16 August 2007

FileDownloader V1.24 and all Versions before - Hijack Web Browser UA string!!!

4 comments

(used by Vanix.Net and others...)

User Agent string like: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.7pre) Gecko/20070815 FileDownloader - Build ID: 2007081504

I did try first to search for a Hijacked LSP to fix it, WinSock fix etc... to point it out here, but the answer is in a replaced prefs.js file in Profile folder by Mozilla Firefox to find.

Thanks to Mr.x from FileDownloader Net (http://filedownloader.net/)

Users of his program called FileDownloader fdn.msi (http://filedownloader.net/fdn_download/download.php)

browse after install the web with branded Webbrowser
Firefox, Internet Explorer and others:

Code snip from file: FDN.exe 1,48 MB (1.553.408 bytes)

10CFD0 4D 6F 7A 69 6C 6C 61 5C 46 69 72 65 66 6F 78 5C Mozilla\Firefox\
10CFE0 50 72 6F 66 69 6C 65 73 5C 00 00 00 FF FF FF FF Profiles\...
10CFF0 03 00 00 00 2A 2E 2A 00 FF FF FF FF 08 00 00 00 ....*.*. ....
10D000 70 72 65 66 73 2E 6A 73 00 00 00 00 FF FF FF FF prefs.js....
10D010 28 00 00 00 4D 6F 7A 69 6C 6C 61 20 46 69 72 65 (...Mozilla Fire
10D020 66 6F 78 5C 64 65 66 61 75 6C 74 73 5C 70 72 65 fox\defaults\pre
10D030 66 5C 66 69 72 65 66 6F 78 2E 6A 73 00 00 00 00 f\firefox.js....
10D040 FF FF FF FF 1F 00 00 00 67 65 6E 65 72 61 6C 2E ....general.
10D050 75 73 65 72 61 67 65 6E 74 2E 65 78 74 72 61 2E useragent.extra.
10D060 66 69 72 65 66 6F 78 00 FF FF FF FF 03 00 00 00 firefox. ....
10D070 22 29 3B 00 FF FF FF FF 04 00 00 00 22 2C 20 22 ");. ....", "
10D080 00 00 00 00 FF FF FF FF 0E 00 00 00 46 69 6C 65 .... ....File
10D090 44 6F 77 6E 6C 6F 61 64 65 72 00 00 FF FF FF FF Downloader..
10D0A0 2E 00 00 00 75 73 65 72 5F 70 72 65 66 28 22 67 ....user_pref("g
10D0B0 65 6E 65 72 61 6C 2E 75 73 65 72 61 67 65 6E 74 eneral.useragent
10D0C0 2E 65 78 74 72 61 2E 66 69 72 65 66 6F 78 22 2C .extra.firefox",
10D0D0 20 22 00 00 FF FF FF FF 12 00 00 00 3B 46 69 6C ".. ....;Fil
10D0E0 65 44 6F 77 6E 6C 6F 61 64 65 72 22 29 3B 00 00 eDownloader");..
10D0F0 FF FF FF FF 3F 00 00 00 75 73 65 72 5F 70 72 65 ?...user_pre
10D100 66 28 22 67 65 6E 65 72 61 6C 2E 75 73 65 72 61 f("general.usera
10D110 67 65 6E 74 2E 65 78 74 72 61 2E 66 69 72 65 66 gent.extra.firef
10D120 6F 78 22 2C 20 22 46 69 6C 65 44 6F 77 6E 6C 6F ox", "FileDownlo
10D130 61 64 65 72 22 29 3B 00 55 8B EC 53 56 57 8B F9 ader");.Uï8SVWï·


Result: Websites such as Web counter, Forums and others means you are a bot. You get for example by a "enhanced" VBulletin board a security Message as well other website scripts as soon you visit.

Looks like this:
Sorry for the inconvenience!
Entschuldigen Sie bitte diese Unannehmlichkeit!
Obviously your access to this site has been suspended by mistake.
Offensichtlich wurde Ihnen der Zugang zu dieser Site fälschlicherweise verweigert.

By solving the arithmetical problem you can visit this website temporarily.
Durch Lösung der Rechenaufgabe können Sie diese WebSite temporär besuchen.

(2 * 5) × (–1) result: =


Please tell us here to remove the lock restriction:
Bitte melden Sie sich hier um die Sperrung aufzuheben:
Complaint Board
Beschwerde Forum


other extensions such as Roboform will be disabled and much more!!!

Solution for Mozilla Webbrowser:

goto Profile folder,
edit prefs.js,
find: user_pref("general.useragent.extra.firefox", "FileDownloader");
delete this line!

duno how in IE (normally used Windows Registry for UA string) and if Opera is concerned with it.
After all IE force me to visit by start this page once: http://en.sergiwa.com/modules/mydownloads/singlefile.php?cid=2&lid=6

Extracted Installer files in attachment: fdn.7z (1006.69 KB)
(don't click the file fdn.msi or FDN.exe if you don't want to edit the "new" UA extension in your webbrowser back to the normal one!!!)


...14h later
after restore Mozilla Webbrowser settings I realize that the Firewall Filter driver have been disabled. Every try to reinstall the firewall failed. Firewall is permanent off in error mod. The legitim Product Activation from some applications include AV subscription (ESET, Agnitum, Kaspersky...) and Windows Genuine Product Key are suddenly invalide. Stolen? The OS is on that system unusable after try to recover cause all backups are injected with it. I cant read binary code before this part above but since 1983 my very first computer Comodore C64 I never seen an application what can do such disaster and destroy Windows unrecoverble.

15 August 2007

BitSpirit 3.3.1.150 Leecher Pack [REPACK EdiTion] by Seba14.org and MoDs.sub.cc

0 comments
Bitspirit

NOREPORT Version
- no upload and download report to tracker
- you will shown as leecher
- complete flag not send to tracker (no snatchlist entry)

REPORT Version
- only download will be not reported to tracker
- you will shown as seeder
- complete flag not send to tracker (no snatchlist entry)

ORIGINAL Version
- Ads Removed (all visual Ads are gone)
- Splash RLE compressed faster start up (the nice one as shown above)
- Country to IP dat

Latest IP filter dat is not include. Suggest to download ozzy's

* Baidu Search traces Ads plug as in Anxz.com Team EdiTion to unplug, I didn't figure out how to. (creates in /config the files: bsspecial.txt and send collected with file bsupdate.txt)
Unpack the dll's search for ' www.baidu.com ' and/or ' cpro.php ' with hexedit and remove them may work. Possible in a dll such as BLink.dll or BSOPLib.dll (upx -decrompress first) BC (can replaced with Anxz once). Meanwhile use windows hostfile and block with this entries Baidu (it's not a very popular Search and advertising site outside China)
127.0.0.1 www.baidu.com
and
127.0.0.1 202.108.22.44


Contains noreport and report LP Mods by Seba (Big thanks)

Download: BitSpirit 3.3.1.150 LP.7z (5.01 MB) first release

NEW!!! Download:
BitSpirit v3.3.1.150 Leecher Pack [REPACK EdiTion] - Mirror
*
BitSpirit 3.3.1.150 LP.7z (4.51 MB) - Mirror | DDL1 | DDL2 | DDL3

MD5: d7a7cc84371bc46b7500b0b971db1e75 BitSpirit 3.3.1.150 LP.7z
MD5: 0548314d6d62e058c72b29da2ec081a2 BitSpirit REPORT.exe
MD5: 17bd36d94167c4dfb10084e063a25b61 BitSpirit NOREPORT.exe
MD5: 0864f9ccfc226432f116ecfca7268326 BitSpirit.exe


* Fixed: unhooked 3 Ads calls
Extras: RegDoctor186.exe

TuoTu v3.0.104 Bugfix release (13. Aug. 2007) English/Chinese

0 comments
104 version ChangeLog 2007-8-13
* Amendment on version from August 10, empty Recycle bin will delete documents -bugfix
* Amendment on version from August 10, HTTP download of large, repeat Downloading -bugfix
* That list does not support user plug-in the flag -bugfix
* Amendments to the other small problems

The official version 3.0.104 Download Address:
Installation version: http://www.tuotu.com/install/TuoTu-3.0.104.exe
Green version: http://www.tuotu.com/install/TuoTu-3.0.104.rar

Mirrors up on Website: http://www.anxz.com/down/1810.html

BBS: http://bbs.tuotu.com
Homepage Download Site: http://tuotu.com/Download.shtm

Java 7 (1.7) Build b17 - August 02, 2007

0 comments
Sun Java SE 7 Runtime Environment PRE-Release (Contains JDK and JRE) The JDK Development Kit can be uninstalled.

Summary of changes in JDK 7 build b17
Windows Platform
Windows Offline Installation, Multi-language JDK file
jdk-7-ea-bin-b17-windows-i586-02_aug_2007.exe, 53.24 MB
Windows AMD64 Platform
Windows AMD64 self-extracting JDK file
jdk-7-ea-bin-b17-windows-amd64-02_aug_2007.exe, 38.36 MB

Other Plattforms
http://download.java.net/jdk7/binaries
In Mozilla Web Browser (Firefox) type in address bar: about:plugins
There must be listed: Java(TM) Platform SE 7 - all latest Firefox Final support Sun Java 1.7

older Versions: Java 7 (1.7) Build b16 - July 20, 2007

LimeWire Pro 4.14.7 Final

0 comments
Another day another new LimeWire Version out now.

Features:
- Ease of use - just install, run, and search
- Ability to search by artist, title, genre, or other meta information
- Elegant multiple search tabbed interface
- "Swarm" downloads from multiple hosts help you get files faster
- iTunes integration for Mac and Windows users
- Unique "ultrapeer" technology reduces bandwidth requirements for most users
- Integrated chat
- Directly connect to a computer
- Browse host feature--even works through firewalls
- Added Bitzi metadata lookup
- International versions: Now available in many new languages
- Connects to the network using GWebCache, a distributed connection system
- Automatic local network searches for lightning-fast downloads
- Support for MAGNET links that allow you to click on web page links that access Gnutella
+ PRO Features

No Changelog at present.

OS.: ALL (Java requ.)

Download: LimeWireWinPro4.14.7.exe (4.63 MB)

for Linux, Mac OSX visit: http://limewirepro.at.tt
or Download from Mirrors:
for Windows: LimeWire_Pro_4.14.7
for Mac OSX: LimeWire_Pro_4.14.7_OSX.dmg
for Linux: LimeWire_Pro_4.14.7_Linux.deb
for other OS: LimeWire_Pro_4.14.7_Other.zip

Limewire is an Open Source P2P Client. The source code is free. You may create the binaries yourself from the GPL licensed sourcecode and distribute them as much as you want, legally.

14 August 2007

Acelerador del Emule By DarkDelphi

0 comments
Este programa configura su emule para sacarle el máximo provecho. Está desarrollado según mis
experiencias con este programa y manuales que he encontrado por ahí. FUNCIONA
REALMENTE, pues hace lo que deberías hacer con esos manuales a mano. El éxito del
programa no se obtiene inmediatamente, sino a la media hora u hora: recuerda que para bajar
más rápido deben de haber primero bajado cosas de tu computadora. Sólo compartiendo se
consigue la descarga más rápida.



Indica la dirección del archivo de configuración (preferenes.ini) del eMule: (El archivo de configuración se suele encontrar en ) "C:\Archivos de programa\eMule\config\preferences.ini"
Buscar archivo de configuracion del emule

Coded in: Delphi
Real Image Checksum: 00077C0Bh
MD5 Hash: f28dbc825fff5d1a42110ea1bbe7c76c Acelerador del Emule By DarkDelphi.exe

Download: Acelerador del Emule By DarkDelphi.exe (449 KB) - DDL1 - DDL2 - DDL3 - Fileshare Mirrors

Archive