A trojan that could get your steam account (I think)

Haggus McGee

Forum Fiend
Joined
Apr 12, 2008
Messages
652
Well, I logged on this afternoon, and was surprised to see a dialogue box from my antivirus, (probably the first time because it does everything [including update] in the background :)). Anyway, it was a trojan called 'Hook-spyware' or something and it had been sorted. I was worried because I had to re-log-on in order to begin steam. Apon doing so, I actually was asked to re-enter my password (never happened before, and I have now sinse changed it) and I was terrified I had been hacked untill log on was sucsessful - I don't know if it is actually possible to get passwords like this, and I am cynical, but if it is, my message is:

1. use different passwords for everything which has money involved
2. use a unique password for your email
3. invest in a decent virus protection if it could save money on damages

I hope this is not some complete overreaction, because I don't know great amounts about viruses, so tell me if this is totally bogus XD.
 
Whether you're overreacting or not, I use keepass for my sensitive passwords (paypal, bank, and a few other things.) It's a slight hassle using it, but if you don't use it and you get ripped off, you won't feel too great, I can just about promise that.
 
That's funny, I am just using it now :) I'd had it installed for a while, but never used it. I can't get it to work with steam or hotmail though...
 
Last edited:
I also use Keepass.

My friends thought it silly when I told them I could login to one account or another when visiting them because I didn't have my USB fob with Keepass on it. I told them I had unique random passwords for almost all of my accounts, and I couldn't remember the password without my USB key.

...they laughed only until one of them got phished (actually, spearphished - ha!) and lost real money. Now, they're in total paranoia.

I have a unique password for each significant account (Steam, personal e-mail, work accounts). For the really sensitive ones, like on-line banking and PayPal, I have unique userids AND passwords that I use for that one account only. I suppose someone might figure out my junk e-mail password, but I don't care. They can help me sift through the 75 e-mails of coupon offers I get every day.
 
I also use Keepass.

My friends thought it silly when I told them I could login to one account or another when visiting them because I didn't have my USB fob with Keepass on it. I told them I had unique random passwords for almost all of my accounts, and I couldn't remember the password without my USB key.

...they laughed only until one of them got phished (actually, spearphished - ha!) and lost real money. Now, they're in total paranoia.

I have a unique password for each significant account (Steam, personal e-mail, work accounts). For the really sensitive ones, like on-line banking and PayPal, I have unique userids AND passwords that I use for that one account only. I suppose someone might figure out my junk e-mail password, but I don't care. They can help me sift through the 75 e-mails of coupon offers I get every day.

Yeah, when you take such precautions, odds are they won't guess your account info. If you do get burned, it's usually through a security weakness in the webapp. Tough luck, but not much more you can do.
 
Heres a great tip
Buy pre-paid visa giftcards from your local store or mart to buy things online.
They can even be linked with paypal since they act as credit cards. So if somebody DOES get your info, they have a bunch of usless numbers attached to no money.

Its what I use for all online purchases.
 
someone got into my steam account once because i used the same password for everything.
 
I use the same password for alot of things, I have nothing of real importance, except steam which is the only unique account password.
 
Well, I logged on this afternoon, and was surprised to see a dialogue box from my antivirus, (probably the first time because it does everything [including update] in the background :)). Anyway, it was a trojan called 'Hook-spyware' or something and it had been sorted. I was worried because I had to re-log-on in order to begin steam. Apon doing so, I actually was asked to re-enter my password (never happened before, and I have now sinse changed it) and I was terrified I had been hacked untill log on was sucsessful - I don't know if it is actually possible to get passwords like this, and I am cynical, but if it is, my message is:

1. use different passwords for everything which has money involved
2. use a unique password for your email
3. invest in a decent virus protection if it could save money on damages

I hope this is not some complete overreaction, because I don't know great amounts about viruses, so tell me if this is totally bogus XD.

You're wrong. Trojans simply cannot get onto your steam account. Trojans can be keyloggers or back doors, but can't be on your account itself.

Only suggestion is to scan your computer. I'm still unclear on what you said, though. Did your account get hacked?
 
No, this thing was in the C drive, and I pretty much had to re-log into all of the things which had auto log in. Steam one said my credentials were wrong or something. I just scanned everything and changed all my passwords. No I did not get hacked, but you tell me what might have happened if I didn't take any of the precautions.
 
If you had/have a keylogger, everything should be considered suspect or compromised. At least, every account you've accessed on that computer since you last knew it was clean.

You need to take preventative steps (change password, change userid, change security question(s), change the "reset" e-mail) on ALL on the accounts which contain personally identifying information, financial significance, or those which could be used to obtain personally identifying information.

e.g. Steam, e-mail, Facebook, MySpace, school accounts, bank accounts, PayPal, Twitter, blogs, IRC, ICQ, Ventrilo, AOL, Yahoo, Hotmail, Gmail, Craigslist, etc.

Of course, you can only do this on a clean PC.
 
Some tips that I use to try and stay safe:
a. Change passwords for everything important at least once a month if not more
b. When logging into accounts, have something liek notepad open. When typing in your username and pw, switch to notepad and scramble it up. Like, "Lo (switch) ki the w (switch)r (switch)eckor (switch) dGa (s) hfus (s) tz (s) enter key (s) (Dice) (s) what's up? etc etc etc
(That was a bit extensive of an example but it keeps anyone looking at keyloggers guessing because now they don't have your username or password, but a bunch of weird scrambles.)
c. use password protection. the keepass you guys use sounds good (anyone got a link for me?), but you could also use non-digital protection if you actually type your own passwords. (Like a file inside a lock-box, or something electronic like http://www.thinkgeek.com/gadgets/security/91a2/.
 
Keepass:

http://keepass.info/

Don't be fooled by the site ending in ".com" which is NOT the official site.
IMHO, Keepass is the password software management program. But others have favorites such as Password Safe and KWallet.

Inserting random spaces and inserting trivial characters, like your example, LordGatz, will help but will only slow down a really good logging system. Will it help simple scripts and keyloggers just keying off the first 15 characters after the "password" field on a HTML form? Sure. But increasingly though, keylogger results are being sent to botnets which have plenty of spare CPU cycles to crunch through different combinations of characters.

In your example, the right letters to comprise your userid are present and in the correct order. A dictionary attack would probably find the right combination, on the right hardware or on a botnet, in about an hour rather than a few hours.

This is yet another reason why a software firewall is so important. Most keyloggers need to "report" their results for analysis to somewhere. If you have a good software firewall which prevents unauthorized data transmission, you have another roadblock to being compromised - even if you inadvertently loaded a keylogger onto your PC.

There's dozens of types of keyloggers, ranging from very simple (capture the next 15 characters after cursor is placed into "password" field) to those which are very sophisticated (capture hardware level interrupts for the keyboard, mouse clicks for on-screen keyboards, and copy memory buffer for contents pasted into password fields).

Keepass (and others) minimize your risk, but nothing is foolproof. Not loading a keylogger onto your computer is still the best bet.
 
A new way people are trying to steal your account!

I just recently got a incoming chat from someone named JohnN!. I know all the friends I have on my steam frineds list and can't seem to find this individual on my list. He just doesn't exist.

I sent the link to Steam and they told me that this was someone who was trying to steal my Steam Account. If you click on the link, your toast. Somehow, these account stealers can access anyone's steam friends list through certain scripts and send you messages.

I've received two messages from two different people in the past and tried to hunt them down in my friends list but still couldn't find them. So I refused to click on the link. Here's an example of what the chat message was sent to me:


JohnN!-: Hello!, Look at the community steam v2.0, comes with many gifts and surprises!, New updates that are the best. http://www.steamcommunnity.com/ greetings!
=(eG)=™ Cigarjohn =FL=: Who are you bro?
=(eG)=™ Cigarjohn =FL=: I don't recognize the name.
Lost connection to Steam, will rejoin chat automatically when connection regained.
JohnN!- is now Offline.
Connected again and rejoined chat.
JohnN!- is now Online.
JohnN!- is now Offline.

This individual won't respond to me cause it's not a real person. It's a computer that I'm talking to.

Just beware my eGO brothers and sisters.

I Just changed my Steam Password just in case. I would hate to lose all those wonderful games that I have purchased in the past.

Peace to all!
 
Last edited:
Hmm.....this is odd. It's simply not possible to steal a steam account by clicking a link. Unless you recently logged into the steam website, you could steal cookies and md5 hashes. But it would have no affect on you if you're on a proxy.

People are getting more clever......
 
You're wrong. Trojans simply cannot get onto your steam account. Trojans can be keyloggers or back doors, but can't be on your account itself.

Only suggestion is to scan your computer. I'm still unclear on what you said, though. Did your account get hacked?


I don't mean to brow beat you but malware can steal your Steam Account without key-logging. It's only a problem if you have Steam save your password for you. Otherwise if Steam doesn't save your password you have to worry about key loggers.

Sadly the source code for stealing/recovering steam accounts is floating around the net.
 
Last edited:
Back
Top