Steam Trojan -- False Positive (help verifying?)

Questions about Wine on Linux
Locked
bbdwy940
Newbie
Newbie
Posts: 2
Joined: Sun Dec 16, 2012 8:24 am

Steam Trojan -- False Positive (help verifying?)

Post by bbdwy940 »

Hi,

I accidentally did a clamscan on my own system (I thought I was doing it on a server I was ssh'd into), before I went to bed last night. When I woke up this morning I found two trojans. Because I had to do other stuff, I decided to just remove my $HOME/.wine directory instead as a safety precaution and deal with it later.

Well, now is later. Unfortunately due to an awful typo the results were not logged. However, after re-installing steam on a fresh wine prefix, fresh new user, proper groups, etc. (as well as my own user) both $HOME/.wine directories for both users picked up the same trojan (note: neither of these users were root).

Code: Select all

# freshclam
# clamscan -ri /home/user1/.wine
.wine/drive_c/Program Files/Steam/bin/avcodec-53.dll: Win.Trojan.5946697 FOUND

----------- SCAN SUMMARY -----------
Known viruses: 1377310
Engine version: 0.97.6
Scanned directories: 417
Scanned files: 2323
Infected files: 1
Data scanned: 210.51 MB
Data read: 185.99 MB (ratio 1.13:1)
Time: 17.146 sec (0 m 17 s)
Same results with a clamscan on user2's /home directory.

Now, before I removed my wine prefix, I found a similarly named Trojan in my Team Fortress 2 directory: $HOME/.wine/drive_c/Program\ Files/Steam/steamapps/<steam username>/team\ fortress\ 2/bin/*avcod*.dll

I don't remember the exact name (but it was a similar filename along the lines of avcodec or whatnot) in the directory I've shown, which is why I used the * wildcard in my line above.

I know Steam (and Team Fortress 2) were updated recently (as in less than a week ago from this post), so I was wondering if anybody else could also clamscan their WINEPREFIX that has Steam in it and confirm the same Trojans (on your current WINEPREFIX and another one for a new user if the new user installs only Steam)?

Otherwise I think maybe I downloaded a bad Steaminstall.msi, or the update servers for Steam were affected maliciously (crossing my fingers it's neither).
lahmbi5678
Level 7
Level 7
Posts: 823
Joined: Thu Aug 27, 2009 6:23 am

Re: Steam Trojan -- False Positive (help verifying?)

Post by lahmbi5678 »

Please upload the avcodec-53.dll to virustotal.com, maybe it's a already known false positive.
bbdwy940
Newbie
Newbie
Posts: 2
Joined: Sun Dec 16, 2012 8:24 am

Re: Steam Trojan -- False Positive (help verifying?)

Post by bbdwy940 »

Actually, I wanted to be sure which is why I'm asking others to scan their Steam directory (or at least $HOME/.wine) to see if they also come up with the same viruses.

However, ClamAV did make an update yesterday for this specific trojan, so maybe it won't get picked up as a trojan if I scan today. Will post results later.
Locked