NOD32 Found a Virus in NERO 7 This Morning

xguntherc

I Click Home To Much
Vista Guru
Hey guys, I was just going to post and see if anyone has heard of anything about Nero recently, or anything about there programs having viruses..

I've had the same Nero 7 now on 3 different computers. I got it FREE Nero 7 Premium a while back. (I don't remember why) but it is NOT illegal, it is not hacked with a keygen or something like that, that a free AV program would find as a false positive. It's just a normal Nero 7 Premium.

I've ran the same NOD32 on this computer for over a year now, with the same Nero 7 and never had a problem. but this morning I woke up to an Error, and a Virus Warning. Threat Detected in my Nero folders. something about cad/0060H795.cad or something like that.

It gave me the option to clean, and or delete. I cleaned it. But this is the first attack my current BIG RIG has ever had. So I just want to look into it to be safe.

Any info, or suggestions, or thoughs would be appreciated.

Thanks!
 

My Computer

System One

  • CPU
    Q9650 E0 4.0 GHz @1.304v
    Motherboard
    eVGA 750i FTW
    Memory
    2x2GB Corsair Dominator PC2-8500C5D
    Graphics card(s)
    eVGA/MSI GTX 260 SLI
    Sound Card
    X-Fi XtremeGamer
    Monitor(s) Displays
    Samsung T240 & 226BW
    Screen Resolution
    1920x1200 & 1680x1050
    Hard Drives
    Seagate Cuda 500GB 32mb Cache SATA 7200.(11) + 500GB Seagate Cuda External eSATA, USB, FW400
    PSU
    PC P&C 750w Silencer PSU
    Case
    CoolerMaster HAF 932 (Water-Cooled)
    Cooling
    Plenty of Fans, and a few 230mm Fans
    Mouse
    Logitech MX-518
    Keyboard
    Logitech G11
    Other Info
    ASUS 20x Optical, Bose Companion 3, ATH-AD500 Cans :), Patriot Xporter 16GB Flash Drive (Very Fast), & Sandisk Micro 8GB. Nikon D40 DSLR with 18-105mm VR & 55-200mm VR
It happened with me too when i ran a NOD 32 virus scan, it caught nero setup.exe as a virus. I confirmed it with NOD32 forums and many users said that its just a false posiive.:mad:
 

My Computer

System One

  • Manufacturer/Model
    Compaq
    CPU
    intel core 2 duo T 5550 @ 1.83 MHz
    Motherboard
    intel 965 chipset family
    Memory
    2 GB DDR 2 SD RAM @ 667 MHz
    Graphics card(s)
    On board upto 358 MB RAM
    Sound Card
    Onboard
    Monitor(s) Displays
    15"
    Hard Drives
    160 GB WDC
when was that???

I've had both on this system forever. It's just weird that NOW it decided to show something and report a threat.. idk. but I deleted it anyways. lol
 

My Computer

System One

  • CPU
    Q9650 E0 4.0 GHz @1.304v
    Motherboard
    eVGA 750i FTW
    Memory
    2x2GB Corsair Dominator PC2-8500C5D
    Graphics card(s)
    eVGA/MSI GTX 260 SLI
    Sound Card
    X-Fi XtremeGamer
    Monitor(s) Displays
    Samsung T240 & 226BW
    Screen Resolution
    1920x1200 & 1680x1050
    Hard Drives
    Seagate Cuda 500GB 32mb Cache SATA 7200.(11) + 500GB Seagate Cuda External eSATA, USB, FW400
    PSU
    PC P&C 750w Silencer PSU
    Case
    CoolerMaster HAF 932 (Water-Cooled)
    Cooling
    Plenty of Fans, and a few 230mm Fans
    Mouse
    Logitech MX-518
    Keyboard
    Logitech G11
    Other Info
    ASUS 20x Optical, Bose Companion 3, ATH-AD500 Cans :), Patriot Xporter 16GB Flash Drive (Very Fast), & Sandisk Micro 8GB. Nikon D40 DSLR with 18-105mm VR & 55-200mm VR
It was about a month ago when i removed norton and installed nod32. because of this false positive, i removed nod32 and now i m happy with avast pro.
 

My Computer

System One

  • Manufacturer/Model
    Compaq
    CPU
    intel core 2 duo T 5550 @ 1.83 MHz
    Motherboard
    intel 965 chipset family
    Memory
    2 GB DDR 2 SD RAM @ 667 MHz
    Graphics card(s)
    On board upto 358 MB RAM
    Sound Card
    Onboard
    Monitor(s) Displays
    15"
    Hard Drives
    160 GB WDC
The only experience I have had is whenever I install Nero 8 (and I recall Nero 9 does it aswell), when the installation starts and the files from Nero.exe are being extracted as you know Nero displays as percentage number as the files are extracted.

Now when that percentage reaches 98-99%, in my case, NOD32 will display a window asking me if I want to clean or delete an infiltration relating to the ASK Toolbar that Nero gives you the option to install straight after the file extraction is complete.

Personally, I don't like and never install those optional toolbars, so at this point NOD32 has placed this file into quarantine and logs, you should uncheck the ASK Toolbar option and carry on with a normal Nero installation.

Please note however, after Nero installation is complete and it asks you to restart the PC, do this, but when your system restarts, DO NOT open Nero until you go to Windows/Microsoft Updates first and check for updates and it will advise you to install the Security Update for Microsoft XML Core Services 4.0 Service Pack 2 for x64-based Systems (KB954430).

Update type: Important

A security issue has been identified in Microsoft XML Core Services (MSXML) that could allow an attacker to compromise your Windows-based system and gain control over it. You can help protect your computer by installing this update from Microsoft. After you install this item, you may have to restart your computer. Once you have installed this item, it cannot be removed.

More information:
http://go.microsoft.com/fwlink/?LinkId=128803

I should also point out that I deleted this file from NOD32 Quarantine and Log Files and immediately ran a full In-depth System scan with NOD and my system was totally clean so I cannot tell you why NOD or any other AntiVirus program recognises this ASK Toolbar thingy majig as a threat.

Regards, Neil
 
Last edited:

My Computer

System One

  • Manufacturer/Model
    Custom Built
    CPU
    Intel Core i7-920
    Motherboard
    Gigabyte GA-EX58-UD3R
    Memory
    8GB Kingston DDR3 1333MHz (4 x 2GB)
    Graphics card(s)
    Gigabyte GV-N26OC-896H-B
    Sound Card
    N/A - On Board via SPDIF
    Monitor(s) Displays
    BenQ 24" E2420HD
    Screen Resolution
    1920 x 1080p Full HD
    Hard Drives
    Western Digital 1 x TB Sata 1 x 320GB Sata
    PSU
    Zalman 1000 Watt
    Case
    Antec Twelve Hundred
    Cooling
    1 x 200mm fan, 6 x 120mm fans, CPU & GPU fan
    Mouse
    Bluetooth Logitech MX 5500 Laser
    Keyboard
    Cordless Logitech MX 5500 Revolution
    Other Info
    2 x Liteon DVD Burners Sata
awesome my smiley.. that is exactly where the file was located.. something about ASKtoolbar. something. your right.

I've never had a problem with this before. and I've installed it more than a few times. why NOD32 decided NOW to do something about it was weird. I did not Quarantine, or Clean. I deleted it.

do I need that Windows update you linked to though?
 

My Computer

System One

  • CPU
    Q9650 E0 4.0 GHz @1.304v
    Motherboard
    eVGA 750i FTW
    Memory
    2x2GB Corsair Dominator PC2-8500C5D
    Graphics card(s)
    eVGA/MSI GTX 260 SLI
    Sound Card
    X-Fi XtremeGamer
    Monitor(s) Displays
    Samsung T240 & 226BW
    Screen Resolution
    1920x1200 & 1680x1050
    Hard Drives
    Seagate Cuda 500GB 32mb Cache SATA 7200.(11) + 500GB Seagate Cuda External eSATA, USB, FW400
    PSU
    PC P&C 750w Silencer PSU
    Case
    CoolerMaster HAF 932 (Water-Cooled)
    Cooling
    Plenty of Fans, and a few 230mm Fans
    Mouse
    Logitech MX-518
    Keyboard
    Logitech G11
    Other Info
    ASUS 20x Optical, Bose Companion 3, ATH-AD500 Cans :), Patriot Xporter 16GB Flash Drive (Very Fast), & Sandisk Micro 8GB. Nikon D40 DSLR with 18-105mm VR & 55-200mm VR
Yes Xguntherc ... I said Yes Xguntherc ... get that bloom'in update my friend!!!

PS: View your Windows Update history, you might already have it.

Regards, Neil
 

My Computer

System One

  • Manufacturer/Model
    Custom Built
    CPU
    Intel Core i7-920
    Motherboard
    Gigabyte GA-EX58-UD3R
    Memory
    8GB Kingston DDR3 1333MHz (4 x 2GB)
    Graphics card(s)
    Gigabyte GV-N26OC-896H-B
    Sound Card
    N/A - On Board via SPDIF
    Monitor(s) Displays
    BenQ 24" E2420HD
    Screen Resolution
    1920 x 1080p Full HD
    Hard Drives
    Western Digital 1 x TB Sata 1 x 320GB Sata
    PSU
    Zalman 1000 Watt
    Case
    Antec Twelve Hundred
    Cooling
    1 x 200mm fan, 6 x 120mm fans, CPU & GPU fan
    Mouse
    Bluetooth Logitech MX 5500 Laser
    Keyboard
    Cordless Logitech MX 5500 Revolution
    Other Info
    2 x Liteon DVD Burners Sata
yup.. I already had that installed on 11/11/08.. the Core service pack 2.

Thanks for input though.. know anything else on the Nero thing?
 

My Computer

System One

  • CPU
    Q9650 E0 4.0 GHz @1.304v
    Motherboard
    eVGA 750i FTW
    Memory
    2x2GB Corsair Dominator PC2-8500C5D
    Graphics card(s)
    eVGA/MSI GTX 260 SLI
    Sound Card
    X-Fi XtremeGamer
    Monitor(s) Displays
    Samsung T240 & 226BW
    Screen Resolution
    1920x1200 & 1680x1050
    Hard Drives
    Seagate Cuda 500GB 32mb Cache SATA 7200.(11) + 500GB Seagate Cuda External eSATA, USB, FW400
    PSU
    PC P&C 750w Silencer PSU
    Case
    CoolerMaster HAF 932 (Water-Cooled)
    Cooling
    Plenty of Fans, and a few 230mm Fans
    Mouse
    Logitech MX-518
    Keyboard
    Logitech G11
    Other Info
    ASUS 20x Optical, Bose Companion 3, ATH-AD500 Cans :), Patriot Xporter 16GB Flash Drive (Very Fast), & Sandisk Micro 8GB. Nikon D40 DSLR with 18-105mm VR & 55-200mm VR
Yeah its true, inside the setup.exe file, NOD32 detects Ask toolbar as virus.
 

My Computer

System One

  • Manufacturer/Model
    Compaq
    CPU
    intel core 2 duo T 5550 @ 1.83 MHz
    Motherboard
    intel 965 chipset family
    Memory
    2 GB DDR 2 SD RAM @ 667 MHz
    Graphics card(s)
    On board upto 358 MB RAM
    Sound Card
    Onboard
    Monitor(s) Displays
    15"
    Hard Drives
    160 GB WDC
Cory

Please explain what you mean by do I know anything else on the Nero thing?

By the way, another program that gives you the option to install that ASK Toolbar is AusLogics Registry Defrag program, so it's best to just uncheck it.

This is what Nero's website says about the ASK Toolbar:

1) What Is The ASK toolbar?

The Ask Toolbar is a tremendously powerful and totally customizable toolbar that installs directly onto your Web browser. Its design allows you to:

  • Search the Web with Ask.com directly from your browser
  • Block annoying pop-ups automatically
  • Save pages and searches, and access them from anywhere
  • Get Direct Answers to many popular searches like dictionary lookups and stock quotes

2) Where Is The ASK Toolbar Offered?

We are currently making this offer as an optional download with the Nero packages, at the user's choice and discretion.

3) Why Is The ASK Toolbar Being Distributed From The Nero Website?

Nero is offering the Ask Toolbar for download from its website as an added bonus to Nero customers. What better way to enhance the digital lifestyle than with a handy toolbar featuring great links and editing tools?

4) Do I Have To Install The ASK Toolbar In Order To Use My Nero Applications?

No, the Ask Toolbar installation is not required for the operation of any Nero application.

5) IS THE ASK TOOLBAR SPYWARE?

No! The Ask Toolbar does not collect any personal information and is completely "spyware"-free and "adware"-free. The Ask Toolbar was specifically designed to provide a great user experience free of any type of direct marketing, data collection, or other similar activities. In fact, the Ask Toolbar further improves your web experience by removing adware such as pop-ups.

Refer to the following link for more useless information on the ASK Toolbar from Nero:

Nero - Support - FAQ - Frequently Asked Questions

Hope This Helps Cory.

Regards, Neil
 

My Computer

System One

  • Manufacturer/Model
    Custom Built
    CPU
    Intel Core i7-920
    Motherboard
    Gigabyte GA-EX58-UD3R
    Memory
    8GB Kingston DDR3 1333MHz (4 x 2GB)
    Graphics card(s)
    Gigabyte GV-N26OC-896H-B
    Sound Card
    N/A - On Board via SPDIF
    Monitor(s) Displays
    BenQ 24" E2420HD
    Screen Resolution
    1920 x 1080p Full HD
    Hard Drives
    Western Digital 1 x TB Sata 1 x 320GB Sata
    PSU
    Zalman 1000 Watt
    Case
    Antec Twelve Hundred
    Cooling
    1 x 200mm fan, 6 x 120mm fans, CPU & GPU fan
    Mouse
    Bluetooth Logitech MX 5500 Laser
    Keyboard
    Cordless Logitech MX 5500 Revolution
    Other Info
    2 x Liteon DVD Burners Sata
Thanks for taking the extra steps there to post all of that.. Rep+ to you.

I just don't understand why it's never threw a threat warning on it before.. but today decided to. maybe an update made it find it.

anyways I just uninstalled NOD 32 4.0 anyways. I recently upgraded from 3.0 security suite to 4.0 and I don't like it.. it takes up MUCH more system resources (No bueno) and it also has problems while I'm browsing the net. I get these 20 second temporary time outs and stuff that only started happening on 4.0

I'm hoping they go away now I'm back to 3.0
 

My Computer

System One

  • CPU
    Q9650 E0 4.0 GHz @1.304v
    Motherboard
    eVGA 750i FTW
    Memory
    2x2GB Corsair Dominator PC2-8500C5D
    Graphics card(s)
    eVGA/MSI GTX 260 SLI
    Sound Card
    X-Fi XtremeGamer
    Monitor(s) Displays
    Samsung T240 & 226BW
    Screen Resolution
    1920x1200 & 1680x1050
    Hard Drives
    Seagate Cuda 500GB 32mb Cache SATA 7200.(11) + 500GB Seagate Cuda External eSATA, USB, FW400
    PSU
    PC P&C 750w Silencer PSU
    Case
    CoolerMaster HAF 932 (Water-Cooled)
    Cooling
    Plenty of Fans, and a few 230mm Fans
    Mouse
    Logitech MX-518
    Keyboard
    Logitech G11
    Other Info
    ASUS 20x Optical, Bose Companion 3, ATH-AD500 Cans :), Patriot Xporter 16GB Flash Drive (Very Fast), & Sandisk Micro 8GB. Nikon D40 DSLR with 18-105mm VR & 55-200mm VR
Yeah Corey I'd be interested to see if it makes any difference for you.

Are you absolutely sure it's NOD32 4 that's slowing it down?

I've used Smart Security 4 and currently I'm using NOD32 4 and Comodo PFW, so I'd be interested to hear how you get on.

What's all that rep stuff mean anyway. What happened to the days where you just helped someone because it made you feel good and the thought of getting something back in return didn't even enter your head.

Oh well, it's a different world we live in now I guess.
 

My Computer

System One

  • Manufacturer/Model
    Custom Built
    CPU
    Intel Core i7-920
    Motherboard
    Gigabyte GA-EX58-UD3R
    Memory
    8GB Kingston DDR3 1333MHz (4 x 2GB)
    Graphics card(s)
    Gigabyte GV-N26OC-896H-B
    Sound Card
    N/A - On Board via SPDIF
    Monitor(s) Displays
    BenQ 24" E2420HD
    Screen Resolution
    1920 x 1080p Full HD
    Hard Drives
    Western Digital 1 x TB Sata 1 x 320GB Sata
    PSU
    Zalman 1000 Watt
    Case
    Antec Twelve Hundred
    Cooling
    1 x 200mm fan, 6 x 120mm fans, CPU & GPU fan
    Mouse
    Bluetooth Logitech MX 5500 Laser
    Keyboard
    Cordless Logitech MX 5500 Revolution
    Other Info
    2 x Liteon DVD Burners Sata
Back
Top