topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Friday December 13, 2024, 6:45 pm
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Author Topic: SmartFTP Users: Adware As Of v.2.5.1004.7  (Read 16682 times)

Nighted

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 572
  • Meat Popsicle
    • View Profile
    • Nighted@deviantART
    • Donate to Member
SmartFTP Users: Adware As Of v.2.5.1004.7
« on: March 03, 2007, 05:58 PM »
Downloaded this from Filehippo today. It tried to add a runonce to my registry concerning this file: NSIS.Library.RegTool.v2.{C480568F-0B79-433A-8399-52D704BACE84}.exe.

Searching shows that this is verified 100% adware. The company that produces this garbage is here: nsismedia.net

One detailed report here.

It was confusing at first as NSIS to me always means Nullsoft Install System, but my spidey sense told me something else entirely. ;)


I`m a firm believer in the philosophy of a ruling class, especially since I rule.
« Last Edit: March 03, 2007, 06:02 PM by Nighted »

dk70

  • Charter Member
  • Joined in 2005
  • ***
  • Posts: 269
    • View Profile
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #1 on: March 03, 2007, 06:51 PM »
I just downloaded and installed SmartFTP from Filehippo. Kaspersky, S&D and I could not recognize NSIS, no file traces. Same version, file is called SFTPNSI.EXE, 3.337.00 bytes.

f0dder

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 9,153
  • [Well, THAT escalated quickly!]
    • View Profile
    • f0dder's place
    • Read more about this member.
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #2 on: March 03, 2007, 06:55 PM »
Might want to throw in md5 sums as well, for good measure.

Offtopic: nighted, what's the screenshot from? explorer with custom color scheme? looks nice :)
- carpe noctem

dk70

  • Charter Member
  • Joined in 2005
  • ***
  • Posts: 269
    • View Profile
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #3 on: March 03, 2007, 07:03 PM »
Since you are infected http://kichik.net/20.../nsis-media-remover/ but other programs should be able to handle it by now. May be some useful info in comments.


Nighted

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 572
  • Meat Popsicle
    • View Profile
    • Nighted@deviantART
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #4 on: March 03, 2007, 07:11 PM »
f0dder, yeah it's a 3D Color Changer scheme. The script is attached.

Can't create a checksum, I deleted the file immediately after blocking the entry from entering my registry and taking the screenshot.
I`m a firm believer in the philosophy of a ruling class, especially since I rule.

Nighted

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 572
  • Meat Popsicle
    • View Profile
    • Nighted@deviantART
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #5 on: March 03, 2007, 07:13 PM »
dk70, I'm not infected. I blocked the registry entry that was to be run on the next reboot and I deleted the file.
I`m a firm believer in the philosophy of a ruling class, especially since I rule.

dk70

  • Charter Member
  • Joined in 2005
  • ***
  • Posts: 269
    • View Profile
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #6 on: March 03, 2007, 07:22 PM »
But if NSIS came from other source than SmartFTP? I dont know. If the regular security programs say you are clean and there are none of those traces I guess you are. NSB133.TMP is also not part of SmartFTP, or I dont have it at least, so who knows what damage have been done.

SmartFTP people cant be that dumb? Would be nice if Filehippo reported back to you and confirmed initial version was infected with adware installation.
« Last Edit: March 03, 2007, 07:27 PM by dk70 »

Nighted

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 572
  • Meat Popsicle
    • View Profile
    • Nighted@deviantART
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #7 on: March 03, 2007, 08:08 PM »
dk70, I think you may be right...I'm going to have to look into this immediately.

I may have stupidly jumped to a conclusion here. I tried the installer sandboxed to see if the files would appear again but no luck. It's just that it coincided with the install of the new SmartFTP revision.  :-[

Here's the MD5 hash of the installer I downloaded in case anyone wants to compare: D2D9547FE2C0A4DD7866EEC6DB10AB1D
I`m a firm believer in the philosophy of a ruling class, especially since I rule.
« Last Edit: March 03, 2007, 08:14 PM by Nighted »

dk70

  • Charter Member
  • Joined in 2005
  • ***
  • Posts: 269
    • View Profile
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #8 on: March 03, 2007, 08:25 PM »
Same as mine and same as the one FileHippo list http://www.filehippo...nload_smartftp/tech/

SMARTFTP.KEY is your license file right? I dont have that either. You didnt use a key-thingy to make that file? Crap must come from somewhere so just asking. You can see from Google http://openwares.org./ has been and may be still is a distribution center of this, any downloads from there?
« Last Edit: March 03, 2007, 08:30 PM by dk70 »

Nighted

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 572
  • Meat Popsicle
    • View Profile
    • Nighted@deviantART
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #9 on: March 03, 2007, 09:09 PM »
I put the keyfile there to make it portable in conjunction with an autoit script.

Never downloaded anything from that site. However, I did upgrade Messenger Plus! last night and that may have something to do with it although I didn't select the ad sponsored option. 
I`m a firm believer in the philosophy of a ruling class, especially since I rule.
« Last Edit: March 03, 2007, 09:12 PM by Nighted »

dk70

  • Charter Member
  • Joined in 2005
  • ***
  • Posts: 269
    • View Profile
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #10 on: March 03, 2007, 10:02 PM »
I think Messenger Plus have gotten so much attention for being carrier of Adware they would not do such a thing. Many find it bad enough as it is.

Anyway, I checked Spybot&Destroy for NSIS. They added it October last year and have updated many times, last January. So I guess we can assume S&D will catch this. I guess same goes for similar tools. I would scan over and over. From the comments at the NSIS remover page disinfection appears to be hard so grab what you can and attack.

If not successful may be an idea to go through a Hijackthis rutine - post it at some security forum like this http://forums.majorg...orumdisplay.php?f=35 , if not here. Could be necessary to seek geeks if removal is impossible unless following a specific order of actions.

What AV let this happen btw?

Nighted

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 572
  • Meat Popsicle
    • View Profile
    • Nighted@deviantART
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #11 on: March 03, 2007, 11:26 PM »
h3h...no AV let this happen. My other machine died, second MSI motherboard dead in a year. (Will never buy anything from MSI again.) I'm on my backup Celeron 850 machine now and turned my virus scanner off last night so I could free up some resources for other things. So, my bad. :tellme:

I'll have it fixed up as good as new in a few hours.
I`m a firm believer in the philosophy of a ruling class, especially since I rule.

KenR

  • Super
  • Blogger
  • Joined in 2006
  • ***
  • Posts: 826
    • View Profile
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #12 on: March 05, 2007, 08:36 AM »
Ok, I'm confused. According to SmartFTP's homepage, the most recent version of the software is   SmartFTP 2.0 Build 1002. I see nothing about Beta or trial versions. So, how can there even be a  version 2.5.x and where is it coming from?

Thanks, Ken

Kenneth P. Reeder, Ph.D.
Clinical Psychologist
Jacksonville, North Carolina  28546

dk70

  • Charter Member
  • Joined in 2005
  • ***
  • Posts: 269
    • View Profile
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #13 on: March 05, 2007, 12:21 PM »
It is a beta, FileHippo has it. But also available at their site - http://www.smartftp.com/download/ at bottom.

I tend to agree with the SmartFTP guy replying on their forum Nighted. But sure is strange, installation process must have been corrupted in your case or did you cancel during and mistook leftovers for NSIS Media because names are similar? Too much security is problem ;)

Nighted

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 572
  • Meat Popsicle
    • View Profile
    • Nighted@deviantART
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #14 on: March 05, 2007, 04:53 PM »
I have no clue what happened. I scanned every drive and found nothing, absolutely zilch. That with fully updated databases for both my virus scanner and malware apps.

My system couldn't be any cleaner. Now it seems most likely it loaded through IE, as IE has always been how I've become infected with malware in the past. I very rarely use it, and the moments my AV was disabled were probably enough to let something get by.

I`m a firm believer in the philosophy of a ruling class, especially since I rule.

KenR

  • Super
  • Blogger
  • Joined in 2006
  • ***
  • Posts: 826
    • View Profile
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #15 on: April 04, 2007, 06:46 PM »
Ok, SmartFTP is now out of Beta. What is the verdict on this topic? Does it contain spyware or not?

Ken
Kenneth P. Reeder, Ph.D.
Clinical Psychologist
Jacksonville, North Carolina  28546

Nighted

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 572
  • Meat Popsicle
    • View Profile
    • Nighted@deviantART
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #16 on: April 05, 2007, 08:28 PM »
No Ken, it doesn't. It was just a fluke incident.
I`m a firm believer in the philosophy of a ruling class, especially since I rule.

KenR

  • Super
  • Blogger
  • Joined in 2006
  • ***
  • Posts: 826
    • View Profile
    • Donate to Member
Re: SmartFTP Users: Adware As Of v.2.5.1004.7
« Reply #17 on: April 05, 2007, 08:44 PM »
Great!!! Thanks very much for letting me know Nighted!

Ken
Kenneth P. Reeder, Ph.D.
Clinical Psychologist
Jacksonville, North Carolina  28546