Unsolved

This post is more than 5 years old

4 Posts

41106

January 15th, 2011 17:00

Dell's DSUPDATE.exe from http://dds1.ddsupdate1.com/ identified as a Trojan virus by Norton

Hi,

Shortly after I purchased the upgrade for Alien Respawn backup software, Norton displayed a warning that a virus has been detected.

Norton claims that the file DSUPDATE.exe, downloaded from http://dds1.ddsupdate1.com/000366/ARUpdate/DSUpdate.ts3 , is a TROJAN.GEN virus.

What is this application used for?

Is the DELL site distributing infected files?

Is Norton wrong?

Below is the entry from the Norton scan log.

-------------------------------------------------------------------------------------------------------------------------------------
c:\program files (x86)\alienrespawn\components\dsupdate\dsupdate.exe
____________________________
____________________________
On computer as of
12/11/2010 at 7:45:42 PM
Last Used:
1/12/2011 at 9:04:17 PM
Startup Item: No
Launched: No
____________________________
____________________________
Many Users
Thousands of users in the Norton Community have used this file.
____________________________
High
This file risk is high.
____________________________
Threat Details
Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
____________________________
Origin

Downloaded from  http://dds1.ddsupdate1.com/000366/ARUpdate/DSUpdate.ts3
____________________________
http://dds1.ddsupdate1.com/000366/ARUpdate/DSUpdate.ts3
SAFE

Downloaded File:
dsupdate.ts3File Created:
dsupdate.exe
____________________________
File Actions
File: \device\harddiskvolumeshadowcopy9\program files (x86)\alienrespawn\components\dsupdate\dsupdate.exe
No fix attempted
File: c:\program files (x86)\alienrespawn\components\dsupdate\dsupdate.exe
Removed
____________________________
File Thumbprint:
Not Available
____________________________

I hope somebody can help me.  I am worried and somewhat annoyed that software I just purchased cannot be fully installed.

Thanks,

scuba-geek

4 Apprentice

 • 

20.5K Posts

January 15th, 2011 18:00

Hi scuba-geek,

Is the DELL site distributing infected files?
Most likely no.

Is Norton wrong?
Possibly unless you have malware that has corrupted that file.

Yes, it seems that many people are having issues with Norton finding that.
It might be helpful to upload the file for some opinions from other vendors.
Please submit a sample of this file:
c:\program files (x86)\alienrespawn\components\dsupdate\dsupdate.exe

to Virus Total –  http://www.virustotal.com/


At the top of the page you will see:
Select file>Browse>Send
Just follow the prompts.
The submission will then be tested against many different AV vendors’ scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.

Feel free to post your Virus Total report here if you like.

4 Posts

January 16th, 2011 13:00

Hi Bugbatter,

I cannot upload the file from my disk because Norton keeps deleting it.

I was able to submit the URL to Virus Total. Here is the report.

Antivirus

Version

Last update

Result

AhnLab-V3

2011.01.16.00

2011.01.16

Trojan/Win32.Inject

AntiVir

7.11.1.146

2011.01.16

-

Antiy-AVL

2.0.3.7

2011.01.16

Trojan/Win32.Inject.gen

Avast

4.8.1351.0

2011.01.16

-

Avast5

5.0.677.0

2011.01.16

-

AVG

10.0.0.1190

2011.01.16

-

BitDefender

7.2

2011.01.16

Trojan.Generic.KDV.48624

CAT-QuickHeal

11.00

2011.01.15

Trojan.Inject.avng

ClamAV

0.96.4.0

2011.01.16

-

Command

5.2.11.5

2011.01.16

-

Comodo

7411

2011.01.16

-

DrWeb

5.0.2.03300

2011.01.16

-

Emsisoft

5.1.0.1

2011.01.15

Trojan.Win32.Inject!IK

eSafe

7.0.17.0

2011.01.13

-

eTrust-Vet

36.1.8100

2011.01.14

-

F-Prot

4.6.2.117

2011.01.16

-

F-Secure

9.0.16160.0

2011.01.16

Trojan.Generic.KDV.48624

Fortinet

4.2.254.0

2011.01.16

W32/Inject.AVNG!tr

GData

21

2011.01.16

Trojan.Generic.KDV.48624

Ikarus

T3.1.1.97.0

2011.01.16

Trojan.Win32.Inject

Jiangmin

13.0.900

2011.01.16

Trojan/Inject.mnm

K7AntiVirus

9.75.3548

2011.01.14

-

Kaspersky

7.0.0.125

2011.01.16

Trojan.Win32.Inject.avng

McAfee

5.400.0.1158

2011.01.16

Generic.dx!vdf

McAfee-GW-Edition

2010.1C

2011.01.16

Generic.dx!vdf

Microsoft

1.6402

2011.01.16

-

NOD32

5792

2011.01.16

-

Norman

6.06.12

2011.01.16

-

nProtect

2011-01-16.01

2011.01.16

Trojan/W32.Inject_Packed.750592

Panda

10.0.2.7

2011.01.16

-

PCTools

7.0.3.5

2011.01.16

Trojan.Gen

Prevx

3.0

2011.01.16

-

Rising

22.82.05.00

2011.01.15

-

Sophos

4.61.0

2011.01.16

-

SUPERAntiSpyware

4.40.0.1006

2011.01.16

-

Symantec

20101.3.0.103

2011.01.16

Trojan.Gen

TheHacker

6.7.0.1.115

2011.01.14

Trojan/Inject.avng

TrendMicro

9.120.0.1004

2011.01.16

-

TrendMicro-HouseCall

9.120.0.1004

2011.01.16

-

VBA32

3.12.14.2

2011.01.14

Trojan.Inject.avng

VIPRE

8090

2011.01.16

Trojan.Win32.Generic!BT

ViRobot

2011.1.15.4256

2011.01.16

-

VirusBuster

13.6.149.0

2011.01.16

Trojan.Inject!7N9YRiWobng

MD5   : 965827fe54a3a0cd7d53713f670ace0a
SHA1  : 041dbac84678150904716ff8f2578d9a73ea9284
SHA256: 216f95c08a99edce99df4a6b836500bbc629a0f14cea3ac2e09b732e61457a64

 

 

 

4 Apprentice

 • 

20.5K Posts

January 16th, 2011 15:00

I'll ask one of the Dell Liaison's to look into this and reply in this topic.

4 Apprentice

 • 

20.5K Posts

January 17th, 2011 12:00

Please take the file out of quarantine. Disable Norton and go directly to HERE. Submit that file and follow the prompts. Please post your report. Thanks.

Don't forget to enable Norton when you are finished.

4 Posts

January 17th, 2011 13:00

Please take the file out of quarantine. Disable Norton and go directly to HERE. Submit that file and follow the prompts. Please post your report. Thanks.

Don't forget to enable Norton when you are finished.

 

Hi Bugbatter,

I performed the steps above. Here is the report;

VirSCAN.org Scanned Report :
Scanned time   : 2011/01/17 13:41:31 (PST)
Scanner results: 43% Scanner(s) (15/35) found malware!
File Name      : dsupdate.exe
File Size      : 750592 byte
File Type      : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5            : 965827fe54a3a0cd7d53713f670ace0a
SHA1           : 041dbac84678150904716ff8f2578d9a73ea9284
Online report  : http://virscan.org/report/9e48bad8bb8301f07a88f4ec7e05c662.html

Scanner        Engine Ver      Sig Ver           Sig Date    Time   Scan result
a-squared      5.1.0.2         20110118002000    2011-01-18  5.19   Trojan.Win32.Inject!IK
AhnLab V3      2011.01.11.00   2011.01.11        2011-01-11  1.54   -
AntiVir        8.2.4.134       7.11.0.248        2010-12-31  0.31   -
Antiy          2.0.18          20101228.6954489  2010-12-28  0.02   -
Arcavir        2010            201101180506      2011-01-18  0.39   -
Authentium     5.1.1           201101171726      2011-01-17  1.69   -
AVAST!         4.7.4           110117-1          2011-01-17  0.19   -
AVG            8.5.850         271.1.1/3386      2011-01-17  1.64   -
BitDefender    7.90123.6659484 7.35758           2011-01-18  6.07   Trojan.Generic.KDV.48624
ClamAV         0.96.5          12535             2011-01-18  0.67   -
Comodo         4.0             7422              2011-01-17  2.52   -
CP Secure      1.3.0.5         2011.01.17        2011-01-17  0.56   -
Dr.Web         5.0.2.3300      2011.01.18        2011-01-18  11.47  -
F-Prot         4.4.4.56        20110117          2011-01-17  1.66   -
F-Secure       7.02.73807      2011.01.17.06     2011-01-17  5.03   Trojan.Win32.Inject.avng [AVP]
Fortinet       4.2.254         12.805            2011-01-17  0.18   W32/Inject.AVNG!tr
GData          21.1582/21.624  20110117          2011-01-17  8.28   Trojan.Win32.Inject.avng [Engine:A]
ViRobot        20110117        2011.01.17        2011-01-17  0.36   -
Ikarus         T3.1.32.15.0    2011.01.17.77548  2011-01-17  5.00   Trojan.Win32.Inject
JiangMin       13.0.900        2011.01.17        2011-01-17  1.61   Trojan/Inject.mnm
Kaspersky      5.5.10          2011.01.17        2011-01-17  0.12   Trojan.Win32.Inject.avng
KingSoft       2009.2.5.15     2011.1.17.18      2011-01-17  0.86   -
McAfee         5400.1158       6229              2011-01-17  18.54  Generic.dx!vdf
Microsoft      1.6402          2011.01.17        2011-01-17  7.28   -
Norman         6.06.12         6.06.00           2011-01-16  16.01  -
Panda          9.05.01         2011.01.17        2011-01-17  1.89   -
Trend Micro    9.200-1012      7.774.13          2011-01-17  0.71   -
Quick Heal     11.00           2011.01.17        2011-01-17  0.90   Trojan.Inject.avng
Rising         20.0            22.83.00.03       2011-01-17  2.96   -
Sophos         3.15.0          4.61              2011-01-18  3.53   -
Sunbelt        3.9.2464.2      8103              2011-01-17  0.72   Trojan.Win32.Generic!BT
Symantec       1.3.0.24        20110116.003      2011-01-16  0.07   Trojan.Gen
nProtect       20110116.01     9619968           2011-01-16  16.14  Trojan/W32.Inject_Packed.750592
The Hacker     6.7.0.1         v00115            2011-01-14  0.56   Trojan/Inject.avng
VBA32          3.12.14.2       20110116.1511     2011-01-16  3.32   Trojan.Inject.avng

4 Apprentice

 • 

20.5K Posts

January 17th, 2011 16:00

Thanks. I'm looking into it.

17 Posts

January 17th, 2011 21:00

I have submitted this file to Norton....Symantec Endpoint Protection finally after uninstalling AlienRespawn and reinstalling it so I could get the file out of Quarantine.  I did the false positive report and submitted the file and I finally received and email back tonight saying that the file is safe and they will update their virus definitions to leave it out in an upcoming update.  At first it was quarantining DSUpdate.exe, but now its quarantining DSUpdate.ts3.  This all started from updated virus definitions from Friday the 14th, had no issues before then.  I did get an updated virus definition about an hour after I received the email, and that is when it left the .exe file alone and went for the ts3.  Hopefully that is not Norton/Symantecs fix.

4 Apprentice

 • 

20.5K Posts

January 18th, 2011 04:00

Thanks for the info.

4 Posts

January 18th, 2011 23:00

Thanks Ravenwjf,

Norton appears to have corrected the problem.  As you pointed out, the DSUpdate,exe is no longer in quarantine.

Bugbatter, thanks for your patience and your kind assitance.

1 Message

January 20th, 2011 11:00

It is not only Norton that is flagging this file.  I use AVG Internet Security at it's most recent update level and it flagged this file as containing a trojan yesterday.

0 events found

No Events found!

Top