Possible Virus? help please!

Hi, this afternoon i had to check my Steam folder and accidentally clicked WINDOWS instead of program files, just to notice there was a new pretty fishy folder in there called 048298C9A4D3490B9FF9AB023A9238F3.TMP

In that folder, there are 3 files: WiseCustomCalla6.dll, WiseCustomCalla.dll and a configurations notepad file named WiseData. I googled them and only found this named related to Mcafee antivirus - which i never used. In properties, theyre said to be Valve files (related to steam) but ive never heard any valve file thats supposed to be in the WINDOWS folder. I also searched for info in the Steam support page (www.steampowered.com) and couldnt find a thing. They were all created yesterday (october 29th), i havent downloaded a thing and none of my antimalware (mbam, superantispyware and spybot search&destroy) or Avast home detect a thing.

HijackThis doesnt accuse anything either - looks the same since my last post ages ago -, so i sent all of them to Virustotal… and nothing was found either.

Heres the HJT log anyways:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:03:41, on 30/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Documents and Settings\Joao\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM..\Run: [nwiz] nwiz.exe /install
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [COMODO Internet Security] “C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe” -h
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-18..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O9 - Extra ‘Tools’ menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O17 - HKLM\System\CCS\Services\Tcpip..{42D630A2-2F17-436D-834E-FFAD8FF1A6CB}: NameServer = 200.204.0.10 200.204.0.138
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Arquivos de programas\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


End of file - 5367 bytes

Could anyone help me find out what these files are? Thank you very much.

By the way, just in case it helps at all, this is whats written in the WiseData file:

[Property]
^Disk^Prompt=[ProductName] [1]
^Costing^Complete=1
^Upgrade^Code={0B0E0421-B2B2-4B4A-BECA-83BF924D86BD}
^Install^Mode=Typical
^R^O^O^T^D^R^I^V^E=C:
^A^C^T^I^O^N=INSTALL
^Preselected=1
^U^I^Level=3
^Original^Database=C:\WINDOWS\Installer\2b782f.msi
^D^A^T^A^B^A^S^E=C:\WINDOWS\Installer\2b782f.msi
^Installed=00:00:00
^U^S^E^R^N^A^M^E=Joao Carlos Ferreira de Azevedo
^Privileged=1
^Redirected^Dll^Support=2
^Msi^Win32^Assembly^Support=5.1.2600.5512
^Date=29/10/2009
^Time=10:25:31
^T^T^C^Support=1
^Color^Bits=32
^Text^Height=16
^Border^Side=1
^Border^Top=1
^Caption^Height=26
^Screen^Y=768
^Screen^X=1024
^System^Language^I^D=1046
^Computer^Name=JOAO-PC
^User^Language^I^D=1046
^User^S^I^D=S-1-5-21-527237240-2147039177-1801674531-1003
^Logon^User=Joao
^Admin^User=1
^Virtual^Memory=4359
^Physical^Memory=3071
^Product^Code={048298C9-A4D3-490B-9FF9-AB023A9238F3}
^Steam=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Steam
^Product^Name=Steam
^Product^Version=1.0.0.0
^Manufacturer=Valve Corporation
^Wise^Debug^Mode=0
^Error^Dialog=ErrorDialog
^Accept=No
^Reinstall^File^Older^Version=o
^Reinstall^Repair=r
^R^A^T^E
^S^E^T^T^I^N^G=10000
^A^R^P^C^O^M^M^E^N^T^S=Steam
^A^P^P^S_^T^E^S^T=1
^I^N^S^T^A^L^L^L^E^V^E^L=3
^Reinstall^File^Version=o
^Wise^Init^Suffix=Wizard…
^Application^Users=AllUsers
^Wise^Init^Admin^Error=You must have administrator rights to run this installation. Please login as an administrator and re-run this installation.
^Wise^Init^Exist^Error=%s Version %s is already installed. You must uninstall the existing version before installing %s Version %s. Do you want to uninstall the existing version of %s?
^A^R^P^N^O^M^O^D^I^F^Y=1
^Product^Language=1033
^P^A^L^M^U^S^E^R^S=0
_^Wise^Dialog^Title^Font^Default={\MS_Sans_Serif_81}
^Wise^Init^Space^Error=Could not create temporary file, not enough free temporary disk space. Please free up disk space and rerun this installation.
_^Wise^Dialog^Font^Default={\MS_Sans_Serif_80}
^A^R^P^H^E^L^P^L^I^N^K=http://support.steampowered.com/
^Wise^C^R^L^F=

^Wise^Dialog^Suffix=Setup
^Wise^Init^Prefix=Initializing
^Maintenance^Mode=Remove
^Wise^Init^Lang^Default=English,1033
^Default^U^I^Font=Arial10
^A^R^P^U^R^L^I^N^F^O^A^B^O^U^T=http://www.steampowered.com/
^A^G^E
^V^E^R^I^F^I^C^A^T^I^O^N=Yes
^I^N^S^T^A^L^L^D^I^R=C:\Arquivos de programas\Steam
^P^R^I^M^A^R^Y^F^O^L^D^E^R=INSTALLDIR
^Wise^Lang^Encode=1
^Msi^Hidden^Properties=WISE_SQL_CONN_STR
^Repository^I^D={CAFFD32C-FF68-46EC-AA73-35889A5969CF}
^P^I^D^Template=12345<###-%%%%%%%>@@@@@
^G^A^M^E^N^A^M^E=Steam
^Wise^Remove^Firewall=0
^Wise^Set^Firewall=0
^S^H^O^W^L^A^N^G^U^A^G^E^S=0
^G^U^I^M^O^D^E=normal
^I^N^S^T^A^L^L^P^A^T^H_^F^A^I^L^E^D_^R^E^A^S^O^N=OK
^R^E^Q^U^I^R^E^D^S^I^Z^E=50000
^T^I^T^L^E=Steam
^Product^I^D=1
^S^T^E^A^M^S^T^A^R^T^P^A^R^A^M=
^R^E^I^N^S^T^A^L^L^M^O^D^E=amus
^R^E^M^O^V^E_^A^L^L=0
^L^A^N^G^U^A^G^E=unknown
^Secure^Custom^Properties=INSTALLDIR;AGE_VERIFICATION;REMOVE_ALL;REINSTALLMODE
^A^P^P^I^D=0
^T^A^R^G^E^T^D^I^R=C:
^Start^Menu^Folder=C:\Documents and Settings\All Users\Menu Iniciar
^Program^Menu^Folder=C:\Documents and Settings\All Users\Menu Iniciar\Programas
^Program^Files^Folder=C:\Arquivos de programas
^Windows^Folder=C:\WINDOWS
^System16^Folder=C:\WINDOWS\system
^Profiles^Folder=C:\WINDOWS
^Send^To^Folder=C:\Documents and Settings\Joao\SendTo
^G^A^C=C:
^Admin^Tools^Folder=C:\Documents and Settings\All Users\Menu iniciar\Programas\Ferramentas administrativas
^W^W^W^R^O^O^T=C:
^Startup^Folder=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar
^App^Data^Folder=C:\Documents and Settings\Joao\Dados de aplicativos
^Common^Files^Folder=C:\Arquivos de programas\Arquivos comuns
^Common^App^Data^Folder=C:\Documents and Settings\All Users\Dados de aplicativos
^Win^Sx^S=C:\WINDOWS
^Local^App^Data^Folder=C:\Documents and Settings\Joao\Configurações locais\Dados de aplicativos
^Net^Hood^Folder=C:\Documents and Settings\Joao\Ambiente de rede
^System^Folder=C:\WINDOWS\system32
^Template^Folder=C:\Documents and Settings\All Users\Modelos
^My^Pictures^Folder=C:\Documents and Settings\Joao\Meus documentos\Minhas imagens
^Personal^Folder=C:\Documents and Settings\Joao\Meus documentos
^Steam^Apps=C:\Arquivos de programas\Steam\SteamApps
^Desktop^Folder=C:\Documents and Settings\All Users\Desktop
^Print^Hood^Folder=C:\Documents and Settings\Joao\Ambiente de impressão
^Temp^Folder=C:\DOCUME~1\Joao\CONFIG~1\Temp
^Favorites^Folder=C:\Documents and Settings\Joao\Favoritos
^Recent^Folder=C:\Documents and Settings\Joao\Recent
^Public=C:\Arquivos de programas\Steam\Public
^Fonts^Folder=C:\WINDOWS\Fonts
^Uninstall=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Steam\Uninstall
bin=C:\Arquivos de programas\Steam\bin
games=C:\Arquivos de programas\Steam\Steam\games
^Steam2=C:\Arquivos de programas\Steam\Steam
^Version^N^T=501
^A^L^L^U^S^E^R^S=1
^Intel=6
^Shell^Advt^Support=1
^O^L^E^Advt^Support=1
^G^P^T^Support=1
^Remote^Admin^T^S=1
^Windows^Volume=C:
^Msi^N^T^Product^Type=1
^Service^Pack^Level^Minor=0
^Service^Pack^Level=3
^Windows^Build=2600
^Version^Msi=3.01
^Version^Database=200
^P^R^O^D^U^C^T^L^A^N^G^U^A^G^E=1033
^C^L^I^E^N^T^P^R^O^C^E^S^S^I^D=3688
^C^L^I^E^N^T^U^I^L^E^V^E^L=2
^C^U^R^R^E^N^T^D^I^R^E^C^T^O^R^Y=C:\Documents and Settings\Joao
^R^E^M^O^V^E=ALL
^Product^To^Be^Registered=1
^Product^State=5
^Package^Code={524477CC-C44B-45C9-9FBB-7BD0D1FA399F}
^Out^Of^Disk^Space=0
^Out^Of^No^Rb^Disk^Space=0
^Primary^Volume^Space^Available=609875056
^Primary^Volume^Space^Required=-7560
^Primary^Volume^Space^Remaining=609882616
^Primary^Volume^Path=C:
[Directory]
Steam=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Steam
INSTALLDIR=C:\Arquivos de programas\Steam
TARGETDIR=C:
StartMenuFolder=C:\Documents and Settings\All Users\Menu Iniciar
ProgramMenuFolder=C:\Documents and Settings\All Users\Menu Iniciar\Programas
ProgramFilesFolder=C:\Arquivos de programas
WindowsFolder=C:\WINDOWS
System16Folder=C:\WINDOWS\system
ProfilesFolder=C:\WINDOWS
SendToFolder=C:\Documents and Settings\Joao\SendTo
GAC=C:
AdminToolsFolder=C:\Documents and Settings\All Users\Menu iniciar\Programas\Ferramentas administrativas
WWWROOT=C:
StartupFolder=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar
AppDataFolder=C:\Documents and Settings\Joao\Dados de aplicativos
CommonFilesFolder=C:\Arquivos de programas\Arquivos comuns
CommonAppDataFolder=C:\Documents and Settings\All Users\Dados de aplicativos
WinSxS=C:\WINDOWS
LocalAppDataFolder=C:\Documents and Settings\Joao\Configurações locais\Dados de aplicativos
NetHoodFolder=C:\Documents and Settings\Joao\Ambiente de rede
SystemFolder=C:\WINDOWS\system32
TemplateFolder=C:\Documents and Settings\All Users\Modelos
MyPicturesFolder=C:\Documents and Settings\Joao\Meus documentos\Minhas imagens
PersonalFolder=C:\Documents and Settings\Joao\Meus documentos
SteamApps=C:\Arquivos de programas\Steam\SteamApps
DesktopFolder=C:\Documents and Settings\All Users\Desktop
PrintHoodFolder=C:\Documents and Settings\Joao\Ambiente de impressão
TempFolder=C:\DOCUME~1\Joao\CONFIG~1\Temp
FavoritesFolder=C:\Documents and Settings\Joao\Favoritos
RecentFolder=C:\Documents and Settings\Joao\Recent
Public=C:\Arquivos de programas\Steam\Public
FontsFolder=C:\WINDOWS\Fonts
Uninstall=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Steam\Uninstall
bin=C:\Arquivos de programas\Steam\bin
games=C:\Arquivos de programas\Steam\Steam\games
Steam2=C:\Arquivos de programas\Steam\Steam\

Hi Jao,

The HJT logfile is clean. As far as the wisecustomcalla.dll is concerned, it is quite possible i.m.o. that this and WiseCustomCalla6.dll, and a configurations notepad file named WiseData are left-overs of a temporary setup files from a progam that was installed from a package built using the “Wise” installer. The fact that the containing folder is named:
" 048298C9A4D3490B9FF9AB023A9238F3.TMP "
is a reasonable indicator of this possibilty which is more than a hunch.
Quite often a setup package contains separate resources for many languages that you choose during setup. If written properly, the installer process should only unpack files used to install the program in that language, however badly written setup packages, or ones where the normal process is overridden to customise setup behaviour (eg. a “silent install” version) can often unpack ALL the resources and forgetto clean up the left-over files after the setup completes.

Normally a setup package uses standard language ID codes like 049 for English, but that is not a hard and fast rule.and "“WiseCustomCalla6-dll.TXT” and upload them here as attachments.

I wonder whether it might be possible for you to rename one of the DLL files and *.exe files by changing their names to eg. “WiseCustomCalla6-dll.TXT” and “WiseCustomCalla-dll.TXT”
I would be curious to inspect one of the 30Kb DLLs, one of the 109Kb DLLs, for more info.

This could be this until so far undecided generic malware find:
http://www.threatexpert.com/report.aspx?md5=1a8414c12643b3d3f5e79423322af75d

Upload the file(s) to virustotals and see what scanners flag it there,

polonus

none of them were identified as malicious by virus total… I actually deleted the folder, only put a copy in avast’s quarantine, and it didnt show again or anything…

You think that could be a steam game i started downloading but never finished? Thats my best guess…

sorry not familiarized with attaching stuff here, both were too big for the same post so one is attached in the previous and now the other one as .txt:

by the way, i searched my system for the folders and processes listed on that threat expert link, none were found, the only things that match are: the two dll files names and the .tmp folder created in c:\WINDOWS; svchost’s size is normal (14KB, in system32, doesnt say it has been modified)

Hi Jao,

This will be interesting to have a look at for the avast people that come here. I think your conclusion is right, and you can easily delete the temporal files in question. I think you were not threatened in the first place, this was just additional crap of the wise installer and nothing by far like some Bifrost malware code. It came with a steam upgrade. Just “let this bit of steam off and vaporize” ;D and you’re good to go.

On the other hand I think that by questioning everything and analyzing all you detect you are a responsible computer user, we should have more like you here, thanks for reporting,

Stay safe and secure is the wish of,
your avast forum anti-malware friend,

polonus

Thank you very much :slight_smile: I hate being paranoid like this lol, but everytime i see something that i find fishy i run for help! i googled alot more about this issue and actually i dont think theres anything wrong… a trojan wouldnt let me delete its files right? Ive also sent some steam files that sometimes get infected to virustotal and theyre all ok. Besides, nothign changed in the HJT log so there couldnt be anything wrong right?

Ho Jao.

I second your conclusion,

polonus

I have the exact folder, but I have a different problem:

My steam was working fine this morning, but I went out for lunch comeback and find out I can’t turn steam on.
So I try uninstalling/re-installing and I get:

048298C9A4D3490B9FF9AB023A9238F3.TMP/WiseCustomCalla.dll cannot be found.

So, I lookup for the file (full, including hidden folders) and couldn’t find the file OR the folder. And the problem is that I haven’t installed anything in the meantime. I did some research and found out that this file is normally created by Mcafee.

I’ve never installed mcafee.
Only Kaspersky.

So, May I receive some help?

Very appreciated.

Hi UltimateKami,

This has to do with the installer that is Wise, it is being used for more programs. Do you try to uninstall/install with a different installer? Get it here: http://www.wise.com/Products/Installations/WiseInstallerEvaluations.aspx and take the file you apparently need from the evaluation program,

polonus

Ok, so I installed Wise and now what must I do to check or fix the problem?