Author Topic: Avast threat pop-up when updating a game through steam  (Read 4966 times)

0 Members and 1 Guest are viewing this topic.

Offline Gbvhbvb

  • Newbie
  • *
  • Posts: 7
Avast threat pop-up when updating a game through steam
« on: August 24, 2016, 02:05:36 AM »
when games are being updated, this pop-ups (ark, dota 2):
object
http://  gpla1.wpc.v1cdn.net/depot/373301/manifest/314515164465416/valid_until=1472600144&hash=13521adf42g2w35gaf3421gfrg235422

infection
url:mal

process:
d:\steam\steam.exe

------------------------------
this has never happened before, it has started 1-2 days ago.
avast scans daily and ran a scan with mbam and both says 0 threats.
also, i haven't installed anything new lately and i only surf the web with sandboxie.

edit: numbers were randolmy copied, it was long and there is no way to copy it form avast.
seems like depot and manifest, are the same like in steamdb (as for terms):
https://steamdb.info/app/346110/depots/
https://steamdb.info/app/346110/history/
« Last Edit: August 24, 2016, 12:05:47 PM by vbwx »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Avast threat pop-up when updating a game through steam
« Reply #1 on: August 24, 2016, 06:00:05 AM »
You can report a URL here: https://www.avast.com/report-a-url.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Gbvhbvb

  • Newbie
  • *
  • Posts: 7
Re: Avast threat pop-up when updating a game through steam
« Reply #2 on: August 24, 2016, 11:04:43 AM »
You can report a URL here: https://www.avast.com/report-a-url.php

that's the point, is it a fp or not?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Avast threat pop-up when updating a game through steam
« Reply #3 on: August 24, 2016, 11:10:11 AM »
Only the guys at the viruslab can answer that. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0


Offline Gbvhbvb

  • Newbie
  • *
  • Posts: 7
Re: Avast threat pop-up when updating a game through steam
« Reply #5 on: August 24, 2016, 12:05:28 PM »
https://www.virustotal.com/en/url/cc3521160f3f8cd1b80d0da0e20d7623367a28230f648043e50b425f0ecc15a1/analysis/1472029904/
ive seen that, but i doubt if there is a malware that specificaly wait for steam to update a game to connect steam.exe to this address.
it doesnt happen in any other times, and it only started 2 days ago.

and avast full scan + mbam full scan with rootkit scan resulted in 0 threats.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Avast threat pop-up when updating a game through steam
« Reply #6 on: August 24, 2016, 12:11:28 PM »
URL:Mal = IP and/or Domain is blocked.
It is not a file that is detected but a web-address that is why file scans don't show anything.

Offline Gbvhbvb

  • Newbie
  • *
  • Posts: 7
Re: Avast threat pop-up when updating a game through steam
« Reply #7 on: August 24, 2016, 12:15:41 PM »
URL:Mal = IP and/or Domain is blocked.
It is not a file that is detected but a web-address that is why file scans don't show anything.
i know that, you dont understand me.
MBAM full + threat scans with rootkit = 0
avast full scan = 0
i checked if there could be a malware that would cause steam to connect to that address when updating a game (which even sounds rediciulous).
so no threats, and steam.exe is a safe program, steam.exe triggers this address when updating games.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Avast threat pop-up when updating a game through steam
« Reply #8 on: August 24, 2016, 12:24:23 PM »
It is you who don't understand.

MBAM and the avast scan don't find anything as it is not scanning web-traffic/addresses.
The detection/alert is for the web-address.

Offline Gbvhbvb

  • Newbie
  • *
  • Posts: 7
Re: Avast threat pop-up when updating a game through steam
« Reply #9 on: August 24, 2016, 12:27:03 PM »
It is you who don't understand.

MBAM and the avast scan don't find anything as it is not scanning web-traffic/addresses.
The detection/alert is for the web-address.
no you still dont understand me.
i know that mbam and avast scan FILES and not web-traffic.
what i try to say is:
steam.exe won't connect to a malicious address by itself, if it was something bad than it would only happen if a rootkit/virus tells it to (file in the pc).
and scans says 0 threats, so it has to be a native steam.exe call.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Avast threat pop-up when updating a game through steam
« Reply #10 on: August 24, 2016, 12:30:15 PM »
You are wrong.
steam connects, that is all.
It doesn't know if a IP/Domain is harmful or not.

Something that is safe can be infected the next second.
So yes, steam can connect to a infected address.

Offline Gbvhbvb

  • Newbie
  • *
  • Posts: 7
Re: Avast threat pop-up when updating a game through steam
« Reply #11 on: August 24, 2016, 12:31:30 PM »
You are wrong.
steam connects, that is all.
It doesn't know if a IP/Domain is harmful or not.

Something that is safe can be infected the next second.
So yes, steam can connect to a infected address.
its a game update to dota 2 and it happened with ark game updates.
there is nothing to be infected from.
if it was on my side then scans wouldnt say 0 threats.

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: Avast threat pop-up when updating a game through steam
« Reply #12 on: August 24, 2016, 02:24:36 PM »
That is what Eddie is saying.  The IP address that Steam is connecting to has an infected site.  Nothing you can do except avoid the site until and if it is cleaned.  You are not infected as Avast has protected you.
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

Offline Gbvhbvb

  • Newbie
  • *
  • Posts: 7
Re: Avast threat pop-up when updating a game through steam
« Reply #13 on: August 24, 2016, 02:28:00 PM »
That is what Eddie is saying.  The IP address that Steam is connecting to has an infected site.  Nothing you can do except avoid the site until and if it is cleaned.  You are not infected as Avast has protected you.
there is no site.
its a bought game (ark) and steam simply updates it, and from what i know all the data sits in steam servers.

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: Avast threat pop-up when updating a game through steam
« Reply #14 on: August 24, 2016, 02:30:57 PM »
Steam has to connect to the server, which seems to have an infected server.  Rare occurance, I know.  Normally, Steam maintains it house well.
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner