Roxio Community: Trojan Horse in Roxio Patch Download? - Roxio Community

Jump to content

Roxio Community
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Trojan Horse in Roxio Patch Download?

#1 User is offline   raytv 

  • Rookie
  • PipPip
  • Group: Members
  • Posts: 27
  • Joined: 30-August 07

Posted 06 September 2007 - 04:41 AM

Contemplating re-installing Creartor 9, I came across Roxio Knowledgebase article, "Invalid CD-Key" error when re-installing..."
Should you get this error you are directed to a patch: emc9rmv.zip. As instructed, I downloaded this to my desktop.
Having not decided if I am going to re-install, it sat there overnight.
This morning, my virus program auto-ran a scan and came up with this:
File: emc9rmv.zip; Result\Infection: Trojan horse Startpage.BLK; Path:Docs & Settings\my name\Desktop\emc9rmv.zip.

My virus program "healed" this item and removed it from my desktop.

What in the world is going on? How did this happen? Anything I did or didn't do?
Ray
0

#2 User is offline   ggrussell 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 15,581
  • Joined: 04-January 06
  • Gender:Male

Posted 06 September 2007 - 04:51 AM

Which Anitvirus? AVG has been finding false positives lately. If you update AVG, it goes away.
Phenom X4 965 3.4Ghz, 4gig DDR3, LG 47" 3D TV, Hitachi 1TB HD, Seagate 500GB, LiteOn iHBS112 Bluray, TSSTCorp SH-222A DVD, ATI HD3300 IGP, VIA HiDef audio with Logitech Z5500 THX certified 5.1 speakers, Epson 4490 scanner, Canon 9000Pro MarkII printer, Sharp AL1551CS laser printer/copier, Sony TRV740 8mm digital, Canon HV20 HDV camcorder and Fuji S7000 for still photos, Win7 Home Premium
---------
System 2: HP DV7 laptop, Turion II Dual Core 2.4Ghz, 4GB RAM, 640GB hard drive, ATI Mobility HD4650, ATI HiDef Audio, Windows 7 Home Premium 64bit.

Gary Russell
TNUSA
0

#3 User is offline   gi7omy 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Digital Guru
  • Posts: 16,915
  • Joined: 10-February 06
  • Gender:Male
  • Location:Belfast, Ireland

Posted 06 September 2007 - 05:01 AM

Actually in this case it alters a registry setting and all AV programs flag it as a 'generic Trojan' because that's how a Trojan operates

You need to disable the A/V for a few moments while you download and install the patch - it's NOT a Trojan despite what the AV may say
If it ain't broke, fiddle with it until it breaks, then fiddle with it until you get it fixed

"Rincewind could scream for mercy in nineteen languages and just scream in another forty-four "

"If computers get too powerful, we can organize them into a committee; that will do them in."

“Computers have enabled people to make more mistakes faster than almost any invention in history, with the possible exception of tequila and hand guns.” — Mitch Ratcliffe


Daithi

Home Brew computer
Intel I7 950 on Gigabyte X58A UD3R mobo
12 GB Three Channel DDRAM
Radeon HD4850 512 MB GDR3 graphics
Signalink USB Audio Codec for ham radio connection
1 x 160 GB, 1 x 330 GB, 1 x 400 GB IDE drives
4 x 250 GB SATA 2
LG HL-DT-ST GGW-H20L BD-RE drive
22" Acer P223W monitor


EMC 7.5 on Windows XP 32 SP3
EMC10 on Windows XP64 SP2
Creator 2011 on Windows 7 Ultimate
ECD6 on Gentoo Linux (running under VMWare)
0

#4 User is offline   raytv 

  • Rookie
  • PipPip
  • Group: Members
  • Posts: 27
  • Joined: 30-August 07

Posted 06 September 2007 - 05:16 AM

QUOTE (ggrussell @ Sep 6 2007, 04:51 AM) <{POST_SNAPBACK}>
Which Anitvirus? AVG has been finding false positives lately. If you update AVG, it goes away.


Yes, AVG.
Thanks, guys. I'm relieved.
I just bought new Norton Internet Security yesterday. Time to install it.
0

#5 User is offline   sknis 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Digital Guru
  • Posts: 22,172
  • Joined: 04-January 06
  • Gender:Male

Posted 06 September 2007 - 05:23 AM

QUOTE (raytv @ Sep 6 2007, 08:16 AM) <{POST_SNAPBACK}>
Yes, AVG.
Thanks, guys. I'm relieved.
I just bought new Norton Internet Security yesterday. Time to install it.

There is a slight possibility that you may get that or another issue about "trial version" with Norton also. You might want to return it and then do some searches for other things that may work better and are less costly.
PC Windows 7 Ultimate 64bit
Velocity Micro ProMagix ©HD 60; evga x58 motherboard, Intel i7 @2.93, 6G RAM, EVGA Nvidia 560TI superclocked video card, SoundBlaster X-Fi Xtreme audio card, Buffalo external blu-ray burner; Creator 2011.

Laptop - Windows 7 Home
Dell XPS 1645, Intel I7 1,6G with overdrive ,4G RAM, 1 GB ATI Mobility Radeon HD 5730, Sound Blaster X-Fi MB Panzer, 500G hard drive.

Apple =OSX 10.5
MacBook Pro; 15.4-inch widescreen display, 2.4GHz Intel Core 2 Duo, 2GB memory, 200GB hard drive, 8x SuperDrive (DVD±R DL/DVD±RW/CD-RW), NVIDIA GeForce 8600M GT with 256MB of GDDR3 memory. ILife 08, Toast 10, Final Cut Express 4 and Photoshop 4.
0

#6 User is offline   gi7omy 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Digital Guru
  • Posts: 16,915
  • Joined: 10-February 06
  • Gender:Male
  • Location:Belfast, Ireland

Posted 06 September 2007 - 05:32 AM

NIS should be fine really (even tho I had nothing but problems with the AV in 2006 and 2007 dying on me after a week or two).

It's Norton SystemWorks (the One Button Checkup/WinDoctor) that causes the 'trial version' problem
If it ain't broke, fiddle with it until it breaks, then fiddle with it until you get it fixed

"Rincewind could scream for mercy in nineteen languages and just scream in another forty-four "

"If computers get too powerful, we can organize them into a committee; that will do them in."

“Computers have enabled people to make more mistakes faster than almost any invention in history, with the possible exception of tequila and hand guns.” — Mitch Ratcliffe


Daithi

Home Brew computer
Intel I7 950 on Gigabyte X58A UD3R mobo
12 GB Three Channel DDRAM
Radeon HD4850 512 MB GDR3 graphics
Signalink USB Audio Codec for ham radio connection
1 x 160 GB, 1 x 330 GB, 1 x 400 GB IDE drives
4 x 250 GB SATA 2
LG HL-DT-ST GGW-H20L BD-RE drive
22" Acer P223W monitor


EMC 7.5 on Windows XP 32 SP3
EMC10 on Windows XP64 SP2
Creator 2011 on Windows 7 Ultimate
ECD6 on Gentoo Linux (running under VMWare)
0

#7 User is offline   raytv 

  • Rookie
  • PipPip
  • Group: Members
  • Posts: 27
  • Joined: 30-August 07

Posted 06 September 2007 - 12:44 PM

QUOTE (gi7omy @ Sep 6 2007, 05:32 AM) <{POST_SNAPBACK}>
NIS should be fine really (even tho I had nothing but problems with the AV in 2006 and 2007 dying on me after a week or two).

It's Norton SystemWorks (the One Button Checkup/WinDoctor) that causes the 'trial version' problem



What? The trial version problem is caused by an anti-virus program?
I have seen the Knowledgebase warning of a re-install coming up as a trial version. But it doesn't say how to fix that.
0

#8 User is offline   gi7omy 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Digital Guru
  • Posts: 16,915
  • Joined: 10-February 06
  • Gender:Male
  • Location:Belfast, Ireland

Posted 06 September 2007 - 01:33 PM

No - NOT by the AV - what happens is the resgitry cleaner part of Norton WinDoctor deletes an entry in the registry causing the program to think it's a 'trial' version

There is NO, repeat NO problem using Norton Internet Security
If it ain't broke, fiddle with it until it breaks, then fiddle with it until you get it fixed

"Rincewind could scream for mercy in nineteen languages and just scream in another forty-four "

"If computers get too powerful, we can organize them into a committee; that will do them in."

“Computers have enabled people to make more mistakes faster than almost any invention in history, with the possible exception of tequila and hand guns.” — Mitch Ratcliffe


Daithi

Home Brew computer
Intel I7 950 on Gigabyte X58A UD3R mobo
12 GB Three Channel DDRAM
Radeon HD4850 512 MB GDR3 graphics
Signalink USB Audio Codec for ham radio connection
1 x 160 GB, 1 x 330 GB, 1 x 400 GB IDE drives
4 x 250 GB SATA 2
LG HL-DT-ST GGW-H20L BD-RE drive
22" Acer P223W monitor


EMC 7.5 on Windows XP 32 SP3
EMC10 on Windows XP64 SP2
Creator 2011 on Windows 7 Ultimate
ECD6 on Gentoo Linux (running under VMWare)
0

#9 User is offline   pantherburr 

  • Rookie
  • PipPip
  • Group: Members
  • Posts: 22
  • Joined: 02-September 07

Posted 07 September 2007 - 04:25 AM

QUOTE (raytv @ Sep 6 2007, 04:41 AM) <{POST_SNAPBACK}>
Contemplating re-installing Creartor 9, I came across Roxio Knowledgebase article, "Invalid CD-Key" error when re-installing..."
Should you get this error you are directed to a patch: emc9rmv.zip. As instructed, I downloaded this to my desktop.
Having not decided if I am going to re-install, it sat there overnight.
This morning, my virus program auto-ran a scan and came up with this:
File: emc9rmv.zip; Result\Infection: Trojan horse Startpage.BLK; Path:Docs & Settings\my name\Desktop\emc9rmv.zip.

My virus program "healed" this item and removed it from my desktop.

What in the world is going on? How did this happen? Anything I did or didn't do?
Ray


Funny you mention this. I got the same thing with AVG, and when I looked at it, the only thing that this 'virus-Trojan' does is change you home page.
Practice random acts of kindness

Dell Vostro 1500, t7300 2.0 GHZ Intel Core Duo
2 GB, DDR2, 667MHZ, 2 DIMM
Windows XP SP2
8X DVD +/- RW
256MB Nvidia geforce 8600m GT
160 GB HD
0

#10 User is offline   gi7omy 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Digital Guru
  • Posts: 16,915
  • Joined: 10-February 06
  • Gender:Male
  • Location:Belfast, Ireland

Posted 07 September 2007 - 04:32 AM

It's not a Trojan - honestly. What it does is to clean out registry entries left behind when you uninstall EMC9 prior to re-installing.

Because it deletes certain registry entries, almost every AV program flags it as a 'generic Trojan' because this is how Trojans behave.

To run it, you have to disable AV for the download (it only takes a very short time) and also when you run it after doing the uninstall. Once it has done its work, then turn the AV back on. (the AV will both block the download and also running it)
If it ain't broke, fiddle with it until it breaks, then fiddle with it until you get it fixed

"Rincewind could scream for mercy in nineteen languages and just scream in another forty-four "

"If computers get too powerful, we can organize them into a committee; that will do them in."

“Computers have enabled people to make more mistakes faster than almost any invention in history, with the possible exception of tequila and hand guns.” — Mitch Ratcliffe


Daithi

Home Brew computer
Intel I7 950 on Gigabyte X58A UD3R mobo
12 GB Three Channel DDRAM
Radeon HD4850 512 MB GDR3 graphics
Signalink USB Audio Codec for ham radio connection
1 x 160 GB, 1 x 330 GB, 1 x 400 GB IDE drives
4 x 250 GB SATA 2
LG HL-DT-ST GGW-H20L BD-RE drive
22" Acer P223W monitor


EMC 7.5 on Windows XP 32 SP3
EMC10 on Windows XP64 SP2
Creator 2011 on Windows 7 Ultimate
ECD6 on Gentoo Linux (running under VMWare)
0

#11 User is offline   WebDad 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 2
  • Joined: 23-August 07

Posted 07 September 2007 - 05:37 AM

I too discovered this "false negative" only yesterday. This morning AVG immediately informed me of the threat. When AVG is finished its full scan how should I handle this?

p.s. I've had nothing but grief with any flavour of Norton I've ever tried. Even including the version provided with Rogers HiSpeed Internet. blink.gif
0

#12 User is offline   gi7omy 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Digital Guru
  • Posts: 16,915
  • Joined: 10-February 06
  • Gender:Male
  • Location:Belfast, Ireland

Posted 07 September 2007 - 05:41 AM

As I said before - turn off the AV while running the file and ONLY run the file AFTER you have done the uninstall from Add/Remove programs
If it ain't broke, fiddle with it until it breaks, then fiddle with it until you get it fixed

"Rincewind could scream for mercy in nineteen languages and just scream in another forty-four "

"If computers get too powerful, we can organize them into a committee; that will do them in."

“Computers have enabled people to make more mistakes faster than almost any invention in history, with the possible exception of tequila and hand guns.” — Mitch Ratcliffe


Daithi

Home Brew computer
Intel I7 950 on Gigabyte X58A UD3R mobo
12 GB Three Channel DDRAM
Radeon HD4850 512 MB GDR3 graphics
Signalink USB Audio Codec for ham radio connection
1 x 160 GB, 1 x 330 GB, 1 x 400 GB IDE drives
4 x 250 GB SATA 2
LG HL-DT-ST GGW-H20L BD-RE drive
22" Acer P223W monitor


EMC 7.5 on Windows XP 32 SP3
EMC10 on Windows XP64 SP2
Creator 2011 on Windows 7 Ultimate
ECD6 on Gentoo Linux (running under VMWare)
0

#13 User is offline   WebDad 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 2
  • Joined: 23-August 07

Posted 07 September 2007 - 05:50 AM

Yes, yes. I understand about shutting down AVG to download the zip & install the .exe. I was really just asking (off-hand) how to handle the "false negative" after AVG finishes. i.e. Move to vault? Ignore? Something else? rolleyes.gif
0

#14 User is online   Beerman 

  • Digital Beer Guru
  • Group: Digital Guru
  • Posts: -8,434
  • Joined: 04-January 06
  • Gender:Male
  • Location:Just outside the Big Easy

Posted 07 September 2007 - 05:56 AM

QUOTE (WebDad @ Sep 7 2007, 08:50 AM) <{POST_SNAPBACK}>
Yes, yes. I understand about shutting down AVG to download the zip & install the .exe. I was really just asking (off-hand) how to handle the "false negative" after AVG finishes. i.e. Move to vault? Ignore? Something else? rolleyes.gif

Set it to ignore it and you shouldn't have to bother with it anymore. Although, when I get a major update from AVG, I find things I've ignored have to be set to ignore again.
Paul
------
Katrina survivor, current BP survivor

Custom Built ASUS M4A79T Deluxe - AMD X4-955-Corsair XMS3 8GB DDR3 Memory-XFX HD-487A-ZHFC Radeon HD 4870 1GB Vid card - Sony & Pioneer DVD Drives-HAF922 Case-1 WD 1TB, 1 Seagate 1TB and 1 Rack Drive-HVR 2250 & HDHomerun Tuners- Creative Soundblaster X-Fi Titanium- Acer H233H monitor-1 ATI DCT-W7 X64 Ultimate
#2-M4A79XTD EVO-AMD X4-925-4GB Corsair Ballistix Tracer DDR3 1600-Antec 750 PSU-Sony DVD/RW-2-1TB HD's- Zalman CNPS9700 LED heatsink-InfiniTV 4 in a Coolermaster 690 II case-W7 x64 Ultimate
0

#15 User is offline   gi7omy 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Digital Guru
  • Posts: 16,915
  • Joined: 10-February 06
  • Gender:Male
  • Location:Belfast, Ireland

Posted 07 September 2007 - 06:00 AM

You should only need to download it and run it once anyway wink.gif
If it ain't broke, fiddle with it until it breaks, then fiddle with it until you get it fixed

"Rincewind could scream for mercy in nineteen languages and just scream in another forty-four "

"If computers get too powerful, we can organize them into a committee; that will do them in."

“Computers have enabled people to make more mistakes faster than almost any invention in history, with the possible exception of tequila and hand guns.” — Mitch Ratcliffe


Daithi

Home Brew computer
Intel I7 950 on Gigabyte X58A UD3R mobo
12 GB Three Channel DDRAM
Radeon HD4850 512 MB GDR3 graphics
Signalink USB Audio Codec for ham radio connection
1 x 160 GB, 1 x 330 GB, 1 x 400 GB IDE drives
4 x 250 GB SATA 2
LG HL-DT-ST GGW-H20L BD-RE drive
22" Acer P223W monitor


EMC 7.5 on Windows XP 32 SP3
EMC10 on Windows XP64 SP2
Creator 2011 on Windows 7 Ultimate
ECD6 on Gentoo Linux (running under VMWare)
0

#16 User is offline   REDWAGON 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Digital Guru
  • Posts: 15,915
  • Joined: 04-January 06
  • Gender:Male
  • Location:Redlands, California

Posted 07 September 2007 - 10:01 AM

I have been using Symantec's Norton Internet Security programs for years now and have never had any problems. I upgraded to NIS 2007 recently (my cost from the internet was way lower than the retail version at stores BTW, ($31.34) and can be installed on up to three (3) different computers) I have installed and un-installed several differnt EMC versions and have never had any security notices or "false" security issues.

Frank...
REDWAGON

Number 1 Custom Built ASUS Intel Computer

Asus P8P67-Deluxe MB
Coolermaster CM 690 II Advanced Case
Crucial M4 128GB SATA III SSD Drive (Windows 7 Professional OS)
Intel Core i7 2600K LGA 1155 Socket
Antec True Power 750 W. PS
Asus GTX-460 Graphics
Sony Optiarc DVD/RW
Asus DRW-2014L1T DVD/RW
Western Digital 2TB Slave Drive
Cooldrives SATA Mobile Drive
Turtle Beach Montigo DDL 7.1 Sound Card
8GB-Corsair XMS3 1600C9 PC-12800
Windows 7 Pro Retail Operating System

Number 2 Custom Build ASUS Intel Computer

Asus P8P67 Deluxe MB
CoolerMaster CM-690 II Advanced Case

Intel i7-2600K LGA Socket 1155 Socket
Antec TruePower 650 Power Supply
Asus ENGTX460 DirectCU/2D/1GB DDR5 Video
Corsair Force GT 120 GB SATA 6GB/s SSD Drive
Western Digital 1TB (Black) Slave Drive
Turtle Beach Montego DDL 7.1 Sound Card
Asus DRW-24B1ST DVD/RW
Asus DRW-2014L1T DVD/RW
Cooldrive SATA II In-case Mobile Drive
SilenX IXTREMA Pro Blue LED 120mm 14dBA 72 cfm (2 each)
Microsoft 600 keyboard/Mouse
Crucial Balistic Tracer DDR3 (2 x 2GB x 2=8GB
Window 7 Ultimate 64 bit Retail Operating System

0

#17 User is offline   gi7omy 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Digital Guru
  • Posts: 16,915
  • Joined: 10-February 06
  • Gender:Male
  • Location:Belfast, Ireland

Posted 07 September 2007 - 10:11 AM

Frank, this particular problem is with emc9rmv.zip - because it deletes registry entries, it gets flagged as a Trojan wink.gif

This post has been edited by gi7omy: 07 September 2007 - 10:11 AM

If it ain't broke, fiddle with it until it breaks, then fiddle with it until you get it fixed

"Rincewind could scream for mercy in nineteen languages and just scream in another forty-four "

"If computers get too powerful, we can organize them into a committee; that will do them in."

“Computers have enabled people to make more mistakes faster than almost any invention in history, with the possible exception of tequila and hand guns.” — Mitch Ratcliffe


Daithi

Home Brew computer
Intel I7 950 on Gigabyte X58A UD3R mobo
12 GB Three Channel DDRAM
Radeon HD4850 512 MB GDR3 graphics
Signalink USB Audio Codec for ham radio connection
1 x 160 GB, 1 x 330 GB, 1 x 400 GB IDE drives
4 x 250 GB SATA 2
LG HL-DT-ST GGW-H20L BD-RE drive
22" Acer P223W monitor


EMC 7.5 on Windows XP 32 SP3
EMC10 on Windows XP64 SP2
Creator 2011 on Windows 7 Ultimate
ECD6 on Gentoo Linux (running under VMWare)
0

#18 User is offline   jeanrosenfeld 

  • Digital Guru
  • PipPipPipPipPipPip
  • Group: Digital Guru
  • Posts: 10,694
  • Joined: 04-January 06
  • Gender:Male

Posted 07 September 2007 - 01:23 PM

Norton AV also flags it: procedure is the same: disable NAV while downloading and running the app.
Dell XPS630i. Chipset: nVIDIA nForce 650i SLI. CPU: Intel Core 2 Quad Q6600 2.4 GHz. RAM: 3 GB (DDR2-800 DDR2 SDRAM). Hard drives: 2x WD25 00AAJS-75VWA 250GB SATA. Video: NVIDIA GeForce 8800 GT 512 MB. Audio: Audigy 2 (Dell OEM). DVD RW drives: Liteon iHAS234, HL-DT-ST DVD+-RW GSA-H73N. All drivers and firmware up to date.
XP Pro SP3 , IE 8, WMP 11, all updates. Creator 2011 Pro.
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users