Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Do you trust the uninstaller?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
(topic move) Hard drive space disappearing, reappearing »
« (topic move) couldnt open disk multi(0)disk(0)rdisk(0). . .  
AuthorAll Replies


SnowyOne
Premium
join:2003-04-05
Kailua, HI
·RoadRunner Cable
·Clearwire Wireless

reply to RavonTUS
Re: Do you trust the uninstaller?

said by RavonTUS See Profile :

So, here is the big question...Do I trust their uninstall program?
Here's an incomplete list of what the "Uninstaller" does.
[ Changes to registry ]
* Creates key "HKLM\Software\AutoLoader\x3uJ1RMQWRMK".
* Sets value "x85fZPOPWCY5fV"="" in key "HKLM\Software\AutoLoader\x3uJ1RMQWRMK".
* Creates key "HKLM\Software\AutoLoader\x3u51RMQWRMK".
* Sets value "x85fZPOPWCY5fV"="" in key "HKLM\Software\AutoLoader\x3u51RMQWRMK".

[ Process/window information ]
* Enumerates running processes.
* Enumerates running processes several parses....

Here's the Jotti scan results

MD5 3e532491eff52adf0c7f2befd94d80a3
Packers detected: -
Scanner results
AntiVir Found Trojan/Dldr.Apropo.R
ArcaVir Found nothing
Avast Found Win32:Apropo-2
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found Adware/Apropos
Kaspersky Anti-Virus Found not-a-virus:AdWare.Apropos.q
NOD32 Found nothing
Norman Virus Control Found W32/Apropos.O
UNA Found nothing
VBA32 Found AdWare.Apropos.q

The "Uninstaller" has URL's as detected by Filealyzer

»download.contextplus.net/repermission/
»envolo.peopleonpage.com:80/servlets/auto
»envolo.peopleonpage.com:80/servlets/auto
»download.contextplus.net/apropos···ller.exe
»download.contextplus.net/apropos···ller.exe
»download.contextplus.net/shared/···ller.exe
»download.contextplus.net/shared/···ller.exe
»download.contextplus.net/
»envolo.peopleonpage.com:80/servlets/auto
»node2.ocslab.com/test/apropos/cl···ller.exe
»node2.ocslab.com/test/apropos/cl···ller.exe
»node2.ocslab.com/test/shared/Aut···ller.exe
»node2.ocslab.com/test/shared/Msv···ller.exe
»download.contextplus.net/
»node2.ocslab.com/apropos/client/···ller.exe
»node2.ocslab.com/apropos/client/···ller.exe
»node2.ocslab.com/shared/AutoUpda···ller.exe
»node2.ocslab.com/shared/Msvcp60Installer.exe

These URL's point to 4 different file downloads

"Msvcp60installer.Exe" * access denied when checking file properties
"a.exe" * access denied when checking file properties
"Aproposclientinstaller.Exe"
"Autoupdateinstaller.Exe"

Either these people have a serious problem with properly naming Exe's or this "Uninstaller" in reality is an "Installer"


IIIBradIII
Comm M-E-L Instr

join:2000-09-28
Greer, SC
Why is this sort of trickery and lies not illegal?!!
Thread is
Forums » Up and Running » Security » Security(topic move) Hard drive space disappearing, reappearing »
« (topic move) couldnt open disk multi(0)disk(0)rdisk(0). . .  


Monday, 09-Nov 04:42:03 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [156] Cable Uncapper Faces Criminal Charges
· [140] AT&T Sues Verizon Over 3G Ads
· [112] Why Run Fiber When You Can Run Ads That Pretend You Do?
· [109] Comcast Is Simply Getting Huge
· [93] Apple Cooking Up New $30 A Month TV Service?
· [83] Bits Of ACTA Agreement Leaking Out
· [80] Will 'Three Strikes' Come To The United States?
· [78] Verizon To Double Smartphone ETFs?
· [77] Verizon: Droid Tethering Will Cost $30 Extra
· [73] Comcast, NBC Deal Almost Complete
Most people now reading
· Lots of problems lately? [Rogers]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Framed for child porn 151; by a PC virus [Security]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Windows 7 boot manager editing questions [Microsoft Help]
· [Rant] Brand New 'Jasper' Xbox360 - RRoD Hardware Failure [Rants, Raves, and Praise]
· Upcoming Games for 2009 [PC gaming GAMES]
· Enhancement Shaman + Heirlooms, what to pick? [World of Warcraft]
· Garbage Disposal and Dishwasher [Home Repair & Improvement]