Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old September 13th, 2012, 08:00 AM
Tigzy Tigzy is offline
Developer
 
Join Date: Sep 2012
Location: France
Posts: 15
Default Re: RogueKiller Installs Malware

Quote:
5. Click the icon, prompted RK update, here it said zip required & offered 7zip.
And that's false. For the same reason as above.
What does the program icon looked like?

Quote:
Larger firms: Symantec MCAFEE, G-Data, KAV etc. etc. Seem to be able to control there products, so this does not happen to them. Even if a 3rd party added something to your product, this should be a warning to you Tigzy, as this only will sour me & others to your product.
I don't understand what you're talking about... what control? You definitely not downloaded the good thing.

If you have nothing to show (any log, any screenshot, any binary) for me there is nothing to do then...
  #27  
Old September 13th, 2012, 08:15 AM
kupo kupo is offline
Frequent Poster
 
Join Date: Jan 2011
Posts: 935
Default Re: RogueKiller Installs Malware

A mod should modify the title, as many user could be alarmed by the mess caused by OP's stupidity.
__________________
Do not feed the trolls!
  #28  
Old September 13th, 2012, 08:28 AM
Rico's Avatar
Rico Rico is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Texas
Posts: 1,407
Default Re: RogueKiller Installs Malware

Quote:
A mod should modify the title, as many user could be alarmed by the mess caused by OP's stupidity.

I'm quite sure the mods can handle this, without you making them aware. I also suggest that you CHILL, on the name calling. Flames do not help!
__________________
"Fear is a poison provided by the mind, and courage is the antidote stored always ready in the soul." D. Koontz
  #29  
Old September 13th, 2012, 08:35 AM
Tigzy Tigzy is offline
Developer
 
Join Date: Sep 2012
Location: France
Posts: 15
Default Re: RogueKiller Installs Malware

You definitely have not report / binary / screenshot to provide?
  #30  
Old September 13th, 2012, 01:04 PM
mick92z's Avatar
mick92z mick92z is offline
Frequent Poster
 
Join Date: Apr 2007
Location: In the box
Posts: 354
Default Re: RogueKiller Installs Malware

Ok, as version 8.0.3 is now out, and i already have version 8.0.2 , i decided to put this to the test. After executing the older version, R.K told me that a update was available , I clicked ok, and my browser opened at the R.K homepage. The program does not update, but simply offers you the option to download the latest version.
While on the homepage, I saw an advert at the top of the page for windows zip, so i download 7zsetup.exe ( or similar ) , sent it to V.T and got 4 detections for adware. ( betterinstaller )
Ran 7zip sandboxed, and was given the option ( two boxes to tick ) for incredibar, I accepted. Browser opened with incredibar installed and has been running for 1 hour now, with no problems
Malwarebytes blocked some more adware Vidsaver-ppi-multi_2012-08-22.exe, I told MBAM to ignore and extracted this file submiited to V.T and got 4 detections , adware (gameplaylabs )
I ran this file sandboxed, but it appeared to terminate ( it ran with no apparent effects, and no message from S.B )
So there was no requirement / prompt from RK to download or install anything other than RK itself.
As for the 7zip ad, there was an opportunity ( or more ) to decline the software, though as Tigzy said , don't click on ads;
I hope this sheds some light on this saga.
Attached Images
    

Last edited by mick92z : September 14th, 2012 at 01:19 AM. Reason: Removed derogatory remarks
  #31  
Old September 13th, 2012, 01:09 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: RogueKiller Installs Malware

Quote:
Originally Posted by mick92z
As for the 7zip ad, there was an opportunity ( or more ) to decline the software, though as Tigzy said , don't click on ads
Amen to that. Better yet, use an ad blocker and don't even subject yourself to the choice.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #32  
Old September 13th, 2012, 01:15 PM
mick92z's Avatar
mick92z mick92z is offline
Frequent Poster
 
Join Date: Apr 2007
Location: In the box
Posts: 354
Default Re: RogueKiller Installs Malware

Quote:
Originally Posted by Page42
Amen to that. Better yet, use an ad blocker and don't even subject yourself to the choice.
I do thats why I could not see the ads before
I had to disable it to see them
  #33  
Old September 13th, 2012, 01:21 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: RogueKiller Installs Malware

I figured you had an ad blocker. I was posting for the less enlightened among us, and apparently they are among us. We're all learning in this forum. This thread, though unfortunately titled, provides some definite do's and don'ts.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #34  
Old September 13th, 2012, 01:43 PM
zapjb's Avatar
zapjb zapjb is offline
Very Frequent Poster
 
Join Date: Nov 2005
Location: USA - Back in a real State in time for a real President.
Posts: 1,976
Default Re: RogueKiller Installs Malware

Image, image image.

I feel empathy towards OP.






But the clicky discussion reminds me when I 1st joined another forum that was not ......
The forum was clean. But the website itself was very dirty, it'd drop trojans by the minute.
Then people would come onto the forum & scream bloody murder. And the members would
just laugh & deride the n00bs. It was a l33t thing. Trial by fire. Good thing I used a different
nic over there. Ah back in the 98SE days.
__________________
PCLinuxOS - Radically simple, it just works. That's why PCLOS is "The Distro Hopper Stopper!"
http://www.pclinuxos.com/

If you don't use Linux. You're going to HELL!!!
  #35  
Old September 13th, 2012, 02:55 PM
Tigzy Tigzy is offline
Developer
 
Join Date: Sep 2012
Location: France
Posts: 15
Default Re: RogueKiller Installs Malware

Yes, that makes sense.
Don't blame me, ads are the only way to be remunerated while keeping the soft free of charges.
I'm not for adblockers (that's another debate) cause if everyone had them the web wouldn't be the same, everything would be not free. Think about it.

Ad is a thing, but I bet the infection was the other thing (userinit and so on...)
We you disinfect your box (supposed to be infected then), how can someone claims one of the tools he uses can be at the origin of an infection?
I guess maybe only specialists know that lots of rootkits are heavily dynamics (bringing lot of malware buddies to the party). This is a thing to consider, your box is maybe not clean, even now.
  #36  
Old September 13th, 2012, 03:40 PM
Rico's Avatar
Rico Rico is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Texas
Posts: 1,407
Default Re: RogueKiller Installs Malware

HMMMM.

You say:

Quote:
After executing the older version, R.K told me that a update was available , I clicked ok, and my browser opened at the R.K homepage. The program does not update, but simply offers you the option to download the latest version.
While on the homepage, I saw an advert at the top of the page for windows zip, so i download 7zsetup.exe ( or similar ) , sent it to V.T and got 4 detections for adware. ( betterinstaller )

So Tigzy site led you to the problem, correct? Do you honestly think you could go to say ESET home page then have a poisoned link. Seems like lack of control as to how RK is being sent out.

You clicked RK's site and from there led to malware. Seems you've proved my point Tigzy is not aware that his product leads to malware. With this being allowed to happen many beside me will have negative thoughts about Tigsy product.
__________________
"Fear is a poison provided by the mind, and courage is the antidote stored always ready in the soul." D. Koontz
  #37  
Old September 13th, 2012, 03:50 PM
mick92z's Avatar
mick92z mick92z is offline
Frequent Poster
 
Join Date: Apr 2007
Location: In the box
Posts: 354
Default Re: RogueKiller Installs Malware

Quote:
Originally Posted by Rico
.
So Tigzy site led you to the problem, correct? .
No, only minor adware, that needed you to click on an ad, and approval to install. ( user consent, several times )See my pictures.
What you had was something entirely different, altogether more serious.

Last edited by mick92z : September 14th, 2012 at 12:50 AM. Reason: made a derogatory remark
  #38  
Old September 13th, 2012, 04:08 PM
silat silat is offline
Regular Poster
 
Join Date: Oct 2006
Posts: 136
Default Re: RogueKiller Installs Malware

Quote:
Originally Posted by Rico
Jesus for the last FREAKING TIME

1 visit RK's web site
2. follow the link for download.
3. test using shadow mode
4. Copy RK to new FD
5. Click the icon, prompted RK update, here it said zip required & offered 7zip.

I FREAKING DID NOT CLICK ANY ADS JUST FOLLOWED INSTRUCTIONS FROM CLICKING RK'S ICON.

I say it's probable that you have no control what happens, when you authorize, others to pimp your product

Larger firms: Symantec MCAFEE, G-Data, KAV etc. etc. Seem to be able to control there products, so this does not happen to them. Even if a 3rd party added something to your product, this should be a warning to you Tigzy, as this only will sour me & others to your product.

Ok I just followed your directions and downloaded the item. It was fine and dandy for me.
__________________
Lew

Win7 64-Sandboxie Paid-
Malwarebytes and SAS On Demand Paid-VMware
Shadow Defender-Emisoft AntiMalware-WFC
  #39  
Old September 13th, 2012, 05:14 PM
Rico's Avatar
Rico Rico is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Texas
Posts: 1,407
Default Re: RogueKiller Installs Malware

Was fine and dandy for me, testing it, test machines had ad bloc + perhaps that's why I did not see the ads.

So in order to make a buck > RK's is distributed to sites that, attach some form of malware to RK's install or update routine, or make the ads viewable by clicking on RK? Is that a fair statement?
__________________
"Fear is a poison provided by the mind, and courage is the antidote stored always ready in the soul." D. Koontz
  #40  
Old September 14th, 2012, 12:56 AM
Longboard's Avatar
Longboard Longboard is offline
Massive Poster
 
Join Date: Oct 2004
Location: Sydney, Australia
Posts: 3,099
Default Re: RogueKiller Installs Malware

Quote:
Originally Posted by Rico
So in order to make a buck > RK's is distributed to sites that, attach some form of malware to RK's install or update routine, or make the ads viewable by clicking on RK? Is that a fair statement?
No.
Quote:
many beside me will have negative thoughts about Tigsy product.
I suspect not

OT: I cant recall 7Zip coming with all that crap attached ??
Just checked: If downloaded from home page: Nil attached.
__________________
Don't confuse me with someone who actually knows what they are talking about.
Linux Registered user 469135
Please, support Medecins Sans Frontieres

Last edited by Longboard : September 14th, 2012 at 01:05 AM.
  #41  
Old September 14th, 2012, 01:54 AM
Tigzy Tigzy is offline
Developer
 
Join Date: Sep 2012
Location: France
Posts: 15
Default Re: RogueKiller Installs Malware

Quote:
RK's is distributed to sites that, attach some form of malware to RK's install or update routine, or make the ads viewable by clicking on RK?

No. RK's webpage include ads, like ANY OTHER download website. Developers include them because their softwares are free or open source. What do you not understand? You want examples? Right.

notepad++ : http://notepad-plus-plus.org/fr/download/v6.1.7.html
softpedia : http://www.softpedia.com/get/Securit...ueKiller.shtml
01net : http://www.01net.com/telecharger/win...ger-25899.html

Quote:
So Tigzy site led you to the problem, correct? Do you honestly think you could go to say ESET home page then have a poisoned link. Seems like lack of control as to how RK is being sent out.

Why do you compare me to a million dollar company? That doesn't make sense, I'm a small dev working alone and for (almost) free.

I explained everything, but I guess you didn't read.
Please, have a look and use your common sense

Quote:
Yes, that makes sense.
Don't blame me, ads are the only way to be remunerated while keeping the soft free of charges.
I'm not for adblockers (that's another debate) cause if everyone had them the web wouldn't be the same, everything would be not free. Think about it.

Ad is a thing, but I bet the infection was the other thing (userinit and so on...)
We you disinfect your box (supposed to be infected then), how can someone claims one of the tools he uses can be at the origin of an infection?
I guess maybe only specialists know that lots of rootkits are heavily dynamics (bringing lot of malware buddies to the party). This is a thing to consider, your box is maybe not clean, even now.

Quote:
many beside me will have negative thoughts about Tigsy product.

If it'd be the case, I'd had to hire a secretary to answer the complaints. (FYI 20000 download per day, I'm approaching the 4 million downloads)
PS: BTW, 7-zip isn't an adware. it's an open source tool. I guess helpers would laugh if you claims being infected by him.

Last edited by Tigzy : September 14th, 2012 at 02:17 AM.
  #42  
Old September 14th, 2012, 08:58 AM
Rico's Avatar
Rico Rico is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Texas
Posts: 1,407
Default Re: RogueKiller Installs Malware

Uncle I give up.

1, RK is a fine product.
2. I clicked an ad after, dbl clicking RK
3. Tested RK with, with Adblockers ON, machine in question no Ad blockers
that's why I saw & incorrectly thought they were associated with RK,
My bad!
4. Can my Mea culpa, no allow, a lowering of defenses?

Thanks & Take Care
Rico
__________________
"Fear is a poison provided by the mind, and courage is the antidote stored always ready in the soul." D. Koontz
  #43  
Old September 14th, 2012, 09:42 AM
Tigzy Tigzy is offline
Developer
 
Join Date: Sep 2012
Location: France
Posts: 15
Default Re: RogueKiller Installs Malware

I sense a bit of sarcasms.
  #44  
Old September 14th, 2012, 09:47 AM
Rico's Avatar
Rico Rico is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Texas
Posts: 1,407
Default Re: RogueKiller Installs Malware

No sarcasm! Just a mistake on my part fueled by frustration. Sorry

Take Care
Rico
__________________
"Fear is a poison provided by the mind, and courage is the antidote stored always ready in the soul." D. Koontz
  #45  
Old September 14th, 2012, 09:49 AM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,791
Default Re: RogueKiller Installs Malware

@Rico

Where EXACTLY did you click when you downloaded RK on this site?
http://tigzy.geekstogo.com/roguekiller.php

Since I visited the site yesterday and in the square in the middle of the page it said "DOWNLOAD" in big green letters, but that in fact is the actual AD that you shouldn't click on.
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-
  #46  
Old September 14th, 2012, 10:10 AM
Tigzy Tigzy is offline
Developer
 
Join Date: Sep 2012
Location: France
Posts: 15
Default Re: RogueKiller Installs Malware

Adsense is known to provide targeted ads. For download webpages, they will choose ads with oversized big green download button. This is efficient because confusing.

If a mod / admin look at this, may he change the title for something less confusing?
  #47  
Old September 14th, 2012, 01:03 PM
LowWaterMark LowWaterMark is offline
Administrator
 
Join Date: Aug 2002
Location: New England
Posts: 15,543
Default Re: Does RogueKiller Install Malware? [Resolved: No it doesn't]

We're going to close this here since the actual circumstances regarding what happened seem to have been cleared up. And the thread starter has changed their position on this, as well.

RogueKiller does not install malware. It is very well known in the industry and is recommended by many of those who help others clean infected systems on a daily basis.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:29 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums