Log in

View Full Version : megui 0.3.2 infected?


enchant1
18th January 2010, 22:44
I haven't had any trouble with megui for quite some time, but I fired it up today, and it updated itself to 0.3.2. Prevx immediately alerted me that I had an infected file.

tools\enc_aacplus\enc_aacPlus.exe was reported as malware.

I did NOT remove it, but attempted to run megui anyways. I started reporting errors:
Unhandled error
Exception message: The system cannot find the file specified.

But with all of the log output, it never tells you what file it couldn't find.
[Error] Log
-[Information] Versions
--[NoImage] MeGUI Version : 0.3.2.0
--[NoImage] OS : Windows XP Professional x86 SP3 (5.1.196608.2600)
--[NoImage] Latest .Net Framework installed : .x (..)
--[NoImage] Avisynth Version : 2.5.8.5
-[Information] AutoEncode job generation log
--[NoImage] Desired Size : 350 MB
--[NoImage] Split Size : null
--[Information] Eliminating duplicate filenames
---[NoImage] Video output file: F:\Burn these\Misc Tv\More\Japanese\Magerarenai Onna\Ep 1\Magerarenai Onna ep01 (704x396 DivX6).264
---[NoImage] Muxed output file: F:\Burn these\Misc Tv\More\Japanese\Magerarenai Onna\Ep 1\Magerarenai Onna ep01 (704x396 DivX6)-muxed.mp4
---[NoImage] Encodable audio stream 0: F:\Burn these\Misc Tv\More\Japanese\Magerarenai Onna\Ep 1\Magerarenai Onna ep01 (704x396 DivX6).m4a
-[Information] Log for job1 (audio, Magerarenai Onna ep01 (704x396 DivX6).wav -> Magerarenai Onna ep01 (704x396 DivX6).m4a)
--[Information] [1/18/2010 2:58:37 PM] Started handling job
--[Information] [1/18/2010 2:58:37 PM] Preprocessing
--[NoImage] Avisynth script
---[NoImage] LoadPlugin("E:\Program Files\megui\tools\avisynth_plugin\NicAudio.dll")
---[NoImage] NicMPG123Source("F:\Burn these\Misc Tv\More\Japanese\Magerarenai Onna\Ep 1\Magerarenai Onna ep01 (704x396 DivX6).wav")
---[NoImage] Normalize()
---[NoImage] return last
--[NoImage] Commandline used: -ignorelength -br 128000 -if - -of "{0}"
--[Information] [1/18/2010 2:58:37 PM] Encoding started
--[Information] [1/18/2010 2:58:37 PM] Encode thread started
--[Information] [1/18/2010 2:58:37 PM] Avisynth script environment opened
--[Information] [1/18/2010 2:58:38 PM] Script loaded
--[Information] Output Decoder
---[NoImage] Channels: 2
---[NoImage] Bits per sample: 32
---[NoImage] Sample rate: 48000
--[NoImage] Commandline: E:\Program Files\megui\tools\neroAacEnc.exe -ignorelength -br 128000 -if - -of "F:\Burn these\Misc Tv\More\Japanese\Magerarenai Onna\Ep 1\Magerarenai Onna ep01 (704x396 DivX6).m4a"
--[Information] [1/18/2010 2:58:38 PM] Encoder process started
--[NoImage] Output from encoder via stderr
---[NoImage] *************************************************************
---[NoImage] * *
---[NoImage] * Nero AAC Encoder *
---[NoImage] * Copyright 2008 Nero AG *
---[NoImage] * All Rights Reserved Worldwide *
---[NoImage] * *
---[NoImage] * Package build date: Sep 17 2008 *
---[NoImage] * Package version: 1.3.3.0 *
---[NoImage] * *
---[NoImage] * See -help for a complete list of available parameters. *
---[NoImage] * *
---[NoImage] *************************************************************
--[Information] [1/18/2010 3:01:43 PM] Postprocessing
--[Information] [1/18/2010 3:01:43 PM] Job completed
-[Error] Unhandled error
--[NoImage] Exception message: The system cannot find the file specified
--[NoImage] Stacktrace
---[NoImage] at System.Diagnostics.Process.StartWithShellExecuteEx(ProcessStartInfo startInfo)
---[NoImage] at System.Diagnostics.Process.Start()
---[NoImage] at System.Diagnostics.Process.Start(ProcessStartInfo startInfo)
---[NoImage] at System.Diagnostics.Process.Start(String fileName)
---[NoImage] at MeGUI.MainForm.mnuForum_Click(Object sender, EventArgs e)
---[NoImage] at System.Windows.Forms.MenuItem.OnClick(EventArgs e)
---[NoImage] at System.Windows.Forms.MenuItem.MenuItemData.Execute()
---[NoImage] at System.Windows.Forms.Command.Invoke()
---[NoImage] at System.Windows.Forms.Command.DispatchID(Int32 id)
---[NoImage] at System.Windows.Forms.Control.WmCommand(Message& m)
---[NoImage] at System.Windows.Forms.Control.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.ScrollableControl.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.ContainerControl.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.Form.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message& m)
---[NoImage] at System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)
--[NoImage] Inner exception: null
-[Information] Log for job2 (video, Magerarenai Onna ep01 (704x396 DivX6).avs -> )
--[Information] [1/18/2010 3:01:43 PM] Started handling job
--[Information] [1/18/2010 3:01:43 PM] Preprocessing
---[Information] Bitrate calculation for video
----[NoImage] Desired size after subtracting audio: 302210KBs
----[NoImage] Calculated desired bitrate: 710kbit/s
--[NoImage] Job commandline: "E:\Program Files\megui\tools\x264\x264.exe" --profile high --level 4.1 --pass 1 --bitrate 710 --stats "F:\Burn these\Misc Tv\More\Japanese\Magerarenai Onna\Ep 1\Magerarenai Onna ep01 (704x396 DivX6).stats" --slow-firstpass --thread-input --deblock -1:-1 --b-adapt 2 --qcomp 0.5 --merange 12 --me umh --direct auto --subme 6 --trellis 2 --sar 1:1 --output NUL "F:\Burn these\Misc Tv\More\Japanese\Magerarenai Onna\Ep 1\Magerarenai Onna ep01 (704x396 DivX6).avs"
--[Information] [1/18/2010 3:01:44 PM] Encoding started
--[NoImage] Standard output stream
--[NoImage] Standard error stream
---[NoImage] avs [info]: 704x396 @ 29.97 fps (104444 frames)
---[NoImage] x264 [info]: using SAR=1/1
---[NoImage] x264 [info]: using cpu capabilities: MMX2 SSE2Fast SSSE3 Cache64
---[NoImage] x264 [info]: profile High, level 4.1
---[NoImage]
---[NoImage] x264 [info]: frame I:678 Avg QP:17.35 size: 29565
---[NoImage] x264 [info]: frame P:45859 Avg QP:20.83 size: 5356
---[NoImage] x264 [info]: frame B:57907 Avg QP:28.78 size: 722
---[NoImage] x264 [info]: consecutive B-frames: 4.6% 50.4% 37.9% 7.1%
---[NoImage] x264 [info]: mb I I16..4: 10.4% 64.4% 25.2%
---[NoImage] x264 [info]: mb P I16..4: 1.1% 2.5% 0.4% P16..4: 34.9% 14.5% 9.4% 0.0% 0.0% skip:37.3%
---[NoImage] x264 [info]: mb B I16..4: 0.4% 0.7% 0.1% B16..8: 6.6% 0.6% 0.5% direct: 2.5% skip:88.6% L0:36.3% L1:42.9% BI:20.7%
---[NoImage] x264 [info]: final ratefactor: 21.74
---[NoImage] x264 [info]: 8x8 transform intra:62.9% inter:45.4%
---[NoImage] x264 [info]: direct mvs spatial:94.5% temporal:5.5%
---[NoImage] x264 [info]: coded y,uvDC,uvAC intra: 54.6% 60.2% 22.6% inter: 9.5% 8.7% 0.7%
---[NoImage] x264 [info]: i16 v,h,dc,p: 41% 25% 17% 16%
---[NoImage] x264 [info]: i8 v,h,dc,ddl,ddr,vr,hd,vl,hu: 24% 19% 30% 4% 4% 5% 4% 5% 4%
---[NoImage] x264 [info]: i4 v,h,dc,ddl,ddr,vr,hd,vl,hu: 32% 18% 15% 5% 6% 7% 6% 6% 5%
---[NoImage] x264 [info]: Weighted P-Frames: Y:0.4%
---[NoImage] x264 [info]: ref P L0: 72.2% 11.0% 12.5% 4.3% 0.1%
---[NoImage] x264 [info]: ref B L0: 83.1% 16.9%
---[NoImage] x264 [info]: kb/s:705.77
---[NoImage] encoded 104444 frames, 44.37 fps, 705.77 kb/s
--[Information] [1/18/2010 3:40:58 PM] Postprocessing
--[Information] [1/18/2010 3:40:58 PM] Job completed
-[Error] Unhandled error
--[NoImage] Exception message: The system cannot find the file specified
--[NoImage] Stacktrace
---[NoImage] at System.Diagnostics.Process.StartWithShellExecuteEx(ProcessStartInfo startInfo)
---[NoImage] at System.Diagnostics.Process.Start()
---[NoImage] at System.Diagnostics.Process.Start(ProcessStartInfo startInfo)
---[NoImage] at System.Diagnostics.Process.Start(String fileName)
---[NoImage] at MeGUI.MainForm.mnuHome_Click(Object sender, EventArgs e)
---[NoImage] at System.Windows.Forms.MenuItem.OnClick(EventArgs e)
---[NoImage] at System.Windows.Forms.MenuItem.MenuItemData.Execute()
---[NoImage] at System.Windows.Forms.Command.Invoke()
---[NoImage] at System.Windows.Forms.Command.DispatchID(Int32 id)
---[NoImage] at System.Windows.Forms.Control.WmCommand(Message& m)
---[NoImage] at System.Windows.Forms.Control.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.ScrollableControl.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.ContainerControl.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.Form.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message& m)
---[NoImage] at System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)
--[NoImage] Inner exception: null
-[Error] Unhandled error
--[NoImage] Exception message: The system cannot find the file specified
--[NoImage] Stacktrace
---[NoImage] at System.Diagnostics.Process.StartWithShellExecuteEx(ProcessStartInfo startInfo)
---[NoImage] at System.Diagnostics.Process.Start()
---[NoImage] at System.Diagnostics.Process.Start(ProcessStartInfo startInfo)
---[NoImage] at System.Diagnostics.Process.Start(String fileName)
---[NoImage] at MeGUI.MainForm.mnuBugTracker_Click(Object sender, EventArgs e)
---[NoImage] at System.Windows.Forms.MenuItem.OnClick(EventArgs e)
---[NoImage] at System.Windows.Forms.MenuItem.MenuItemData.Execute()
---[NoImage] at System.Windows.Forms.Command.Invoke()
---[NoImage] at System.Windows.Forms.Command.DispatchID(Int32 id)
---[NoImage] at System.Windows.Forms.Control.WmCommand(Message& m)
---[NoImage] at System.Windows.Forms.Control.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.ScrollableControl.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.ContainerControl.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.Form.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message& m)
---[NoImage] at System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
---[NoImage] at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)
--[NoImage] Inner exception: null
-[Information] Log for job3 (video, Magerarenai Onna ep01 (704x396 DivX6).avs -> Magerarenai Onna ep01 (704x396 DivX6).264)
--[Information] [1/18/2010 3:40:58 PM] Started handling job
--[Information] [1/18/2010 3:40:58 PM] Preprocessing
--[NoImage] Job commandline: "E:\Program Files\megui\tools\x264\x264.exe" --profile high --level 4.1 --pass 2 --bitrate 710 --stats "F:\Burn these\Misc Tv\More\Japanese\Magerarenai Onna\Ep 1\Magerarenai Onna ep01 (704x396 DivX6).stats" --thread-input --deblock -1:-1 --b-adapt 2 --qcomp 0.5 --merange 12 --me umh --direct auto --subme 6 --trellis 2 --sar 1:1 --aud --output "F:\Burn these\Misc Tv\More\Japanese\Magerarenai Onna\Ep 1\Magerarenai Onna ep01 (704x396 DivX6).264" "F:\Burn these\Misc Tv\More\Japanese\Magerarenai Onna\Ep 1\Magerarenai Onna ep01 (704x396 DivX6).avs"
--[Information] [1/18/2010 3:40:59 PM] Encoding started
--[NoImage] Standard output stream
--[NoImage] Standard error stream
---[NoImage] avs [info]: 704x396 @ 29.97 fps (104444 frames)
---[NoImage] x264 [info]: using SAR=1/1
---[NoImage] x264 [info]: using cpu capabilities: MMX2 SSE2Fast SSSE3 Cache64
---[NoImage] x264 [info]: profile High, level 4.1
--[Information] [1/18/2010 4:36:49 PM] Job completed

Poutnik
18th January 2010, 23:42
You can upload and test suspicious files at free online antimalware services http://www.virustotal.com/ or http://virusscan.jotti.org/
They use multiple AV engines to test.

enchant1
18th January 2010, 23:47
You can upload and test suspicious files at free online antimalware services http://www.virustotal.com/ or http://virusscan.jotti.org/
They use multiple AV engines to test.

Thanks for the help. The only thing it find was at virustotal.com, and it was when it ran it through prevx. I think I'll contact those people and find out what the problem is.

quantum5uicid3
19th January 2010, 01:08
enc_aacPlus.exe
md5= 9a23281352df9ba2e2f8d299b3cc58c9

Poutnik
19th January 2010, 07:20
Thanks for the help. The only thing it find was at virustotal.com, and it was when it ran it through prevx. I think I'll contact those people and find out what the problem is.

I guess it can be false positive, if only one or very few of less appreciated av products found anything.