Beware: Unlocker 1.8.7 bundled with adware/spyware/junkware

Discussion in 'other software & services' started by Masterton, Jul 21, 2009.

Thread Status:
Not open for further replies.
  1. Darth AkSarBen

    Darth AkSarBen Registered Member

    Joined:
    Feb 4, 2008
    Posts:
    109
    Location:
    Near Fennville, MI USA
    I have the Unlocker 1.8.7 at home and used it and never had any issues with it. However, at the winery, I had it on one of the computers, and yesterday it said it was a Wine32/Agen.QBA trojan If I go to www.download.com and try to download it, our Nod 32 freezes the website and disconnects so that it cannot be downloaded. This is an odd thing. Why would this work and all of a sudden it now finds it as a trojan?
    Nod32 4.0.437.0 version. latest updates.
     
  2. MerleOne

    MerleOne Registered Member

    Joined:
    Mar 6, 2006
    Posts:
    1,336
    Location:
    France

    Maybe because NOD32 is signature-based and these are updated regularly. One day a file is OK, the day after it is blacklisted. It just happens. Try to upload the file to VirusTotal and check the result. If you decide this software is harmless, you can probably exclude him (potentially dangerous), or just try another one like LockHunter.
     
  3. Banger696

    Banger696 Registered Member

    Joined:
    Sep 6, 2006
    Posts:
    274
    I have just downloaded 1.8.7 from the official site and it appears the developer has cleaned it up. Nod32 was reporting a virus but the newly downloaded application is reporting as clean.
     
  4. 1boss1

    1boss1 Registered Member

    Joined:
    Jun 26, 2009
    Posts:
    401
    Location:
    Australia
    I've used Unlocker for a very long time without issue, however i decided to download it again and pull it to pieces.

    First Norton says fine:

    norton-alert.png

    I unpacked the installer with Universal Extractor, and this is a tree view of all files/folders packaged in the installer and the installer itself:

    Unlocker1.png

    The .sys driver contains references to functions such as ExFreePool, MmMapLockedPagesSpecifyCache, IoDeleteSymbolicLink, IoFileObjectType and various others that you would expect with a file unlocker.

    If the Ebay Shortcuts is unticked during install, the Unlocker code does exactly what it says on the tin and no more.

    Now, i also decompiled EbayShortcuts and went through all the ASM, now i'm no expert in malware binary analysis but i know enough to get by. You can see one of the strings the Ebay Shortcuts code references here:

    Unlocker2.png

    I don't really like this part, this installer is from adon-media.de GmbH a German site who state they are an online advertising site. The Ebay Shortcuts exe tries to connect with this URL using a "Get" query:

    _http://www.adon-media.de/red/2302/?s=Austria&c=1

    Which at the moment is showing a broken MySql query, the exe also drops cookies in locations such as this:

    It also fetches a page from Ebay using an "affiliate" query string in the URL. Here is the Anubis report of the Ebay exe file. I'd have to install Wireshark and test it a bit more, but if the cookie is indeed "forced" on the machine without the user choosing to visit Ebay of their own accord it's a breach of the Ebay affiliate agreement.

    As for what it's it's supposed to be pulling from that currently broken script above i can't tell it could of been anything. It could be a malware payload, it could be a cookie stuffing scheme where they force cookie on your machine to earn revenue, it could be a simple counter to gauge the number of installs.. Who knows.

    So, Unlocker itself is a good program and there's nothing untoward i can see if you install it and opt out of the Ebay options during install. However the author is using a really lousy affiliate company for revenue, and i don't particularly like what the Ebay Shortcuts does.
     
  5. Mors_Victrix

    Mors_Victrix Registered Member

    Joined:
    May 25, 2008
    Posts:
    24
    I'd suggest trying EjectUSB, I am using it for some time now and am very happy with it..
    http://www.pocketappreview.com/main/item/17

    As for unlocker, it helped me many times and am sorry to hear all this, but you can always install an older version if you don't trust the new one..
     
  6. demoneye

    demoneye Registered Member

    Joined:
    Dec 30, 2007
    Posts:
    1,356
    Location:
    ISRHell
    good thread!!

    good 2 know ulocker 1.8.X contain some sort of hidden stuff installing....
    a big ~offensive phrase removed~ from unlocker development team :thumbd: :mad: :mad: :mad:


    cheers:D
     
    Last edited by a moderator: Sep 17, 2009
  7. JerryM

    JerryM Registered Member

    Joined:
    Aug 31, 2003
    Posts:
    4,306
    I have used it for years with satisfaction. Evidently the latest version, 1.8.7 has some adware.
    What is that adware, and how is it harmful?

    Where can I find an older version that does not have the adware?

    Regards,
    Jerry
     
  8. GlobalForce

    GlobalForce Regular Poster

    Joined:
    Jun 30, 2004
    Posts:
    3,581
    Location:
    Garden State, USA
  9. axial

    axial Registered Member

    Joined:
    Jun 27, 2007
    Posts:
    479
    GF -- thank you for posting about the update!
     
  10. Banger696

    Banger696 Registered Member

    Joined:
    Sep 6, 2006
    Posts:
    274
    NOD32 is reporting an unwanted application in that download (v1.8.8 ), but when installed and ebay shortcuts unticked seems clean.
     
  11. MeFer

    MeFer Registered Member

    Joined:
    Dec 16, 2008
    Posts:
    89
  12. JerryM

    JerryM Registered Member

    Joined:
    Aug 31, 2003
    Posts:
    4,306
  13. Anonymous696

    Anonymous696 Registered Member

    Joined:
    May 28, 2009
    Posts:
    16
    How about using the portable version of Unlocker.

    Unlocker 1.8.8 Portable - From this website

    MD5: 1dde1b34286c82a8f32fa22c5677c38c / SHA1: c0811fdc3bb10f3b48f821c2e4905a0638aef78e


    http://ccollomb.free.fr/unlocker/#download
     
  14. pinso

    pinso Registered Member

    Joined:
    Jun 28, 2009
    Posts:
    257
    Location:
    India
    i absolutely agree with it too, after installing unlocker 1.8.8 my PC has started freezing, even after countless Restoring of my Backup,,,,somewhere this trojan seems to hide somewhere, dont download/install this stuff. It really is a junk n a tremendous wates of time, however i think this is an excellent program for removing TEMP files from the PC, which seems to stubbornly stick even after pressing the DELETE key, Unlocker does the job of unlocking and Deleting this files nicely.
    However Unlocker 1.8.5 is absolutely clean and i dont think any changes is their in this program.
    Download UNLOCKER 1.8.5:http://www.filehippo.com/download_unlocker/download/e2b3c414199c3ed0104f9be85802df77/
     
  15. 1boss1

    1boss1 Registered Member

    Joined:
    Jun 26, 2009
    Posts:
    401
    Location:
    Australia
    Has anyone found since upgrading to Win7 unlocker is useless and unlocks nothing?
     
  16. GlobalForce

    GlobalForce Regular Poster

    Joined:
    Jun 30, 2004
    Posts:
    3,581
    Location:
    Garden State, USA
    It's not intended for seven nor sixty-four compatible. LockHunter looks to be ;) the new kid on the block. <== Then, you knew this.
     
  17. thanatos_theos

    thanatos_theos Registered Member

    Joined:
    Apr 28, 2007
    Posts:
    582
    The Unlocker site is dead. Anyone know the new site or is the product discontinued? Thanks.

    hxxp://ccollomb.free.fr/unlocker/ - dead
     
  18. DOSawaits

    DOSawaits Registered Member

    Joined:
    Dec 11, 2008
    Posts:
    469
    Location:
    Belgium
    His malware is probably detected by all known anti-virus tools, so there's no more reason to share it.:cool:
     
  19. nomarjr3

    nomarjr3 Registered Member

    Joined:
    Jul 31, 2007
    Posts:
    502
    Yes, you are right.

    I unticked the check box for 'ebay shortcuts', but it seems Unlocker installed something related to eBay that sends hidden packets which somehow bypasses most software firewall.


    Removed it immediately.. I don't like software that do something fishy on my system :mad:
     
  20. GlobalForce

    GlobalForce Regular Poster

    Joined:
    Jun 30, 2004
    Posts:
    3,581
    Location:
    Garden State, USA
    Proof? or general comment (nomarjr3 only please)?

    "It seems Unlocker installed something related to eBay that sends hidden packets which somehow bypasses most software firewall."
     
  21. MerleOne

    MerleOne Registered Member

    Joined:
    Mar 6, 2006
    Posts:
    1,336
    Location:
    France
    Try LockHunter instead ?
     
  22. Chubb

    Chubb Registered Member

    Joined:
    Aug 9, 2005
    Posts:
    1,967
    LockHunter has been at beta 3 since Apr 2009. It is already 2010! Still at beta 3? Maybe LockHunter is dead already.
     
  23. MerleOne

    MerleOne Registered Member

    Joined:
    Mar 6, 2006
    Posts:
    1,336
    Location:
    France
    Maybe so, but it has been working flawlessly on all my systems. Since it is a free tool, I can understand the developer doesn't make it a priority.
     
  24. Pinga

    Pinga Registered Member

    Joined:
    Aug 31, 2006
    Posts:
    1,420
    Location:
    Europe
  25. culla

    culla Registered Member

    Joined:
    Aug 15, 2005
    Posts:
    504
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.