BleepingComputer.com: Foistware

Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Foistware And how to avoid it

#1 User is offline   Leurgy 

  • Voted most likely
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 3,743
  • Joined: 19-September 04
  • Gender:Male
  • Location:Collingwood, Ontario, Canada

Posted 02 October 2005 - 12:26 PM

This thread will illustrate what happens when you go to a malicious website that won't let you leave without downloading their program. Its very hard to get away from once you go there. It will also discuss what to do when this happens and how to get out of the situation without getting any unwanted malware related programs installed on your computer without your consent or knowledge.

Please be aware that these are only screenshots and nothing will happen to your computer. They are not clickable. The following is based on using Internet Explorer and concerns a feature called "Install on demand". There are instructions at the end of the post for disabling this feature

So you click on a link for an anti-spyware program or maybe its a popup or a link in your email and you are taken to a website like this:

Posted Image



If you don't have Install on demand disabled and you use Internet Explorer you are already the unwitting recipient of the following download. It has been downloaded and installed on your computer. You are infected with malware now. This is known as a "Drive By Download".

Posted Image


If you do have Install on demand disabled you receive the above security warning and you would think that you are ok. You click No. You try to navigate away from the site, but wait, what this?

Posted Image


No, no, no, You don't want to do this. You click cancel. Now you get this:


Posted Image


Now what are you going to do? I don't believe that if you clicked Ok on that box that you would have the option of Run or Open, which implies a Cancel option too. I think the download may start right away.

Its important not to panic or to get frustrated and click Ok just to make the boxes go away. Personally, I chickened out at this point. If you were using a ZoneAlarm Firewall or any other type that has an Internet Lock this would be the ideal time to use it. In order to get out of this you need to close the browser using the Task Manager/Close Programs feature accessed by using Ctrl+Alt+Delete and closing the page. The second time I went to this site when I forced the window to close I got a blue screen.

If I get brave I'll go back and click Ok on that last one. :thumbsup:

In Firefox, you can disable the automatic install feature this way:

"tools tab", under "tools, options, web features", the
default setting is "Allow websites to install software". Uncheck that.

Thanks to our jgweed for that info.

In Internet Explorer go to Tools>Internet Options>Advanced and take the check mark from Enable Install On Demand (Internet Explorer) and Enable Install On Demand (Other). The consequence of this will be that you will begin to see Security Warnings when something tries to install on your computer. Unless it is something you want to install (which happens rarely) always say no.

Many thanks to Pandy for all her hard work on the screenshots in this post and her timely advice.

This post has been edited by Pandy: 13 April 2006 - 07:53 AM

**** We use our powers for good, not evil ****
When the only tool you own is a hammer, every problem begins to resemble a nail. Abraham Maslo

#2 User is offline   Pandy 

  • Bleepin' GloMod
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 9,494
  • Joined: 11-April 04
  • Gender:Female
  • Location:Whence I came

Posted 02 October 2005 - 12:33 PM

Leurgy. It was my distinct pleasure to assist you. :thumbsup:
Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight.Hide not your talents. They for use were made. What's a sundial in the shade?~Benjamin Franklin I am a Bleeping Computer fan! Are you? Like us on Facebook Follow us on Twitter

#3 User is offline   Grinler 

  • Bleep Bleep!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Admin
  • Posts: 36,174
  • Joined: 24-January 04
  • Gender:Male
  • Location:USA

Posted 02 October 2005 - 08:19 PM

Very informative posts and a great job on the research. This is a great example on how our members can see how malware/foistware/adware can get installed on their computers and how to avoid it.

Kudos!

#4 User is offline   UKBiker 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 8
  • Joined: 26-May 05

Posted 03 October 2005 - 09:45 PM

Excellent write up. Well done.


UKBiker

#5 User is offline   Dollyeyes 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Members
  • Posts: 226
  • Joined: 06-September 05
  • Gender:Female
  • Location:Nottingham, England town!

Posted 08 October 2005 - 11:28 AM

:thumbsup: As a newbie..i have just read this item and it was so easy for a non-puter savvy person like myself to understand.....thankyou pandy and Leurgy! :flowers:
Posted Image
Of all the things Ive lost...I miss my mind the most!

#6 User is offline   Haroldo 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 115
  • Joined: 05-April 04

Posted 08 October 2005 - 03:46 PM

Your fans over at CoU will see this link

#7 User is online   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 46,208
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

  Posted 08 October 2005 - 07:37 PM

A great wtite up as you know I got hammered by one of those a few days ago. I hope every body reads the aticle. Because these sites can be monsters.. Thanks for all the work..... :thumbsup: :flowers:
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#8 User is offline   Pandy 

  • Bleepin' GloMod
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 9,494
  • Joined: 11-April 04
  • Gender:Female
  • Location:Whence I came

Posted 09 October 2005 - 01:00 AM

Oh Haroldo Thank you so much for the link there at CoU. That's awesome! :thumbsup:
Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight.Hide not your talents. They for use were made. What's a sundial in the shade?~Benjamin Franklin I am a Bleeping Computer fan! Are you? Like us on Facebook Follow us on Twitter

#9 User is offline   yano 

  • I can see what you post!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 6,469
  • Joined: 14-February 05
  • Gender:Male

Posted 09 October 2005 - 05:15 AM

Great advice! Very helpful in protecting yourself, regardless if you use Firefox or IE.

Personally I leave the "Allow Websites to Install Software." Checked, however I have only Mozilla's Official Firefox Extension website under the "allow list."

#10 User is offline   Elixer 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 05-October 05

Posted 10 October 2005 - 01:33 PM

Very helpful for users and a good read.
Resident Geek

"There is an answer to every question, but is there an answer to every problem?"

#11 User is offline   Albert Frankenstein 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 2,707
  • Joined: 23-September 05
  • Gender:Female
  • Location:Michigan, USA

Posted 10 October 2005 - 04:22 PM

Thanks for the info. I actually just accidentally visited one of these sites. I had misspelled a popular antivirus web site's URL and got the bad web site instead.

Sneaky little devils, ain't they!
ALBERT FRANKENSTEIN
I'M SO SMART IT'S SCARY!


Currently home chillin' with the fam and my two dogs!

#12 User is offline   rms4evr 

  • Distinguished Member
  • PipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 811
  • Joined: 11-October 05
  • Gender:Female
  • Location:East Coast

Posted 13 October 2005 - 08:15 PM

Thanks for the tip! I hate those sites. It's one of the reasons I switched to Mozilla.

#13 User is offline   Ravenshade 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 8
  • Joined: 02-June 05
  • Location:San Diego, CA

Posted 14 October 2005 - 06:15 PM

Thanks for the tips, always appreciated guys.

#14 User is offline   Animal 

  • Bleepin' Animinion
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Site Admin
  • Posts: 17,979
  • Joined: 18-August 05
  • Gender:Male
  • Location:Location, Location

Posted 15 October 2005 - 11:05 PM

Leurgy and Pandy,

It is my distinct pleasure to utilize my 100th post to, congratulate you both on an excellent job on this topic. It's very well written and illustrated. And long overdue to have this "Bleeping" subject addressed. Keep up the great work you two.

Be (Foistware) Safe

Da Animal

The Internet is so big, so powerful and pointless that for some people it is a complete substitute for life.
Andrew Brown

Posted Image
A learning experience is one of those things that say, "You know that thing you just did? Don't do that." — Douglas Adams.
Why is the word abbreviation so long?
Follow BleepingComputer on: Facebook | Twitter | Google+

#15 User is offline   Pandy 

  • Bleepin' GloMod
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 9,494
  • Joined: 11-April 04
  • Gender:Female
  • Location:Whence I came

  Posted 16 October 2005 - 10:21 PM

:thumbsup: Animal Thank you :flowers:
Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight.Hide not your talents. They for use were made. What's a sundial in the shade?~Benjamin Franklin I am a Bleeping Computer fan! Are you? Like us on Facebook Follow us on Twitter

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users