Go Back   Steam Users' Forums > Steam Game Discussions > M - P > Portal 2

Reply
Click here to go to the first staff post in this thread.  
Thread Tools Display Modes
Old 05-09-2012, 12:58 AM   #1
PotcFdk
 
 
 
Join Date: Jan 2011
Reputation: 25
Posts: 78
The final hours of Portal 2 - Malware

The Topic
There is some malicious Code on the Valve servers.

What are you talking about?
As soon as you start "The Final Hours of Portal 2",
you automatically connect to thefinalhoursofportal2.com
This site has been hacked.
Somebody injected malicious code which I'm going to show later on.

The Problem
Your Client / The final hours of Portal 2 connects to that website, or to be more specific, some subpages.
There is an illegally inserted IFrame to pokosa.com* on the page.

The Solution
There's really nothing we can do about it. It's in Valve's Hands.
I've send them an email and contacted the Steam Support.
Steam Support told me it's my Browser's fault...

The Solution Episode One
Odessa Cubbage has posted in here that Valve is finally aware of the problem.
Also, The final Hours of Portal 2 has been disabled for all users temporarily.
Quote:
Originally Posted by Odessa Cubbage View Post
The site owner has been notified that there's a problem.
The Solution Episode Two
The Malware seems to be removed from the servers.
The Final Hours Of Portal 2 has been reactivated
and everybody is able to play it again.
No official statement has been posted yet.


Some Information
Well then, here is some information for all the people who don't know what happened / what to do now.

There was an IFrame maliciously injected on the servers that were hosting some content for The Final Hours Of Portal 2.
This IFrame loaded a script from another webserver (mentioned before).
That script should be now be well-known and in the malware-list of your Anti-Virus solution.
It is recommended to do a full-scan of your system to make sure the script doesn't hide somewhere.
I personally also recommend to clear all kinds of Internet/Web Caches because scripts often reside in these places.


* Better don't visit that website.

Last edited by PotcFdk: 05-22-2012 at 10:55 AM. Reason: Added some useful information.
PotcFdk is offline  
Reply With Quote
Old 05-09-2012, 01:11 AM   #2
Lalee88
 
 
 
Join Date: Dec 2011
Reputation: 0
Posts: 9
I've bought it yesterday and got the same warning (I'm using Avast)...
Maybe it's a false alarm?
I haven't found anything useful about anybody else having this issue...
Lalee88 is offline   Reply With Quote
Old 05-09-2012, 01:39 AM   #3
kuangeleven
 
Join Date: Jun 2010
Reputation: 0
Posts: 2
Firefox says that the webpage is reported to be malicious.
Weird.

Last edited by kuangeleven: 05-09-2012 at 01:43 AM.
kuangeleven is offline   Reply With Quote
Old 05-09-2012, 02:55 AM   #4
Alililele
 
 
 
Join Date: Apr 2011
Reputation: 5
Posts: 33
Exclamation

"Blackhole Exploit Kit"
this is what AVG gives me
Alililele is offline   Reply With Quote
Old 05-09-2012, 03:15 AM   #5
Sparkpin
 
 
 
Join Date: May 2011
Reputation: 27
Posts: 130
In my back history, it DOES say pokasa.com

Both MBAM and Microsoft Security Essentials were tripped.

Mbam Said something about ccvshost.exe

I think the Final Hours of Portal 2 has been infected
Sparkpin is offline   Reply With Quote
Old 05-09-2012, 03:22 AM   #6
FunPika
 
 
 
Join Date: Oct 2010
Reputation: 2
Posts: 22
"Web Attack: Mass Injection Website" is what I am getting from Norton.
FunPika is offline   Reply With Quote
Old 05-09-2012, 03:46 AM   #7
e_nigma
 
Join Date: Dec 2010
Reputation: 1
Posts: 32
This should be reported to Valve, apparently, someone hacked the server that hosts the otherwise legit content and inserted malware.
e_nigma is offline   Reply With Quote
Old 05-09-2012, 04:53 AM   #8
PotcFdk
 
 
 
Join Date: Jan 2011
Reputation: 25
Posts: 78
I just wrote an email to Valve.

Last edited by PotcFdk: 05-09-2012 at 04:58 AM.
PotcFdk is offline   Reply With Quote
Old 05-11-2012, 03:58 PM   #9
e_nigma
 
Join Date: Dec 2010
Reputation: 1
Posts: 32
I've just bought the thing and the malware is still there. I sent a message to Steam Support, hopefully, they'll do something about it.
e_nigma is offline   Reply With Quote
Old 05-11-2012, 04:01 PM   #10
daze23
 
 
 
Join Date: May 2012
Reputation: 35
Posts: 155
yep, I got a warning from chrome
daze23 is offline   Reply With Quote
Old 05-11-2012, 04:05 PM   #11
lostprophetpunk
 
 
 
Join Date: Jun 2011
Reputation: 440
Posts: 2,208
You might want to remove that link...
lostprophetpunk is offline   Reply With Quote
Old 05-12-2012, 03:37 AM   #12
rLegolas
 
 
 
Join Date: Apr 2009
Reputation: 8
Posts: 50
This is it.

http://i.imgur.com/N9ERt.jpg
rLegolas is offline   Reply With Quote
Old 05-12-2012, 03:56 AM   #13
schrodingergeek
 
 
 
Join Date: Apr 2011
Reputation: 99
Posts: 174
AVG flagged it for me too.
schrodingergeek is offline   Reply With Quote
Old 05-12-2012, 07:16 AM   #14
PotcFdk
 
 
 
Join Date: Jan 2011
Reputation: 25
Posts: 78
Quote:
Originally Posted by rLegolas View Post
Nice, you have found the place where the game shows the webpage.
PotcFdk is offline   Reply With Quote
Old 05-12-2012, 08:46 AM   #15
Spyro Cool
 
 
 
Join Date: Oct 2011
Reputation: 441
Posts: 669
Ok. I installed it a few months ago. Do I need to delete it or just not use it.

And can my friend download it now but not use it?
Spyro Cool is offline   Reply With Quote
Reply

Go Back   Steam Users' Forums > Steam Game Discussions > M - P > Portal 2


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT -7. The time now is 03:57 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
Site Content Copyright Valve Corporation 1998-2012, All Rights Reserved.