses". If one is manually entered there, note it down and remove it.

If you wish to force a valid trusted DNS, you can manually set it to one, for example:

Perferred DNS server: 8.8.8.8
Alternate DNS server: 8.8.4.4

(Those are the Google DNS servers, trusted, secure and free to use - else you could find and use your ISP DNS servers or another open public DNS, so long you trust it and it performs fast, while being secure enough not to be spoofed)

Validate settings upon exit and "OK" back out.

Clean the web-browser hi-jacker

Download and use the Free Edition of Spybot (or similar anti-malware):
https://www.safer-networking.org/mirrors/

Malwarebytes is another very good one, but Spybot specializes more in web-browser hi-jack cleaning and future prevention.

Note: Ensure when you go webpages, that it's valid and not changed/injected on you. Specially on downloads. Do NOT download the adware fake scanners. If you are concerned, download via another PC (not infected), then WRITE PROTECT it on a thumb stick or similar, to transfer over to the infected. If doing this, just ensure the virus can't jump onto the thumb stick and respread.

If using Spybot to clean, update it's definations first, then run a full scan, wait and show results. It will find a lot, even minor privacy risks and cookies. Look for the high threat levels and clean, or just clean all.

Afterwards optionally apply it's immunization tool. This will add a block list to your web-browser(s) of known adware/malware websites, helping prevent this issue occuring again in the future.

Under your web-browser(s): Remove all plugins/extentions, reset the browsers default settings and clear out all the cache / temporary internet files.

Reboot back to normal and recheck it's clean.
those DNS server addresses are not valid??
Azza ☠ Mar 21, 2016 @ 4:12pm 
Originally posted by add -> bhudiismurf:
Originally posted by Azza ☠:
Avoid downloading that anti-virus scanner suggested under the Javascript box. It will be a fake and cause actually more infection or demand for payments.

Reboot your PC into Safemode, as this will help prevent the adware from running while you clean.

Ensure you DNS isn't spoofed.

DNS = Domain Name System. It's the web server which looks up that URL typed in your Address Bar and converts it to an IP Address. If it's been replaced, it means that URL can be redirected to a malicious IP Address instead of the real one.

Under your Control Panel > Network and Sharing Center > Click on your Connection (whatever it might be you use for the internet), listed under "Connections".

This will bring up a "Status", under activity click "Properties".

Find "Internet Protocol Version 4 (TCP /IPv4)" and click "Properties" on that selected.

You will find under this, "Obtain DNS server address automatically" and "Use the following DNS server addresses". If one is manually entered there, note it down and remove it.

If you wish to force a valid trusted DNS, you can manually set it to one, for example:

Perferred DNS server: 8.8.8.8
Alternate DNS server: 8.8.4.4

(Those are the Google DNS servers, trusted, secure and free to use - else you could find and use your ISP DNS servers or another open public DNS, so long you trust it and it performs fast, while being secure enough not to be spoofed)

Validate settings upon exit and "OK" back out.

Clean the web-browser hi-jacker

Download and use the Free Edition of Spybot (or similar anti-malware):
https://www.safer-networking.org/mirrors/

Malwarebytes is another very good one, but Spybot specializes more in web-browser hi-jack cleaning and future prevention.

Note: Ensure when you go webpages, that it's valid and not changed/injected on you. Specially on downloads. Do NOT download the adware fake scanners. If you are concerned, download via another PC (not infected), then WRITE PROTECT it on a thumb stick or similar, to transfer over to the infected. If doing this, just ensure the virus can't jump onto the thumb stick and respread.

If using Spybot to clean, update it's definations first, then run a full scan, wait and show results. It will find a lot, even minor privacy risks and cookies. Look for the high threat levels and clean, or just clean all.

Afterwards optionally apply it's immunization tool. This will add a block list to your web-browser(s) of known adware/malware websites, helping prevent this issue occuring again in the future.

Under your web-browser(s): Remove all plugins/extentions, reset the browsers default settings and clear out all the cache / temporary internet files.

Reboot back to normal and recheck it's clean.
those DNS server addresses are not valid??

They are, google search "google dns settings" and Google itself will list them for you.

Each IP field can take up to 3 numbers: XXX.XXX.XXX.XXX

However it's only 1 number per field: XX8.XX8.XX8.XX8 (leave out the X as empty)

Are you using IPv4 or IPv6? Those are the IPv4 DNS servers.
Last edited by Azza ☠; Mar 21, 2016 @ 4:14pm
eram Mar 21, 2016 @ 4:13pm 
Use opendns if you are experiencing issues with the google dns.
208.67.222.123
208.67.220.123

https://store.opendns.com/setup/#/familyshield
bhudii Mar 21, 2016 @ 4:22pm 
Originally posted by Azza ☠:
Originally posted by add -> bhudiismurf:
those DNS server addresses are not valid??

They are, google search "google dns settings" and Google itself will list them for you.

Each IP field can take up to 3 numbers: XXX.XXX.XXX.XXX

However it's only 1 number per field: XX8.XX8.XX8.XX8 (leave out the X as empty)

Are you using IPv4 or IPv6? Those are the IPv4 DNS servers.
im using IPv6
bhudii Mar 21, 2016 @ 4:25pm 
i dont need any of this dns stuff tho, i just need it off of my steam.
bhudii Mar 21, 2016 @ 4:26pm 
Just got this now when I have logged onto steam on my second account, it has opened a browser window outside of the game even before I have launched it and the JavaScript window has come up again???? FFS https://gyazo.com/8c62d61de1cb133994c7ca5c794ea228
Originally posted by add -> bhudiismurf:
Just got this now when I have logged onto steam on my second account, it has opened a browser window outside of the game even before I have launched it and the JavaScript window has come up again???? FFS https://gyazo.com/8c62d61de1cb133994c7ca5c794ea228
because your computer is infected youll see it everywhere
< 1 2 >
Showing 1-15 of 21 comments
Per page: 1530 50

Date Posted: Mar 21, 2016 @ 3:39pm
Posts: 21