everytime i run dss i get this..

Discuss Malware removal, techniques, trends, etc. and repairing Windows after removal.
Forum rules
1. Try to give more than you take, when possible.
2. Don't be a prick.

everytime i run dss i get this..

Postby Cc1 » Wed Aug 21, 2013 12:30 pm

Install Manager.exe (Adware Installer)

<?xml version="1.0" encoding="UTF-16"?>
<APEvent SchemaVersion="4.0.0" DefaultConfig="false" EventTypeEnum="2" TimeoutInSeconds="0" MonitorID="2003" MsgID="{E449E847-7342-4A48-A968-2DD057A9AD9A}" MonitorTypeEnum="2" RecommendScan="true" SDKVersion="6.2.5528.0" ThreatDefVersion="20734" APEventID="{FFB1F14E-56E4-4297-B8D0-8ED14D038189}" IsAllowOk="true" IsAllowAlwaysOk="true" IsBlockOk="true" IsBlockAlwaysOk="true" IsQuarantineOk="true" EventActorEnum="2" EventDateTime="2013-08-21T16:11:18" TransactionID="" RemoteClientAddress="">
<ParentProcess FilePath="C:\Windows\TEMP\is-65TM7.tmp\itdownload_stub.exe" PID="6008" FileSize="45322" MD5="" CRC8="E8DD5ED347680000" CobraPackHash="0000000000000000" KnownAsEnum="1" ThreatID="0" AddedToUserKnown="false" Company="" FileVersion="" ProductName="" ProductVersion="" Description="" Copyright=""/>
<FileMonitor FilePath="C:\Windows\temp\nso3931.tmp\InstallManager.exe" MD5="9ce52b57c6b2fbd40aa7aa4ec16c462a" CRC8="8979EF9DCF7B0000" CobraPackHash="7E0318350163504A" KnownAsEnum="2" ThreatID="4786532" Company="" FileVersion="" ProductName="" ProductVersion="" Description="" Copyright=""/>
<FinalDispositionInfo DispositionEnum="2" AuthorityEnum="2" QuarantineStatusCode="1" QID="" UserName="\\NT AUTHORITY\SYSTEM" ErrorEnum="0"/>
</APEvent>

Active Protection Event Details
Event Type 2 -- Notify
Timeout 0(s)
Monitor Source 2003 -- On File Access
Message ID {E449E847-7342-4A48-A968-2DD057A9AD9A}
Monitor Type 2 -- File
Recommend System Scan Yes
AP SDK Version 6.2.5528.0
Threat Definitions Version 20734
Event Actor Enum 2 -- Object
Event Date/Time 2013-08-21T16:11:18
Remote Client Address

Application Information
File Path C:\Windows\TEMP\is-65TM7.tmp\itdownload_stub.exe
Process ID 6008
File Size 45322(B)
CRC8 E8DD5ED347680000
Application Rating 1 -- Known Good
Added To Always Allow List No

Attempted to modify the following file
File Path C:\Windows\temp\nso3931.tmp\InstallManager.exe
MD5 9ce52b57c6b2fbd40aa7aa4ec16c462a
CRC8 8979EF9DCF7B0000
Application Rating 2 -- Known Bad
Threat ID 4786532

Action Taken
User Name \\NT AUTHORITY\SYSTEM
Action 2 -- Blocked
Reason 2 -- VIPRE Known
Cc1
 
Posts: 44
Joined: Sat Aug 17, 2013 5:42 am

Re: everytime i run dss i get this..

Postby Nick » Wed Aug 21, 2013 12:53 pm

guess that answers your question on the MyPC Backup thread, you've been infected somehow. probably the PC you have dSSMC on is infected and it's infecting all of the installers you are creating, thus installing the junk like in the other thread.
Author of d7x and other PC technician's tools. http://www.d7xTech.com

Image
User avatar
Nick
Site Admin
 
Posts: 2784
Joined: Mon Nov 19, 2012 7:54 pm

Re: everytime i run dss i get this..

Postby Cc1 » Wed Aug 21, 2013 3:04 pm

Nick wrote:guess that answers your question on the MyPC Backup thread, you've been infected somehow. probably the PC you have dSSMC on is infected and it's infecting all of the installers you are creating, thus installing the junk like in the other thread.


Hi Nick, no this is a customers system. that gets this after they run dss.
Cc1
 
Posts: 44
Joined: Sat Aug 17, 2013 5:42 am

Re: everytime i run dss i get this..

Postby Nick » Wed Aug 21, 2013 3:15 pm

...oh, so you're saying only one PC is infected and this is not happening on other systems... ok so looks like you've got some cleaning to do on one system only, I would take that as quite the relief!

Still, I'm skeptical and I would definitely do some investigation on your PC with dSSMC, because to follow up from the other thread, no I never got "MyPC Backup" or anything else mysteriously appear over a day later.
Author of d7x and other PC technician's tools. http://www.d7xTech.com

Image
User avatar
Nick
Site Admin
 
Posts: 2784
Joined: Mon Nov 19, 2012 7:54 pm

Re: everytime i run dss i get this..

Postby Cc1 » Wed Aug 21, 2013 3:20 pm

this happened on one of my office systems and 2 other customers that i know of. I have deployed 5 copys so far.
Cc1
 
Posts: 44
Joined: Sat Aug 17, 2013 5:42 am

Re: everytime i run dss i get this..

Postby Nick » Wed Aug 21, 2013 3:29 pm

moving this thread to malware removal.

Looks like you've got some work to do, namely find out where itdownload_stub.exe and InstallManager.exe are coming from. They are in temp so my bet is another executable is extracting them. It happens when you run dSS so my bet is that your copy is infected.

dSupportSuite.exe v3.1.7 is 1,871,224 bytes. Your copy is likely a version or two older but the size won't vary much beyond that with the minimal changes I've made to code recently. My suspicion is that either your dSupportSuite.exe is significantly larger than it should be, or your installer is significantly larger than it should be. My generic installer is 4,233,590 bytes but that can vary a bit depending on the size of your logos or anything else bundled in.

Still I'm skeptical of your PC with dSSMC on it, and it's also possible that you have an infected Inno Setup compiler. My Compil32.exe is 1,102,848 bytes and I think that is v5.5.3 which has been out for some time so yours should match that. I don't see a point in hashing the file as most malware just add to the file size when file is infected, only sophisticated viruses would make an attempt to conceal the extra code.
Author of d7x and other PC technician's tools. http://www.d7xTech.com

Image
User avatar
Nick
Site Admin
 
Posts: 2784
Joined: Mon Nov 19, 2012 7:54 pm

Re: everytime i run dss i get this..

Postby Cc1 » Thu Aug 22, 2013 11:21 am

hi my installer is: 3.99 MB (4,190,113 bytes) 3.1.7

My Compiler is 1.05 MB (1,102,848 bytes) - do you want to have a look at my installer file?
Cc1
 
Posts: 44
Joined: Sat Aug 17, 2013 5:42 am

Re: everytime i run dss i get this..

Postby Nick » Sat Aug 24, 2013 5:28 am

no it's probably fine. what is the size (and version) of dSupportSuite.exe on an affected computer?
Author of d7x and other PC technician's tools. http://www.d7xTech.com

Image
User avatar
Nick
Site Admin
 
Posts: 2784
Joined: Mon Nov 19, 2012 7:54 pm


Return to Malware Removal