<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hosts News : BitTorrent CidHelp</title><link>http://msmvps.com/blogs/hostsnews/archive/tags/BitTorrent+CidHelp/default.aspx</link><description>Tags: BitTorrent CidHelp</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>BitTorrent users Beware!</title><link>http://msmvps.com/blogs/hostsnews/archive/2007/07/19/bittorrent-users-beware.aspx</link><pubDate>Thu, 19 Jul 2007 12:48:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1039370</guid><dc:creator>winhelp2002</dc:creator><slash:comments>0</slash:comments><comments>http://msmvps.com/blogs/hostsnews/archive/2007/07/19/bittorrent-users-beware.aspx#comments</comments><description>&lt;p&gt;&amp;quot;&lt;em&gt;BitTorrent is a method of distributing large amounts of data (P2P) widely without the original distributor incurring the entire costs of hardware, hosting and bandwidth resources.&amp;quot; &lt;/em&gt;[Full Wikipedia description &lt;a class="" href="http://en.wikipedia.org/wiki/BitTorrent" target="_blank"&gt;here&lt;/a&gt;]&lt;/p&gt;
&lt;p&gt;Seems the Cash4Downloads folks have teamed up with CidHelp (C2Media/LOP) to distribute &amp;quot;free software&amp;quot; for users looking for BitTorrent programs. So let&amp;#39;s see what they offer ...&lt;/p&gt;
&lt;p&gt;&lt;img style="WIDTH:394px;HEIGHT:409px;" height="409" src="http://mvps.org/winhelp2002/blog/get-torrent.gif" width="394" border="1" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;As you can see ... &amp;quot;no spyware, no adware, no malware&amp;quot; ... oh really? I scanned the download at VirusTotal&lt;/p&gt;
&lt;p&gt;Get-Torrent-2.0.0.0-setup-0350.exe&lt;/p&gt;
&lt;p&gt;BitDefender 7.2 2007.07.19 Trojan.FatObfus.A&lt;br /&gt;DrWeb 4.33 2007.07.18 Trojan.Packed.149&lt;br /&gt;F-Secure 6.70.13030.0 2007.07.18 Trojan.Win32.Obfuscated.dt&lt;br /&gt;Ikarus T3.1.1.8 2007.07.18 Trojan.Win32.Obfuscated.en&lt;br /&gt;Kaspersky 4.0.2.24 2007.07.19 not-a-virus:AdWare.Win32.Lop.bo&lt;/p&gt;
&lt;p&gt;[or]&lt;br /&gt;BitRoll-2.2.0.0-setup-0410.exe&lt;/p&gt;
&lt;p&gt;Avast 4.7.997.0 2007.07.18 Win32:Trojan-gen. {Other}&lt;br /&gt;BitDefender 7.2 2007.07.19 Trojan.Agent.AOJ&lt;br /&gt;DrWeb 4.33 2007.07.18 Trojan.Packed.149&lt;br /&gt;F-Secure 6.70.13030.0 2007.07.18 Trojan.Win32.Obfuscated.en &lt;br /&gt;Ikarus T3.1.1.8 2007.07.18 Trojan.Win32.Obfuscated.en &lt;br /&gt;Kaspersky 4.0.2.24 2007.07.19 not-a-virus:AdWare.Win32.Lop.bo &lt;br /&gt;Microsoft 1.2704 2007.07.18 Trojan:Win32/Busky.C&lt;br /&gt;Symantec 10 2007.07.19 Torrent101&lt;/p&gt;
&lt;p&gt;There are about 15 other related sites all hosted on the same IP address (69.72.144.122) however the majority of the downloads are redirected and actually coming from &lt;strong&gt;67.15.107.166&lt;/strong&gt;. I would highly suggest adding that IP address to the Internet Explorer &amp;quot;&lt;a class="" href="http://mvps.org/winhelp2002/restricted.htm" target="_blank"&gt;Restricted Zone&lt;/a&gt;&amp;quot; as this will prevent the download.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://mvps.org/winhelp2002/blog/get-torrent2.gif" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;As you can see in the VirusTotal results several Antivirus vendors have their own descriptions, but I can assure you these are CidHelp (C2Media/LOP) related.&lt;/p&gt;
&lt;p&gt;&lt;a class="" href="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-071213-0024-99&amp;amp;tabid=2" target="_blank"&gt;Symantec.WinZix&lt;/a&gt; states: &amp;quot;The program may then download a copy of Adware.Lop on to the computer.&amp;quot;&lt;br /&gt;McAfee &lt;a class="" href="http://69.64.185.84/sites/torrent101.com/downloads/5188818/" target="_blank"&gt;SiteAdvisor.torrent101.com&lt;/a&gt; download analysis shows the following Registry edits are made:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow]&lt;br /&gt;ADD&amp;nbsp;netbios-wait.com=&amp;quot;&amp;quot;&lt;br /&gt;ADD&amp;nbsp;netsearchsoft.com=&amp;quot;&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Now &lt;em&gt;netbios-wait&lt;/em&gt; and &lt;em&gt;netsearchsoft&lt;/em&gt; are both C2Media/LOP sites ... looks like the world of BitTorrent can be a dangerous place. Especially if you install one of these &amp;quot;no spyware, no adware, no malware&amp;quot; programs.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1039370" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/BitTorrent+CidHelp/default.aspx">BitTorrent CidHelp</category></item></channel></rss>