Go Back    Forum > Digital Life > Computers

Reply
 
LinkBack Thread Tools
  #1  
09-29-2012, 06:59 AM
kpmedia's Avatar
kpmedia kpmedia is offline
Site Staff | Web Hosting, Photo
 
Join Date: Feb 2004
Posts: 4,311
Thanked 374 Times in 341 Posts
For most of 2012, I've been using the freeware "YTD Video Downloader" for downloading videos off of Youtube. Today I wanted to save a video from Youtube, opened the program, and it prompted me for an update. The changelog showed some bug fixes and feature additions, so I went ahead and allowed the update.

Big mistake.

YTD Video Downloader proceeded to dump malware on the system.

WinPatrol caught and blocked the attempts to add new startup programs to the computer, as well as change all my browser home pages. It tried to alter IE, Firefox and Chrome homepage and search default settings. The search was to be changed to some sort of Yahoo affiliate-looking link.

The following crap was added:
  • An "Application Updater" Windows service, with files located at C:\Program Files (x86)\Common Files\Application Updater\
  • The "YTD Toolbar" from Spigot, located at C:\Program Files (x86)\Spigot\
  • Several dozen registry entries.
How to Remove:

Step 1 -- Stop Processes / Unlocker:

The "SearchSettings.exe" process was terminated with the Task Manager (part of Windows; right-click on taskbar to get to it).

I then used Unlocker to nuke/halt the Spigot folder. Unlocker is a tool that allows deletion of files considered "active" by Windows, by severing said connections. Get Unlocker from the official site: http://www.emptyloop.com/unlocker

Next I stopped the Application Updater service (right-click on My Computer, go to Manage; new window pops up, go to services, search for the Application Updater), and nuked its folder.

Both folder were then deleted in Windows, and the recycle bin emptied.

Step 2 -- Registry Clean-Up / CCleaner:

This left a pile of garbage in the registry. I first used CCleaner to remove most of it. Then I ran regedit.exe (Registry Editor; Start > Run > regedit.exe) and searched for the following terms: (1) "applicationupdater", (2) "spigot", and (3) "searchsettings". I deleted dedicated trees, and remove individual entries barfed into other trees (like browser settings).

RegEdit.exe comes with Windows.
Get CCleaner from the official site: http://www.filehippo.com/download_ccleaner


My Official Opinion on YTD Video Downloader:

This is a malicious piece of crap written by assholes. It's about as useful as hitting my laptop with a sledge hammer.
While KeepVid.com has grown more annoying over time (by using pure Java), at least it doesn't inject a computer with malware.

What's truly irritating is how the Spigot / ApplicationUpdater / YTD Toolbar garbage was wrapped into a payload bomb inside the YTD Video Downloader installer. It was silent, hidden, and had no option to avoid installation. The ApplicationUpdater.exe service was there to allow continued passive installs/updates of who-knows-what. They managed to leverage social engineering to bypass Windows 7 UAC safeguards, by tricking the user into updating a program that previously lacked junk.


- Did my advice help you? Then become a Premium Member and support this site.
- Please Like Us on Facebook | Follow Us on Twitter

- Need a good web host? Ask me for help! Get the shared, VPS, semi-dedicated, cloud, or reseller you need.
Reply With Quote
Someday, 12:01 PM
admin's Avatar
Ads / Sponsors
 
Join Date: ∞
Posts: 42
Thanks: ∞
Thanked 42 Times in 42 Posts
Reply




Similar Threads
Thread Thread Starter Forum Replies Last Post
vBSEO Hack/Exploit! Adds unknown plugins, turns links red, causes database errors kpmedia Website and Server Troubleshooting 1 08-22-2014 12:42 AM
Observations of using RAID-0 on a video editing computer manthing Computers 2 02-07-2012 05:12 AM
Getting Closer: Computer Build for video capturing Kenneth M Project Planning, Workflows 15 03-09-2011 02:39 PM
WPAds WordPress plugin adds slashes in wp-admin? New version here! kpmedia Website and Server Troubleshooting 0 01-24-2011 12:45 PM
Blu-ray adds new 100GB and 128GB disc/format specs! kpmedia Blank Media 0 04-08-2010 02:45 AM




 
All times are GMT -5. The time now is 11:14 PM