Spyware Warrior Spyware Warrior
Help with Spyware, Hijacking & Other Internet Nuisances
 
FAQ :: Search :: Memberlist :: Usergroups :: Register
Profile :: Log in to check your private messages :: Log in

Some insight on xblock_free.exe please - very suspicious

 
Post new topic   This topic is locked: you cannot edit posts or make replies.    Spyware Warrior Forum Index -> Anti-Spyware and Security Software Discussion
View previous topic :: View next topic  
Author Message
questioneverything
Newbie


Joined: 02 Dec 2004
Last Visit: 14 Dec 2004
Posts: 2

PostPosted: Thu Dec 02, 2004 9:24 pm    Post subject: Some insight on xblock_free.exe please - very suspicious Reply with quote

I Downloaded xcleaner_free.exe from

http://www.xblock.com/cgi-bin/download.pl/-13232-/xcleaner_free.exe

After running the application and exiting from the interface I noticed it kept itself resident in memory. When I returned to the http://spywarewarrior.com/ forum my firewall flagged a remote machine from the spywarewarrior domain attempting to control my machine via port 1181.

Whenever I attempted to navigate through the forum, the firewall flagged xcleaner_free.exe attempting to connect to the spywarewarrior IP. If the connection was ever allowed an immediate response to connect from the remote machine via 1181 was identified.

I find it awfully suspicious and a threat to this forum's credibility that xcleaner is placed as a sticky topic promoting the tool.

I have not had time to capture the packets or investigate further. Before I dig any deeper, would anyone like to share any insights.


OS: Windows 2000
Firewall: Sygate Pro
_________________
question everything!
Back to top
View user's profile Send private message
3162
Honorary Site Admin


Joined: 31 Mar 2004
Last Visit: 04 May 2009
Posts: 4452

PostPosted: Sat Dec 04, 2004 4:42 pm    Post subject: Reply with quote

Quote:
I find it awfully suspicious and a threat to this forum's credibility that xcleaner is placed as a sticky topic promoting the tool.


Which sticky, please?
_________________
Proud member of the Chest Zipper Club!
Back to top
View user's profile Send private message
questioneverything
Newbie


Joined: 02 Dec 2004
Last Visit: 14 Dec 2004
Posts: 2

PostPosted: Tue Dec 14, 2004 8:30 am    Post subject: forum with title: Sticky: Quick Fix for Spyware Removal Reply with quote

This online scanner was developed in partnership with XBlock
Sticky: Quick Fix for Spyware Removal is peddling a trojan horse itself!

<rd/xblock/>, maker of X-Cleaner Spyware Remover. It scans for all supported "adwares" and many of the "spywares", keyloggers, and trojans that the downloadable freeware version <http://www.xblock.com/cgi-bin/download.pl/-13232-/xcleaner_free.exe> of X-Cleaner also targets.


This is the message contained within the sticky post.

I continue to investigate and this is really awful. This one act may destroy the hard work of so many committed to providing accurate information. Just think the forum disguises itself as a support tool only to peddle torjan horses and malware itself. Is it possible? Sure it is - consider history itself. Now ask yourself, how come no one is answering or investigating the issue.
_________________
question everything!
Back to top
View user's profile Send private message
suzi
Site Admin


Joined: 27 Jul 2003
Last Visit: 21 May 2013
Posts: 10271
Location: sunny California

PostPosted: Tue Dec 14, 2004 9:24 am    Post subject: Reply with quote

Could you please post a link to the sticky that you are referring to?

I'm not really clear on what you are saying here.
_________________
Former Microsoft MVP 2005-2009, Consumer Security
Please do not PM or Email me for personal support. Post in the Forums instead and we will all learn. Smile
Back to top
View user's profile Send private message Visit poster's website
xblocksys
Malware Expert


Joined: 14 Dec 2004
Last Visit: 22 Aug 2006
Posts: 56

PostPosted: Tue Dec 14, 2004 10:00 am    Post subject: Reply with quote

The forum you are referring to seems to be spywareinfo.com? Are you saying Mike Healan is peddling spyware? I find that hard to believe.

In no way shape or form has Xblock ever downloaded a trojan horse on a person's harddrive or bundled rogue adware or spyware with our freeware. We have always been above aboard and have a long track record of this.

I will, however, have our tech team investigate the technical claims you make. Right off the bat I can tell you that X-cleaner freeware does NOT stay resident in memory. This is easily validated.

Can you provide the URL of the actual web page this was downloaded from- so we can eliminate the possability of some rogue using link masking. e.g. using the front of a reputable company to install their own form of malware.

Quote:
When I returned to the http://spywarewarrior.com/ forum my firewall flagged a remote machine from the spywarewarrior domain attempting to control my machine via port 1181.


You are saying that SpywareWarrior is attempting to control your machine? Are you also insinuating that SpywareWarrior is also in on this trojan behavior? Again, I find that hard, if not impossible to believe.

The only way to verify this claim is through analysis of the actual executable Can you also send, and this is important, a copy of the actual executable that you downloaded to coder@xblock.com.

We will get to the bottom of it and post our findings once you send the executable. But I assert again that we have and would never bundle a trojan horse with our software.

Not only is it illegal It just makes no sense whatsoever.

Thanks in advance.

Xblock

[/b]
Back to top
View user's profile Send private message Visit poster's website
CYBERCYNIC
Warrior


Joined: 14 Dec 2004
Last Visit: 15 Jul 2008
Posts: 53
Location: Emerald City

PostPosted: Tue Dec 14, 2004 10:06 am    Post subject: Reply with quote

I have a copy of X-cleaner free on my computer. It doesn't stay resident in memory, nor have I detected any suspicious internet activity.

LDH
Back to top
View user's profile Send private message
xblock
Malware Expert


Joined: 11 Oct 2004
Last Visit: 28 Jan 2009
Posts: 6

PostPosted: Tue Dec 14, 2004 10:56 am    Post subject: Reply with quote

Since we are "questioning everything":

There are no known trojans using port 1181 according to this.
http://lists.sans.org/pipermail/list/2003-February/055710.html

Are you sure you are not running any P2P by any chance?

The only thing that I found using that port is "RappidAssist".
http://www.rapidassist.com/requirements.asp

This is a _commercially licensed_ remote assistance program. I very much doubt that a "hacker" would be using it, because:
- It needs to be licensed against a server
- It always requests authorisation from the user
- The user can always see what is going on.
Back to top
View user's profile Send private message Visit poster's website
MadameX
Site Admin


Joined: 12 Jul 2004
Last Visit: 27 Apr 2008
Posts: 1438

PostPosted: Tue Dec 14, 2004 11:09 am    Post subject: Reply with quote

After reading through this thread, I have to say, IMO, that this looks 'fishy' to me.

This person hasn't responded back to post.

Did he/she ever send any of the requested info to you, xblocksys?

If not, I'm of the mind that someone is trying to start trouble here.

Deb
_________________
CARMA
Back to top
View user's profile Send private message Visit poster's website
Crap Wear Worrier
Warrior Guru


Joined: 08 Dec 2004
Last Visit: 05 May 2009
Posts: 364
Location: Far end of nowhere

PostPosted: Tue Dec 14, 2004 11:11 am    Post subject: Reply with quote

Funny, that's what I wondered.
Back to top
View user's profile Send private message
xblock
Malware Expert


Joined: 11 Oct 2004
Last Visit: 28 Jan 2009
Posts: 6

PostPosted: Tue Dec 14, 2004 11:30 am    Post subject: Reply with quote

As of time of this post, nobody at XBlock.com received any futher information on this, or any file.

I see the following scenarios possible (no judgement implied)
- poster is confused/has unrelated infection on his machine
- Poster is doing FUD campain for a competitor

When/If we receive an actual file looking like "X-Cleaner", but with any of the alleged behaviour then I will:

- Run yet another security check on our server
- Appologise to the poster for the initial sceptisim
- Try to track down who pulled this one off, send a horde of hungry lawyers at them, and feed whatever remains to a canine at hand.
- Send a documented log of the analysis and a warning accross the entire anti-spyware community

Side note:
We have thousands of downloads a day of X-Cleaner freeware (check the download.com stats) , so if either the X-Cleaner version was hacked on our site (or even if it was xblock that did it), I suspect there would be a hailstorm of complaints on the net.

What we _did_ see in the past is some spyware playing tricks with the HOST file or the browser to hinder people from downloading X-Cleaner. There is little we can do against that, you cannot remotely protect a users PC BEFORE he downloaded the software.
Back to top
View user's profile Send private message Visit poster's website
wawadave
Warrior Obsessed


Joined: 25 Jan 2004
Last Visit: 24 Jul 2009
Posts: 3448
Location: Illegitimus non carborundum

PostPosted: Tue Dec 14, 2004 4:40 pm    Post subject: Reply with quote

sounds like an infection allready presant.
and i thought only ms used fud? Evil or Very Mad
_________________
RFID tags! SPYWARE
Tired of proprietary Cor-pirationware?
http://www.openoffice.org/
Installing Vista http://tinyurl.com/2l9qyd
Back to top
View user's profile Send private message Send e-mail Visit poster's website
xblock
Malware Expert


Joined: 11 Oct 2004
Last Visit: 28 Jan 2009
Posts: 6

PostPosted: Wed Feb 02, 2005 10:17 pm    Post subject: Nothing received yet... Reply with quote

As of the date of this post, nobody at XBlock Systems received any supplemental information on the initial claim, wheter directly or indirectly.

So, I suggest we call it "a post caused by a misunderstanding", and close the thread ??
Back to top
View user's profile Send private message Visit poster's website
3162
Honorary Site Admin


Joined: 31 Mar 2004
Last Visit: 04 May 2009
Posts: 4452

PostPosted: Thu Feb 03, 2005 5:17 am    Post subject: Reply with quote

Good enough for me.
Topic Locked.
_________________
Proud member of the Chest Zipper Club!
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   This topic is locked: you cannot edit posts or make replies.    Spyware Warrior Forum Index -> Anti-Spyware and Security Software Discussion All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



smartBlue Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group