Malware Warning in these BitTorrent Clients!!! "
TorrentSpy is promoting a malicious BitTorrent client. Operating a BitTorrent site can incur significant costs, particularly when involved in litigation with organizations such as the
MPAA. However, endorsing harmful BitTorrent clients like
Get-Torrent to your user base is not an appropriate resolution, even if financial incentives are offered per installation. It appears that financial considerations may be influencing these decisions. Get-Torrent is among numerous malicious BitTorrent clients advertised on various torrent platforms. These clients, along with a range of other free malware applications, are developed and distributed by
WakeNet AB, a Swedish company based in Stockholm and Berg. Their primary objective is to entice individuals into downloading seemingly useful applications, only to infect their computers with
adware bundles that are challenging to remove. Despite numerous forum discussions, including those on TorrentSpy, cautioning unsuspecting users about these clients, TorrentSpy continues to actively promote Get-Torrent, leading to the infection of hundreds of their users' computers and a proliferation of intrusive pop-up advertisements. In contrast to TorrentSpy, the majority of BitTorrent site administrators decline to advertise these clients. The Pirate Bay and
Mininova have successfully prohibited these malicious clients from advertising through Adbrite, and BTjunkie and many other sites also refuse to host them.
The malware distributed with BitTorrent clients such as Get-Torrent, Torrent101, TorrentQ, and BitRoll is a sponsored program known as "Cidhelp." While it is ostensibly removable via the Windows Control Panel, anti-spyware or anti-virus programs frequently corrupt its files, rendering uninstallation impossible while the program continues to generate numerous pop-up advertisements.
In April ran a
Google Adwords campaigns on the
Bitroll, Torrent101 and Torrentq websites warning users not to install these clients. Even though it was fun and probably prevented a couple of hundred people from installing the clients, it is far from an ideal solution. The best way is to spread the word, start forum threads and write blog posts or emails to warn others.
Unfortunately, several popular torrent sites carried advertising for these bad clients but thankfully, sites like The Pirate Bay saw the damage these things can cause and
removed the adverts. TPB’s brokep wrote, “We’re getting a lot of email about people downloading torrent clients that are advertised on the site. Do not download them! We have put a ban for the ad companies to sell ads for these clients on our site.” Mininova and Snarf-it also blocked the adverts.
In February, we received information regarding another client, TorrentQ, following a tip from the owner of BT-Junkie. This client was, in fact, a re-branded version of a pre-existing entity.
In April, to safeguard unsuspecting file-sharers from malware installations, we initiated Google Adword campaigns on the BitRoll, Torrent101, and TorrentQ websites, highlighting the inherent risks associated with these clients.

It appears that Google has disassociated itself from unfavorable news, as evidenced by the subsequent removal of AdSense advertisements from the affected websites. Regrettably, we are now encountering another problematic torrent client. Get-Torrent represents the most recent addition to a series of torrent clients laden with malware, all of which appear to originate from the same compromised source as BitRoll, Torrent101, and TorrentQ.
Source: http://torrentfreak.com/torrentspy-advertises-malicious-bittorrent-client/ - http://torrentfreak.com/malicious-bittorrent-clients-new-coat-of-paint-same-bad-story/
TrackBackIt has come to our attention that Get-Torrent, Torrent101, TorrentQ, and BitRoll are generating an excessive number of intrusive pop-up advertisements. Despite this, TorrentSpy is actively endorsing these clients. We've observed that the phrase "Use Get-Torrent for high speed downloads" is displayed prominently beneath each download, potentially misleading users into installing these applications.
Both The Pirate Bay and Mininova have previously prohibited these clients from advertising through Adbrite. It appears that TorrentSpy may be prioritizing financial considerations over the security of its user base.
Please verify your files using ExeInfo PE version 0.0.1.7 A (289 signatures), developed by A.S.L. for Win32.
It is advisable to unpack these files, as antivirus scanners may not detect certain viruses or other threats, and some packed/protected executables could trigger "false positive" alerts. Prior to installation, please submit the files for analysis to VirusTotal.
XoftSpySE 4.33.248 (ddl - mirror - mirrors) may detect most Adware, Spyware, Pop-Up Generators, Keyloggers, Trojans, Hijackers and Malware as in some RapidShare tools have been found, Kaspersky and NOD32 didn't found anything.
The narrative progresses.
Updated on August 6, 2007, by Mods.sub.cc.
Revised client names associated with malware, along with new websites and web hosting providers.
1.
New names of the Malware BitTorrent clients (all have a size of around 1 MB):
- BitDownload (Version 3.2.0.0)
- BitGrabber (Version 4.2.0.0)
- TorrentSoftware (Version 4.2.0.0)
- TorrentGamers
- BitsOfPorn
2.
New Websites Please be advised that BitGrabber, BitDownload, TorrentSoftware, Get-Torrent, BitRoll, Torrent101, TorrentQ, BitsOfPorn, DivoPlayer, axdlplug, TorrentGamers, and WinZix, as well as all offerings from Cash4Downloads (http://www.torrentmusic.org/index.php?go=programs), are identified as adware bundlers. These applications incorporate adware components and employ aggressive, deceptive advertising practices.
It is strongly recommended to refrain from downloading or utilizing any of these clients from web hosting sites located at IP addresses such as 69.72.144.122, 66.45.230.133, etc., irrespective of their domain names or BitTorrent client product names.
Reference: Attention aux logiciels Bittorrent et Popups.
CiD- Nous vous recommandons d'éviter l'installation de ces logiciels.
- Pour de plus amples informations, veuillez consulter la procédure de suppression des Popups CiD et BitDownloader/BitGrabber.
- **Procédure de suppression des Popups CiD et BitDownloader/BitGrabber :**
- 1. **Désinstallation de BitDownload et suppression des popups :**
- * Accédez à la section "Ajout/Suppression de programmes" de votre système d'exploitation.
- * Recherchez et désinstallez "CiD Help" si cette entrée est présente.
- * Une fenêtre vous demandant de ressaisir un code devrait apparaître (voir ci-dessous). Veuillez le saisir à nouveau, puis cliquez sur "UNINSTALL".
- * Désinstallez "BitDownload" ou "BitGrabber" via la section "Ajout/Suppression de programmes".
- * Supprimez les dossiers suivants s'ils existent :
- * C:\Program Files\BitGrabber
- * C:\Program Files\BitDownload
- * C:\Program Files\Multi_Media_France
- 2. **Si "CiD Help" n'est pas présent :**
- * Téléchargez l'outil "lopremover".
- * Saisissez le numéro qui s'affiche à l'écran, puis cliquez sur "UNINSTALL"..
Vous avez la possibilité de télécharger et d'exécuter
SpySweeper afin d'optimiser la performance de votre système informatique.
Pour ce faire, veuillez télécharger SpySweeper en cliquant sur le lien "Free Trial" situé à l'extrême droite de la page.
Une fois le téléchargement terminé, procédez à l'installation et au démarrage de l'application.
Le programme vous invitera à télécharger la dernière version des définitions, ce que nous vous recommandons d'accepter.
Par la suite, accédez au bouton "Options" situé sur le panneau de gauche.
Dans l'onglet "Options", veuillez cocher les éléments suivants :
Sweep Memory
Sweep Registry
Sweep Cookies
Sweep All User Accounts
Enable Direct Disk Sweeping
Sweep Contents of Compressed Files
Sweep for Rootkits
Assurez-vous de décocher l'option "Do not Sweep System Restore Folder".
Cliquez ensuite sur "Sweep Now" dans le panneau de gauche.
Puis, cliquez sur le bouton "Start".
Une fois l'analyse terminée, cliquez sur le bouton "Next".
Vérifiez que toutes les options sont cochées et cliquez à nouveau sur le bouton "Next".
Lorsque tous les éléments identifiés auront été supprimés.
Il est important de noter que lors de l'installation, les termes de la licence d'utilisation (disponibles en anglais) stipulent que le programme pourrait générer des fenêtres pop-up publicitaires et modifier votre page de démarrage ainsi que votre moteur de recherche par défaut sur votre navigateur web.
Type in Google Search box exactly this: "-setup.exe (1MB)" or some words/sentence as in the templates (Download site) of them websites are to see and identical to each other (see screenshots) The web is full of these clients!
They are registered to GoDaddy. Report them to GoDaddy who have a policy against hosting spam/malware and their domains will get pulled.
ReplyDeleteRegistrant:
Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States
Registered through: GoDaddy.com, Inc. (http://www.godaddy.com)
Domain Name: BITGRABBER.COM
Created on: 12-Dec-06
Expires on: 12-Dec-07
Last Updated on:
Administrative Contact:
Private, Registration Whois Privacy and Spam Prevention by DomainTools.com
Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States
(480) 624-2599 Fax -- (480) 624-2599
Technical Contact:
Private, Registration Whois Privacy and Spam Prevention by DomainTools.com
Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States
(480) 624-2599 Fax -- (480) 624-2599
Domain servers in listed order:
NS1.ZONEEDIT.COM
NS7.ZONEEDIT.COM
ref: http://whois.domaintools.com/bitgrabber.com
------------
Whois Record
Domain ID:D134326448-LROR
Domain Name:BITDOWNLOAD.ORG
Created On:04-Dec-2006 15:52:20 UTC
Last Updated On:03-Feb-2007 03:47:09 UTC
Expiration Date:04-Dec-2007 15:52:20 UTC
Sponsoring Registrar:GoDaddy.com, Inc. (R91-LROR)
Status:CLIENT DELETE PROHIBITED
Status:CLIENT RENEW PROHIBITED
Status:CLIENT TRANSFER PROHIBITED
Status:CLIENT UPDATE PROHIBITED
Registrant ID:GODA-025742519
Registrant Name:Registration Private
Registrant Organization:Domains by Proxy, Inc.
Registrant Street1:DomainsByProxy.com
Registrant Street2:15111 N. Hayden Rd., Ste 160, PMB 353
Registrant Street3:
Registrant City:Scottsdale
Registrant State/Province:Arizona
Registrant Postal Code:85260
Registrant Country:US
Registrant Phone:+1.4806242599
Registrant Phone Ext.:
Registrant FAX:+1.4806242599
Registrant FAX Ext.:
Registrant Email:Whois Privacy and Spam Prevention by DomainTools.com
Admin ID:GODA-225742519
Admin Name:Registration Private
Admin Organization:Domains by Proxy, Inc.
Admin Street1:DomainsByProxy.com
Admin Street2:15111 N. Hayden Rd., Ste 160, PMB 353
Admin Street3:
Admin City:Scottsdale
Admin State/Province:Arizona
Admin Postal Code:85260
Admin Country:US
Admin Phone:+1.4806242599
Admin Phone Ext.:
Admin FAX:+1.4806242599
Admin FAX Ext.:
Admin Email:Whois Privacy and Spam Prevention by DomainTools.com
Tech ID:GODA-125742519
Tech Name:Registration Private
Tech Organization:Domains by Proxy, Inc.
Tech Street1:DomainsByProxy.com
Tech Street2:15111 N. Hayden Rd., Ste 160, PMB 353
Tech Street3:
Tech City:Scottsdale
Tech State/Province:Arizona
Tech Postal Code:85260
Tech Country:US
Tech Phone:+1.4806242599
Tech Phone Ext.:
Tech FAX:+1.4806242599
Tech FAX Ext.:
Tech Email:Whois Privacy and Spam Prevention by DomainTools.com
Name Server:NS1.ZONEEDIT.COM
Name Server:NS7.ZONEEDIT.COM
http://whois.domaintools.com/bitdownload.org
I'm gona download them all and install one by one to look into the code. Will post a comment with all ip's, url's in the code of these clients include the User Agent strings. Maybe a batch file can be done to uninstall easy this sh1t complete after the examinations is done.
ReplyDeleteGreez
Gerd
P.S.
Done it on my blog too
"There are several advanced and much better BitTorrent clients available today, but we still feel there is something missing in them. They don't show any ads. The other clients have tons of features and great functionality, but they all are overly complex to configure and to understand for a stupid user.
ReplyDeleteBitDownload´s and BitGrabber's purpose is to provide users with a great BitTorrent client that is clean, just some Adware and Malware will appear in the Web browser but it's easy to use, and great to get started with. While you download with this client pop up windows advertisements shown up from self. We prefer good quality Ads over quantity -- less features that work better.
With BitDownload and BitGrabber, everyone can use and enjoy BitTorrent technology without being a computer newbee to reverse engineering it's code and see the truth.
Happy downloading by automatic browser advertising pop ups!"
Team ZA Reversing Product Description corrections
1. Domain alerts to all possible website filter include Google's Firefox, McAfee,...
ReplyDelete2. Send in the file to all Antivirus, Antispyware/Antimalware... Companies to update/include them signatures in coming updates.
3. See them websites visitors almost Venezuela on top (Alexa and other traffic measurement sites). Write on blogs and others in them Language a warning of these BitTorrent clients.
All of this clients and hosts are Registered through: GoDaddy.com, India
ReplyDeletelook at this:
ReplyDeletehttp://www.scroogle.org/cgi-bin/nbbw.cgi?Gw=bitgrabber.com
Results:
TorrentPortal
(forums.torrentportal.com)
and
http://forums.spybot.info/archive/index.php/t-10259.html
+
3wplayer : hxxp://www.3wplayer.com - BitDownload : hxxp://www.bitdownload.org - BitGrabber : hxxp://www.bitgrabber.com - BitRoll : hxxp://www.bitroll.com .. ..."
www.needforspeedcarbon.fr/recherche/google-3wplayer.html
...
BitGrabber is an adware bundler that is bundled with adware components and uses aggressive, deceptive advertising. BitGrabber is an adware bundler that is bundled with adware components and uses aggressive, deceptive advertising.0
http://www.spywaresignatures.com/details.php?spyware=bitgrabber
internet is full of this stuff:
ReplyDeletehttp://spywarefiles.prevx.com/RRGDEI038108841/BITDOWNLOAD+-+SOMASEX.EXE.html
http://www.bluetack.co.uk/forums/index.php?s=33d607c7f7ccd35f07b398c2b800f45c&showtopic=17080&pid=82316&st=0&#entry82316
Torrent101-3.1.0.1-setup-0283.exe
TorrentQ-2.1.0.0-setup-0350.exe
BitDownload-3.2.0.0-setup-0310.exe
Looks exactly like the "BitDownload" and "fastest_BitTorrent_downloader.zip" stuff I've been tracking for the
past three months on gnutella. Looks like they just tweaked their name a bit but the filenames are still in the
same pattern, e.g: "BitDownload-3.0.0.0-setup-0273.exe"
hxxp://www.get-torrent.com/index.php
detected: adware not-a-virus:AdWare.Win32.Lop.bo URL: hxxp://67.15.107.166/get-torrent/070520/Get-Torrent-2.0.0.0-setup-0350.exe//data0002
detected: Trojan program Trojan.Win32.Obfuscated.en URL: hxxp://67.15.107.166/get-torrent/070520/Get-Torrent-2.0.0.0-setup-0350.exe//data0013
Malware Bittorrent client:67.15.107.166-67.15.107.166
Wakenet P2P Malware:67.15.107.160 67.15.107.191
Company Name: WakeNet AB
http://www.spywareguide.com/creator_show.php?id=419
ev1s-67-15-107-160.ev1servers.net - 67.15.107.160
OrgName: WakeNet AB
OrgID: WAKEN
Address: Tanneforsv 17
City: Stockholm
StateProv:
PostalCode: S-122 47
Country: SE
NetRange: 67.15.107.160 - 67.15.107.191
OrgTechHandle: JWE65-ARIN
OrgTechName: Wennberg, Johan
OrgTechPhone: 46707756006
OrgTechEmail: johan@wakenet.se
RTechHandle: CNE36-ARIN
RTechName: Newcomb, Chris
RTechPhone: +1-713-579-2850
RTechEmail: ipadmin@ev1servers.net
main distribution nodes:
Malware Bittorrent client - DINSA, Ministry of Defence (in the UK) (25.34.12.6):25.0.0.0-25.255.255.255
(Maybe they're spoofing this address, but I'm blocking all military ranges anyway)
Malware Bittorrent client - Merit Network Inc. (Large .edu range, apparently):35.34.12.6-35.34.12.6
(I'm not going to block all of 35.0.0.0-35.255.255.255 just for this, which is probably a spoof)
Malware Bittorrent client - Saudi Data VSAT Project:62.149.120.134-62.149.120.134
(I'm not going to block all of 62.149.120.0-62.149.127.255 just for this either)
Malware Bittorrent client - Hostway Corporation (66.113.139.56):66.113.139.56-66.113.139.56
(Hosting range is 66.113.128.0-66.113.255.255)
Malware Bittorrent client - FDC Servers.net, LLC FDCSERVERS:67.159.44.3-67.159.44.4
Malware Bittorrent client - FDC Servers.net, LLC FDCSERVERS:67.159.44.100-67.159.44.129
Malware Bittorrent client - FDC Servers.net, LLC FDCSERVERS:67.159.44.160-67.159.44.190
(As for me, I block all of 67.159.44.0-67.159.44.255)
Malware Bittorrent client - FIBER TECHNOLOGIES NETWORKS BRW-15171-FIBER:67.99.176.30-67.99.176.30
(I block all of 67.99.176.0-67.99.176.255 already)
Malware Bittorrent client - Syrian Telecommunication Establishment STE ISP Network 1:82.137.205.249-82.137.205.249
82.137.200.0-82.137.207.255
Malware Bittorrent client - NTT America, Inc. NTTA-128-121:128.121.3.81-128.121.3.81
Malware Bittorrent client - Filasteen al-Muslimah (Palestinian website hosted in Myanmar):202.71.103.178-202.71.103.178
Malware Bittorrent client - IPORTENT-LAN on Bezeq International range (using 212.179.133.218):212.179.133.216-212.179.133.223
Malware Bittorrent client - PALNET INTERNAL NETWORK (using 217.66.226.15):217.66.224.0-217.66.231.127
http://forum.securitycadets.com/index.php?showtopic=2063
http://forum.securitycadets.com/index.php?showtopic=1584
http://www.bitdownload.biz/
http://www.scroogle.org/cgi-bin/nbbw.cgi?Gw=bitdownload