Majorgeeks.com!!

Discussion in 'malware problems & news' started by assersegsten, Aug 29, 2018.

  1. assersegsten

    assersegsten Registered Member

    Joined:
    Sep 13, 2016
    Posts:
    73
    Location:
    denmark
    Hello everyone,I just want to warn everybody against what you download at Majorgeeks.com,yesterday an update for the Pale Moon browser(64-bit)was ready download,but the file was infected with ransomware,but Bitdefender saved my *** and restored my files,I do not know the variant,I just know what Bitdefender reported back to me,so please be careful.

    Regards assersegsten.

    PS. it is the first time I ever encountered any problems with files from Majorgeeks.com.
     
  2. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    That's scary. Are you sure it wasn't a false positive? BD can be a little over enthusiastic at times.
     
  3. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Please keep us updated. If your experience was authentic then Houston we have a problem.

    Majorgeeks is generally been safe as far as I know but on a recent visit of my own, and it's been well over a year since I D/L'ed anything from the site, I was properly annoyed when an in-your-face slide in showed up. Ticked me off and away I went.
     
  4. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    @assersegsten Did you download it from one of links you can see on the right side of the following image? The reason I ask, is that you'll often find ads with download links on MajorGeeks, which can lead to downloading the program advertised, rather than the software you wanted to download. The downloads you can see in the image are direct links to the author's site.
    MG..png

    I just downloaded the 64 bit version and it was not detected, when I scanned it at VirusTotal. I can see that the current version was released only about a day ago.
     
    Last edited: Aug 29, 2018
  5. guest

    guest Guest

    Sometimes Majorgeeks is hosting downloads "Download@MajorGeeks" , sometimes the link of the download is redirected to the Author's site: "Download@Authors Site"
    In the case of Palemoon the installer is downladed from the Author's Site ("Download@Authors Site"):
    Code:
    http://relmirror.palemoon.org/release/palemoon-28.0.0.1.win32.installer.exe
    http://relmirror.palemoon.org/release/palemoon-28.0.0.1.win64.installer.exe
    
    Nethertheless it is always a good idea to check the hashsum before launching of downloadeded installers [sadly not all are providing hashes on their website].
    Hashsums (and GPG Signatures) are available on the website of PaleMoon.
     
    Last edited by a moderator: Aug 29, 2018
  6. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,351
    Location:
    Europe, UE citizen
    Someone that already use a VM - for example - could repeat the download and send the file to Virus Total.
     
  7. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    I already did that and the file was not detected. I don't use a VM, but there was no need, as I was just scanning the file, not running it.
     
  8. assersegsten

    assersegsten Registered Member

    Joined:
    Sep 13, 2016
    Posts:
    73
    Location:
    denmark
    Yes I downloaded it from the links you have shown.:)
     
  9. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Kaspersky says it's clean. I'd assume a false positive. I've never had an infected file from MajorGeeks. I've visited their site daily form many years.
     
  10. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    I have never had issues from MajorGeeks either and is the only site I recommend if you can't get it from the Authors site.
     
  11. Rainwalker

    Rainwalker Registered Member

    Joined:
    May 18, 2003
    Posts:
    2,720
    Location:
    USA
    I have been using MajorGeeks for many years and never had a single problem.
     
  12. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,951
    I usually download my programs from the author's site, but Majorgeeks is the only place where I also download programs every now and then. I absolutely trust them; one of my daily go-to websites.
     
  13. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    Can someone explain to me how to safely download ImgBurn.exe from www dot ImgBurn dot com ?
     
  14. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,077
    Location:
    U.S.A.
  15. guest

    guest Guest

    Mirror 7 is an installer bundled with InstallCore (PUP)
    Without OpenCandy = for example Mirror 4 [free-codecs] or Mirror 6 [Majorgeeks]
    (3.101.913 bytes - SHA256: 49AA06EAFFE431F05687109FEE25F66781ABBE1108F3F8CA78C79BDEC8753420)
     
    Last edited by a moderator: Aug 29, 2018
  16. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,077
    Location:
    U.S.A.
    OK, that's good to know. Thanks!
     
  17. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    That's the one!

    kind of what I figured after scanning it via VirusTotal, at least in terms of it being laced with crapware. My question was sort of a rhetorical one, although I wasn't sure if there was a way to download the file without the wrapper crap attached to it from ImgBurn dot com. I also noticed the checksum of the tainted download matched the checksum when I used
    Code:
    certUtil -hashfile pathToFileToCheck
    run from a command line.

    Thank you for checking!
     
  18. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    It is using InstallCore, not OpenCandy. But, that doesn't matter, as they both work the same way. It's safe to run the installer, because if you pay attention when installing and decline the offer to install third party software, then only ImgBurn will be installed. Alternatively, you can use the installer from MajorGeeks, as it does not use InstallCore and as a result, does not come bundled with any extras.
     
  19. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    I would be interested to know what scanners detected it and what it was detected as, because, it quite possibly was a false positive.
     
  20. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,077
    Location:
    U.S.A.
    roger_m, thanks for the clarification. :thumb:
     
  21. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    It used to come bundled with OpenCandy from the dev site and there was no way to opt out. Good to see there has been a change, not that I use ImgBurn these days.
     
  22. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    Fair enough, and I remember you pointing this sort of thing out in a different thread a while back, so I kind of figured the option to avoid the crapware was available in this download, but that makes it no more appealing to me. All I ever want out of any download is the exact file I'm after, without the song and dance of having to opt out of the crapware during the installation. There's no question in my mind the creator of these wrapper downloads is to trick the individual into installing all the garbage that comes with them. Their intentions are nefarious in nature. Even though one can opt out, it would be very easy for the unaware to miss it and unintentionally install the included garbage.

    This is clearly a case where downloading from the developer's website, even where the checksum matches, does not actually result in a safe download. I used to be a proponent of this approach and even preached about it in these forums, but recently I realized it doesn't guarantee a clean and safe download.
     
  23. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    You should always be able to opt out of OpenCandy. If you couldn't opt out, then something must have gone wrong. OpenCandy and InstallCore are essentially the same.
     
  24. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    If you pay attention during the install, then it's easy to opt out. These days, you need to pay close attention when installing any software.
    Yes, they make money from the installs of unwanted software and that is why it is installed by default.
     
  25. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Roger, it was written in the EULA that if you wanted to install ImgBurn you had to accept the PUP. There was no box to uncheck. I had MBAM 2.x at the time and it removed OpenCandy.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.