AOA AOA AOA Folding For Team 45 AOA Files Home Front Page Become an AOA Subscriber! UserCP Calendar Memberlist FAQ Search Forum Home


Go Back   AOA > Software > Data Security
Register FAQ Members List Calendar Arcade Search Today's Posts Mark Forums Read

Data Security Viruses, Firewalls and Safe computing


Reply
 
LinkBack Thread Tools Rate Thread
  #1 (permalink)  
Old 7th June, 2006, 09:15 AM
skool h8r's Avatar
Member
 
Join Date: January 2005
Location: Rotherham, UK
Posts: 3,140
Send a message via MSN to skool h8r

i caught you out TweaksRUS!

hi all,
i've found something which i'm quite concerned about that seems may have affected a lot of people here. When i was scanning my system with ad-aware, i found something (see the attached image). Now i don't know how or why, but XG appear to have been putting ServerLogic.Hyperlinker adware into their drivers! The proof is in the picture my friends.

Any thoughts on this my friends?
Attached Thumbnails
i-caught-you-out-tweaksrus-xg_drivers_dataminer.png  
__________________

Wolfdale E8400 @ 4.0Ghz @ 1.400v
Dual-Channel 4Gb Corsair Dominator PC2-8500C5 @ 1069Mhz @ 5-5-5-15-2T (Cooled by Dominator Fan)
PNY 8800GT 512MB @ Stock (64.0GB/s Bandwidth, 11.2 GPixel, 39.2GTexel /sec)
Asus P5K-E Wifi @ 445 FSB (1780 QDR) (1.55V N/B)
CPU cooled by IFX-14 and Antec Tricool 120mm.
Antec PowerMax 850W

________________
1920x1200 Gamer (24" Widescreen)
13221 3DMark06
22935 3DMark05
42097 3DMark03

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 7th June, 2006, 09:30 AM
Favu's Avatar
AOA's resident barman
 
Join Date: October 2005
Location: /Wales/Abergavenny
Posts: 4,004
Send a message via ICQ to Favu Send a message via AIM to Favu Send a message via MSN to Favu

Thats on the murky side of uncool
__________________
AOA Team fah
 

Custom 8-bit Sharp Z80 @ 4.194304 MHz
Reflective LCD @ 160 × 144
8 kByte S-RAM






Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 7th June, 2006, 09:33 AM
Gizmo's Avatar
Chief BBS Administrator
 
Join Date: May 2003
Location: Webb City, Mo
Posts: 13,934
Send a message via ICQ to Gizmo Send a message via AIM to Gizmo Send a message via MSN to Gizmo Send a message via Yahoo to Gizmo Send a message via Skype™ to Gizmo

Which version of drivers? Also, have you tried another malware tool like SpyBot to see what it says? Before we go jumping to conclusions here, let's get all of the facts.
__________________
Avatar and sig graphic by Pitch. Subscribers!
Ask about a custom graphic or avatar today!
 
Later,
Gizmo
Thermal Diode Mod and Direct-Die Water Block
8-Cheetah 18GiB U-2 SCSI
MegaRAID Enterprise 1500/128MiB
Samsung SyncMaster 955DF
TTGI/Superflower TTS-520 PSU
 

 
AOA Team filesAOA Team wcgAOA Team fah
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 7th June, 2006, 09:36 AM
Pitch's Avatar
AOA Staff
 
Join Date: February 2004
Location: The cake is a lie.
Posts: 4,977
Send a message via MSN to Pitch

Which driver version?
__________________


XBL/PNS = neolad
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 7th June, 2006, 09:46 AM
Samuknow's Avatar
Member
 
Join Date: September 2001
Location: Indianapolis, Indiana
Posts: 8,459
Send a message via MSN to Samuknow

FYI

Threat risk: Low Risk
Low risk threats should not harm your machine or compromise your privacy and security unless they have been installed without your knowledge and consent. A low risk threat may be a program, network tool, or system utility that you knowingly and deliberately installed and that you wish to keep. Although some low risk programs may track online habits -- as provided for in a privacy policy or End User License Agreement (EULA) -- or display advertising within the applications themselves, these programs have only vague, minimal or negligible effects on your privacy. Low risk threats may also be cookies, which can be used to track your online activities, though without identifying you personally.

Description: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
__________________
"FEAR NOT" Isaiah 41:10
eVga 680i SLI 122-CK-NF68-A1
E6400 @ 3.3 @ 1.25V
2 x 8800 GTS SLI
3 x 21" Sony Trinitron
Tuniq 3 modified case.
PSU - Tuniq 950 watt Miniplant review
AOA Team fah
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 7th June, 2006, 09:53 AM
Pitch's Avatar
AOA Staff
 
Join Date: February 2004
Location: The cake is a lie.
Posts: 4,977
Send a message via MSN to Pitch

A scan of the same folder with the lastest version on Adaware and the lastest driver versions.

I can find nothing wrong.
Attached Thumbnails
i-caught-you-out-tweaksrus-tru.jpg  
__________________


XBL/PNS = neolad
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 7th June, 2006, 10:03 AM
Gizmo's Avatar
Chief BBS Administrator
 
Join Date: May 2003
Location: Webb City, Mo
Posts: 13,934
Send a message via ICQ to Gizmo Send a message via AIM to Gizmo Send a message via MSN to Gizmo Send a message via Yahoo to Gizmo Send a message via Skype™ to Gizmo

Pitch, are those the nVidia drivers, or the XG drivers?
__________________
Avatar and sig graphic by Pitch. Subscribers!
Ask about a custom graphic or avatar today!
 
Later,
Gizmo
Thermal Diode Mod and Direct-Die Water Block
8-Cheetah 18GiB U-2 SCSI
MegaRAID Enterprise 1500/128MiB
Samsung SyncMaster 955DF
TTGI/Superflower TTS-520 PSU
 

 
AOA Team filesAOA Team wcgAOA Team fah
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 7th June, 2006, 10:06 AM
Pitch's Avatar
AOA Staff
 
Join Date: February 2004
Location: The cake is a lie.
Posts: 4,977
Send a message via MSN to Pitch

XG.

The path scanned was C:\nVidia Forceware\XTreme-G 91.28.v2
__________________


XBL/PNS = neolad
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 7th June, 2006, 10:06 AM
skool h8r's Avatar
Member
 
Join Date: January 2005
Location: Rotherham, UK
Posts: 3,140
Send a message via MSN to skool h8r

These are, although old, could still be in the newer releases, the 77.76 XG drivers.
__________________

Wolfdale E8400 @ 4.0Ghz @ 1.400v
Dual-Channel 4Gb Corsair Dominator PC2-8500C5 @ 1069Mhz @ 5-5-5-15-2T (Cooled by Dominator Fan)
PNY 8800GT 512MB @ Stock (64.0GB/s Bandwidth, 11.2 GPixel, 39.2GTexel /sec)
Asus P5K-E Wifi @ 445 FSB (1780 QDR) (1.55V N/B)
CPU cooled by IFX-14 and Antec Tricool 120mm.
Antec PowerMax 850W

________________
1920x1200 Gamer (24" Widescreen)
13221 3DMark06
22935 3DMark05
42097 3DMark03

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 7th June, 2006, 10:09 AM
Pitch's Avatar
AOA Staff
 
Join Date: February 2004
Location: The cake is a lie.
Posts: 4,977
Send a message via MSN to Pitch

Downloading and Scanning now.
__________________


XBL/PNS = neolad
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 7th June, 2006, 10:12 AM
skool h8r's Avatar
Member
 
Join Date: January 2005
Location: Rotherham, UK
Posts: 3,140
Send a message via MSN to skool h8r

I did think it was a bit strange that XG's would be like this. I'm not saying it's on purpose, but i've got to assume that.
__________________

Wolfdale E8400 @ 4.0Ghz @ 1.400v
Dual-Channel 4Gb Corsair Dominator PC2-8500C5 @ 1069Mhz @ 5-5-5-15-2T (Cooled by Dominator Fan)
PNY 8800GT 512MB @ Stock (64.0GB/s Bandwidth, 11.2 GPixel, 39.2GTexel /sec)
Asus P5K-E Wifi @ 445 FSB (1780 QDR) (1.55V N/B)
CPU cooled by IFX-14 and Antec Tricool 120mm.
Antec PowerMax 850W

________________
1920x1200 Gamer (24" Widescreen)
13221 3DMark06
22935 3DMark05
42097 3DMark03

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 7th June, 2006, 10:20 AM
Áedán's Avatar
Chief Systems Administrator
 
Join Date: September 2001
Location: Europe
Posts: 11,797

I suspect that AdAware's signature matching on uninst.exe might be a little out... Unless someone can prove otherwise that is.
__________________
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #13 (permalink)  
Old 7th June, 2006, 10:27 AM
Pitch's Avatar
AOA Staff
 
Join Date: February 2004
Location: The cake is a lie.
Posts: 4,977
Send a message via MSN to Pitch

Adaware shows the file as infected, Spybot however registers it clean. I think Áedán is right.
__________________


XBL/PNS = neolad
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #14 (permalink)  
Old 7th June, 2006, 10:27 AM
Gizmo's Avatar
Chief BBS Administrator
 
Join Date: May 2003
Location: Webb City, Mo
Posts: 13,934
Send a message via ICQ to Gizmo Send a message via AIM to Gizmo Send a message via MSN to Gizmo Send a message via Yahoo to Gizmo Send a message via Skype™ to Gizmo

Quote:
Originally Posted by skool h8r
I did think it was a bit strange that XG's would be like this. I'm not saying it's on purpose, but i've got to assume that.
When dealing with malware and spyware, it is never safe to assume anything.

In this particular case, I am suspicious that you are infected by a piece of spyware that is hiding itself as an uninstaller. I have scanned the 91.31 drivers (both XG and nVidia) and there is no uninst.exe file contained in either of them. The XG packager DOES contain a file called uninst0001.exe, but it appears to be benign.
__________________
Avatar and sig graphic by Pitch. Subscribers!
Ask about a custom graphic or avatar today!
 
Later,
Gizmo
Thermal Diode Mod and Direct-Die Water Block
8-Cheetah 18GiB U-2 SCSI
MegaRAID Enterprise 1500/128MiB
Samsung SyncMaster 955DF
TTGI/Superflower TTS-520 PSU
 

 
AOA Team filesAOA Team wcgAOA Team fah
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #15 (permalink)  
Old 7th June, 2006, 10:30 AM
Gizmo's Avatar
Chief BBS Administrator
 
Join Date: May 2003
Location: Webb City, Mo
Posts: 13,934
Send a message via ICQ to Gizmo Send a message via AIM to Gizmo Send a message via MSN to Gizmo Send a message via Yahoo to Gizmo Send a message via Skype™ to Gizmo

He's got the ServerLogic.HyperLink spyware installed, or has had it installed; if you look at the report, AdAware shows that the registry entry is there. The question we need to answer is, did it come from the drivers or something else?
__________________
Avatar and sig graphic by Pitch. Subscribers!
Ask about a custom graphic or avatar today!
 
Later,
Gizmo
Thermal Diode Mod and Direct-Die Water Block
8-Cheetah 18GiB U-2 SCSI
MegaRAID Enterprise 1500/128MiB
Samsung SyncMaster 955DF
TTGI/Superflower TTS-520 PSU
 

 
AOA Team filesAOA Team wcgAOA Team fah
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #16 (permalink)  
Old 7th June, 2006, 10:39 AM
Pitch's Avatar
AOA Staff
 
Join Date: February 2004
Location: The cake is a lie.
Posts: 4,977
Send a message via MSN to Pitch

Worth noting is that although the file is idendified as infected by Adaware, it's not showing my system as being infected.
__________________


XBL/PNS = neolad
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #17 (permalink)  
Old 7th June, 2006, 10:42 AM
Gizmo's Avatar
Chief BBS Administrator
 
Join Date: May 2003
Location: Webb City, Mo
Posts: 13,934
Send a message via ICQ to Gizmo Send a message via AIM to Gizmo Send a message via MSN to Gizmo Send a message via Yahoo to Gizmo Send a message via Skype™ to Gizmo

Quote:
Originally Posted by Pitch
Adaware shows the file as infected, Spybot however registers it clean. I think Áedán is right.
Oh really?!

You've got the uninst.exe file?
__________________
Avatar and sig graphic by Pitch. Subscribers!
Ask about a custom graphic or avatar today!
 
Later,
Gizmo
Thermal Diode Mod and Direct-Die Water Block
8-Cheetah 18GiB U-2 SCSI
MegaRAID Enterprise 1500/128MiB
Samsung SyncMaster 955DF
TTGI/Superflower TTS-520 PSU
 

 
AOA Team filesAOA Team wcgAOA Team fah
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #18 (permalink)  
Old 7th June, 2006, 10:43 AM
Samuknow's Avatar
Member
 
Join Date: September 2001
Location: Indianapolis, Indiana
Posts: 8,459