DreamMaker.dll virus/ malware ???

Trojan.Win32.Obfuscated!IK found by A Squared

Hi, I emailed this to support at stardock.com on the 11th of Dec, but other than the automated reply I have heard nothing.I was given a link in the reply to a ticket but this page just ends up being blank.  I have tried in both Firefox and IE but still no joy.

I'll copy out the email below in the hope that someone here can help as Stardock seem to have forgotten my original email.

thanks for any input

Hi, I have just recently reinstalled A squared Pro. It has come up with a listing against dreammaker.dll stating that it contains Trojan.Win32.Obfuscated!IK.  I am unsure whether A squared is giving me a false positive and would guess if it is, you would have already heard this from other subscribers.

I have submitted the file to virusscan.joti.org, virus.org and virustotal.com.  All three come back positive for the above Trojan with the Ikarus scanner, and two with positive result from A squared (virus total doesn’t check with A squared).  This isn’t too much of a surprise as A-squared have incorporated Ikarus scanning technology in to their own product.
So can you tell me if this is a real problem or a false positive?

Many thanks

16,765 views 11 replies
Reply #1 Top

Please give us your system info and a link to the manufacture of the anti-virus product in question.

Reply #2 Top

I would Imagine as you are a current customer you downloaded it from a Stardock source, and thus would be a false positive.

On occasion a part of a program can be mistakenly flagged as an Virus or other malware. Rest assured SD makes its money off of Software sales not data theft etc, so they would not build nor distribute viruses or malware..*it tends to drive customers off*

I imagine Support will talk with the proper people at the scanning CO. and get the positives sorted out..

Reply #3 Top

Hi, thanks for the replies.

@Shelbygt_the_Car

Ok system info.  Using Win Vista Ultimate 32bit.  Security software on my pc is as follows:  Kaspersky Internet Security 2009, Trojan Remover, A-Squared Anti-Malware, Spybot Search & Destroy, Malwarebytes Anti-Malware, Super Anti-Spyware and of course Windows Defender. 

The only positive result is from A-Squared.  As I have said above I have submitted the file to Virus.Org, Jotti's Online malware scan and VirusTotal. Only the Ikarus and A-Squared threw up a questionable result. A-Squared incorporates Ikarus scanning technologies. 

As for my system it's an EVGA 680i, QX6700, TT Big Typ VX, 2*2GB kit, XFX 8800GTX, Antec900, Benq FP241WZ.

@ HG_Eliminator

I imagine you are right, that it is a false positive. It's just that I have received no word from Stardock regarding this and I found this a bit unnerving.

thanks again guys for the replies.

ts

Reply #4 Top

As Stardock didn't respond either via email or this thread I have let my subscription lapse. 

Cheers

Reply #5 Top

As Stardock didn't respond either via email or this thread I have let my subscription lapse.

Stardock doesn't release viruses.  It'd be really bad form.  False positives happen.

If you ever decide to resubscribe, we'll be here.

Reply #6 Top

Quoting Zubaz, reply 5


If you ever decide to resubscribe, we'll be here.

Thanks for that.

I am not accusing Stardock of releasing viruses.

A polite email to support, a polite thread asking them whether they knew of false postivies, both were ignored.  Other than a link to a blank page (my ticket) from an automated reply I have heard nothing from Stardock. 

A reply telling me that they would look in to the false positives would have been good. A reply saying that they knew of the false positives and were dealing with the manufacturers of A Squared would have been brilliant.  A reply that they knew of a virus masquerading as this file would have been disturbing but at least I would have known what to do. Simply put a reply would have been nice.

 

As it was I was left in limbo and ignored, hence my decision not to renew my subscription.

Reply #7 Top

A polite email to support, a polite thread asking them whether they knew of false postivies, both were ignored. Other than a link to a blank page (my ticket) from an automated reply I have heard nothing from Stardock.
Can you provide me with a case # from your automated email?

+1 Loading…
Reply #8 Top

details from email I received on the 11th of December.

  Listed below are details of this Ticket.

   Ticket ID: BLQ-124062
   Subject: possible virus/ malware dreammaker.dll
   Department: Support - General
   Priority: Received
   Status: Open

 

When I log in to the page with either Firefox 3.0.5 or IE, I get a blank white page with viewticket&ticketid=179629 at the end of the url.

 

Reply #9 Top

This is a known issue with the software, and is a false positive.  Unfortunately, the same obfuscation methods we use to prevent people from decompiling our code are often used in viruses for the same reasons.  It's a common mistake made not just by A squared.  Usually this will show up as Trojan.W32.Obfuscated or Trojan.W32.Execrypter.  This is actually just the heuristic engine detecting that the file has been obfuscated.  It is by no means a threat and none of Stardock's software contains malware of any sort.  The best course of action is to update your definition files, and if the problem persists, add an exception for the app.

+1 Loading…
Reply #10 Top

Thank you both Zubaz and Shirley for replying. 

@ Zubaz, I received your pm and as I do not want to argue or antagonise the situation I will accept what you say.  That there was a database error is more preferable to being ignored.  Thank you for looking in to it for me.

@ Shirley, I understand and agree with the need for protection for your software, it is true that desirable software appears on the warez sites and I accept the protection you use.

However, accepting the above, I still find it unsettling that a known issue I was having only got a response when I wrote that I had let my subscription lapse. In the two weeks from my original post there was no response from Stardock.  Not good.

But as I said earlier, thank you for repsonding and I wish you both well.

 

Reply #11 Top

The forum post here [Dec 28] will have been displaced off the front page/recent threads by other responses so can easily go unnoticed.

Stardock Support tends to monitor the WC site forums but this is not the prime Support source.  That is via email ... [email protected] 

The prime necessity when receiving such a report as yours is to chase the 'offending' AV company for correction/update to prevent further false-positives.  Their 'getting it wrong' is the greater issue.

Also, having as many AV/spyware proggies as you list is very often a problem in itself.  Many do not 'play well' with others...;)