Help - Search - Members - Calendar
Full Version: Imageshack Promotes Malware
BleepingComputer.com > General Topics > Photo Albums, Images, and Videos
   
Rimmer
I don't know if this is new but I was disappointed to see one of these fake "warning messages" come up when I followed a link to Imageshack - a site I and others here have recommended members use for photo storage.

The warning is an advertising link to a site which sells SpywareCleaner - a product listed as rogue anti-spyware at Spyware Warrior.

For those that may not know:
Don't click the Ad! Nothing has been detected on your system. It's a con job.
Scarlett
What?? No way. Say it aint so. OMG I cant believe it.

That is crazy, I wonder if they (ImageShack) is aware of what is behind the ad. Or if so, do they care? *Shrug
Rimmer
I've emailed ImageShack and await a reply.
Scarlett
Cool, please keep us all posted.
ddeerrff
I've seen that same one on DrudgeReport too. While we feel (know) that the software advertised is of dubious quality or even malicious, the products are legal and have a right to legitimate advertising. It would be nice if these sites would be more discriminating about what ads they run, but I can't really fault imageshack or Drudge for accepting these adds.

All we can do is make sure as many people as possible know that these are not the best products for the job.
Rimmer
I think there's more that can be done than that. As individuals we can register complaints to Imageshack and as a forum we can withdraw our recommendation of ImageShack to our members. If we informed them officially - a decision that lies in the hands of the site owner and staff of course - that this was happening I would have thought it would apply pressure to Imageshack to reconsider their advertising criteria.
cybormoron
thanks rimmer...i hotlink alot of images at imageshack also but they'll never see another from me. i'm glad i caught this thread. in fact i came here to post a screenshot but i won't now. we shall all just have to find another good image host. i hope you don't mind if i share this notice at some of my other board hangouts?
ddeerrff
QUOTE(Rimmer @ Jan 8 2006, 10:42 PM) *
I think there's more that can be done than that. As individuals we can register complaints to Imageshack and as a forum we can withdraw our recommendation of ImageShack to our members. If we informed them officially - a decision that lies in the hands of the site owner and staff of course - that this was happening I would have thought it would apply pressure to Imageshack to reconsider their advertising criteria.


Don't get me wrong, I get annoyed seeing these too. If someone has a form letter (or boilerplate) to send to these sites I would be happy to do my part.
Rimmer
Sorry for the slow response.
cybermoron - please feel free to alert others and solicit their help. However I would not use the title of my post (re malware) as that seems, on reflection, to be going too far.

Reading more of the links at Spyware warrior it seems SpywareCleaner appeared in November 2005 as one of a group of about six or seven anti-spyware products which closely resemble Ad-Aware 6.0. See http://www.spywarewarrior.com/family_resemblances.htm#5
They were all written by one guy in Serbia, in 2004, contracted by a company that also peddles pornography. The author makes assurances the product(s) were clean when he wrote them but their evolution is controlled by the owning company. He was contracted to update the application a few months (after their release?) later. Testers of the "Free Scan" report multiple false positives. Links lead only to the purchase form and the form (which asks for banking and credit card details) is insecure.

So given the above it would seem the product itself is not itself malware or wasn't when written, but it may leave users open to attack through poor updating practices and poor resourcing. It also seems the company that owns the product provides no protection for their customers privacy and is engaged in deceptive advertising and is allegedly linked to illegal activities. Still want to buy it for $69.95?

ddeerrff -I don't have a form letter and I don't know what a "boilerplate" is but here's what I wrote to ImageShack - feel free to cut and paste or maybe someone could turn it into a form letter?
QUOTE
Your current advertisements which begin "Warning Spyware Notice" promote a product called SpywareCleaner which is listed as rogue anti-spyware at the Spyware Warrior site http://www.spywarewarrior.com/rogue_anti-spyware.htm

As a member of a computer help forum which specialises in removing malware from computer systems, I am alarmed that you should allow the promotion of such dubious software. The advertisement is deceptive as it pretends to be a message from the user's system, and the product it advertises is of dubious benefit for reasons detailed at the Spyware Warrior site. Use of this product in place of peer-approved products may make the computer systems of your members (and ours) more vulnerable to spam, spyware and other malware.

I hope you will review your criteria for advertising content and prevent such material from appearing in future.

Regards,
Rimmer


Here is the link to email ImageShack - http://reg.imageshack.us/content.php?page=email&q=customer
Customer Feedback is probably the best choice though I sent mine to Marketing as I was following links about advertising.

Note: No reply received other than the automated thanks. The SpywareCleaner Ad is not coming up today.
phawgg
Originally, I recommended photobucket.com. My problem (the only one) with that site is that I maxed out the capacity to store images. Freely. 95% of 'em were for here, but as time has left them deep in the back pages, or deleted, my original concern for site integrity regarding threads that might indeed still be viewed has lessened somewhat.
ddeerrff
Thanks Rimmer.
Scarlett
QUOTE(Rimmer @ Jan 10 2006, 12:41 AM) *
Note: No reply received other than the automated thanks. The SpywareCleaner Ad is not coming up today.


Well it seems to me that even though all you received from the folks at Imageshack was an automated thanks, that you must of gotten through to them. Since the ad no longer shows.

Well Done! clapping.gif

Maybe they were not at all aware of what was behind the ad. *Shrug
Rimmer
Scarlett - I doubt the ad is gone, I think they just appear on rotation.
Scarlett
Well dangit, then there needs to be more done then.

As soon as I can I will send an e-mail off to.
Neverwill
www.imagedump.net lots better..and very fast..doesnt look like a very good site..but try it out some time
Rimmer
Neverwill - Imagedump seems very, very under construction. Not fast at all for me. No terms of service? I registered and it said "come back on the 15th" Huh??? Looks like it has potential though e.g. 2MB max image size! Saved this:


Seems to work! Going by the url it is just a dump (no album structure) - so if you loose the image link/tag/url you can never find it again?

phawgg - photobucket seems fairly good but they have a 512KB image size restriction and 50MB total space on the free accounts. A bit restrictive for some purposes.

Does anyone have any experience with Photosite?
boopme
Hello, man was I surprised to see that malware. I let my son read the posts as he laughed when I showed him come 5.25's. Well he advised me that he'd clicked a link there to remove something. Anyway I scanned my pc with Adaware to see if it was anything and it found some new things. i cannot be sure if they actually are a result of that click. But I never had comet ware before and I didn't add any screensavers to my pc. Plus the result of 2 possible browser hijack attempts didn't please me. Here is that section of the report.
I also have used Imageshack many times before without seeing anything like that. Again thanks Rimmer for your diligence.

Note: I see now it posts a Casale media advertisement.
Does anyone else's links do this?

POSSIBLE BROWSER HIJACK ATTEMPT
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[37]=Regkey : SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7E980B9B-8AE5-466A-B6D6-DA8CF814E78A}
obj[38]=RegValue : SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} "Installer"


COMETSYSTEMS
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[35]=Regkey : clsid\{722d2939-a14a-41a9-9eac-ab8f4e295819}
obj[36]=Regkey : clsid\{88d758a3-d33b-45fd-91e3-67749b4057fa}
obj[54]=Regkey : interface\{760aca60-79c3-4875-9d19-b14a5b3fea77}
obj[55]=Regkey : interface\{883ea659-ed80-46f9-9ed2-83327f67789f}
obj[56]=Regkey : interface\{b64c73d7-459e-4816-91f9-1348f8e36984}
obj[57]=Regkey : screensaversinstaller.installer
obj[58]=Regkey : screensaversinstaller.installer.1
obj[59]=Regkey : screensaversinstaller.sinstaller
obj[60]=Regkey : screensaversinstaller.sinstaller.1
obj[61]=Regkey : typelib\{0ab5b0d8-2b74-4c1c-8fa4-e52550b8b45b}
Leurgy
Another alternative I just came across is http://tinypic.com/
Rimmer
Tinypic looked good at first, but on closer examination....

Rimmer
If by misfortune you have the Winfixer scumware here's how to remove it:

http://www.bleepingcomputer.com/forums/ind...610&hl=winfixer
boopme
So what hosting site (s) are left? sad.gif
Rimmer
Very good question... I'd be happy to hear other suggestions.

I'm still waiting on Imageshack to reply (have sent another "email") but maybe we go back to recommending them with a caveat about the suspect Ads? Likewise Photobucket?

Photosite looks interesting, but I'm having internet problems so cannot check it out at present. sad.gif
Scarlett
Rimmer perhaps if more gave donations to these photo hosting sites, they would not have to stoop to these levels.... *Shrug smile.gif Just thinking out loud.
phawgg
I'm using this one now:

http://www.imagevenue.com/
Scarlett
Phawgg

Now that one just could be the ticket. Thanks for the link. smile.gif

For everyone's convenience here are ImageVenue's FAQ's

http://www.imagevenue.com/faq.php
phawgg
Registration is optional.
A quick upload/link
or make a directory after registering
and it seems basically unlimited from there.

Or pay 1.66 per month ... thumbup.gif

[img=http://img138.imagevenue.com/loc88/th_47b1d_python.jpg]
Neverwill
im tellin yah... www.imagedump.net :D haha..there gettin a dual xeon 2.6 server or something like that...and music hosting capabilitys soon
phawgg


The ImageDump also looks good, Neverwill
Rimmer
I'm having a lot of trouble posting at present because my satellite connection is really flakey and the ISP tells me nothing.
Scarlett - Why is it a problem just having URLs? That's perfect for the "Insert Image" tool in the reply windows. The tool adds the 'img' tags for you.
As regards donations - I don't think they are necessary unless it's obviously a private operation. Most of these image sites are corporations which get revenue from advertising, and usually the free service is just a lead-in to a paid service anyway.

Phawgg - imagevenue looks good. Max size 1.5MB unlimited number of images. Yum! smile.gif

A representative of Imageshack sent me a confirmation that my emails had been received but made no other comment. Their site ads have been like this -

-for some time now. We won't know for sure unless they comment.

I thought the Imageshack service was pretty solid - very little downtime, quick downloading. I'm thinking I'll go back to recommending them (until I'm confident of Imagevenue etc.) with a warning about possible advertising content.

Now it's Photobucket I'm more concerned about! sad.gif
Scarlett
Rimmer Good point ie: donations. smile.gif

I have edited all info. regarding the site I had mentioned.

Not to impressed with the attitude shown by some of it members.
It seems that politeness is not a general forte' there.
And the site itself is quite involved, much more then most members probably need.

I'd rather move on and check out the other suggestions. And well, I do like ImageShack & Photobucket and will continue to recommend them.

In my pinned topic "How to Insert Images Within a Post" I may need to add some sort of warning of the suspect ads in question.
*Shrug
I'd gladly accept any help with the warning. ;)
Rimmer
My 3rd attempt to post a reply, curse you Telstra! mad.gif

Imagedump seems to be getting itself together though its still pretty rough. Given BCs family friendly policy I don't think we're going to be recommending it soon though as the advertising is a little "mature age only":
(Click the thumnail)



Scarlett - how about this?
CAUTION
Photobucket, TinyPic and Imageshack may display advertisements
of a deceptive nature disguised as system messages.
Clicking on these ads may result in malware being installed on your system.
Please do not click on any advertising content or other messages while using these sites.
phawgg
That'll work.

I need the hair loss ads.
I dunno 'bout the 19yr old onwebcam. lmfao.gif

bottomline:

clicking on advertising content can always be a source of problems ?
yano
I use mooland.com for large files. However I still imageshack. I really don't see the point of trying to avoid it because of the ads. You can't control them, why not use the Firefox extension "nuke all."
*Desdinova*
perhaps imagehigh is a good, cleaner alternative ? smile.gif

http://www.imagehigh.com
Scarlett
Thanks *Desdinova*

That looks great! Do you use it? And if so for very long?
*Desdinova*
Hi Scarlett smile.gif


Yes, I use it for about 6 weeks or so (not registrated), and personally I really like it thumbup.gif

* Haven't experienced that the server was down by yet (Imageshack really has many and long downtimes lately)
* You can upload lager files and simultaneously for more images
* No disturbing ads when you click a thumbnail (Imageshack shows since a few days (?) a "falling" advertention in the middle of the hosted image when one clicks the thumbnail-version to enlarge it)
* It's fast and easy to use

Although that "Useful Links: StuffAllFree" at the bottom, might not be trustworthy unsure.gif
but if not, it is not "that" present as in Imageshack


Enjoy tongue.gif
Scarlett
Thanks for the quick reply, *Desdinova*.

And for all the additional info.

You rawk!
Rimmer
*Desdinova* - Imagehigh looks very promising, thanks for the link!

yano -
QUOTE
I really don't see the point of trying to avoid it because of the ads.

My point is that BC is a site with a strong bias toward helping novice computer users. It would seem to me to be irresponsible and counterproductive to then recommend (as we do) that those users go to sites that allow adverts, for very dubious products, disguised as fake system messages. You and I both know not to click on these ads because that may allow malware to be downloaded onto our systems, novice users may be more easily duped.

The aim of this thread was threefold:
  1. To warn members to beware of these kind of ads.
  2. To encourage people to pressure imageshack not to run them.
  3. To find an alternative image host which does not run this type of ad.
Personally I haven't seen any of the 'malware' ads on Imageshack since our mini email campaign so maybe we did some good there? Well done those of you who did contact them. thumbup.gif
acklan
Another solution for HSI user would be to use IIS to host your own pictures via a free DynDNS service.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.