Steam infected with adware - DNS Unlocker

JamesL2015

New Member
Thread author
Verified
Sep 3, 2015
19
I hope this is what you are after.
 

Attachments

  • Adware1.png
    Adware1.png
    13.8 KB · Views: 9
  • Adware2.png
    Adware2.png
    14.8 KB · Views: 9
  • Adware3.png
    Adware3.png
    156.4 KB · Views: 9
  • Adware4.png
    Adware4.png
    157.9 KB · Views: 8

JamesL2015

New Member
Thread author
Verified
Sep 3, 2015
19
I haven't seen ads in steam since that fixlog was run through FRST to delete the htmlcache, so I'm assuming it nuked the virus in steam.

I also had a couple of hours spare yesterday, and factory reset my phone, just in case it was the source and was just coming through the hotspot. The adware is still in chrome.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
 

JamesL2015

New Member
Thread author
Verified
Sep 3, 2015
19
This one's turning out to be a tricky little bugger, isn't it?
 

Attachments

  • Addition.txt
    62.1 KB · Views: 2
  • FRST.txt
    59.7 KB · Views: 2

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Uninstall Chrome

Export your bookmarks
Import or export bookmarks - Chrome Help


Close all Chrome windows and tabs.
Go to the Start menu > Control Panel.
Click Programs and Features.
Double-click Google Chrome.
Click Uninstall from the confirmation dialog. Delete your user profile information, like your browser preferences, bookmarks, and history, select the "Also delete your browsing data" checkbox.


Click Start, copy in search %LOCALAPPDATA%\ and remove folder Google

Download Chrome
Chrome Browser

Do not sign in into your Google account and let me know how is the situation now?
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
RogueKiller.png
Scan with RogueKiller

Please download RogueKiller and save the file to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    RogueKiller.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the pre-scan will be done. It shouldn't take more than 2-3 minutes.
  • Accept the Terms of use.
  • When the Scan button becomes available, please click it. RogueKiller will start a full scan.
  • Let this process run uninterrupted!.
  • When finished, a Report button will become available. Click it. You will be presented with a logfile.
Please include the content of this logfile in your next reply.
 

JamesL2015

New Member
Thread author
Verified
Sep 3, 2015
19
Ok, here is the report.

Now chrome is virtually unusable because of a persistent popup that occurs on every single website, so for the foreseeable future, I am switching to Firefox.
 

Attachments

  • RogueKiller Report.txt
    4.3 KB · Views: 1
  • Adware5.png
    Adware5.png
    18.2 KB · Views: 2

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
51a46ae42d560-malwarebytes_anti_malware.png
Scan with Malwarebytes' Anti-Malware

Please re-run
51a46ae42d560-malwarebytes_anti_malware.png
Malwarebytes' Anti-Malware.

  • First of all, select update.
  • Once updated, click the Settings tab, in the left panel choose Detection & Protection and tick Scan for rootkits.
  • Click the Scan tab, choose Threat Scan is checked and click Scan Now.
  • If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs and double-click the newest Scan Log.
  • At the bottom click Export and choose Text file.
Save the file to your desktop and include its content in your next reply.



FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
 

JamesL2015

New Member
Thread author
Verified
Sep 3, 2015
19
Here you go.
 

Attachments

  • Addition.txt
    67.5 KB · Views: 1
  • FRST.txt
    57.6 KB · Views: 1
  • Malware Bytes Report.txt
    1.1 KB · Views: 1

JamesL2015

New Member
Thread author
Verified
Sep 3, 2015
19
I meant to add, aswell, it's starting to infect my Firefox browser, now that I am starting to use that.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Please go to: VirusTotal
  • Click the Choose File button.
  • Please copy/paste the following text into the 'File name:' box:

    Code:
    C:\Users\JamesLangley\SCS\ScpServer\bin\ScpService.exe
  • Click Open then click the Scan it! button just below.
  • This will scan the file. Please be patient.
  • If you get a message saying File already analyzed: click Reanalyse
  • Once scanned, copy and paste the URL from your browser address bar in your next reply.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top