The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Recent Razer drivers spiked with Trojan

    Discussion in 'Gaming (Software and Graphics Cards)' started by flipfire, Sep 24, 2009.

  1. flipfire

    flipfire Moderately Boss

    Reputations:
    6,156
    Messages:
    11,214
    Likes Received:
    68
    Trophy Points:
    466
    Source: http://www.pcadvisor.co.uk/news/index.cfm?newsid=3202340&
    http://www.geek.com/articles/news/razer-driver-downloads-include-a-trojan-20090923/

    This was the reason i couldnt get my Lachesis software to work for the past few days. Ive been getting viruses warnings with AVG8.5 and even spybot S&D picked it up, but i ignored it as a regular temp file virus.

    Razer took down the drive support site and reviewed it under Trend Micros recommendation.
     
  2. Snowm0bile

    Snowm0bile Starcraftologist

    Reputations:
    265
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    55
    thats good info, thanks for posting this bc i was going to update mine tonight.

    or is it still bad?
     
  3. flipfire

    flipfire Moderately Boss

    Reputations:
    6,156
    Messages:
    11,214
    Likes Received:
    68
    Trophy Points:
    466
    It should be all clean now, but it never hurts to check. If you have an AV like AVG, Avast or Avira it should pick it up straight away.

    Razer took down the site for 24 hours to clean out the infectious drivers. They found 8 device drivers were spiked with the win32.asprox trojan.
     
  4. LaptopNut

    LaptopNut Notebook Virtuoso

    Reputations:
    1,610
    Messages:
    3,745
    Likes Received:
    92
    Trophy Points:
    116
    It is good never to rely on signature detection only. I always think it best to use behavior monitor security software or sandbox type methods. Either way, a layered defense is always a good idea along with regular backups of a known clean system.
     
  5. aznofazns

    aznofazns Performance Junkie

    Reputations:
    159
    Messages:
    945
    Likes Received:
    0
    Trophy Points:
    30
    Wow... I'm glad I haven't updated my Diamondback 3G drivers recently, as my Norton subscription expired a few weeks ago (not that Norton would have prevented the Trojan from owning my computer anyway). Thanks for the heads up.
     
  6. flipfire

    flipfire Moderately Boss

    Reputations:
    6,156
    Messages:
    11,214
    Likes Received:
    68
    Trophy Points:
    466
    The virus has become persistent, i think it has attached itself to the mouse's synapse memory or something.

    I am getting rootkit and usbctrl.exe virus alerts all over the place. I think i may have to do a clean install.

    Ive contacted Razer but they still have not responded
     
  7. Harleyquin07

    Harleyquin07 エミヤ

    Reputations:
    603
    Messages:
    3,376
    Likes Received:
    78
    Trophy Points:
    116
    Unlucky with the drivers, but is this the first time hackers have actually bothered hacking gaming mice websites just to spread virii?
     
  8. The Fire Snake

    The Fire Snake Notebook Virtuoso

    Reputations:
    426
    Messages:
    2,889
    Likes Received:
    0
    Trophy Points:
    55
    How did this happen? The drivers are from Razer itself, right? Or did someone post their own "drivers" to the site but they looked like they came from Razer?
     
  9. Harleyquin07

    Harleyquin07 エミヤ

    Reputations:
    603
    Messages:
    3,376
    Likes Received:
    78
    Trophy Points:
    116
    Like the article said, the manufacturer's website got hacked and the proper drivers replaced with the tainted versions.
     
  10. KimoT

    KimoT Are we not men?

    Reputations:
    560
    Messages:
    1,128
    Likes Received:
    0
    Trophy Points:
    55
    I ended up having to do a clean install of Windows. I emailed Razer support, they apologized and offered a tee shirt for my trouble.
     
  11. flipfire

    flipfire Moderately Boss

    Reputations:
    6,156
    Messages:
    11,214
    Likes Received:
    68
    Trophy Points:
    466
    Serious i wrote a 20min email explaining my situation and i get this drone reply 36 hours later

    They totally didnt read what i wrote which is annoying. Seeing as i did specifically write on my inital email what OS, firmware, AV i was using and AV's i tried.

    I own full razer gear (Death adder, Lachesis, Tarantula, Mantis and Goliathus pad) and i get this crap support

    Here is my virus vault log ever since i installed those damned drivers:

    [​IMG]
     
  12. KimoT

    KimoT Are we not men?

    Reputations:
    560
    Messages:
    1,128
    Likes Received:
    0
    Trophy Points:
    55
    For making me reinstall Windows (which I do all the time anyway):

    Unfair Advantage Series - Well Equipped (Black, X Large) 1
    Razer Beanie 1
    Razer Messenger Bag (Cyclist Bag)  with Distressed THS 1

    Just shipped today. Not bad.
     
  13. flipfire

    flipfire Moderately Boss

    Reputations:
    6,156
    Messages:
    11,214
    Likes Received:
    68
    Trophy Points:
    466
    Director of Customer Satisfaction emailed me back yesterday told me i would get free SWAG but he only asked for my shirt size

    Hopefully i get those too...i want the messenger bag!
     
  14. KimoT

    KimoT Are we not men?

    Reputations:
    560
    Messages:
    1,128
    Likes Received:
    0
    Trophy Points:
    55
    They only asked me for shirt size, too. That's all I was expecting until I saw the shipping confirmation email.
     
  15. Signal2Noise

    Signal2Noise Über-geek.

    Reputations:
    445
    Messages:
    1,970
    Likes Received:
    0
    Trophy Points:
    55
    That's nice of Razer to offer consolation T-shirts.

    Almost makes me wish I owned a Razer. Almost. :p
     
  16. Mastershroom

    Mastershroom wat

    Reputations:
    3,833
    Messages:
    8,209
    Likes Received:
    16
    Trophy Points:
    206
    Could this be why Belkin has removed their drivers for the N52TE speed pad? It uses Razer Synapse memory.
     
  17. flipfire

    flipfire Moderately Boss

    Reputations:
    6,156
    Messages:
    11,214
    Likes Received:
    68
    Trophy Points:
    466
    I got my razer messenger bag and shirt today. The bag is pretty big, tons of pockets for everything.

    Its worth $100+ so i guess its better compensation than nothing.
     
  18. stevenxowens792

    stevenxowens792 Notebook Virtuoso

    Reputations:
    952
    Messages:
    2,040
    Likes Received:
    0
    Trophy Points:
    0
    Hey, does anyone know what day the trojan started? The reason I ask is because I installed the death adder driver on 9/15. Was the infection this early? I think it says 9/19 on. I just want to be sure. I ran a virus check and didn't find anything but now I am a bit paranoid. Thanks,
    stevenx
     
  19. flipfire

    flipfire Moderately Boss

    Reputations:
    6,156
    Messages:
    11,214
    Likes Received:
    68
    Trophy Points:
    466
    Most AV's will detect it no problem. What AV are you using?
     
  20. stevenxowens792

    stevenxowens792 Notebook Virtuoso

    Reputations:
    952
    Messages:
    2,040
    Likes Received:
    0
    Trophy Points:
    0
    avg free version. I checked it last week and I was clean. I am just paranoid.
    Thanks,

    Stevenx
     
  21. KimoT

    KimoT Are we not men?

    Reputations:
    560
    Messages:
    1,128
    Likes Received:
    0
    Trophy Points:
    55
    September 19-22 are the dates for the bad drivers.