*WARNING* Format Factory now installs toolbars!

Discussion in 'other security issues & news' started by HAN, Apr 1, 2010.

Thread Status:
Not open for further replies.
  1. HAN

    HAN Registered Member

    Joined:
    Feb 24, 2005
    Posts:
    2,080
    Location:
    USA
    Just downloaded and installed the latest version of Format Factory 2.3. It installed the Ask Toolbar and something called the QuickStores Toolbar. Both were totally hidden installations. No chance to uncheck or disapprove of the installations.

    Too bad as this was a nice project. But it is now officially trashware! :mad:
     
  2. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
    where did you download it from?

    edit:n/m found it

    edit2: and so it does install 2 toolbars without your say so. That is notty and lame behaviour
     
    Last edited: Apr 1, 2010
  3. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    Strange how you didn't get the notification screen shown.This was from the download link on the developer's site.:doubt:
     

    Attached Files:

  4. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
    i also got it from developer's site, brothercom link. Maybe the installer is broken then.
     
  5. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    Yes it was the Brothersoft download I tried too,most odd.
     
  6. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
    did you extract the .exe from the .zip file or did you run from within it like i did? Using Win7
     
  7. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    I extracted it first,running on an XP VM.
     
  8. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
    do you have a moment to rerun it but this time from within .zip?
     
  9. HAN

    HAN Registered Member

    Joined:
    Feb 24, 2005
    Posts:
    2,080
    Location:
    USA
    Got it from the Brother link. I was very careful when installing it as they had an eBay shortcut before. But it was always out in the open. I swear, no warning this time until the toolbars were in... :(
     
  10. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    Just rolled back the VM and installed it directly from the zip,same result got the notification screen.Not sure what to make of it unless,as you say it was a faulty installer that's been rectified now.I only just downloaded it before posting here.

    HAN are you using Win7 too?
     
  11. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
    Thanks. I guess it might as well be some faulty install on OP's and my config
     
  12. HAN

    HAN Registered Member

    Joined:
    Feb 24, 2005
    Posts:
    2,080
    Location:
    USA
    No, XP Pro SP3. It cleaned off ok AFAIK. I was running with no extra safety net as this was always a reliable app before. Just normal AV and such. WinPatrol and MJ Registry Watcher went off thankfully...
     
  13. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    Ok I just installed this on my Vista system out of curiosity and the same as you guys it installed the junk silently.Seems that for some reason it works differently in a VM,it reminds me of the behaviour of some 'VM aware' malware.Time to restore a clean snapshot.
     
  14. HAN

    HAN Registered Member

    Joined:
    Feb 24, 2005
    Posts:
    2,080
    Location:
    USA
    Well, it doesn't make things any better but LOL, at least I know I'm not hallucinating in my old age... :D
     
  15. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    Haha no it seems something dodgy is going on.Shame because FF is supposedly awesome at what it does.
     
  16. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
    and I installed it in VM and guess what....got the prompt for the toolbars. Well well
     
  17. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    It's very suspicious rogue like behaviour if this is intentional.It'll be worth seeing what feedback there is over this issue since FF is (was) extremely popular.I just hope this isn't the start of a new trend in silent junkware installs.
     
  18. Amishrabbit

    Amishrabbit Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1
    I just did a similar test. I have VMWare VMs with XP SP1, SP2, and SP3 installed, and a real testbed running XP SP2. I downloaded the FormatFactory 2.30 installer from http://www.brothersoft.com/download-formatfactory-98431.html (linked from http://www.formatoz.com/download.html) and ran the installer under each clean VM and the real box.

    Under VMWare XP SP1 and SP2, the installer caused a bluescreen during installation. Screenshot attached.

    Research_XP_2010-2010-04-02-10-42-00.png

    After a reboot, the program appeared to work fine (though I didn't test all its functions) and there were no Ask or shopping toolbars installed. Presumably, the bluescreen interrupted the installation process before the Ask toolbar executable was able to run.

    The installer completed the installation process in SP3, including the opt-out dialog box at the end (shown higher up in the thread). The program did not install the toolbar when all the checkboxes were cleared.

    On the real box, the installer completed the installation, and displayed the same 'opt-out' dialog box, observing my preferences when I deselected the checkboxes.

    I recorded a movie of the entire installation process showing the before and after state of IE with no toolbars. If I can figure out where to upload and link this quicktime file, I will do so. (Suggestions welcomed)

    If you were to use Universal Extractor on the installer (http://legroom.net/software/uniextract) you would be able to see that it is a 7zip compressed NSIS installer file. Uniextract easily took it apart. When you do this, you will find all the Ask.com toolbar executables in a subdirectory named $PLUGINSDIR

    The NSIS.nsi script (a file embedded in all NSIS installers that drives the installer Wizard and background processes during installation) does not contain any code for "VM Aware" behavior as described above. You can validate this for yourself. I find it hard to believe that it would behave differently in a different OS, but I don't have a Vista testbed on which to test it.

    Don't know what to say, but obviously your mileage may vary. I am not an apologist for Ask.com but unlike some of you I could not reproduce the alleged behavior where the dialog does not appear on a real box but appears on a VM.

    -=A
     
  19. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
    and it does vary + we don't get the bsod on the install either VM or real box but then we don't get prompts for toolbars if in real box (and so far on XP, Vista and Win7). Whatever it is it should be fixed to always prompt for toolbars. Always
     
  20. lubieplacki

    lubieplacki Registered Member

    Joined:
    Mar 24, 2010
    Posts:
    151
    Location:
    Poland
    I downloaded FormatFactory from FormatFactory homepage. Packed in .zip archiwe. After instalation I have screen like in post number 3. I'm using XP SP3.
     
  21. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    It would appear that this is a bug somewhere in the installer rather than intentionally stealthy behaviour,something must be blocking the option screen from running for some users.o_O
     
  22. skbaltimore

    skbaltimore Registered Member

    Joined:
    Jul 5, 2004
    Posts:
    306
    I just d/l'd & installed Format Factory 2.30. I'm running XP Pro SP3, and unzipped/extracted the d/l prior to installing. I noticed the options to install all that crap, and didn't like the fact that it was even there, but there was definitely an option to NOT install the stuff, by unchecking the boxes that were checked by default. This is the first time I've ever used this program, so I have no past track record. But I'd seen a comment somewhere that this program had adware, and when I saw the toolbars I had an idea where the criticism was coming from -- especially if there were versions in which the option to not install was absent.
     
    Last edited: May 27, 2010
  23. sg09

    sg09 Registered Member

    Joined:
    Jul 11, 2009
    Posts:
    2,713
    Location:
    Kolkata, India
    While I installed it I got the options too...
     
Loading...
Thread Status:
Not open for further replies.