Jump to content

Can you get malware from the steam workshop?

Pom2000

Can you get malware from the steamworkshop? And if you can how to prevent and Fix it

Link to comment
Share on other sites

Link to post
Share on other sites

12 minutes ago, Pom2000 said:

Can you get malware from the steamworkshop? And if you can how to prevent and Fix it

One would assume that steam virus scans and such everything uploaded there, but there's no such thing as bulletproof, so always take at least some precautions anywhere you can.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, tkitch said:

One would assume that steam virus scans and such everything uploaded there, but there's no such thing as bulletproof, so always take at least some precautions anywhere you can.

Ok thx for letting me know

Link to comment
Share on other sites

Link to post
Share on other sites

Worthwhile to mention as well that some AV programs will produce false positives, especially if the add on is messing with anything outside of the game's installation folder. My rule of thumb is always to check the reviews.

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, uncreativespace said:

Worthwhile to mention as well that some AV programs will produce false positives, especially if the add on is messing with anything outside of the game's installation folder. My rule of thumb is always to check the reviews.

Ok thx for telling i got some stuff from the workshop and pc did a Windows Defender scan and it was blocked from acces in my documents folder so i checkt the reviews and there where non do u got Any other tips?

Link to comment
Share on other sites

Link to post
Share on other sites

26 minutes ago, Pom2000 said:

Ok thx for telling i got some stuff from the workshop and pc did a Windows Defender scan and it was blocked from acces in my documents folder so i checkt the reviews and there where non do u got Any other tips?

If you're positive that the game (and any downloaded content) is generally trusted by the community and doesn't contain an exploit you can tell Defender to trust the game's executable or anything running from the parent folder (Google is your friend on how to do that).

Some versions of Defender will block a lot of older titles from accessing save files in the Documents folder if it doesn't have a profile for it which can be a pain. (Civilization V is an example)

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, uncreativespace said:

If you're positive that the game (and any downloaded content) is generally trusted by the community and doesn't contain an exploit you can tell Defender to trust the game's executable or anything running from the parent folder (Google is your friend on how to do that).

Defender will block a lot of older titles from accessing save files in the Documents folder which can be a pain.

The thing is it was trailmakers.exe that blocked Windows Defender from scanning the documents folder and normally it does not but i adder a car or smthn from the steam workshop 

 

Link to comment
Share on other sites

Link to post
Share on other sites

YES this is possible,

 

especially if the game can open a webpage by itself.

 

Then a malicious addon can force open a bazillion webpages each containing ads, malware and many links.

 

if you are logged in as admin this is more dangerous as some malware could auto install itself,

if you are logged in as a regular user, you will get a admin prompt for the password

╔═════════════╦═══════════════════════════════════════════╗
║__________________║ hardware_____________________________________________________ ║
╠═════════════╬═══════════════════════════════════════════╣
║ cpu ______________║ ryzen 9 5900x_________________________________________________ ║
╠═════════════╬═══════════════════════════════════════════╣
║ GPU______________║ ASUS strix LC RX6800xt______________________________________ _║
╠═════════════╬═══════════════════════════════════════════╣
║ motherboard_______ ║ asus crosshair formulla VIII______________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ memory___________║ CMW32GX4M2Z3600C18 ______________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ SSD______________║ Samsung 980 PRO 1TB_________________________________________ ║
╠═════════════╬═══════════════════════════════════════════╣
║ PSU______________║ Corsair RM850x 850W _______________________ __________________║
╠═════════════╬═══════════════════════════════════════════╣
║ CPU cooler _______ ║ Be Quiet be quiet! PURE LOOP 360mm ____________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ Case_____________ ║ Thermaltake Core X71 __________________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ HDD_____________ ║ 2TB and 6TB HDD ____________________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ Front IO__________   ║ LG blu-ray drive & 3.5" card reader, [trough a 5.25 to 3.5 bay]__________║
╠═════════════╬═══════════════════════════════════════════╣ 
║ OS_______________ ║ Windows 10 PRO______________________________________________║
╚═════════════╩═══════════════════════════════════════════╝

 

Link to comment
Share on other sites

Link to post
Share on other sites

Not sure about other games, but specifically with Gmod. There have been issues with Malicious lua files that could've installed a backdoor on your system in the past. But the mods are on top of it for the most part now. So just avoid new workshop items, and you should be okay. 

The most famous was the cough virus back in 2014

https://www.pcgamesn.com/indie/garry-s-mod-virus-filled-servers-sound-coughing

Link to comment
Share on other sites

Link to post
Share on other sites

On 12/2/2021 at 10:16 PM, tkitch said:

One would assume that steam virus scans and such everything uploaded there

funny thing afaik they dont.* they rely on the "community" to find malicious stuff (thats also how you get things like "vanguard" which by all means must be considered malware)

 

* of course,  surprisingly unsurprisingly i dont find anything official,  but it has happened in the past (ex: Street fighter V's infamous  "rootkit") so that at least implies no checks , as does the fact there doesn't seem an official statement about the subject ...

 

 

On 12/2/2021 at 10:03 PM, Pom2000 said:

how to prevent

you can scan every item with a good av software (ex: malwarebytes) and upload the file(s) to virustotal before you "install" them.

i did that the one time i used steam workshop, i usually get mods from nexus, who actually tests (most) mods before letting users download them.

^ i still check everything i download with malwarebytes though 🤷‍♂️

The direction tells you... the direction

-Scott Manley, 2021

 

Softwares used:

Corsair Link (Anime Edition) 

MSI Afterburner 

OpenRGB

Lively Wallpaper 

OBS Studio

Shutter Encoder

Avidemux

FSResizer

Audacity 

VLC

WMP

GIMP

HWiNFO64

Paint

3D Paint

GitHub Desktop 

Superposition 

Prime95

Aida64

GPUZ

CPUZ

Generic Logviewer

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Always check your video card and CPU usage while playing new games.  Some people are adding hash mining into their games to make other people mine for them and that slips through some times. 

Link to comment
Share on other sites

Link to post
Share on other sites

17 hours ago, IRMacGuyver said:

Always check your video card and CPU usage while playing games.  Some people are adding hash mining into their games to make other people mine for them and that slips through some times. 

But... ? how do you know the game isn't legit using 90% cpu and 99% gpu for example? this seems like good advice,  but it also seems rather impractical if not nearly impossible... unless im missing something having good av software and actually using it properly would be better advice?

 

Also tbh, its possible sure but i downloaded a gazillion of mods and around 100 "workshop items" and haven't encountered a single "virus" yet, the only things (out of a "gazillion" mods mind you, we talking several 100 GBs here.. ) i ever found was one clearly false detection and another even more false detection  - because that mod and so called accompanying "virus" originated from my *own* pc... and ofc wasnt a virus at all... lol. i think people apparently get their viruses elsewhere  (ahem p0rn...) or other malicious sites or even email "attachments" ...  it seems really unlikely to get something from Steam (even when its definitely "possible")

 

 

 

The direction tells you... the direction

-Scott Manley, 2021

 

Softwares used:

Corsair Link (Anime Edition) 

MSI Afterburner 

OpenRGB

Lively Wallpaper 

OBS Studio

Shutter Encoder

Avidemux

FSResizer

Audacity 

VLC

WMP

GIMP

HWiNFO64

Paint

3D Paint

GitHub Desktop 

Superposition 

Prime95

Aida64

GPUZ

CPUZ

Generic Logviewer

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

19 hours ago, IRMacGuyver said:

Always check your video card and CPU usage while playing games.  Some people are adding hash mining into their games to make other people mine for them and that slips through some times. 

maybe 10 years ago downloading from shady free fps games no one knew the location or who owned it..

 

Novadays..

On steam? Nah they would get found out pretty quickly.

Useful threads: PSU Tier List | Motherboard Tier List | Graphics Card Cooling Tier List ❤️

Baby: MPG X570 GAMING PLUS | AMD Ryzen 9 5900x /w PBO | Corsair H150i Pro RGB | ASRock RX 7900 XTX Phantom Gaming OC (3020Mhz & 2650Memory) | Corsair Vengeance RGB PRO 32GB DDR4 (4x8GB) 3600 MHz | Corsair RM1000x |  WD_BLACK SN850 | WD_BLACK SN750 | Samsung EVO 850 | Kingston A400 |  PNY CS900 | Lian Li O11 Dynamic White | Display(s): Samsung Oddesy G7, ASUS TUF GAMING VG27AQZ 27" & MSI G274F

 

I also drive a volvo as one does being norwegian haha, a volvo v70 d3 from 2016.

Reliability was a key thing and its my second car, working pretty well for its 6 years age xD

Link to comment
Share on other sites

Link to post
Share on other sites

On 12/16/2021 at 2:50 PM, MultiGamerClub said:

maybe 10 years ago downloading from shady free fps games no one knew the location or who owned it..

 

Novadays..

On steam? Nah they would get found out pretty quickly.

"pretty quickly" doesn't mean before it's put up for the public to download.  That it is possible was my only point.  Steam doesn't completely test everything themselves they rely on community feedback. 

Link to comment
Share on other sites

Link to post
Share on other sites

On 12/16/2021 at 1:37 PM, Mark Kaine said:

But... ? how do you know the game isn't legit using 90% cpu and 99% gpu for example?

You just have to guess based on the visual quality.  Most the time the games that do this look like ass so they have more headroom for their mining scam.  People don't seem to implement them on games that only have amazing graphics with little room for extra code.  Though I wont put it past EA or Ubisoft. 

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, IRMacGuyver said:

"pretty quickly" doesn't mean before it's put up for the public to download.  That it is possible was my only point.  Steam doesn't completely test everything themselves they rely on community feedback. 

At one point of time i remember there was an old fps game that got added to steam, they hadnt renewed their license to use a spesific program and every anti-virus company flagged the file(s) as a major virus that needs to be contained right away.. Guess what it what? A program logging / launcher background details on the games startup.. Without file = Game useless.

 

I think 95% of the few thousand posts on the forums back then was about this bug alone and it took them a week or something to fix it.. This is many years back but even back then i knew this was fake and still allowed it.. All tho most people around me and on the internet was freaking out about some files in the games folder acting up.. LOL

 

Then again, for all i know it could be a virus but i had played this same game since 2008 or something and i knew it wasnt that shitty.. or atleast not yet at the time.

Now i think the game is gone, i remember it changed owners probably 6-7 times before it went under.. Damn i miss you AVA.

Useful threads: PSU Tier List | Motherboard Tier List | Graphics Card Cooling Tier List ❤️

Baby: MPG X570 GAMING PLUS | AMD Ryzen 9 5900x /w PBO | Corsair H150i Pro RGB | ASRock RX 7900 XTX Phantom Gaming OC (3020Mhz & 2650Memory) | Corsair Vengeance RGB PRO 32GB DDR4 (4x8GB) 3600 MHz | Corsair RM1000x |  WD_BLACK SN850 | WD_BLACK SN750 | Samsung EVO 850 | Kingston A400 |  PNY CS900 | Lian Li O11 Dynamic White | Display(s): Samsung Oddesy G7, ASUS TUF GAMING VG27AQZ 27" & MSI G274F

 

I also drive a volvo as one does being norwegian haha, a volvo v70 d3 from 2016.

Reliability was a key thing and its my second car, working pretty well for its 6 years age xD

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×