Trojan from a 'SAFE' download :)

Neno

Level 6
Thread author
Verified
Well-known
Jan 4, 2012
278
Just got infected with trojan and a PUP, from the link that should have been safe.
WSA cought trojan and MBAM dealt with PUP trash.
I downloaded Wise Care 365 pro via the provided link installed it and got my browser page changed trough it instantly.
Shame i didnt made some screenshots :(

'http://wise-care-365-pro.en.softonic.com/download'
 

Attachments

  • SiteScan.jpg
    SiteScan.jpg
    96.7 KB · Views: 408

trainbus120

Level 10
Verified
Sep 12, 2013
454
Just got infected with trojan and a PUP, from the link that should have been safe.
WSA cought trojan and MBAM dealt with PUP trash.
I downloaded Wise Care 365 pro via the provided link installed it and got my browser page changed trough it instantly.
Shame i didnt made some screenshots :(

'http://wise-care-365-pro.en.softonic.com/download'
Its always advisable to download software from the official website. Since other sources like in your case may pretend to be safe but may not be so.
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,403
Avoid using the Green Safe Download button on Softonic.
upload_2014-5-5_16-25-38.png

It will likely download something like this, a web installer less than 400KB. Notice it says "Softonic_Downloader_for..."
upload_2014-5-5_16-23-43.png


Observe the Softonic download page. What you downloaded is highlighted in RED. A Web installer than contains potentially unwanted software, signed by Softonic International.

An alternate download highlighted in GREEN. An offline installer, 8.11MB signed by Lespeed Technology Ltd.
http://www.herdprotect.com/wisecare365.exe-ba95126630b4d737183464feae66a49c517d4074.aspx
You can check WiseCleaner is safe by confirming it's signed by Lespeed Tech. as with their direct download, as seen in the second image.

wcleaner1.png


Downloading from wisecleaner.com (direct download) and mirror site (download.cnet.com) - Not ad-sponsored.

wcleaner2.png


Executing program from Softnotic (highlighted in RED) versus a program downloaded directly from wisecleaner.com or a trusted mirror (highlighted in GREEN).

wcleaner3.png


+1 for visiting to download from the developers site, or a trusted mirror. And check what you're installing is what you want.

http://www.urlvoid.com/scan/softonic.com/
https://www.mywot.com/en/scorecard/softonic.com (See image for some of the recent comments).

upload_2014-5-5_15-58-30.png
 

Neno

Level 6
Thread author
Verified
Well-known
Jan 4, 2012
278
I did all that. But the Wise Care was infected not the downloader nor the recommended programs. Their version of Wise 365 was infected only and it was not signed (unknown signature).
 

King Alpha

Level 25
Verified
Top Poster
Content Creator
Well-known
Jun 21, 2013
1,492
I downloaded and installed Wise Care today and I haven't encountered any problems. What's your AV?
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,403
Do you know what or who it was signed by?
 

Neno

Level 6
Thread author
Verified
Well-known
Jan 4, 2012
278
Webroot SA, it was a virus and MBAM found it too, it did change the homepage in IE and it was not signed at all. I intentionally left it trough UAC unsigned relying on my malware protection suites and it was caught by it. As I already told, I only started Wise Care 365 nothing else from the download (by Softsonic downloader). After I got infected I used Virus.Total to check the link just to see their result and found out it is actually a clean download site.
I made this topic only because of it.
Before I uninstalled Wise Care I started it and it was on some kind of Arabic language. It seems virus was the part of installer not a part from actual Wise Care executable.
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,403
The site may be clean, but the download is not (referring to the topic title, 'SAFE download' can be seen below too).

If you clicked on
upload_2014-5-5_16-25-38-png.10720
to download Wise Cleaner 365.

This is what you downloaded:
https://www.virustotal.com/en/file/...73e100c50a5249ce90e9f4f1/analysis/1397975346/

Code:
Agnitum - PUA.Softonic!20140419
Baidu-International - Adware.Win32.SoftonicDownloader.F20140419
Comodo - Application.Win32.Agent.SOFE20140414
DrWeb - Adware.Downware.276020140420
ESET-NOD32 - a variant of Win32/SoftonicDownloader.F20140420
Malwarebytes - PUP.Optional.Softonic.A20140420
Rising - PE:Malware.Obscure/Heur!1.9E0320140420
VIPRE - Softonic Downloader (fs)

I've tested Softnotic Downloader before, they use some sneaky tricks to disguise the adware, and to trick the user.

Hope this helps. :)
 
  • Like
Reactions: King Alpha

Neno

Level 6
Thread author
Verified
Well-known
Jan 4, 2012
278
The site may be clean, but the download is not (referring to the topic title, 'SAFE download' can be seen below too).

If you clicked on
upload_2014-5-5_16-25-38-png.10720
to download Wise Cleaner 365.

This is what you downloaded:
https://www.virustotal.com/en/file/...73e100c50a5249ce90e9f4f1/analysis/1397975346/

Code:
Agnitum - PUA.Softonic!20140419
Baidu-International - Adware.Win32.SoftonicDownloader.F20140419
Comodo - Application.Win32.Agent.SOFE20140414
DrWeb - Adware.Downware.276020140420
ESET-NOD32 - a variant of Win32/SoftonicDownloader.F20140420
Malwarebytes - PUP.Optional.Softonic.A20140420
Rising - PE:Malware.Obscure/Heur!1.9E0320140420
VIPRE - Softonic Downloader (fs)

I've tested Softnotic Downloader before, they use some sneaky tricks to disguise the adware, and to trick the user.

Hope this helps. :)

True Huracan. I did download it trough that 'button' and I think it is exactly that one (I got rid of it before I even read the name :)).
I made this post because it looks like they don't even check the links from their own site which I found ridiculous and harmful.
 

Littlebits

Retired Staff
May 3, 2011
3,893
Never use shady download sites:
Get the installer from the official vendor's site or use trusted download sites.
Most popular trusted download sites:
1. Softpedia
2. MajorGeeks
3. FileHippo
4. SnapFiles
5. DownloadCrew or BetaNews Fileform.

Enjoy!! :D
 
I

illumination

The site may be clean, but the download is not (referring to the topic title, 'SAFE download' can be seen below too).

If you clicked on
upload_2014-5-5_16-25-38-png.10720
to download Wise Cleaner 365.

This is what you downloaded:
https://www.virustotal.com/en/file/...73e100c50a5249ce90e9f4f1/analysis/1397975346/

Code:
Agnitum - PUA.Softonic!20140419
Baidu-International - Adware.Win32.SoftonicDownloader.F20140419
Comodo - Application.Win32.Agent.SOFE20140414
DrWeb - Adware.Downware.276020140420
ESET-NOD32 - a variant of Win32/SoftonicDownloader.F20140420
Malwarebytes - PUP.Optional.Softonic.A20140420
Rising - PE:Malware.Obscure/Heur!1.9E0320140420
VIPRE - Softonic Downloader (fs)

I've tested Softnotic Downloader before, they use some sneaky tricks to disguise the adware, and to trick the user.

Hope this helps. :)

Exactly why i use Virus Total to check all links before downloading :)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top