Вот инфа для размышления от товарища Victor_VG
Цитата: Любопытный момент:
Поймал на установке несанкционированного шпионского модуля Glorylogic ISO Workshop v2.0 - ставит ask.com шпиона и сразу отсылает всю инфу и списки
п/я на ask.com. в логах отсылки списки п/я не указывает, но в TCP пакетах
WireShark их зафиксировал, а официально никакой рекламы нет - лицензия
Freeware и упоминаний о наличии рекламы на сервере нет.
Поэтому отношу для себя данный пакет к классу троянов, да и по возможностям
он бестолков - почти ничего не умеет, и до той же EZB UltraISO ему далеко
как до Луны Четыре красивых иконки в окне и не предсказуемый результат
работы. Более ничего. установка шпионского модуля в логах его инсталяции не
фиксируется, отследил в Process Hacker факт запгрузки и запуска его
установкой скрытого(!) по технологии руткитов процесса установки
"вспомогательного" модуля, и естественно, что так же у пользователя не
спрашивают ставить или нет в %TMP% библиотеку AskSLib.dll, а молча её
ставят и после отсылают на ask.com инфу, а также после молча ставят их панель
скачивая её установщик askToolbarInstaller-1.13.2.0.exe и запуская его на выполнение в
скрытом режиме как руткит.... Хорошо, что у меня брандмауер на роутере вовремя
сработал и сообщил о скачивании с не санкционированного узла и тут же на хосте
ClamAV поднял тревогу - троян лезет в сеть!
И учитывая то, что из двух "бесплатных" программ одна использует эти технологии я не удивился обнаружив их же и во второй их "радости" - Image Tuner...
[more=А вот и вот логи работы сего чуда...]
Первый - проверяет систему:
Цитата: ******************************Checking Session******************************
[(UTC) 26/11/2011 - 01:01:59:205]: OS = 5.1.1.sp3.x86
[(UTC) 26/11/2011 - 01:01:59:205]: CommandLine = "/tb=BA2"
[(UTC) 26/11/2011 - 01:01:59:205]: RequestLocal = 0, DefaultLocal = 0
[(UTC) 26/11/2011 - 01:01:59:205]: Begin downloading manifest:
RemoteManifestPath = "http://apnmedia.ask.com/media/toolbar/stub/1.0.0.0/ApnIC.dll?tb=BA2&version=1.0.0.0"
LocalManifestPath = "H:\Tmp\AskSLib.dll"
CommandLine = "/tb=BA2 /timeout=6"
[(UTC) 26/11/2011 - 01:01:59:799]: Downloader(BITS) : timeout = 6 seconds
[(UTC) 26/11/2011 - 01:02:01:517]: Downloader(BITS) : Exiting with state = 6, ElapsedTime = 1.50 seconds.
[(UTC) 26/11/2011 - 01:02:01:564]: End downloading manifest:
Boolean return = 1
CommandLine = "/tb=BA2 /timeout=6 /downloadtime=1500"
[(UTC) 26/11/2011 - 01:02:01:955]: Validation of LocalManifest Digital Signature Succeeded
[(UTC) 26/11/2011 - 01:02:01:986]: Begin LocalManifest::CheckInstall():
CommandLine = "/tb=BA2 /timeout=6 /downloadtime=1500 /debug"
[(UTC) 26/11/2011 - 01:02:05:970]: End LocalManifest::CheckInstall():
return code = -1
CommandLine = "/tb=BA2"
[(UTC) 26/11/2011 - 01:02:05:970]: Session exit with code = -1
Второй - загрузка askToolbarInstaller-1.13.2.0.exe:
Цитата: INFO 11/26/2011, 5:2:2 Proceed with checks. Cleanup not required
INFO 11/26/2011, 5:2:2 BA2
INFO 11/26/2011, 5:2:2 Checking for OS / browser support
INFO 11/26/2011, 5:2:2 OS supports toolbar installation
INFO 11/26/2011, 5:2:2 Default browser is allowed
INFO 11/26/2011, 5:2:2 Interim toolbar does not exist
INFO 11/26/2011, 5:2:2 CAP toolbar does not exist
INFO 11/26/2011, 5:2:2 Super toolbar does not exist
INFO 11/26/2011, 5:2:5 Set Registry "HKEY_CURRENT_USER\SOFTWARE\Ask.com.tmp\General" with value(s):
INFO 11/26/2011, 5:2:5 apn_dbr = "Null" Succeeded.
INFO 11/26/2011, 5:2:5 cbid = "^A65" Succeeded.
INFO 11/26/2011, 5:2:5 client = "ic" Succeeded.
INFO 11/26/2011, 5:2:5 clientv = "5.1.0.0" Succeeded.
INFO 11/26/2011, 5:2:5 cr = "0" Succeeded.
INFO 11/26/2011, 5:2:5 crumb = "2011.11.25+17.02.05-toolbar005iad-RU-TW9zY293LFJ1c3NpYW4gRmVkZXJhdGlvbg%3D%3D" Succeeded.
INFO 11/26/2011, 5:2:5 dbr = "" Succeeded.
INFO 11/26/2011, 5:2:5 dot = "6" Succeeded.
INFO 11/26/2011, 5:2:5 dt = "1500" Succeeded.
INFO 11/26/2011, 5:2:5 dtid = "^YYYYYY^CL^RU" Succeeded.
INFO 11/26/2011, 5:2:5 eichk = "http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=^A65^YYYYYY^CL^RU&encb={incbid}&chk={ic_chk}&ts={random}&guid={guid}&dt={dt}&wft={wft}&inst={inst}&tb={tb}&hos={hos}&harch={harch}&hloc={hloc}&iv={iv}&fv={fv}&dbr={dbr}&vb={vb}&msi={msi}&dot={dot}" Succeeded.
INFO 11/26/2011, 5:2:5 einst = "http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=einst&p2=^A65^YYYYYY^CL^RU&stb={wr_tbr}&ssa={wr_sa}&shpr={wr_hpr}&res={ci_res}&erc={ci_erc}&itime={itime}&hos={hos}&harch={harch}&hloc={hloc}&iv={iv}&fv={fv}&dbr={dbr}&vb={vb}&msi={msi}&ts={random}&guid={guid}&wft={wft}&dot={dot}&inst={inst}&tb={tb}&dt={dt}&erd={erd}" Succeeded.
INFO 11/26/2011, 5:2:5 ewrap = "http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=ewrap&p2=^A65^YYYYYY^CL^RU&stb={wr_tbr}&ssa={wr_sa}&shpr={wr_hpr}¶m={param}&ts={random}&guid={guid}&dt={dt}&inst={inst}&tb={tb}&hos={hos}&harch={harch}&hloc={hloc}&iv={iv}&fv={fv}&dbr={dbr}&vb={vb}&msi={msi}&wft={wft}&dot={dot}&erd={erd}" Succeeded.
INFO 11/26/2011, 5:2:5 ff-max-version = "8.*" Succeeded.
INFO 11/26/2011, 5:2:5 fflu = "-2" Succeeded.
INFO 11/26/2011, 5:2:5 fv = "" Succeeded.
INFO 11/26/2011, 5:2:5 guid = "a023323f-205b-4269-af98-7ec81a553850" Succeeded.
INFO 11/26/2011, 5:2:5 harch = "32" Succeeded.
INFO 11/26/2011, 5:2:5 hloc = "ru-RU" Succeeded.
INFO 11/26/2011, 5:2:5 homepageurl = "http://ru.ask.com/?l=dis&o=APN10138&gct=hp" Succeeded.
INFO 11/26/2011, 5:2:5 hos = "5.1.1.sp3.x86" Succeeded.
INFO 11/26/2011, 5:2:5 iedis = "0" Succeeded.
INFO 11/26/2011, 5:2:5 ielu = "-2" Succeeded.
INFO 11/26/2011, 5:2:5 iev = "8.0.6001.18702" Succeeded.
INFO 11/26/2011, 5:2:5 inst = "200" Succeeded.
INFO 11/26/2011, 5:2:5 iv = "8.0.6001.18702" Succeeded.
INFO 11/26/2011, 5:2:5 l = "dis" Succeeded.
INFO 11/26/2011, 5:2:5 locale = "ru_RU" Succeeded.
INFO 11/26/2011, 5:2:5 location = "Moscow,Russian Federation" Succeeded.
INFO 11/26/2011, 5:2:5 make-offer = "0" Succeeded.
INFO 11/26/2011, 5:2:5 o = "APN10138" Succeeded.
INFO 11/26/2011, 5:2:5 oi = "nop" Succeeded.
INFO 11/26/2011, 5:2:5 qsrc = "2871" Succeeded.
INFO 11/26/2011, 5:2:5 repurl = "http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=^A65^YYYYYY^CL^RU&encb={incbid}&chk={ic_chk}&ts={random}&guid=" Succeeded.
INFO 11/26/2011, 5:2:5 tb = "BA2" Succeeded.
INFO 11/26/2011, 5:2:5 tb-installer-path = "http://apnmedia.ask.com/media/toolbar/supertoolbar/profile-ask/askToolbarInstaller-1.13.2.0.exe" Succeeded.
INFO 11/26/2011, 5:2:5 tb-version = "5.13.2.0" Succeeded.
INFO 11/26/2011, 5:2:5 to = "" Succeeded.
INFO 11/26/2011, 5:2:5 wft = "remote" Succeeded.
INFO 11/26/2011, 5:2:5 Set Registry "HKEY_CURRENT_USER\SOFTWARE\Ask.com.tmp\Installer" with value(s):
INFO 11/26/2011, 5:2:5 eichk = "http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=^A65^YYYYYY^CL^RU&encb={incbid}&chk={ic_chk}&ts={random}&guid={guid}&dt={dt}&wft={wft}&inst={inst}&tb={tb}&hos={hos}&harch={harch}&hloc={hloc}&iv={iv}&fv={fv}&dbr={dbr}&vb={vb}&msi={msi}&dot={dot}" Succeeded.
INFO 11/26/2011, 5:2:5 ff-max-version = "8.*" Succeeded.
INFO 11/26/2011, 5:2:5 guid = "a023323f-205b-4269-af98-7ec81a553850" Succeeded.
INFO 11/26/2011, 5:2:5 homepageurl = "http://ru.ask.com/?l=dis&o=APN10138&gct=hp" Succeeded.
INFO 11/26/2011, 5:2:5 make-offer = "0" Succeeded.
INFO 11/26/2011, 5:2:5 oi = "nop" Succeeded.
INFO 11/26/2011, 5:2:5 repurl = "http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=^A65^YYYYYY^CL^RU&encb={incbid}&chk={ic_chk}&ts={random}&guid=" Succeeded.
INFO 11/26/2011, 5:2:5 Set Registry "HKEY_CURRENT_USER\SOFTWARE\Ask.com.tmp\Macro" with value(s):
INFO 11/26/2011, 5:2:5 cbid = "^A65" Succeeded.
INFO 11/26/2011, 5:2:5 crumb = "2011.11.25+17.02.05-toolbar005iad-RU-TW9zY293LFJ1c3NpYW4gRmVkZXJhdGlvbg%3D%3D" Succeeded.
INFO 11/26/2011, 5:2:5 dtid = "^YYYYYY^CL^RU" Succeeded.
INFO 11/26/2011, 5:2:5 l = "dis" Succeeded.
INFO 11/26/2011, 5:2:5 locale = "ru_RU" Succeeded.
INFO 11/26/2011, 5:2:5 location = "Moscow,Russian Federation" Succeeded.
INFO 11/26/2011, 5:2:5 o = "APN10138" Succeeded.
INFO 11/26/2011, 5:2:5 qsrc = "2871" Succeeded.
INFO 11/26/2011, 5:2:5 to = "" Succeeded.
INFO 11/26/2011, 5:2:5 Install API Call - Success : HTTP Status Code - 200
INFO 11/26/2011, 5:2:5 Server returned makeoffer != 1
INFO 11/26/2011, 5:2:5 Installer offer should not be shown
INFO 11/26/2011, 5:2:5 Whatzup reporting- Success
INFO 11/26/2011, 5:2:5 Whatzup reporting URL
INFO 11/26/2011, 5:2:5 http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=^A65^YYYYYY^CL^RU&encb={incbid}&chk={ic_chk}&ts={random}&guid={guid}&dt={dt}&wft={wft}&inst={inst}&tb={tb}&hos={hos}&harch={harch}&hloc={hloc}&iv={iv}&fv={fv}&dbr={dbr}&vb={vb}&msi={msi}&dot={dot}
INFO 11/26/2011, 5:2:5 Return code = -1
И в реестр либа гадит:
Код: Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Ask.com.tmp]
[HKEY_CURRENT_USER\Software\Ask.com.tmp\General]
"apn_dbr"="Null"
"cbid"="^A65"
"client"="ic"
"clientv"="5.1.0.0"
"cr"="0"
"crumb"="2011.11.25+17.02.05-toolbar005iad-RU-TW9zY293LFJ1c3NpYW4gRmVkZXJhdGlvbg%3D%3D"
"dbr"=""
"dot"="6"
"dt"="1500"
"dtid"="^YYYYYY^CL^RU"
"eichk"="http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=^A65^YYYYYY^CL^RU&encb={incbid}&chk={ic_chk}&ts={random}&guid={guid}&dt={dt}&wft={wft}&inst={inst}&tb={tb}&hos={hos}&harch={harch}&hloc={hloc}&iv={iv}&fv={fv}&dbr={dbr}&vb={vb}&msi={msi}&dot={dot}"
"einst"="http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=einst&p2=^A65^YYYYYY^CL^RU&stb={wr_tbr}&ssa={wr_sa}&shpr={wr_hpr}&res={ci_res}&erc={ci_erc}&itime={itime}&hos={hos}&harch={harch}&hloc={hloc}&iv={iv}&fv={fv}&dbr={dbr}&vb={vb}&msi={msi}&ts={random}&guid={guid}&wft={wft}&dot={dot}&inst={inst}&tb={tb}&dt={dt}&erd={erd}"
"ewrap"="http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=ewrap&p2=^A65^YYYYYY^CL^RU&stb={wr_tbr}&ssa={wr_sa}&shpr={wr_hpr}¶m={param}&ts={random}&guid={guid}&dt={dt}&inst={inst}&tb={tb}&hos={hos}&harch={harch}&hloc={hloc}&iv={iv}&fv={fv}&dbr={dbr}&vb={vb}&msi={msi}&wft={wft}&dot={dot}&erd={erd}"
"ff-max-version"="8.*"
"fflu"="-2"
"fv"=""
"guid"="a023323f-205b-4269-af98-7ec81a553850"
"harch"="32"
"hloc"="ru-RU"
"homepageurl"="http://ru.ask.com/?l=dis&o=APN10138&gct=hp"
"hos"="5.1.1.sp3.x86"
"iedis"="0"
"ielu"="-2"
"iev"="8.0.6001.18702"
"inst"="200"
"iv"="8.0.6001.18702"
"l"="dis"
"locale"="ru_RU"
"location"="Moscow,Russian Federation"
"make-offer"="0"
"o"="APN10138"
"oi"="nop"
"qsrc"="2871"
"repurl"="http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=^A65^YYYYYY^CL^RU&encb={incbid}&chk={ic_chk}&ts={random}&guid="
"tb"="BA2"
"tb-installer-path"="http://apnmedia.ask.com/media/toolbar/supertoolbar/profile-ask/askToolbarInstaller-1.13.2.0.exe"
"tb-version"="5.13.2.0"
"to"=""
"wft"="remote"
[HKEY_CURRENT_USER\Software\Ask.com.tmp\Installer]
"eichk"="http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=^A65^YYYYYY^CL^RU&encb={incbid}&chk={ic_chk}&ts={random}&guid={guid}&dt={dt}&wft={wft}&inst={inst}&tb={tb}&hos={hos}&harch={harch}&hloc={hloc}&iv={iv}&fv={fv}&dbr={dbr}&vb={vb}&msi={msi}&dot={dot}"
"ff-max-version"="8.*"
"guid"="a023323f-205b-4269-af98-7ec81a553850"
"homepageurl"="http://ru.ask.com/?l=dis&o=APN10138&gct=hp"
"make-offer"="0"
"oi"="nop"
"repurl"="http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&p2=^A65^YYYYYY^CL^RU&encb={incbid}&chk={ic_chk}&ts={random}&guid="
[HKEY_CURRENT_USER\Software\Ask.com.tmp\Macro]
"cbid"="^A65"
"crumb"="2011.11.25+17.02.05-toolbar005iad-RU-TW9zY293LFJ1c3NpYW4gRmVkZXJhdGlvbg%3D%3D"
"dtid"="^YYYYYY^CL^RU"
"l"="dis"
"locale"="ru_RU"
"location"="Moscow,Russian Federation"
"o"="APN10138"
"qsrc"="2871"
"to"=""