Skip to content
This repository has been archived by the owner on Sep 21, 2021. It is now read-only.

Detected as trojan by Kaspersky Total Security, computer failing to restart #58

Open
NannoSilver opened this issue May 24, 2021 · 0 comments

Comments

@NannoSilver
Copy link

NannoSilver commented May 24, 2021

Description

Just after install dissenter-1.5.114-installer.exe at my Windows 10 x64 (and before to click 'finish" at the setup.exe final screen) the Kaspersky Total Security 21.3.10.391(b), with all updates to date (24 MAY 2021), started to show messages saying dissenter, or its components, possibly the setup.exe was showing suspicious behavior and/or trying to monitor the computer, or something similar to that, requesting to remove the software and restart the computer.

I removed dissenter manually, that was looking fine, and allowed Kaspersky to "delete/clean and restart the computer".

While Windows 10 was preparing to restart poped-up some message saying problems in a file I could not take note of the name, but had "script" in the file name (cscript.exe ?).

The restart failed, Windows could not shut-down to perform restart.
I had to turn-off the computer pressing and holding I/O button of my laptop.

New startup initiated, but failed, showing a completely dark screen.
Turned off again pressing the button.
New startup initiated, but failed again, showing just the mouse cursor over a completely dark screen.
Turned off again pressing the button.
New startup initiated, this time Windows entered in a TEMP user account, saying could not login in my usual user account.

Looking the processes running, I could find something related to dissenter update running.
I killed the process and deleted all files, that were located at
c:\program files (x86)\dissenter-1.x
I searched for other dissenter files, but could not find.

This is what I could find in Kaspersky:
Event: Object deleted
Application: Dissenter Installer
User: DESKTOP-xxxxxxxx
User type: Active user
Component: System Watcher
Result description: Deleted
Type: Trojan
Name: PDM:Trojan.Win32.Generic
Threat level: High
Object type: Process
Object path: c:\users\xxxxxxxx\appdata\local\temp\cr_e4f61.tmp
Object name: setup.exe

The dissenter-1.5.114-installer.exe was downloaded from GAB.com and has valid digital signature.
Downloaded from https://apps.gab.com/application/5d3f93a29dd49a5b1d9fc27f/resource/5e781f20d4d8d137d3a0a6e6/content

I had a bad time to recover my computer, but now everything seems fine.

Dissenter Browser is version 1.5.114, while Brave is at version 1.24.86.
Seems Dissenter is no longer maintained/tested and updated.
I think you may consider to remove all related to Dissenter from gab.com to prevent other users to have the same problem.
That can bring bad reputation to gab.com

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant