We're back online!

Welcome to Leechermods 2026 We’re officially heading into our  20th year !   Apologies for the recent downtime; I've been busy updating our  DNS configurations  for better security ( HTTPS ). A full site redesign (CSS, HTML, Java and AI features) is also on the way to fix broken graphics and sync up with a new CDN server .  Stay tuned!

Malicious BitTorrent Clients: New Coat of Paint, Same Bad Story

Malware Warning in these BitTorrent Clients!!! "TorrentSpy is promoting a malicious BitTorrent client. Operating a BitTorrent site can incur significant costs, particularly when involved in litigation with organizations such as the MPAA. However, endorsing harmful BitTorrent clients like Get-Torrent to your user base is not an appropriate resolution, even if financial incentives are offered per installation. It appears that financial considerations may be influencing these decisions. Get-Torrent is among numerous malicious BitTorrent clients advertised on various torrent platforms. These clients, along with a range of other free malware applications, are developed and distributed by WakeNet AB, a Swedish company based in Stockholm and Berg. Their primary objective is to entice individuals into downloading seemingly useful applications, only to infect their computers with adware bundles that are challenging to remove. Despite numerous forum discussions, including those on TorrentSpy, cautioning unsuspecting users about these clients, TorrentSpy continues to actively promote Get-Torrent, leading to the infection of hundreds of their users' computers and a proliferation of intrusive pop-up advertisements. In contrast to TorrentSpy, the majority of BitTorrent site administrators decline to advertise these clients. The Pirate Bay and Mininova have successfully prohibited these malicious clients from advertising through Adbrite, and BTjunkie and many other sites also refuse to host them.
The malware distributed with BitTorrent clients such as Get-Torrent, Torrent101, TorrentQ, and BitRoll is a sponsored program known as "Cidhelp." While it is ostensibly removable via the Windows Control Panel, anti-spyware or anti-virus programs frequently corrupt its files, rendering uninstallation impossible while the program continues to generate numerous pop-up advertisements.

In April ran a Google Adwords campaigns on the Bitroll, Torrent101 and Torrentq websites warning users not to install these clients. Even though it was fun and probably prevented a couple of hundred people from installing the clients, it is far from an ideal solution. The best way is to spread the word, start forum threads and write blog posts or emails to warn others.
Unfortunately, several popular torrent sites carried advertising for these bad clients but thankfully, sites like The Pirate Bay saw the damage these things can cause and removed the adverts. TPB’s brokep wrote, “We’re getting a lot of email about people downloading torrent clients that are advertised on the site. Do not download them! We have put a ban for the ad companies to sell ads for these clients on our site.” Mininova and Snarf-it also blocked the adverts.

In February, we received information regarding another client, TorrentQ, following a tip from the owner of BT-Junkie. This client was, in fact, a re-branded version of a pre-existing entity.

In April, to safeguard unsuspecting file-sharers from malware installations, we initiated Google Adword campaigns on the BitRoll, Torrent101, and TorrentQ websites, highlighting the inherent risks associated with these clients. It appears that Google has disassociated itself from unfavorable news, as evidenced by the subsequent removal of AdSense advertisements from the affected websites. Regrettably, we are now encountering another problematic torrent client. Get-Torrent represents the most recent addition to a series of torrent clients laden with malware, all of which appear to originate from the same compromised source as BitRoll, Torrent101, and TorrentQ.

Source: http://torrentfreak.com/torrentspy-advertises-malicious-bittorrent-client/ - http://torrentfreak.com/malicious-bittorrent-clients-new-coat-of-paint-same-bad-story/

TrackBack

It has come to our attention that Get-Torrent, Torrent101, TorrentQ, and BitRoll are generating an excessive number of intrusive pop-up advertisements. Despite this, TorrentSpy is actively endorsing these clients. We've observed that the phrase "Use Get-Torrent for high speed downloads" is displayed prominently beneath each download, potentially misleading users into installing these applications.

Both The Pirate Bay and Mininova have previously prohibited these clients from advertising through Adbrite. It appears that TorrentSpy may be prioritizing financial considerations over the security of its user base.

Please verify your files using ExeInfo PE version 0.0.1.7 A (289 signatures), developed by A.S.L. for Win32.


It is advisable to unpack these files, as antivirus scanners may not detect certain viruses or other threats, and some packed/protected executables could trigger "false positive" alerts. Prior to installation, please submit the files for analysis to VirusTotal.

XoftSpySE 4.33.248 (ddl - mirror - mirrors) may detect most Adware, Spyware, Pop-Up Generators, Keyloggers, Trojans, Hijackers and Malware as in some RapidShare tools have been found, Kaspersky and NOD32 didn't found anything.
The narrative progresses.
Updated on August 6, 2007, by Mods.sub.cc.
Revised client names associated with malware, along with new websites and web hosting providers.

1. New names of the Malware BitTorrent clients (all have a size of around 1 MB):
  • BitDownload (Version 3.2.0.0)
  • BitGrabber (Version 4.2.0.0)
  • TorrentSoftware (Version 4.2.0.0)
  • TorrentGamers
  • BitsOfPorn
2. New Websites
Please be advised that BitGrabber, BitDownload, TorrentSoftware, Get-Torrent, BitRoll, Torrent101, TorrentQ, BitsOfPorn, DivoPlayer, axdlplug, TorrentGamers, and WinZix, as well as all offerings from Cash4Downloads (http://www.torrentmusic.org/index.php?go=programs), are identified as adware bundlers. These applications incorporate adware components and employ aggressive, deceptive advertising practices.

It is strongly recommended to refrain from downloading or utilizing any of these clients from web hosting sites located at IP addresses such as 69.72.144.122, 66.45.230.133, etc., irrespective of their domain names or BitTorrent client product names.

Reference: Attention aux logiciels Bittorrent et Popups. CiD
    • Nous vous recommandons d'éviter l'installation de ces logiciels.

    • Pour de plus amples informations, veuillez consulter la procédure de suppression des Popups CiD et BitDownloader/BitGrabber.

    • **Procédure de suppression des Popups CiD et BitDownloader/BitGrabber :**

    • 1. **Désinstallation de BitDownload et suppression des popups :**
    •     * Accédez à la section "Ajout/Suppression de programmes" de votre système d'exploitation.
    •     * Recherchez et désinstallez "CiD Help" si cette entrée est présente.
    •     * Une fenêtre vous demandant de ressaisir un code devrait apparaître (voir ci-dessous). Veuillez le saisir à nouveau, puis cliquez sur "UNINSTALL".
    •     * Désinstallez "BitDownload" ou "BitGrabber" via la section "Ajout/Suppression de programmes".
    •     * Supprimez les dossiers suivants s'ils existent :
    •         * C:\Program Files\BitGrabber
    •         * C:\Program Files\BitDownload
    •         * C:\Program Files\Multi_Media_France

    • 2. **Si "CiD Help" n'est pas présent :**
    •     * Téléchargez l'outil "lopremover".
    •     * Saisissez le numéro qui s'affiche à l'écran, puis cliquez sur "UNINSTALL"..


Vous avez la possibilité de télécharger et d'exécuter SpySweeper afin d'optimiser la performance de votre système informatique.
Pour ce faire, veuillez télécharger SpySweeper en cliquant sur le lien "Free Trial" situé à l'extrême droite de la page.
Une fois le téléchargement terminé, procédez à l'installation et au démarrage de l'application.
Le programme vous invitera à télécharger la dernière version des définitions, ce que nous vous recommandons d'accepter.
Par la suite, accédez au bouton "Options" situé sur le panneau de gauche.
Dans l'onglet "Options", veuillez cocher les éléments suivants :
Sweep Memory
Sweep Registry
Sweep Cookies
Sweep All User Accounts
Enable Direct Disk Sweeping
Sweep Contents of Compressed Files
Sweep for Rootkits
Assurez-vous de décocher l'option "Do not Sweep System Restore Folder".
Cliquez ensuite sur "Sweep Now" dans le panneau de gauche.
Puis, cliquez sur le bouton "Start".
Une fois l'analyse terminée, cliquez sur le bouton "Next".
Vérifiez que toutes les options sont cochées et cliquez à nouveau sur le bouton "Next".
Lorsque tous les éléments identifiés auront été supprimés.
Il est important de noter que lors de l'installation, les termes de la licence d'utilisation (disponibles en anglais) stipulent que le programme pourrait générer des fenêtres pop-up publicitaires et modifier votre page de démarrage ainsi que votre moteur de recherche par défaut sur votre navigateur web.

Type in Google Search box exactly this: "-setup.exe (1MB)" or some words/sentence as in the templates (Download site) of them websites are to see and identical to each other (see screenshots) The web is full of these clients!

Comments

  1. They are registered to GoDaddy. Report them to GoDaddy who have a policy against hosting spam/malware and their domains will get pulled.

    Registrant:
    Domains by Proxy, Inc.
    DomainsByProxy.com
    15111 N. Hayden Rd., Ste 160, PMB 353
    Scottsdale, Arizona 85260
    United States

    Registered through: GoDaddy.com, Inc. (http://www.godaddy.com)
    Domain Name: BITGRABBER.COM
    Created on: 12-Dec-06
    Expires on: 12-Dec-07
    Last Updated on:

    Administrative Contact:
    Private, Registration Whois Privacy and Spam Prevention by DomainTools.com
    Domains by Proxy, Inc.
    DomainsByProxy.com
    15111 N. Hayden Rd., Ste 160, PMB 353
    Scottsdale, Arizona 85260
    United States
    (480) 624-2599 Fax -- (480) 624-2599

    Technical Contact:
    Private, Registration Whois Privacy and Spam Prevention by DomainTools.com
    Domains by Proxy, Inc.
    DomainsByProxy.com
    15111 N. Hayden Rd., Ste 160, PMB 353
    Scottsdale, Arizona 85260
    United States
    (480) 624-2599 Fax -- (480) 624-2599

    Domain servers in listed order:
    NS1.ZONEEDIT.COM
    NS7.ZONEEDIT.COM
    ref: http://whois.domaintools.com/bitgrabber.com


    ------------


    Whois Record

    Domain ID:D134326448-LROR
    Domain Name:BITDOWNLOAD.ORG
    Created On:04-Dec-2006 15:52:20 UTC
    Last Updated On:03-Feb-2007 03:47:09 UTC
    Expiration Date:04-Dec-2007 15:52:20 UTC
    Sponsoring Registrar:GoDaddy.com, Inc. (R91-LROR)
    Status:CLIENT DELETE PROHIBITED
    Status:CLIENT RENEW PROHIBITED
    Status:CLIENT TRANSFER PROHIBITED
    Status:CLIENT UPDATE PROHIBITED
    Registrant ID:GODA-025742519
    Registrant Name:Registration Private
    Registrant Organization:Domains by Proxy, Inc.
    Registrant Street1:DomainsByProxy.com
    Registrant Street2:15111 N. Hayden Rd., Ste 160, PMB 353
    Registrant Street3:
    Registrant City:Scottsdale
    Registrant State/Province:Arizona
    Registrant Postal Code:85260
    Registrant Country:US
    Registrant Phone:+1.4806242599
    Registrant Phone Ext.:
    Registrant FAX:+1.4806242599
    Registrant FAX Ext.:
    Registrant Email:Whois Privacy and Spam Prevention by DomainTools.com
    Admin ID:GODA-225742519
    Admin Name:Registration Private
    Admin Organization:Domains by Proxy, Inc.
    Admin Street1:DomainsByProxy.com
    Admin Street2:15111 N. Hayden Rd., Ste 160, PMB 353
    Admin Street3:
    Admin City:Scottsdale
    Admin State/Province:Arizona
    Admin Postal Code:85260
    Admin Country:US
    Admin Phone:+1.4806242599
    Admin Phone Ext.:
    Admin FAX:+1.4806242599
    Admin FAX Ext.:
    Admin Email:Whois Privacy and Spam Prevention by DomainTools.com
    Tech ID:GODA-125742519
    Tech Name:Registration Private
    Tech Organization:Domains by Proxy, Inc.
    Tech Street1:DomainsByProxy.com
    Tech Street2:15111 N. Hayden Rd., Ste 160, PMB 353
    Tech Street3:
    Tech City:Scottsdale
    Tech State/Province:Arizona
    Tech Postal Code:85260
    Tech Country:US
    Tech Phone:+1.4806242599
    Tech Phone Ext.:
    Tech FAX:+1.4806242599
    Tech FAX Ext.:
    Tech Email:Whois Privacy and Spam Prevention by DomainTools.com
    Name Server:NS1.ZONEEDIT.COM
    Name Server:NS7.ZONEEDIT.COM

    http://whois.domaintools.com/bitdownload.org

    ReplyDelete
  2. I'm gona download them all and install one by one to look into the code. Will post a comment with all ip's, url's in the code of these clients include the User Agent strings. Maybe a batch file can be done to uninstall easy this sh1t complete after the examinations is done.

    Greez
    Gerd

    P.S.
    Done it on my blog too

    ReplyDelete
  3. "There are several advanced and much better BitTorrent clients available today, but we still feel there is something missing in them. They don't show any ads. The other clients have tons of features and great functionality, but they all are overly complex to configure and to understand for a stupid user.

    BitDownload´s and BitGrabber's purpose is to provide users with a great BitTorrent client that is clean, just some Adware and Malware will appear in the Web browser but it's easy to use, and great to get started with. While you download with this client pop up windows advertisements shown up from self. We prefer good quality Ads over quantity -- less features that work better.

    With BitDownload and BitGrabber, everyone can use and enjoy BitTorrent technology without being a computer newbee to reverse engineering it's code and see the truth.

    Happy downloading by automatic browser advertising pop ups!"


    Team ZA Reversing Product Description corrections

    ReplyDelete
  4. 1. Domain alerts to all possible website filter include Google's Firefox, McAfee,...
    2. Send in the file to all Antivirus, Antispyware/Antimalware... Companies to update/include them signatures in coming updates.
    3. See them websites visitors almost Venezuela on top (Alexa and other traffic measurement sites). Write on blogs and others in them Language a warning of these BitTorrent clients.

    ReplyDelete
  5. All of this clients and hosts are Registered through: GoDaddy.com, India

    ReplyDelete
  6. look at this:
    http://www.scroogle.org/cgi-bin/nbbw.cgi?Gw=bitgrabber.com
    Results:

    TorrentPortal
    (forums.torrentportal.com)

    and
    http://forums.spybot.info/archive/index.php/t-10259.html

    +
    3wplayer : hxxp://www.3wplayer.com - BitDownload : hxxp://www.bitdownload.org - BitGrabber : hxxp://www.bitgrabber.com - BitRoll : hxxp://www.bitroll.com .. ..."
    www.needforspeedcarbon.fr/recherche/google-3wplayer.html
    ...
    BitGrabber is an adware bundler that is bundled with adware components and uses aggressive, deceptive advertising. BitGrabber is an adware bundler that is bundled with adware components and uses aggressive, deceptive advertising.0
    http://www.spywaresignatures.com/details.php?spyware=bitgrabber

    ReplyDelete
  7. internet is full of this stuff:
    http://spywarefiles.prevx.com/RRGDEI038108841/BITDOWNLOAD+-+SOMASEX.EXE.html
    http://www.bluetack.co.uk/forums/index.php?s=33d607c7f7ccd35f07b398c2b800f45c&showtopic=17080&pid=82316&st=0&#entry82316
    Torrent101-3.1.0.1-setup-0283.exe
    TorrentQ-2.1.0.0-setup-0350.exe
    BitDownload-3.2.0.0-setup-0310.exe
    Looks exactly like the "BitDownload" and "fastest_BitTorrent_downloader.zip" stuff I've been tracking for the
    past three months on gnutella. Looks like they just tweaked their name a bit but the filenames are still in the
    same pattern, e.g: "BitDownload-3.0.0.0-setup-0273.exe"
    hxxp://www.get-torrent.com/index.php

    detected: adware not-a-virus:AdWare.Win32.Lop.bo URL: hxxp://67.15.107.166/get-torrent/070520/Get-Torrent-2.0.0.0-setup-0350.exe//data0002

    detected: Trojan program Trojan.Win32.Obfuscated.en URL: hxxp://67.15.107.166/get-torrent/070520/Get-Torrent-2.0.0.0-setup-0350.exe//data0013
    Malware Bittorrent client:67.15.107.166-67.15.107.166
    Wakenet P2P Malware:67.15.107.160 67.15.107.191

    Company Name: WakeNet AB
    http://www.spywareguide.com/creator_show.php?id=419


    ev1s-67-15-107-160.ev1servers.net - 67.15.107.160

    OrgName: WakeNet AB
    OrgID: WAKEN
    Address: Tanneforsv 17
    City: Stockholm
    StateProv:
    PostalCode: S-122 47
    Country: SE
    NetRange: 67.15.107.160 - 67.15.107.191

    OrgTechHandle: JWE65-ARIN
    OrgTechName: Wennberg, Johan
    OrgTechPhone: 46707756006
    OrgTechEmail: johan@wakenet.se

    RTechHandle: CNE36-ARIN
    RTechName: Newcomb, Chris
    RTechPhone: +1-713-579-2850
    RTechEmail: ipadmin@ev1servers.net

    main distribution nodes:

    Malware Bittorrent client - DINSA, Ministry of Defence (in the UK) (25.34.12.6):25.0.0.0-25.255.255.255
    (Maybe they're spoofing this address, but I'm blocking all military ranges anyway)

    Malware Bittorrent client - Merit Network Inc. (Large .edu range, apparently):35.34.12.6-35.34.12.6
    (I'm not going to block all of 35.0.0.0-35.255.255.255 just for this, which is probably a spoof)

    Malware Bittorrent client - Saudi Data VSAT Project:62.149.120.134-62.149.120.134
    (I'm not going to block all of 62.149.120.0-62.149.127.255 just for this either)

    Malware Bittorrent client - Hostway Corporation (66.113.139.56):66.113.139.56-66.113.139.56
    (Hosting range is 66.113.128.0-66.113.255.255)

    Malware Bittorrent client - FDC Servers.net, LLC FDCSERVERS:67.159.44.3-67.159.44.4
    Malware Bittorrent client - FDC Servers.net, LLC FDCSERVERS:67.159.44.100-67.159.44.129
    Malware Bittorrent client - FDC Servers.net, LLC FDCSERVERS:67.159.44.160-67.159.44.190
    (As for me, I block all of 67.159.44.0-67.159.44.255)

    Malware Bittorrent client - FIBER TECHNOLOGIES NETWORKS BRW-15171-FIBER:67.99.176.30-67.99.176.30
    (I block all of 67.99.176.0-67.99.176.255 already)

    Malware Bittorrent client - Syrian Telecommunication Establishment STE ISP Network 1:82.137.205.249-82.137.205.249
    82.137.200.0-82.137.207.255

    Malware Bittorrent client - NTT America, Inc. NTTA-128-121:128.121.3.81-128.121.3.81

    Malware Bittorrent client - Filasteen al-Muslimah (Palestinian website hosted in Myanmar):202.71.103.178-202.71.103.178

    Malware Bittorrent client - IPORTENT-LAN on Bezeq International range (using 212.179.133.218):212.179.133.216-212.179.133.223

    Malware Bittorrent client - PALNET INTERNAL NETWORK (using 217.66.226.15):217.66.224.0-217.66.231.127

    http://forum.securitycadets.com/index.php?showtopic=2063
    http://forum.securitycadets.com/index.php?showtopic=1584

    http://www.bitdownload.biz/
    http://www.scroogle.org/cgi-bin/nbbw.cgi?Gw=bitdownload

    ReplyDelete

Post a Comment

We would appreciate if you as readers of our blog, show us some feedback by signing up to this site with Friend Connect.
This will encourage us to publish updates in the future.

Popular posts from this blog

5x WinRAR Personal licence keys - Contest

Malwarebytes Anti-Malware PRO review - write a comment and one from 16 Licenses can be yours