New Nero update includes Worm

TheYak

Junior Member
Jan 19, 2007
8
0
0
Wanted to post this here to warn potential users.

Ahead Software recently released the newest version of its Nero burning software. This seems to be a fairly major update as the last few have had version numbers 7.5.x.x while this one updates it to 7.7.x.x.

It initially shipped with an optional Yahoo! Toolbar, while later downloads gave the option to download a package with and without it. Recently, it was changed to the Ask toolbar. With this incarnation, the Ask toolbar option was removed from the download page and the program prompts during the install instead (defaulting, of course, to enabling the toolbar).

While it's irritating to have bundleware included with software I purchased, it was easy enough to avoid installing it. What I found later, though, is a little more disturbing.

Scanning with Avira AntiVir revealed that the Nero installation files (two of the .CAB files) as well as an installed file (the Nero HD video encoder) contain a worm; specifically, the MSN IM worm Licat J. No other traces were found of the worm on my system - only in Nero. The worm propagates spyware that browser hijacks as well as capturing/sending contact info from MSN.

Now, it could be accidental, but you'd think that these things would be scanned before posting. Also, their past behavior doesn't exactly demonstrate integrity.

It's easy enough to test with the download being a Nero demo by default (thus free) as well as AntiVir Personal Edition's free download.

I checked again on a different PC with the same results - two temp files with the worm and one final installation file containing it.

So, any Nero users should be cautious with this new update, and potential Nero users might want to re-think a transition.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
It could be a "false positive" too. My Kaspersky antivirus false-positived on the official Service Pack 2 installation file direct from Microsoft. Kaspersky got it fixed. Obviously Microsoft's file is not infected.

At any rate, I'm downloading the file to see what Kaspersky, McAfee, Symantec, Live OneCare and TrendMicro make of it.
 

TheYak

Junior Member
Jan 19, 2007
8
0
0
Good point on the false positive, particularly since I'm using heuristic checking. Looking forward to see what the other AVs say.

[Edit: Didn't note all anecdotal evidence before. This was the first time in version 7 that Nero required a full uninstall / restart before installation. When installation resumed, it started prior to WinXP's process-loading. I took this as a good sign since 7.5 was slow & unstable quite often, but it'd also be a good way to bypass AV guards. Admittedly, I'm touched with paranoia, though I'm hoping it's a false positive]
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Kaspersky AntiVirus Personal 6 reported this:

detected: riskware not-a-virus:AdTool.Win32.MyWebSearch

file: C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\AQ7ZLEW0\Nero-7.7.5.1_eng_update[1].exe//Toolbar.exe


So at the minimum, there's some stupid toolbar bundled with it. Kaspersky nuked it upon arrival, so I have to download another (190MB) copy to check it with other antivirus. Details at 11...
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
McAfee command-line scanner, all options enabled: no threats found

Symantec online virus scanner: no threats found

TrendMicro HouseCall online scanner: no threats found

Microsoft Live OneCare online scanner: no threats found

F-Secure online scanner (uses Kaspersky engine): surprisingly, no threats found.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: TheYak
So, it's a false positive, or at worst over-aggressive spyware screening.
I think you're right. But it sure is annoying that they would even THINK of bundling a dasm toolbar with a product that we're paying for in the first place. Earth to Nero... this is the customer base calling...
 

bruceb

Diamond Member
Aug 20, 2004
8,874
111
106
You are correct .. Nero is starting to get lousy .. so I stick with Nero Ultra Edition 6.6.1.4
it works fine and has no bloatware with it .. I also have UltraISO and Roxio Easy CD / DVD
Media Creator 6 (roxio does not offer free updates) License for UltraISO does allow free updates
 

MustISO

Lifer
Oct 9, 1999
11,928
12
81
I'm still using NERO 6.6.0.14 and very happy with it. Sometimes the new versions are just so much crappier.
 

John

Moderator Emeritus<br>Elite Member
Oct 9, 1999
33,944
1
0
Originally posted by: MustISO
I'm still using NERO 6.6.0.14 and very happy with it. Sometimes the new versions are just so much crappier.

QFT, I still use 6.6.0.18 since it's the last version (from what I've read) that works with DVD Shrink. Until I encounter major issues I do not plan on switching to a new version anytime soon.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |