| View previous topic :: View next topic |
| Author |
Message |
questioneverything Newbie
Joined: 02 Dec 2004 Last Visit: 14 Dec 2004 Posts: 2
|
Posted: Thu Dec 02, 2004 9:24 pm Post subject: Some insight on xblock_free.exe please - very suspicious |
|
|
I Downloaded xcleaner_free.exe from
http://www.xblock.com/cgi-bin/download.pl/-13232-/xcleaner_free.exe
After running the application and exiting from the interface I noticed it kept itself resident in memory. When I returned to the http://spywarewarrior.com/ forum my firewall flagged a remote machine from the spywarewarrior domain attempting to control my machine via port 1181.
Whenever I attempted to navigate through the forum, the firewall flagged xcleaner_free.exe attempting to connect to the spywarewarrior IP. If the connection was ever allowed an immediate response to connect from the remote machine via 1181 was identified.
I find it awfully suspicious and a threat to this forum's credibility that xcleaner is placed as a sticky topic promoting the tool.
I have not had time to capture the packets or investigate further. Before I dig any deeper, would anyone like to share any insights.
OS: Windows 2000
Firewall: Sygate Pro _________________ question everything! |
|
| Back to top |
|
 |
3162 Honorary Site Admin

Joined: 31 Mar 2004 Last Visit: 04 May 2009 Posts: 4452
|
Posted: Sat Dec 04, 2004 4:42 pm Post subject: |
|
|
| Quote: |
| I find it awfully suspicious and a threat to this forum's credibility that xcleaner is placed as a sticky topic promoting the tool. |
Which sticky, please? _________________ Proud member of the Chest Zipper Club! |
|
| Back to top |
|
 |
questioneverything Newbie
Joined: 02 Dec 2004 Last Visit: 14 Dec 2004 Posts: 2
|
Posted: Tue Dec 14, 2004 8:30 am Post subject: forum with title: Sticky: Quick Fix for Spyware Removal |
|
|
This online scanner was developed in partnership with XBlock
Sticky: Quick Fix for Spyware Removal is peddling a trojan horse itself!
<rd/xblock/>, maker of X-Cleaner Spyware Remover. It scans for all supported "adwares" and many of the "spywares", keyloggers, and trojans that the downloadable freeware version <http://www.xblock.com/cgi-bin/download.pl/-13232-/xcleaner_free.exe> of X-Cleaner also targets.
This is the message contained within the sticky post.
I continue to investigate and this is really awful. This one act may destroy the hard work of so many committed to providing accurate information. Just think the forum disguises itself as a support tool only to peddle torjan horses and malware itself. Is it possible? Sure it is - consider history itself. Now ask yourself, how come no one is answering or investigating the issue. _________________ question everything! |
|
| Back to top |
|
 |
suzi Site Admin

Joined: 27 Jul 2003 Last Visit: 21 May 2013 Posts: 10271 Location: sunny California
|
Posted: Tue Dec 14, 2004 9:24 am Post subject: |
|
|
Could you please post a link to the sticky that you are referring to?
I'm not really clear on what you are saying here. _________________ Former Microsoft MVP 2005-2009, Consumer Security
Please do not PM or Email me for personal support. Post in the Forums instead and we will all learn.  |
|
| Back to top |
|
 |
xblocksys Malware Expert

Joined: 14 Dec 2004 Last Visit: 22 Aug 2006 Posts: 56
|
Posted: Tue Dec 14, 2004 10:00 am Post subject: |
|
|
The forum you are referring to seems to be spywareinfo.com? Are you saying Mike Healan is peddling spyware? I find that hard to believe.
In no way shape or form has Xblock ever downloaded a trojan horse on a person's harddrive or bundled rogue adware or spyware with our freeware. We have always been above aboard and have a long track record of this.
I will, however, have our tech team investigate the technical claims you make. Right off the bat I can tell you that X-cleaner freeware does NOT stay resident in memory. This is easily validated.
Can you provide the URL of the actual web page this was downloaded from- so we can eliminate the possability of some rogue using link masking. e.g. using the front of a reputable company to install their own form of malware.
| Quote: |
| When I returned to the http://spywarewarrior.com/ forum my firewall flagged a remote machine from the spywarewarrior domain attempting to control my machine via port 1181. |
You are saying that SpywareWarrior is attempting to control your machine? Are you also insinuating that SpywareWarrior is also in on this trojan behavior? Again, I find that hard, if not impossible to believe.
The only way to verify this claim is through analysis of the actual executable Can you also send, and this is important, a copy of the actual executable that you downloaded to coder@xblock.com.
We will get to the bottom of it and post our findings once you send the executable. But I assert again that we have and would never bundle a trojan horse with our software.
Not only is it illegal It just makes no sense whatsoever.
Thanks in advance.
Xblock
[/b] |
|
| Back to top |
|
 |
CYBERCYNIC Warrior

Joined: 14 Dec 2004 Last Visit: 15 Jul 2008 Posts: 53 Location: Emerald City
|
Posted: Tue Dec 14, 2004 10:06 am Post subject: |
|
|
I have a copy of X-cleaner free on my computer. It doesn't stay resident in memory, nor have I detected any suspicious internet activity.
LDH |
|
| Back to top |
|
 |
xblock Malware Expert

Joined: 11 Oct 2004 Last Visit: 28 Jan 2009 Posts: 6
|
Posted: Tue Dec 14, 2004 10:56 am Post subject: |
|
|
Since we are "questioning everything":
There are no known trojans using port 1181 according to this.
http://lists.sans.org/pipermail/list/2003-February/055710.html
Are you sure you are not running any P2P by any chance?
The only thing that I found using that port is "RappidAssist".
http://www.rapidassist.com/requirements.asp
This is a _commercially licensed_ remote assistance program. I very much doubt that a "hacker" would be using it, because:
- It needs to be licensed against a server
- It always requests authorisation from the user
- The user can always see what is going on. |
|
| Back to top |
|
 |
MadameX Site Admin

Joined: 12 Jul 2004 Last Visit: 27 Apr 2008 Posts: 1438
|
Posted: Tue Dec 14, 2004 11:09 am Post subject: |
|
|
After reading through this thread, I have to say, IMO, that this looks 'fishy' to me.
This person hasn't responded back to post.
Did he/she ever send any of the requested info to you, xblocksys?
If not, I'm of the mind that someone is trying to start trouble here.
Deb _________________ CARMA |
|
| Back to top |
|
 |
Crap Wear Worrier Warrior Guru

Joined: 08 Dec 2004 Last Visit: 05 May 2009 Posts: 364 Location: Far end of nowhere
|
Posted: Tue Dec 14, 2004 11:11 am Post subject: |
|
|
| Funny, that's what I wondered. |
|
| Back to top |
|
 |
xblock Malware Expert

Joined: 11 Oct 2004 Last Visit: 28 Jan 2009 Posts: 6
|
Posted: Tue Dec 14, 2004 11:30 am Post subject: |
|
|
As of time of this post, nobody at XBlock.com received any futher information on this, or any file.
I see the following scenarios possible (no judgement implied)
- poster is confused/has unrelated infection on his machine
- Poster is doing FUD campain for a competitor
When/If we receive an actual file looking like "X-Cleaner", but with any of the alleged behaviour then I will:
- Run yet another security check on our server
- Appologise to the poster for the initial sceptisim
- Try to track down who pulled this one off, send a horde of hungry lawyers at them, and feed whatever remains to a canine at hand.
- Send a documented log of the analysis and a warning accross the entire anti-spyware community
Side note:
We have thousands of downloads a day of X-Cleaner freeware (check the download.com stats) , so if either the X-Cleaner version was hacked on our site (or even if it was xblock that did it), I suspect there would be a hailstorm of complaints on the net.
What we _did_ see in the past is some spyware playing tricks with the HOST file or the browser to hinder people from downloading X-Cleaner. There is little we can do against that, you cannot remotely protect a users PC BEFORE he downloaded the software. |
|
| Back to top |
|
 |
wawadave Warrior Obsessed

Joined: 25 Jan 2004 Last Visit: 24 Jul 2009 Posts: 3448 Location: Illegitimus non carborundum
|
|
| Back to top |
|
 |
xblock Malware Expert

Joined: 11 Oct 2004 Last Visit: 28 Jan 2009 Posts: 6
|
Posted: Wed Feb 02, 2005 10:17 pm Post subject: Nothing received yet... |
|
|
As of the date of this post, nobody at XBlock Systems received any supplemental information on the initial claim, wheter directly or indirectly.
So, I suggest we call it "a post caused by a misunderstanding", and close the thread ?? |
|
| Back to top |
|
 |
3162 Honorary Site Admin

Joined: 31 Mar 2004 Last Visit: 04 May 2009 Posts: 4452
|
Posted: Thu Feb 03, 2005 5:17 am Post subject: |
|
|
Good enough for me.
Topic Locked. _________________ Proud member of the Chest Zipper Club! |
|
| Back to top |
|
 |
|