Windows Vista Forums
Vista Forums Home Join Vista Forums Tech Publications Windows 7 Forum Vista Tutorials Webcasts Tags

Welcome to Vista Forums we are your forum for Windows Vista help and discussion. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

Vista rootkit issue - all legit. software

Update your Vista Drivers
Reply
 
Thread Tools Display Modes
Old 10-02-2007   #1 (permalink)
Bob
Guest


 

Vista rootkit issue - all legit. software

Hi

I have Windows Vista Home Premium pre-installed on my new HP laptop.

Every time I go to open a folder that has audio, ripped from a CD, in .wav
format, my hard-drive goes overtime, running almost 100% constantly. System
responsiveness to a single-click is about 30 to 60 seconds. This is the
definite trigger, (the folder).

I have Norton Internet Security 2007, not my first choice of av software
installed, and I also run Windows Defender. I update regularly and run IE
with very tight security settings.

I recently purchased and installed Ashampoo Burning Studio 7, as my burning
needs are for simple document backups.

I ripped my first audio CD since I purchased today and that's when my
problems began.

I have stopped and permanently disabled the Windows Search Index service to
prevent further hard-drive activity.

I do own Sony Sound Forge Audio Studio 9.

Nothing on this laptop has been an issue since today and ripping that audio
CD into .wav. By the way, when I rip a CD, Ashampoo connects to the Internet
to collect the music CD's track and album details.

I have tried a couple of free rootkit detection app's but nothing yet. NIS
2007 is supposed to detect them...

I don't need to rip CD's normally or in future but I do want to know if I
have a rootkit and/or DRM issue on this laptop.

Wadda ya think?

Many thanks

Bob


My System SpecsSystem Spec
Old 10-02-2007   #2 (permalink)
Bob
Guest


 

Re: Vista rootkit issue - all legit. software

Thanks Mr Arnold

I have used some of that software and have found no 'rogue' processes.

I have deleted the music folder that has caused the problem. This appears to
be some kind of digital rights management issue.

To check if the burning application I used is the culprit, I'm going to try
and extract music using another program.

Thanks again.

Bob


"Mr. Arnold" <MR. Arnold@xxxxxx> wrote in message
news:ObYzaGiBIHA.4160@xxxxxx
Quote:

>
> "Bob" <bob@xxxxxx> wrote in message
> news:13g79ajr46ph120@xxxxxx
Quote:

>> Hi
>>
>> I have Windows Vista Home Premium pre-installed on my new HP laptop.
>>
>> Every time I go to open a folder that has audio, ripped from a CD, in
>> .wav format, my hard-drive goes overtime, running almost 100% constantly.
>> System responsiveness to a single-click is about 30 to 60 seconds. This
>> is the definite trigger, (the folder).
>>
>> I have Norton Internet Security 2007, not my first choice of av software
>> installed, and I also run Windows Defender. I update regularly and run IE
>> with very tight security settings.
>>
>> I recently purchased and installed Ashampoo Burning Studio 7, as my
>> burning needs are for simple document backups.
>>
>> I ripped my first audio CD since I purchased today and that's when my
>> problems began.
>>
>> I have stopped and permanently disabled the Windows Search Index service
>> to prevent further hard-drive activity.
>>
>> I do own Sony Sound Forge Audio Studio 9.
>>
>> Nothing on this laptop has been an issue since today and ripping that
>> audio CD into .wav. By the way, when I rip a CD, Ashampoo connects to the
>> Internet to collect the music CD's track and album details.
>>
>> I have tried a couple of free rootkit detection app's but nothing yet.
>> NIS 2007 is supposed to detect them...
>>
>> I don't need to rip CD's normally or in future but I do want to know if I
>> have a rootkit and/or DRM issue on this laptop.
>>
>> Wadda ya think?
>>
>> Many thanks
>
> <http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_Rootkit_Tools_in_a_Windows_Environment.html>
> <http://www.pcworld.com/downloads/file/fid,23780-order,1-page,1/description.html>
> <http://www.microsoft.com/technet/sysinternals/default.mspx>
>
> ActivePorts doesn't work on Vista, but CurrPort does.
>
> <http://www.nirsoft.net/>
>
> Also use Google to find information on how to use Process Explorer.
>
>
>
My System SpecsSystem Spec
Old 10-02-2007   #3 (permalink)
Bob
Guest


 

Re: Vista rootkit issue - all legit. software - found the problem - the burning app I was using...

My CD burning application appears to be the culprit.

I managed to extract audio from the same CD, using another application and I
can access those .wav files and the folder they're contained in just fine.

My conclusion at this point therefore is that Ashampoo Burning Studio 7.1
contains some form of digital rights management protection that is used when
extracting audio from CD's, or it activates some form of digital rights
management protection in Vista.

I'm not sure if I should keep using the software, as it may lead to other
vulnerabilites later. At this point I do plan to keep using it though.

Bob

"Mr. Arnold" <MR. Arnold@xxxxxx> wrote in message
news:ObYzaGiBIHA.4160@xxxxxx
Quote:

>
> "Bob" <bob@xxxxxx> wrote in message
> news:13g79ajr46ph120@xxxxxx
Quote:

>> Hi
>>
>> I have Windows Vista Home Premium pre-installed on my new HP laptop.
>>
>> Every time I go to open a folder that has audio, ripped from a CD, in
>> .wav format, my hard-drive goes overtime, running almost 100% constantly.
>> System responsiveness to a single-click is about 30 to 60 seconds. This
>> is the definite trigger, (the folder).
>>
>> I have Norton Internet Security 2007, not my first choice of av software
>> installed, and I also run Windows Defender. I update regularly and run IE
>> with very tight security settings.
>>
>> I recently purchased and installed Ashampoo Burning Studio 7, as my
>> burning needs are for simple document backups.
>>
>> I ripped my first audio CD since I purchased today and that's when my
>> problems began.
>>
>> I have stopped and permanently disabled the Windows Search Index service
>> to prevent further hard-drive activity.
>>
>> I do own Sony Sound Forge Audio Studio 9.
>>
>> Nothing on this laptop has been an issue since today and ripping that
>> audio CD into .wav. By the way, when I rip a CD, Ashampoo connects to the
>> Internet to collect the music CD's track and album details.
>>
>> I have tried a couple of free rootkit detection app's but nothing yet.
>> NIS 2007 is supposed to detect them...
>>
>> I don't need to rip CD's normally or in future but I do want to know if I
>> have a rootkit and/or DRM issue on this laptop.
>>
>> Wadda ya think?
>>
>> Many thanks
>
> <http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_Rootkit_Tools_in_a_Windows_Environment.html>
> <http://www.pcworld.com/downloads/file/fid,23780-order,1-page,1/description.html>
> <http://www.microsoft.com/technet/sysinternals/default.mspx>
>
> ActivePorts doesn't work on Vista, but CurrPort does.
>
> <http://www.nirsoft.net/>
>
> Also use Google to find information on how to use Process Explorer.
>
>
>
My System SpecsSystem Spec
Old 10-03-2007   #4 (permalink)
Mr. Arnold
Guest


 

Re: Vista rootkit issue - all legit. software


"Bob" <bob@xxxxxx> wrote in message
news:13g79ajr46ph120@xxxxxx
Quote:

> Hi
>
> I have Windows Vista Home Premium pre-installed on my new HP laptop.
>
> Every time I go to open a folder that has audio, ripped from a CD, in .wav
> format, my hard-drive goes overtime, running almost 100% constantly.
> System responsiveness to a single-click is about 30 to 60 seconds. This is
> the definite trigger, (the folder).
>
> I have Norton Internet Security 2007, not my first choice of av software
> installed, and I also run Windows Defender. I update regularly and run IE
> with very tight security settings.
>
> I recently purchased and installed Ashampoo Burning Studio 7, as my
> burning needs are for simple document backups.
>
> I ripped my first audio CD since I purchased today and that's when my
> problems began.
>
> I have stopped and permanently disabled the Windows Search Index service
> to prevent further hard-drive activity.
>
> I do own Sony Sound Forge Audio Studio 9.
>
> Nothing on this laptop has been an issue since today and ripping that
> audio CD into .wav. By the way, when I rip a CD, Ashampoo connects to the
> Internet to collect the music CD's track and album details.
>
> I have tried a couple of free rootkit detection app's but nothing yet. NIS
> 2007 is supposed to detect them...
>
> I don't need to rip CD's normally or in future but I do want to know if I
> have a rootkit and/or DRM issue on this laptop.
>
> Wadda ya think?
>
> Many thanks
<http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_Rootkit_Tools_in_a_Windows_Environment.html>
<http://www.pcworld.com/downloads/file/fid,23780-order,1-page,1/description.html>
<http://www.microsoft.com/technet/sysinternals/default.mspx>

ActivePorts doesn't work on Vista, but CurrPort does.

<http://www.nirsoft.net/>

Also use Google to find information on how to use Process Explorer.



My System SpecsSystem Spec
Old 10-04-2007   #5 (permalink)
Dave Wood [MS]
Guest


 

Re: Vista rootkit issue - all legit. software - found the problem - the burning app I was using...

I could be wrong, but absolutely nothing about your symptoms suggest to me
this is related to DRM. Instead it sounds like a regular bug somewhere. When
you hit this 100% activity on your system, can you use Task Manager on the
'Process' tab to see which process on your system is using 100% CPU?


"Bob" <bob@xxxxxx> wrote in message
news:13g8gbhj3dkrcc5@xxxxxx
Quote:

> My CD burning application appears to be the culprit.
>
> I managed to extract audio from the same CD, using another application and
> I can access those .wav files and the folder they're contained in just
> fine.
>
> My conclusion at this point therefore is that Ashampoo Burning Studio 7.1
> contains some form of digital rights management protection that is used
> when extracting audio from CD's, or it activates some form of digital
> rights management protection in Vista.
>
> I'm not sure if I should keep using the software, as it may lead to other
> vulnerabilites later. At this point I do plan to keep using it though.
>
> Bob
>
> "Mr. Arnold" <MR. Arnold@xxxxxx> wrote in message
> news:ObYzaGiBIHA.4160@xxxxxx
Quote:

>>
>> "Bob" <bob@xxxxxx> wrote in message
>> news:13g79ajr46ph120@xxxxxx
Quote:

>>> Hi
>>>
>>> I have Windows Vista Home Premium pre-installed on my new HP laptop.
>>>
>>> Every time I go to open a folder that has audio, ripped from a CD, in
>>> .wav format, my hard-drive goes overtime, running almost 100%
>>> constantly. System responsiveness to a single-click is about 30 to 60
>>> seconds. This is the definite trigger, (the folder).
>>>
>>> I have Norton Internet Security 2007, not my first choice of av software
>>> installed, and I also run Windows Defender. I update regularly and run
>>> IE with very tight security settings.
>>>
>>> I recently purchased and installed Ashampoo Burning Studio 7, as my
>>> burning needs are for simple document backups.
>>>
>>> I ripped my first audio CD since I purchased today and that's when my
>>> problems began.
>>>
>>> I have stopped and permanently disabled the Windows Search Index service
>>> to prevent further hard-drive activity.
>>>
>>> I do own Sony Sound Forge Audio Studio 9.
>>>
>>> Nothing on this laptop has been an issue since today and ripping that
>>> audio CD into .wav. By the way, when I rip a CD, Ashampoo connects to
>>> the Internet to collect the music CD's track and album details.
>>>
>>> I have tried a couple of free rootkit detection app's but nothing yet.
>>> NIS 2007 is supposed to detect them...
>>>
>>> I don't need to rip CD's normally or in future but I do want to know if
>>> I have a rootkit and/or DRM issue on this laptop.
>>>
>>> Wadda ya think?
>>>
>>> Many thanks
>>
>> <http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_Rootkit_Tools_in_a_Windows_Environment.html>
>> <http://www.pcworld.com/downloads/file/fid,23780-order,1-page,1/description.html>
>> <http://www.microsoft.com/technet/sysinternals/default.mspx>
>>
>> ActivePorts doesn't work on Vista, but CurrPort does.
>>
>> <http://www.nirsoft.net/>
>>
>> Also use Google to find information on how to use Process Explorer.
>>
>>
>>
>
My System SpecsSystem Spec
Old 10-04-2007   #6 (permalink)
Alun Jones
Guest


 

Re: Vista rootkit issue - all legit. software - found the problem - the burning app I was using...

Careful - 100% drive activity does not necessarily correlate to 100% CPU
usage.

Try the Performance and Reliability Monitor.

Alun.
~~~~

"Dave Wood [MS]" <davewood@xxxxxx> wrote in message
news:efXD4jsBIHA.1212@xxxxxx
Quote:

>I could be wrong, but absolutely nothing about your symptoms suggest to me
>this is related to DRM. Instead it sounds like a regular bug somewhere.
>When you hit this 100% activity on your system, can you use Task Manager on
>the 'Process' tab to see which process on your system is using 100% CPU?
>
>
> "Bob" <bob@xxxxxx> wrote in message
> news:13g8gbhj3dkrcc5@xxxxxx
Quote:

>> My CD burning application appears to be the culprit.
>>
>> I managed to extract audio from the same CD, using another application
>> and I can access those .wav files and the folder they're contained in
>> just fine.
>>
>> My conclusion at this point therefore is that Ashampoo Burning Studio 7.1
>> contains some form of digital rights management protection that is used
>> when extracting audio from CD's, or it activates some form of digital
>> rights management protection in Vista.
>>
>> I'm not sure if I should keep using the software, as it may lead to other
>> vulnerabilites later. At this point I do plan to keep using it though.
>>
>> Bob
>>
>> "Mr. Arnold" <MR. Arnold@xxxxxx> wrote in message
>> news:ObYzaGiBIHA.4160@xxxxxx
Quote:

>>>
>>> "Bob" <bob@xxxxxx> wrote in message
>>> news:13g79ajr46ph120@xxxxxx
>>>> Hi
>>>>
>>>> I have Windows Vista Home Premium pre-installed on my new HP laptop.
>>>>
>>>> Every time I go to open a folder that has audio, ripped from a CD, in
>>>> .wav format, my hard-drive goes overtime, running almost 100%
>>>> constantly. System responsiveness to a single-click is about 30 to 60
>>>> seconds. This is the definite trigger, (the folder).
>>>>
>>>> I have Norton Internet Security 2007, not my first choice of av
>>>> software installed, and I also run Windows Defender. I update regularly
>>>> and run IE with very tight security settings.
>>>>
>>>> I recently purchased and installed Ashampoo Burning Studio 7, as my
>>>> burning needs are for simple document backups.
>>>>
>>>> I ripped my first audio CD since I purchased today and that's when my
>>>> problems began.
>>>>
>>>> I have stopped and permanently disabled the Windows Search Index
>>>> service to prevent further hard-drive activity.
>>>>
>>>> I do own Sony Sound Forge Audio Studio 9.
>>>>
>>>> Nothing on this laptop has been an issue since today and ripping that
>>>> audio CD into .wav. By the way, when I rip a CD, Ashampoo connects to
>>>> the Internet to collect the music CD's track and album details.
>>>>
>>>> I have tried a couple of free rootkit detection app's but nothing yet.
>>>> NIS 2007 is supposed to detect them...
>>>>
>>>> I don't need to rip CD's normally or in future but I do want to know if
>>>> I have a rootkit and/or DRM issue on this laptop.
>>>>
>>>> Wadda ya think?
>>>>
>>>> Many thanks
>>>
>>> <http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_Rootkit_Tools_in_a_Windows_Environment.html>
>>> <http://www.pcworld.com/downloads/file/fid,23780-order,1-page,1/description.html>
>>> <http://www.microsoft.com/technet/sysinternals/default.mspx>
>>>
>>> ActivePorts doesn't work on Vista, but CurrPort does.
>>>
>>> <http://www.nirsoft.net/>
>>>
>>> Also use Google to find information on how to use Process Explorer.
>>>
>>>
>>>
>>
>

My System SpecsSystem Spec
Old 10-04-2007   #7 (permalink)
Bob
Guest


 

Re: Vista rootkit issue - all legit. software - found the problem - the burning app I was using...

I believe svchost was accessing the drive when I struggled at the time to
get access to the the perf. and reliability monitor.

I was mostly concerned about a rootkit or something affecting my PC. I don't
appear to have a rootkit on the PC.

It only happens when I extract audio from a copied CD with that particular
app.

Thanks for the replies guys


"Alun Jones" <alun@xxxxxx> wrote in message
news:%23F$QuQtBIHA.1208@xxxxxx
Quote:

> Careful - 100% drive activity does not necessarily correlate to 100% CPU
> usage.
>
> Try the Performance and Reliability Monitor.
>
> Alun.
> ~~~~
>
> "Dave Wood [MS]" <davewood@xxxxxx> wrote in message
> news:efXD4jsBIHA.1212@xxxxxx
Quote:

>>I could be wrong, but absolutely nothing about your symptoms suggest to me
>>this is related to DRM. Instead it sounds like a regular bug somewhere.
>>When you hit this 100% activity on your system, can you use Task Manager
>>on the 'Process' tab to see which process on your system is using 100%
>>CPU?
>>
>>
>> "Bob" <bob@xxxxxx> wrote in message
>> news:13g8gbhj3dkrcc5@xxxxxx
Quote:

>>> My CD burning application appears to be the culprit.
>>>
>>> I managed to extract audio from the same CD, using another application
>>> and I can access those .wav files and the folder they're contained in
>>> just fine.
>>>
>>> My conclusion at this point therefore is that Ashampoo Burning Studio
>>> 7.1 contains some form of digital rights management protection that is
>>> used when extracting audio from CD's, or it activates some form of
>>> digital rights management protection in Vista.
>>>
>>> I'm not sure if I should keep using the software, as it may lead to
>>> other vulnerabilites later. At this point I do plan to keep using it
>>> though.
>>>
>>> Bob
>>>
>>> "Mr. Arnold" <MR. Arnold@xxxxxx> wrote in message
>>> news:ObYzaGiBIHA.4160@xxxxxx
>>>>
>>>> "Bob" <bob@xxxxxx> wrote in message
>>>> news:13g79ajr46ph120@xxxxxx
>>>>> Hi
>>>>>
>>>>> I have Windows Vista Home Premium pre-installed on my new HP laptop.
>>>>>
>>>>> Every time I go to open a folder that has audio, ripped from a CD, in
>>>>> .wav format, my hard-drive goes overtime, running almost 100%
>>>>> constantly. System responsiveness to a single-click is about 30 to 60
>>>>> seconds. This is the definite trigger, (the folder).
>>>>>
>>>>> I have Norton Internet Security 2007, not my first choice of av
>>>>> software installed, and I also run Windows Defender. I update
>>>>> regularly and run IE with very tight security settings.
>>>>>
>>>>> I recently purchased and installed Ashampoo Burning Studio 7, as my
>>>>> burning needs are for simple document backups.
>>>>>
>>>>> I ripped my first audio CD since I purchased today and that's when my
>>>>> problems began.
>>>>>
>>>>> I have stopped and permanently disabled the Windows Search Index
>>>>> service to prevent further hard-drive activity.
>>>>>
>>>>> I do own Sony Sound Forge Audio Studio 9.
>>>>>
>>>>> Nothing on this laptop has been an issue since today and ripping that
>>>>> audio CD into .wav. By the way, when I rip a CD, Ashampoo connects to
>>>>> the Internet to collect the music CD's track and album details.
>>>>>
>>>>> I have tried a couple of free rootkit detection app's but nothing yet.
>>>>> NIS 2007 is supposed to detect them...
>>>>>
>>>>> I don't need to rip CD's normally or in future but I do want to know
>>>>> if I have a rootkit and/or DRM issue on this laptop.
>>>>>
>>>>> Wadda ya think?
>>>>>
>>>>> Many thanks
>>>>
>>>> <http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_Rootkit_Tools_in_a_Windows_Environment.html>
>>>> <http://www.pcworld.com/downloads/file/fid,23780-order,1-page,1/description.html>
>>>> <http://www.microsoft.com/technet/sysinternals/default.mspx>
>>>>
>>>> ActivePorts doesn't work on Vista, but CurrPort does.
>>>>
>>>> <http://www.nirsoft.net/>
>>>>
>>>> Also use Google to find information on how to use Process Explorer.
>>>>
>>>>
>>>>
>>>
>>
>
>
My System SpecsSystem Spec
Reply
Update your Vista Drivers

Thread Tools
Display Modes



Similar Threads
Thread Thread Starter Forum Replies Last Post
Vista Software Permission Issue Joe Bitner Vista General 2 11-29-2007 09:49 PM
Vista rootkit or digital rights management issue - repost? Bob Vista security 4 10-05-2007 08:25 PM
Vista rootkit issue? All legit software. Open an .wav folder with a few wav files and hard-drive goes 100% endlessly Bob Vista security 0 10-02-2007 10:22 AM
Can a Rootkit Be Certified for Vista? p2... spamhotmail Vista General 1 03-17-2007 06:05 PM
Can a Rootkit Be Certified for Vista? spamhotmail Vista General 0 03-17-2007 03:48 PM


Complimentary Industry Resources

Vista Forums has joined forces with TradePub.com to offer you a new, exciting, and entirely free professional resource. Visit http://vistax64.tradepub.com today to browse our selection of complimentary Industry magazines, white papers, webinars, podcasts, and more across 34 industry sectors. No credit cards, coupons, or promo codes required. Try it today!




Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51