Jump to content

Recommended Posts

Posted

Hi there!

I just  got a warning when trying to update Stream Elements about a trojan, I think it might be a false positive but wanted to double check.

Im currently on Windows 10, version 22h2.
With Kaspersky Security Cloud version 21.3.10.391

Virus.PNG

Posted

Welcome to Kaspersky Community.

 

1st of all, I would update Your KSCloud 21.3, it's getting obsolete, current version is 21.21:

 

 

Your KSCloud license will activate the new Kaspersky Plus.

 

Where can I download that detected exe?

  • Like 1
Posted

Thanks for the info, I have already updated the version.

In regards of the exe, it is a plugin for OBS used for multistreaming, this specific exe is only used when updating the plugin, so my guess is that installing OBS and then the plugin should also install the update.exe?

  • Like 1
Posted

Yeah, that's how I got it, I dont think you can get it independently 

  • Like 1
Posted

Ok, what version of OSB do You have installed?

Posted

For OBS I have the 31.0.1, and for StreamElements I have the 25.6.19.485, they are both older versions since I had not opened it in a while, and updating them is what caused the alarm to pop up

  • Like 1
Posted

I've downloaded different installers of new OSB, but scanning them on demand, I can't get any detection:

 

image.thumb.png.8bf0b2d3dadbb71a3054e7c4978105e5.png

Posted

I have just installed OBS 31.0.4 + the same SE plugin version:

 

image.thumb.png.400fe45db75a816db588d3b0d11388a4.png

 

No detection 🤔

  • Like 1
Posted (edited)

@TakenCOmb Could you at least post (as a text) the detected file hash from the file anti-virus reports? Example:

Screenshot_10.thumb.png.b47010508162f855cbc1bf299908400d.png

Or maybe this file is in quarantine/in the folder (path see in the report)? If yes - you may analyse it here.

Edited by AlexeyK
  • Like 2
Posted (edited)

Hi there, sorry for the late response.
 

Evento: Se detectó un objeto malicioso
Componente: Prevención de intrusiones
Descripción del resultado: Detectado
Tipo: Troyano
Nombre: Trojan-Downloader.Win32.Tovkater.dsxp
Nivel de amenaza: Alta
Ruta del objeto: C:\Users\Dylan\AppData\Roaming\obs-studio\plugin_config\obs-streamelements
Nombre del objeto: obs-streamelements-update.exe

I also tried to update it today after having my Kaspersky version updated and I still get the same flag 


Evento: Se detectó un objeto malicioso
Componente: Prevención de intrusiones
Descripción del resultado: Detectado
Tipo: Troyano
Nombre: Trojan-Downloader.Win32.Tovkater.dsxp
Nivel de amenaza: Alta
Ruta del objeto: C:\Users\Dylan\AppData\Roaming\obs-studio\plugin_config\obs-streamelements
Nombre del objeto: obs-streamelements-update.exe

 

viruspng.PNG

Edited by TakenCOmb
  • Thanks 1
Flood and Flood's wife
Posted (edited)
4 hours ago, TakenCOmb said:

Hi there, sorry for the late response.viruspng.PNG

Hello @TakenCOmb

Thank you for the information & screen-print!

  1. OPEN the Report window as BIG as possible by selecting the tiny square in the top-right-hand-corner (A)
  2. Select the Trojan alert (B)
  3. In the lower-section of the Report window, on the right-hand-side, use the arrow to scroll to the bottom of the Trojan details (C)
  4. Select & copy the MD5 information & post back please? (D)

image.thumb.png.9a5c1f4e8e352ee6ab1b7d108bd255aa.png

image.thumb.png.6ab6ce0d39c30e8fdeff4ce7f4bde94b.png

Thank you🙏
Flood🐳+🐋

Edited by Flood and Flood's wife
Added original image posted by TakenCOmb, 8th July 2025
  • Like 1
TakenCOmb
Posted

Hi there, here is the screenshot

Captura.PNG

Just realized the 2 screenshots look awful, no idea why, they are full screen, I will also send the text from there

Precisión: Exacta
Nivel de amenaza: Alta
Tipo de objeto: Archivo
Nombre del objeto: obs-streamelements-update.exe
Ruta del objeto: C:\Users\Dylan\AppData\Roaming\obs-studio\plugin_config\obs-streamelements
MD5 de un objeto: 6DED485D1954B9CA6C29F04507FDA7BD
Motivo: Bases de datos
Fecha de publicación de las bases de datos: 07/07/2025 08:28:00 p. m.

  • Thanks 1
TakenCOmb
Posted

I tought so too, KS is preventing the download, is there a way to let it through?

 

 

 

harlan4096
Posted

As I can't get that file as an update, try this:

If You have the file in Your K. Quarantine, You can disable protection temporally, Restore the file to its original source, compress it with password "infected" (without "), upload it to cloud service, and send me the link to download it.

  • Like 2
TakenCOmb
Posted

Hey there, unfortunately I can't do that, I did not quarantine the file and can no longer get it since I fixed the issue by uninstalling the old version and getting the new one, to be clear, this does not happen when downloading stream elements plugin, I was able to install the new version with no issues, this happened when I got a pop up for the update and clicked on 'update'. The stream elements update is what is getting flagged.

 

 

 

 

  • Like 2

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...