Unsolved
This post is more than 5 years old
4 Posts
0
41106
January 15th, 2011 17:00
Dell's DSUPDATE.exe from http://dds1.ddsupdate1.com/ identified as a Trojan virus by Norton
Hi,
Shortly after I purchased the upgrade for Alien Respawn backup software, Norton displayed a warning that a virus has been detected.
Norton claims that the file DSUPDATE.exe, downloaded from http://dds1.ddsupdate1.com/000366/ARUpdate/DSUpdate.ts3 , is a TROJAN.GEN virus.
What is this application used for?
Is the DELL site distributing infected files?
Is Norton wrong?
Below is the entry from the Norton scan log.
-------------------------------------------------------------------------------------------------------------------------------------
c:\program files (x86)\alienrespawn\components\dsupdate\dsupdate.exe
____________________________
____________________________
On computer as of
12/11/2010 at 7:45:42 PM
Last Used:
1/12/2011 at 9:04:17 PM
Startup Item: No
Launched: No
____________________________
____________________________
Many Users
Thousands of users in the Norton Community have used this file.
____________________________
High
This file risk is high.
____________________________
Threat Details
Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
____________________________
Origin
Downloaded from http://dds1.ddsupdate1.com/000366/ARUpdate/DSUpdate.ts3
____________________________
http://dds1.ddsupdate1.com/000366/ARUpdate/DSUpdate.ts3
SAFE
Downloaded File:
dsupdate.ts3File Created:
dsupdate.exe
____________________________
File Actions
File: \device\harddiskvolumeshadowcopy9\program files (x86)\alienrespawn\components\dsupdate\dsupdate.exe
No fix attempted
File: c:\program files (x86)\alienrespawn\components\dsupdate\dsupdate.exe
Removed
____________________________
File Thumbprint:
Not Available
____________________________
I hope somebody can help me. I am worried and somewhat annoyed that software I just purchased cannot be fully installed.
Thanks,
scuba-geek
0 events found


Bugbatter
4 Apprentice
•
20.5K Posts
0
January 15th, 2011 18:00
Hi scuba-geek,
Most likely no. Possibly unless you have malware that has corrupted that file.Yes, it seems that many people are having issues with Norton finding that.
It might be helpful to upload the file for some opinions from other vendors.
Please submit a sample of this file:
c:\program files (x86)\alienrespawn\components\dsupdate\dsupdate.exe
to Virus Total – http://www.virustotal.com/
At the top of the page you will see:
Select file>Browse>Send
Just follow the prompts.
The submission will then be tested against many different AV vendors’ scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.
Feel free to post your Virus Total report here if you like.
scuba-geek
4 Posts
0
January 16th, 2011 13:00
Hi Bugbatter,
I cannot upload the file from my disk because Norton keeps deleting it.
I was able to submit the URL to Virus Total. Here is the report.
Antivirus
Version
Last update
Result
AhnLab-V3
2011.01.16.00
2011.01.16
Trojan/Win32.Inject
AntiVir
7.11.1.146
2011.01.16
-
Antiy-AVL
2.0.3.7
2011.01.16
Trojan/Win32.Inject.gen
Avast
4.8.1351.0
2011.01.16
-
Avast5
5.0.677.0
2011.01.16
-
AVG
10.0.0.1190
2011.01.16
-
BitDefender
7.2
2011.01.16
Trojan.Generic.KDV.48624
CAT-QuickHeal
11.00
2011.01.15
Trojan.Inject.avng
ClamAV
0.96.4.0
2011.01.16
-
Command
5.2.11.5
2011.01.16
-
Comodo
7411
2011.01.16
-
DrWeb
5.0.2.03300
2011.01.16
-
Emsisoft
5.1.0.1
2011.01.15
Trojan.Win32.Inject!IK
eSafe
7.0.17.0
2011.01.13
-
eTrust-Vet
36.1.8100
2011.01.14
-
F-Prot
4.6.2.117
2011.01.16
-
F-Secure
9.0.16160.0
2011.01.16
Trojan.Generic.KDV.48624
Fortinet
4.2.254.0
2011.01.16
W32/Inject.AVNG!tr
GData
21
2011.01.16
Trojan.Generic.KDV.48624
Ikarus
T3.1.1.97.0
2011.01.16
Trojan.Win32.Inject
Jiangmin
13.0.900
2011.01.16
Trojan/Inject.mnm
K7AntiVirus
9.75.3548
2011.01.14
-
Kaspersky
7.0.0.125
2011.01.16
Trojan.Win32.Inject.avng
McAfee
5.400.0.1158
2011.01.16
Generic.dx!vdf
McAfee-GW-Edition
2010.1C
2011.01.16
Generic.dx!vdf
Microsoft
1.6402
2011.01.16
-
NOD32
5792
2011.01.16
-
Norman
6.06.12
2011.01.16
-
nProtect
2011-01-16.01
2011.01.16
Trojan/W32.Inject_Packed.750592
Panda
10.0.2.7
2011.01.16
-
PCTools
7.0.3.5
2011.01.16
Trojan.Gen
Prevx
3.0
2011.01.16
-
Rising
22.82.05.00
2011.01.15
-
Sophos
4.61.0
2011.01.16
-
SUPERAntiSpyware
4.40.0.1006
2011.01.16
-
Symantec
20101.3.0.103
2011.01.16
Trojan.Gen
TheHacker
6.7.0.1.115
2011.01.14
Trojan/Inject.avng
TrendMicro
9.120.0.1004
2011.01.16
-
TrendMicro-HouseCall
9.120.0.1004
2011.01.16
-
VBA32
3.12.14.2
2011.01.14
Trojan.Inject.avng
VIPRE
8090
2011.01.16
Trojan.Win32.Generic!BT
ViRobot
2011.1.15.4256
2011.01.16
-
VirusBuster
13.6.149.0
2011.01.16
Trojan.Inject!7N9YRiWobng
Bugbatter
4 Apprentice
•
20.5K Posts
0
January 16th, 2011 15:00
I'll ask one of the Dell Liaison's to look into this and reply in this topic.
Bugbatter
4 Apprentice
•
20.5K Posts
0
January 17th, 2011 12:00
Please take the file out of quarantine. Disable Norton and go directly to HERE. Submit that file and follow the prompts. Please post your report. Thanks.
Don't forget to enable Norton when you are finished.
scuba-geek
4 Posts
0
January 17th, 2011 13:00
Hi Bugbatter,
I performed the steps above. Here is the report;
VirSCAN.org Scanned Report :
Scanned time : 2011/01/17 13:41:31 (PST)
Scanner results: 43% Scanner(s) (15/35) found malware!
File Name : dsupdate.exe
File Size : 750592 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 965827fe54a3a0cd7d53713f670ace0a
SHA1 : 041dbac84678150904716ff8f2578d9a73ea9284
Online report : http://virscan.org/report/9e48bad8bb8301f07a88f4ec7e05c662.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.1.0.2 20110118002000 2011-01-18 5.19 Trojan.Win32.Inject!IK
AhnLab V3 2011.01.11.00 2011.01.11 2011-01-11 1.54 -
AntiVir 8.2.4.134 7.11.0.248 2010-12-31 0.31 -
Antiy 2.0.18 20101228.6954489 2010-12-28 0.02 -
Arcavir 2010 201101180506 2011-01-18 0.39 -
Authentium 5.1.1 201101171726 2011-01-17 1.69 -
AVAST! 4.7.4 110117-1 2011-01-17 0.19 -
AVG 8.5.850 271.1.1/3386 2011-01-17 1.64 -
BitDefender 7.90123.6659484 7.35758 2011-01-18 6.07 Trojan.Generic.KDV.48624
ClamAV 0.96.5 12535 2011-01-18 0.67 -
Comodo 4.0 7422 2011-01-17 2.52 -
CP Secure 1.3.0.5 2011.01.17 2011-01-17 0.56 -
Dr.Web 5.0.2.3300 2011.01.18 2011-01-18 11.47 -
F-Prot 4.4.4.56 20110117 2011-01-17 1.66 -
F-Secure 7.02.73807 2011.01.17.06 2011-01-17 5.03 Trojan.Win32.Inject.avng [AVP]
Fortinet 4.2.254 12.805 2011-01-17 0.18 W32/Inject.AVNG!tr
GData 21.1582/21.624 20110117 2011-01-17 8.28 Trojan.Win32.Inject.avng [Engine:A]
ViRobot 20110117 2011.01.17 2011-01-17 0.36 -
Ikarus T3.1.32.15.0 2011.01.17.77548 2011-01-17 5.00 Trojan.Win32.Inject
JiangMin 13.0.900 2011.01.17 2011-01-17 1.61 Trojan/Inject.mnm
Kaspersky 5.5.10 2011.01.17 2011-01-17 0.12 Trojan.Win32.Inject.avng
KingSoft 2009.2.5.15 2011.1.17.18 2011-01-17 0.86 -
McAfee 5400.1158 6229 2011-01-17 18.54 Generic.dx!vdf
Microsoft 1.6402 2011.01.17 2011-01-17 7.28 -
Norman 6.06.12 6.06.00 2011-01-16 16.01 -
Panda 9.05.01 2011.01.17 2011-01-17 1.89 -
Trend Micro 9.200-1012 7.774.13 2011-01-17 0.71 -
Quick Heal 11.00 2011.01.17 2011-01-17 0.90 Trojan.Inject.avng
Rising 20.0 22.83.00.03 2011-01-17 2.96 -
Sophos 3.15.0 4.61 2011-01-18 3.53 -
Sunbelt 3.9.2464.2 8103 2011-01-17 0.72 Trojan.Win32.Generic!BT
Symantec 1.3.0.24 20110116.003 2011-01-16 0.07 Trojan.Gen
nProtect 20110116.01 9619968 2011-01-16 16.14 Trojan/W32.Inject_Packed.750592
The Hacker 6.7.0.1 v00115 2011-01-14 0.56 Trojan/Inject.avng
VBA32 3.12.14.2 20110116.1511 2011-01-16 3.32 Trojan.Inject.avng
Bugbatter
4 Apprentice
•
20.5K Posts
0
January 17th, 2011 16:00
Thanks. I'm looking into it.
Ravenwjf
17 Posts
0
January 17th, 2011 21:00
I have submitted this file to Norton....Symantec Endpoint Protection finally after uninstalling AlienRespawn and reinstalling it so I could get the file out of Quarantine. I did the false positive report and submitted the file and I finally received and email back tonight saying that the file is safe and they will update their virus definitions to leave it out in an upcoming update. At first it was quarantining DSUpdate.exe, but now its quarantining DSUpdate.ts3. This all started from updated virus definitions from Friday the 14th, had no issues before then. I did get an updated virus definition about an hour after I received the email, and that is when it left the .exe file alone and went for the ts3. Hopefully that is not Norton/Symantecs fix.
Bugbatter
4 Apprentice
•
20.5K Posts
0
January 18th, 2011 04:00
Thanks for the info.
scuba-geek
4 Posts
0
January 18th, 2011 23:00
Thanks Ravenwjf,
Norton appears to have corrected the problem. As you pointed out, the DSUpdate,exe is no longer in quarantine.
Bugbatter, thanks for your patience and your kind assitance.
Alaparos
1 Message
0
January 20th, 2011 11:00
It is not only Norton that is flagging this file. I use AVG Internet Security at it's most recent update level and it flagged this file as containing a trojan yesterday.