Copy link to clipboard
Copied
Hey -
I just updated my Creative Cloud apps, and found that my AV blocked Adobe from running an app called "CoinMiner."
I think this means either Adobe is doing this intentionally (bad) or someone hacked your update files and Adobe is doing this unintentionally (very bad).
I have blocked this application, so feel free to take whatever action you think is appropriate.
Richard
Hi Richard,
I've seen the same issue, specifically the RedDecoder DLL files (both X86 and x64) presumably from Adobe Premier are being flagged as coin miners by Microsoft AV and deleted. Unfortunately we haven't been able to get a sample and submit it to Microsoft as a false positive as every time the update server re-downloads and attempts to distribute the files, they get deleted. This has only begun within the last few days.
If anyone out there has these DLL files and can submit to MS to re-ch
...Copy link to clipboard
Copied
I can't submit them - the files are too large. --Eileen
Copy link to clipboard
Copied
What files were you trying to submit and where Eileen?
There are 2 files detected by our M$ AV:
REDDecoder-x86.dll
REDDecoder-x64.dll
Microsoft premier support allows 1gb uploads. I can't imagine these two files are larger than than that!
Copy link to clipboard
Copied
We have several reports of the software being tagged PUA:Win32/CoinMiner. We are packaging the software for the device license. CoinMiner is being found in different software packages - packaged by different techs. It is being found in different builds too. I have one from 2016 and 2017 that it is getting tagged with the CoinMiner virus.
PUA:Win32/CoinMiner 2/20/2018
containerfile:_C:\Users\username\Desktop\ADVCCJan2018.zip;file:_C:\Users\username\Desktop\ADVCCJan2018.zip->ADVCCJan2018/Build/HD/AEFT15.0.1/AdobeAfterEffects15AllTrial.zip->1/universal/Professional/Support Files/REDDecoder-x64.dll;file:_C:\Users\username\Desktop\ADVCCJan2018.zip->ADVCCJan2018/Build/HD/AEFT15.0.1/AdobeAfterEffects15AllTrial.zip->1/universal/Professional/Support Files/REDDecoder-x86.dll;file:_C:\Users\username\Desktop\ADVCCJan2018.zip->ADVCCJan2018/Build/HD/AME12.0.1/AdobeMediaEncoder12AllTrial.zip->1/universal/App/REDDecoder-x64.dll;file:_C:\Users\username\Desktop\ADVCCJan2018.zip->ADVCCJan2018/Build/HD/AME12.0.1/AdobeMediaEncoder12AllTrial.zip->1/universal/App/REDDecoder-x86.dll;file:_C:\Users\username\Desktop\ADVCCJan2018.zip->ADVCCJan2018/Build/HD/AUDT11.0.1/AdobeAudition11All.zip->1/universal/App/REDDecoder-x64.dll;file:_C:\Users\username\Desktop\ADVCCJan2018.zip->ADVCCJan2018/Build/HD/AUDT11.0.1/AdobeAudition11All.zip->1/universal/App/REDDecoder-x86.dll;file:_C:\Users\username\De NT AUTHORITY\NETWORK SERVICE
Copy link to clipboard
Copied
Please check the digital signature on the specific file that is giving the report. What signer? What date? Does it show as valid when you click Details?
Copy link to clipboard
Copied
Hi,
First update your Anti Virus and then try to re-install your latest product. I have tried with latest Windows defender (ver. 1.261.1547.0) and it installed without any issue.
Copy link to clipboard
Copied
I'm sorted now after a magical reboot it no longer detects as a virus
Find more inspiration, events, and resources on the new Adobe Community
Explore Now