DCSkullFreak 2020 年 10 月 26 日 上午 10:59
malware found in steam folders after downloading game
Trojan:Win32/AgentTesla!ml
This program is dangerous and executes commands from an attacker

What is AgentTesla!ml ?
A powerful, easy-to-use password stealing program known as Agent Tesla has been infecting computers since 2014, but recently this malware strain has seen a surge in popularity — attracting more than 6,300 customers who pay subscription fees to license the software. Although Agent Tesla includes a multitude of features designed to help it remain undetected on host computers, the malware’s apparent creator seems to have done little to hide his real-life identity.
https://krebsonsecurity.com/2018/10/who-is-agent-tesla/

( Recent articles are suggesting a surge during Covid19 Check for breaches )

C:\Steam\dgVoodoo2_71_2.zip
C:\Users\Desktop\AppData\Local\Steam\htmlcache\Cache\f_000a3d
< >
目前顯示第 1-9 則留言,共 9
Spawn of Totoro 2020 年 10 月 26 日 上午 11:03 
htmlcache is the web browser in Steam. That would indicates you visited a site that had malware, through the web browser.
Crazy Tiger 2020 年 10 月 26 日 上午 11:03 
And which game downloaded it for you then?

Though it looks more like malware coming from a different source that installed itself in there.
DCSkullFreak 2020 年 10 月 26 日 下午 11:54 
Soul Reaver, Soul Reaver 2 and Baldurs Gate 3

dgVoodo2 is a graphics wrapper that converts old graphics APIs to Direct3D 11 or Direct3D 12 (as of version 2.7) for use on Windows 7,8 & 10 (i.e soulreaver &soulreaver 2)

the only browser related activity connected with steam would have been game pages visted through the steam que or possibly Larian Studios as part of the beta.

with all due respect, the postulation of other activity granting phishing access was already visited on the forum and was given considerable thought, it seems doubtful to be the case, the timing of the flagged and quarantined Malware is to coincidental.

This bit of password stealing Malware usually hides itself in code of (at the very least) legitimate looking Email,Files or Webbrowsers etc. as pointed out by cyberluddite.

Caution is all that was meant to be raised, as several articles suggested there has been a surge during covid19 of this thing being spread in all forms,in benign looking, legitimate looking, sites, services.
DCSkullFreak 2020 年 10 月 26 日 下午 11:57 
Odd I just tried posting a type written reply to the thread. A link (I did not add) showed up in the thread. I nudged it and a steam page came up flagging it as potentially malicious.
Crazy Tiger 2020 年 10 月 27 日 上午 12:10 
I asked some friends who have those games, none of them have the files you describe. Graphic wrappers also do not get installed nor downloaded in the main Steam folder.

Still would point to malware from another source and not through games in Steam.
DCSkullFreak 2020 年 10 月 27 日 上午 12:30 
lol nice! Had a bit of a start thanks for bringing red alert down to Tilly bumped the control panel.

thanks for your input Crazy Tiger that would lean more in the direction of the browser task for Larian Studios. If it targets browsers/pages that could be the culprit over writing the file could have just been where it was attached.

It could just as easily have been a sore sport or a troll on a multiplayer game targeting a gamertag with a friend request, with no other malintent than to lock you out of your account.
Brian9824 2020 年 10 月 27 日 上午 5:27 
Or the most likely case is that the user visited a site, got infected, and the file hid itself in the steam folder....

The odds of that are FAAAR more likely then it being in one of those games.
J4MESOX4D 2020 年 10 月 27 日 上午 5:55 
None of these games are shipped with Malware. If this happened, millions of users would be affected and Valve would be in extreme hot water. AV's would also be going haywire.

Voodoo is nothing to do with Steam either so you've most likely planted an external download into the Steam directory that was malicious. I was using Voodoo the other day for the original Metal Gear Solid and it's a standalone program. It sounds like you've tried to inject a clean directory with something external that is either bad or has contained something dangerous.
crunchyfrog 2020 年 10 月 27 日 上午 10:01 
引用自 Crazy Tiger
I asked some friends who have those games, none of them have the files you describe. Graphic wrappers also do not get installed nor downloaded in the main Steam folder.

Still would point to malware from another source and not through games in Steam.

Yup, I've got Soul Reaver 2 and I've recently been fiddling with it to get it to run, and none of this happens for me.

I'm more inclined to agree that you picked this up elsewhere and it's spread. By the sound of its behaviour, it sounds pretty classic malware activity - to send you to certain sites through your normal PC usage.

< >
目前顯示第 1-9 則留言,共 9
每頁顯示: 1530 50

張貼日期: 2020 年 10 月 26 日 上午 10:59
回覆: 4