Jump to content

nlite infected by 180solutions ? Youre kidding !


retox

Recommended Posts

After scanning for spyware I have been informed by pest patrol thatn-lite carries 180solutions zango software

and that pest patrol considers n-lite to be a risk - it lists zango as being by 180solutions. This wasnt infected by my computer it was carried into the computer on a download of n-lite

I got the file from this page here

http://www.nliteos.com/download.html

and it was the top link on the "self extracting archive" menu (not the mirrors from the site itself)

I just tested the ones from the mirror sites and they are OK

I retested the top link and its definitely infected

You might be wondering why I dislike 180solutions so much, well when you realise that they scam 2billion a year out of spamming the internet (or used to - personally I think they still do) and when you have had entire business networks go down because of them - perhaps you will realise.

Nlite has infected your computer - check the registry for the word "sodoku" and then read on

http://www3.ca.com/securityadvisor/pest/pe...px?id=453100325

you may like to read up on the following

There are problems you will probably encounter with any title by 180solutions, just bear in mind the FBI threatened the directors with a legal case and also informed them they would press for custodial sentences unless they co-operated in making a case against other fraudsters - perpertrators of spyware viral code and other malware. Now considering they were making spambots at the time - do you want to take the risk - read on.

full story here at Ben Edelman's website - Edelman helped the FBI track these... "people" down

Ben's current research includes analyzing methods and effects of spyware, with a focus on installation methods and revenue sources. Ben has documented advertisers supporting spyware, advertising intermediaries funding spyware, affiliate commission fraud, and click fraud ...I present a methodology for rigorously examining the activities of 180's Zango software, and I show the results of my examination, including a list of affected merchants.

http://www.benedelman.org/spyware/180-affiliates/

http://www.benedelman.org

news item here

http://www.xbiz.com/news_piece.php?id=11111

Before you read any further see this page

http://www3.ca.com/securityadvisor/pest/pe...px?id=453100325

and find out if your registry or any files in unattended installations are infected

also

google for +180solutions +fbi

basically 180solutions is company that was raking in around 2 Billion dollars a year frrom infecting computers and networks with trojans and other malware designed to get advertising onto your desktop

My point being that its up to you whether you trust this software but I know for a fact that 180solutions is one of the most corrupt companies in existence and if I were you I'd think long and hard about using anything that was ever anything to do with them in a corporate environment or on my own home network.

You just cant trust it. I want to know what zango software is doing in n-lite ?

180 solutions is now spending a great deal of money to tell people they went to the FBI and that theyve cleaned up their act- infact the FBI basically went to them and threatened them with many years behind bars - also do you really believe anyone is going to give up 2Billion a year that easily?

Edited by retox
Link to comment
Share on other sites


i have scanned the file

here

hxxp://www.virustotal.com

here

hxxp://virusscan.jotti.org/

And here

hxxp://housecall65.trendmicro.com

The sites report the file as clean , either this has been silently fixed or you have made mistake

Edited by glent
Link to comment
Share on other sites

I got the file from this page here

http://www.nliteos.com/download.html

and it was the top link on the "self extracting archive" menu (not the mirrors from the site itself)

I just tested the ones from the mirror sites and they are OK

I retested the top link and its definitely infected

theres no mistake - if I download the self extracting archive from nliteos.com (not the ones from the mirror sites but the top one on the menu ) it definitely adds to my registry the zango software - theres no mistake - its that one file is infected FOR DEFINITE - dont rely on a scan - download the file and check the registry for the word "sudoku" then when it infects your computer edit it out and try a different download site for nlite - it wont do it. Then go back to the top link install n-lite and its there again - I'm not making this up !

Link to comment
Share on other sites

infact I just re-tested it and its still infected !!!!!

you on drugs?

av-16512.jpg

and youre asking me that ?

look its pretty simple - you go to nlite os

http://www.nliteos.com/download.html

download from a mirror site the self extracting archive

install it

run it

search your registry does it contain an entry with the word sudoku? No

now get the version thats not on a mirror site

install it

run it

search registry

now the signature for the 180solutions software will be there

if you need to know full details of the signature read up on

180solutions zango software

the last time there was a mass infection there were 400,000 computers in one spambot network

If necessary I will get Edelman to test it for me - he is quite willing to do that, I have

had corespondence with him before now.

Incase the implications arent that obvious to you - anyone thats installing a disk made with the software will have to be careful they arent creating a spambot or spyware network

Edited by retox
Link to comment
Share on other sites

i didnt know u are a guru in spyware and u found it just by scaning manually after some word u made up.....go party or other activities ....i scaned nlite with a lot of av and antispyware.....

and by the way if u dont like it cause its infecting you pc with the word u said DONT USE IT!!!!!1

Link to comment
Share on other sites

infact I just re-tested it and its still infected !!!!!

look its pretty simple - you go to nlite os

http://www.nliteos.com/download.html

download from a mirror site the self extracting archive

install it

run it

search your registry does it contain an entry with the word sudoku? No

now get the version thats not on a mirror site

install it

run it

search registry

now the signature for the 180solutions software will be there

Did that,but the word did not appear in my registry, Maybe your already infected before?

this do not need to be a flame war :no:

Edited by glent
Link to comment
Share on other sites

i didnt know u are a guru in spyware and u found it just by scaning manually after some word u made up.....go party or other activities ....i scaned nlite with a lot of av and antispyware.....

and by the way if u dont like it cause its infecting you pc with the word u said DONT USE IT!!!!!1

well now you do know !

erm infact several anti spyware programs I just ran confirmed what I have been saying - I have been looking into the problem since 4am uk time and - All I have is the fact that on a fresh install downloaded from the nlite site they reported the error I'm not trying do anything but alert you to a problem - if you dont take it seriously enough thats your luck out

It was not a false positive and it was reported by my antispyware as zango software by 180solutions

which puts its signature in the registry and that signature contains the word sudoku

now I dont know what your problem is ! but I can tell you 2 things 1) this happened exactly as I reported it

and 2) the problem is now not occuring as of about 15 minutes ago (13:18 uk time)

two other facts are that it occured also using a download I took at around 7am yesterday morning

the other fact being that I tested it at 7am on a completely fresh install this morning on a computer not interfaced with the internet and got the same results as at 4:30am

also just FYI - there is little chance this could have come from anywhere else I am hooked up to a firewall and all my http traffic is scanned for malware before it gets to me by a subscription service - all my ports are closed and none of my antivirus scanners on any of the security behind the firewall picked it up till I rebooted and scanned the registry but my antispyware scanners saw it straight away

Edited by retox
Link to comment
Share on other sites

i cant seem to find spyware in it anyware

Is anyone actually reading anything thats written or do you just reply to the first post

I'm telling you this happened and that by scanning the file that you download you would not have found it - also the file that infected my computer came from one single link on the download page - not the others

the only way to detect the infection is when it enters the registry and places registry values there

you cannot scan the file and detect it - you have to look in the registry

but since its stopped now and the file appears to have been cleaned - its largely academic now

I'll say it one more time - jeez

you can only find the infection in the registry not by scanning the file

for people who havent found the references to it

http://www3.ca.com/securityadvisor/pest/pe...px?id=453100325

http://research.sunbelt-software.com/threa...;threatid=69482

http://www.pctools.com/mrc/infections/view/2500/

anyway - I've had enough - you do what you want with the information but I havent had any reason to say this other than to tell you to be careful - if you dont take that advice its up to you

Edited by retox
Link to comment
Share on other sites

well why are you interested - it strikes me that youre pretty fast to deny anything was wrong - surely it would have been better to ask what the values were in the registry. Its pretty much ineffectual to ask what software I used if the way to verify the infection is by scanning the registry

by typing "regedit" into a command prompt and looking for the signature

if it was a false positive or a faulty scanner the signatures wouldnt have been there

Since they were in the registry and only got there after installing the software its obvious the software n-lite carried them there

now why you cant accept this I dont know but I GOT A PRETTY GOOD IDEA WHY

Link to comment
Share on other sites

Same here. Picked the one you said, installed, ran spyware scanner (something I never bother with), and it found absolutely NOTHING at all. No "sudoku" anywhere in my registry either. Stop spreading lies!

Don't take my word for it either:

nliteokty9.th.png

Not that I'm nlite user, but I figured that just couldn't be true.

If you have spyware problems just ditch IE already, don't blame 'em on nlite.

Edited by crahak
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...