Adware, malware, spyware, hijacker discussion and information

[Gain Knowledge]  [Install Prevention]  [Maintain Security]  [Spyware Removal Help]


It is currently Sat Jul 31, 2010 2:12 pm

All times are UTC - 7 hours




Post new topic Reply to topic  [ 13 posts ] 
Author Message
 Post subject: Adware Pusher an MS MVP?!?!?!?!?!!!!
PostPosted: Thu Oct 05, 2006 8:31 am 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15493
Location: PHX, AZ
I write this and am astonished at how it has come about.

I write this and wonder just what type of person gets awarded this status for pushing adware onto thousands and thousands of unsuspecting users.

I write this and wonder just what was MS thinking when they thought this person was an asset to the Net community.

I write this and am currently rethinking my association with the MS MVP program if it can let someone like this join its ranks.

Patchou, the creator of MessengerPlus! has been made an MS MVP.

Yeah, that's right, someone who has profitted off the mistakes of users who installed their adware program, which has gone from worse to bad in it's installation methods, is now an awardee of of Microsofts MVP program.

This is a sad day and one which will cause great pause for any others who wish to join it's ranks, while over at companies like Claria, 180Solutions\Zango and whoever else makes adware, must be salivating over. This opens the door for anyone such as Patchou to apply or be submitted.

More later.

_________________
Image


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Thu Oct 05, 2006 9:03 am 
Offline
Site Admin
Site Admin
User avatar

Joined: Sun May 15, 2005 12:42 pm
Posts: 3472
Location: Newcastle, UK
EEEEEEEK!

Quote:
You can count on me to continue promoting Windows Live and its surrounding technologies. Messenger is here to stay after all, and so is Messenger Pus!.


From (lil feckers not getting no traffic on my account):
www .msgpluslive.net/news/2006/10/05/mvp-award-hello-windows-live/

Think I'm officially losing any respect I had for the MSMVP program .... what the feck were MS smoking when they decided this one? (whatever it was, please keep it the heck away from me!!!!)

_________________
Regards

Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net

Keeping it FREE!


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Thu Oct 05, 2006 10:05 am 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15493
Location: PHX, AZ
You can express your outrage over at Digg

_________________
Image


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Thu Oct 05, 2006 3:48 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15493
Location: PHX, AZ
Some more links pertaining to Mr. Patchou's bit of adware. All from Sandi @ Spywaresucks, noted IE MS MVP:

http://msmvps.com/blogs/spywaresucks/ar ... 03407.aspx

http://msmvps.com/blogs/spywaresucks/ar ... 02793.aspx

http://msmvps.com/blogs/spywaresucks/ar ... 89692.aspx

http://msmvps.com/blogs/spywaresucks/ar ... 78084.aspx

_________________
Image


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Thu Oct 05, 2006 6:17 pm 
Offline
Moderators
Moderators
User avatar

Joined: Wed Feb 02, 2005 9:47 am
Posts: 2570
Location: South Central Montana USA
Quote:
. HP and Dell will not take kindly to any suggestion that their pre-approved install/recovery disks contain any sort of malware. This is from the second link posted

Sorry to be the one to burst your bubble Sandi, but HP certainly does come with preinstalled malware. I'm not talking about a recovery disk, I'm talking about a "pristine" out of the box supposed to be custom built laptop with Wild Tangent firmly in place.

I can not play one game that came with the lappy without installing Wild Tangent, or so I am told by the installer. I have been doing some poking around and in one spot found I should be able to get rid of Wild Tangent and still play the games. I can't test this out because I had to send the laptop back for repair to the keyboard.

I am not happy about this at all and not really sure what to do about it.....but your wrong about HP or Dell's integrity. Dell is big on Real-Time and it's own brand of spy-ware that phones home the users every move.

_________________
Image Image


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Fri Oct 06, 2006 4:19 am 
Offline
Countermeasures Team
Countermeasures Team
User avatar

Joined: Tue Nov 15, 2005 12:53 pm
Posts: 76
Location: UK
This realy disgust me. There is an MS Community thread about this (credit to Susan from MRU) - it really makes you wonder. However I have not posted it in public as I am not sure if it is ok to do so

_________________
Malware Removal Guides and Self Help
Image++Image
Image
Image


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Fri Oct 06, 2006 8:01 am 
Offline

Joined: Fri Feb 18, 2005 11:07 pm
Posts: 87
Location: ** USA **
JeanInMontana wrote:
Quote:
. HP and Dell will not take kindly to any suggestion that their pre-approved install/recovery disks contain any sort of malware. This is from the second link posted

Sorry to be the one to burst your bubble Sandi, but HP certainly does come with preinstalled malware. I'm not talking about a recovery disk, I'm talking about a "pristine" out of the box supposed to be custom built laptop with Wild Tangent firmly in place. //snip//

I am not happy about this at all and not really sure what to do about it.....but your wrong about HP or Dell's integrity. Dell is big on Real-Time and it's own brand of spy-ware that phones home the users every move.


I have experienced this as well on my last three HP systems. There are intrusive programs within their "Help & Support" files, collecting data among other things. Several programs that come bundled with their OS have little bits here and there, the mp3 programs being the most agressive.

I read through Sandi's blogs, the reaction from the "Plus Team" was very enlightening. People who are honest and not covering anything up don't need to hire a pack to flame for them. (I certainly wouldn't for you Tom! ;-)

Speaking of which, congratulations on being awarded. I hope it can continue to be an honor, as you truly deserve the recognition.

_________________
- CD -
Any society that would give up a little liberty to gain a little security will deserve neither and lose both.
- Benjamin Franklin


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Fri Oct 06, 2006 11:27 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15493
Location: PHX, AZ
Here is some install analysis done by Grinler, from Bleeping Computer:

Quote:
Here is a summary of what LOP does , process and executable wise, so we we
can put the evidence of LOP and what it does behind us and just get the
formal letter completed.

Here is the sequence:

Install messenger plus.

Choose to Install sponsor and now the fun starts.

MSG+ Installer downloads lop installer from
r9849.bins.lop.com/bins/int/7k11_pk2.int or other similar url.

Lop installer installs a bunch of exes and a fake DLL exe which are stored
under the logged in users profile as random names/folders and under the all
users profile as random names/folders. One exe is actually a dll with an exe
extension. The actual legitimate exe is stored in All Users. The DLL exe is
located in the logged in users profile. I am not a programmer, but why
microsoft allows DLLs to be renamed EXE's and still be launched as DLLs is
beyond me.

Lop installer adds the fake exe as BHO in the registry so when IE starts it
shows popups and starts another of the EXEs.

Lop installer adds one of its exe's as a Run in the registry to that it
launches IE in the background and starts one of the other EXEs.

Lop installer creates a hidden job in C:\Windows\Tasks. Name similar to:

A700637A918C1DD6.job

These jobs start an exe which starts IE in the background and launches
another one of the EXEs. This EXE is launched every hour, so if you dont
kill the file or kill the job, cleaning up the other entries will just start
this process over every hour.

It also creates another directory under the logged in users profile with
other other executables such as the scheduled job executable, the
installer, etc.

Basically, the BHO and EXEs are a ring of chained events, each starting each
other. Very similar to how CWS_NS3 (Home search assistant) worked. You need
to remove all points of precense or this thing will just keep starting
itself over from the other 2 points.

So for example, In my install, job starts
c:\docume~1\forens~1\applic~1\tonspo~1\coalplayroam.exe which starts
c:\docume~1\forens~1\applic~1\tonspo~1\firstaxis.exe (the originall
installer) which starts C:\Documents and Settings\All Users\Application
Data\Locks Clock Plus Option\Dart Idle.exe which starts firstaxis.exe again.
Each of these processes having the ability to once again start an instance
of IE. Oh and lets not forget that when you start IE, the BHO also launches
the executable. This is why this thing is such a PITA. Everthing launches
each other.

This circular chain of events can be started at each point on the chain.

Hijackthis gets these lines:

O2 - BHO: (no name) - {8E1F0B57-662A-9F87-E4E2-BA6C306EBDB7} -
C:\DOCUME~1\FORENS~1\APPLIC~1\ANTESE~1\test lies.exe
O4 - HKLM\..\Run: [plus option junk third] C:\Documents and Settings\All
Users\Application Data\Locks Clock Plus Option\Dart Idle.exe
O4 - HKCU\..\Run: [boob mpeg]
C:\DOCUME~1\FORENS~1\APPLIC~1\TONSPO~1\FIRSTAXIS.exe

Last but not least, I did not read the MSG+ eula, but its installer contacts
home base when the program finishes installing:

GET /setupcomplete.php?ra=92ba1d97&up=0&mp=4240&lg=en&sp=1 HTTP/1.1
User-Agent: MessengerPlusLive
Host: software.msgpluslive.net
Cache-Control: no-cache

GET /software/setupcomplete.php?ra=92ba1d97&up=0&mp=4240&lg=en&sp=1 HTTP/1.1
User-Agent: MessengerPlusLive
Connection: Keep-Alive
Cache-Control: no-cache
Host: xxx.msgplusliveDOTnet
Cookie: langusr=en


-

_________________
Image


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Mon Oct 09, 2006 10:37 am 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15493
Location: PHX, AZ
Well, there is still no 'official' word from MS, but it's already out on the Net that they have reconsidered his award and revoked it based on the content of the adware, LOP, in his MessengerPlus! application

When and if we see something 'official' I'll post it here too.

There was a thread over at his forums with all sorts of commentary, both good and bad, including many MVPS who posted there, but as is not out of the norm, the thread has disappeared.

I was actually surprised that some of his members sort of agreed.

Tons of commentary by the less mature asswipes from their forum can be found at PGs here and here

_________________
Image


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Mon Oct 09, 2006 9:03 pm 
Offline
Moderators
Moderators
User avatar

Joined: Wed Feb 02, 2005 9:47 am
Posts: 2570
Location: South Central Montana USA
The thread is still at the forums. I found an interesting post in it.

Quote:
RE: MVP Award - Hello Windows Live!

quote:Originally posted by jegar

quote:Originally posted by ShawnZ

quote:Originally posted by LEE123
I'm not bashing his program - it's amazing code, and I congratulate Patchou on it. I just don't think he can expect an MVP for bundling adware with it.



for the last time, they didn't remove him because his program has adware. they knew about the adware for ages, and they knew about it when adding him to the team. microsoft only removed him because people bitched.



Sorry dude this is the official statement from Microsoft:

quote:" Cyril Paciullo was awarded with MVP status this year on the basis of his technical expertise and strong community contribution. However, his active MVP Award status was revoked as soon as the extent of the connection between his application and spyware was made apparent to the MVP Program."


Source of article please?

Microsoft know that Messenger Plus! Live does not bundle spyware.

The above quote comes from traxor's post second post on that page. Too bad they didn't include a link to the MS quote.

_________________
Image Image


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Mon Oct 09, 2006 11:17 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15493
Location: PHX, AZ
That's not the thread, there was a whole other thread where they stated about Patchou losing the award, that's the one they deleted\moved.

And there is no link to any 'official' MS quote anywhere, I have read every damn article I could fins, and they all say the same thing about a 'statement' but provide no link. :twisted:

_________________
Image


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Tue Oct 10, 2006 6:21 am 
Offline
Countermeasures Team
Countermeasures Team
User avatar

Joined: Tue Nov 15, 2005 12:53 pm
Posts: 76
Location: UK
It's a shame that it became to this. Kids thinking they are Rambo. And us trying to explain our reasons.

And again like many have said before. No word from the person in question. :|

_________________
Malware Removal Guides and Self Help
Image++Image
Image
Image


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Fri Oct 20, 2006 10:41 pm 
Offline
Moderators
Moderators
User avatar

Joined: Fri Feb 18, 2005 2:53 am
Posts: 732
Location: Las Vegas, NV. USA
Just a couple of links of this:

http://www.cio.com/blog_view.html?CID=25601

http://www.pcadvisor.co.uk/news/index.cfm?newsid=7284

http://www.betanews.com/article/Adware_ ... 1160421323


Top
 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 13 posts ] 

All times are UTC - 7 hours


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  

Who is online

Who is online In total there are 0 users online :: 0 registered, 0 hidden and 0 guests (based on users active over the past 5 minutes)
Most users ever online was 115 on Tue Jul 13, 2010 5:32 pm

Users browsing this forum: No registered users and 0 guests

New posts    No new posts    Forum locked
Powered by phpBB