Help - Search - Members - Calendar
Full Version: FlashGet latest version is spyware?
B.I.S.S. Forums > Malware Research Forum > Malware IP Research Section
Anti_Spyware
Hi, I am not sure what exactly is going on in the latest version of FlashGet but I have noticed almost constantly it keeps trying to connect to these 5 IPs/hostnames:

CODE
1.  es1.zcominic.com (59.151.31.139)

inetnum:      59.151.0.0 - 59.151.127.255
netname:      CHINA-ABITCOOL
descr:        Abitcool(China) Inc.
descr:        Beijing, China
country:      CN
admin-c:      WH381-AP
tech-c:       WH381-AP
mnt-by:       MAINT-CNNIC-AP
mnt-routes:   MAINT-CNNIC-AP
status:       ALLOCATED PORTABLE
changed:      ipas@cnnic.net.cn 20060228
source:       APNIC

route:        59.151.0.0/18
descr:        CHINA-ABITCOOL
descr:        Abitcool(China) Inc.
country:      CN
origin:       AS17428
mnt-by:       MAINT-CNNIC-AP
changed:      ipas@cnnic.net.cn 20050324
source:       APNIC

person:       Wei He
nic-hdl:      WH381-AP
e-mail:       ipmaster@abitcool.com
address:      BOE Science Park, 10 Jiuxianqiao Road, Chaoyang District,Beijing 100016, China
phone:        +86-10-84562121
fax-no:       +86-10-84564234
country:      CN
changed:      ipadmin@abitcool.com 20060228
mnt-by:       MAINT-CN-YANGYT
source:       APNIC

inetnum:      59.151.0.0 - 59.151.127.255
netname:      CHINA-ABITCOOL
descr:        Abitcool(China) Inc.
descr:        Beijing, China
country:      CN
admin-c:      WH381-CN
tech-c:       WH381-CN
mnt-by:       MAINT-CNNIC-AP
mnt-lower:    MAINT-CN-21VIANET
mnt-routes:   MAINT-CNNIC-AP
status:       ALLOCATED PORTABLE
changed:      ipas@cnnic.net.cn 20060228
source:       CNNIC

person:       Wei He
address:      BOE Science Park, 10 Jiuxianqiao Road, Chaoyang District,Beijing 100016, China
country:      CN
phone:        +86-10-84562121
fax-no:       +86-10-84564234
e-mail:       ipmaster@abitcool.com
nic-hdl:      WH381-CN
mnt-by:       MAINT-CN-YANGYT
changed:      ipmaster@abitcool.com 20060227
source:       CNNIC



2.  66.199.250.170



OrgName:    EZZI.NET
OrgID:      EZZIN
Address:    AccessIT - Hosting Services
Address:    75 Broad Street, Suite 1902
City:       New York
StateProv:  NY
PostalCode: 10004
Country:    US

ReferralServer: rwhois://rwhois.s2.ezzi.net:4321

NetRange:   66.199.224.0 - 66.199.255.255
CIDR:       66.199.224.0/19
NetName:    NETBLK-EZZI
NetHandle:  NET-66-199-224-0-1
Parent:     NET-66-0-0-0-0
NetType:    Direct Allocation
NameServer: S2.EZZI.NET
NameServer: S1.EZZI.NET
Comment:    
RegDate:    2003-08-22
Updated:    2004-05-28

RNOCHandle: AD125-ARIN
RNOCName:   Dhoon, Ali
RNOCPhone:  +1-646-375-3379
RNOCEmail:  adhoon@accessitx.com

OrgAbuseHandle: EAA12-ARIN
OrgAbuseName:   Ezzi Abuse Account
OrgAbusePhone:  +1-866-438-3994
OrgAbuseEmail:  abuse@ezzi.net

OrgTechHandle: AD125-ARIN
OrgTechName:   Dhoon, Ali
OrgTechPhone:  +1-646-375-3379
OrgTechEmail:  adhoon@accessitx.com



3.  72.51.37.237 (athlon64.com)


Peer 1 Network Inc. PEER1-BLK-08 (NET-72-51-0-0-1)
                                  72.51.0.0 - 72.51.63.255
ServerBeach PEER1-SERVERBEACH-06A (NET-72-51-32-0-1)
                                  72.51.32.0 - 72.51.47.255

4.  219.239.90.172

inetnum:      219.238.0.0 - 219.239.255.255
netname:      DXTNET
country:      CN
descr:        Beijing Teletron Telecom Engineering Co., Ltd.
admin-c:      PP40-AP
tech-c:       PP40-AP
status:       ALLOCATED PORTABLE
changed:      ipas@cnnic.net.cn 20040706
mnt-by:       MAINT-CNNIC-AP
source:       APNIC

person:       Pang Patrick
nic-hdl:      PP40-AP
e-mail:       bill.pang@bj.datadragon.net
address:      Fl./8, South Building, Bridge Mansion, No. 53
phone:        +86-10-63181513
fax-no:       +86-10-63181597
country:      CN
changed:      ipas@cnnic.net.cn 20030304
mnt-by:       MAINT-CNNIC-AP
source:       APNIC

inetnum:      219.238.0.0 - 219.239.255.255
netname:      DXTNET
country:      CN
descr:        Beijing Teletron Telecom Engineering Co., Ltd.
admin-c:      PP40-CN
tech-c:       PP40-CN
status:       ALLOCATED PORTABLE
changed:      ipas@cnnic.net.cn 20040706
mnt-by:       MAINT-CNNIC-AP
source:       CNNIC

person:       Pang Patrick
nic-hdl:      PP40-CN
e-mail:       bill.pang@bj.datadragon.net
address:      Fl./8, South Building, Bridge Mansion, No. 53
phone:        +86-10-63181513
fax-no:       +86-10-63181597
country:      CN
changed:      ipas@cnnic.net.cn 20030304
mnt-by:       MAINT-CNNIC-AP
source:       CNNIC


5.  server0.emulebt.com (60.28.197.35)



inetnum:      60.28.197.0 - 60.28.197.255
netname:      QXHL-LID-BJ
country:      CN
descr:          Qianxianghulian Limited company
admin-c:      HZ19-AP
tech-c:          HZ19-AP
status:          ASSIGNED NON-PORTABLE
changed:      ipaddr@ywb.online.tj.cn 20070523
mnt-by:          MAINT-CNCGROUP-TJ
source:          APNIC

route:        60.28.0.0/15
descr:        CNC Group CHINA169 Tianjin Province Network
country:      CN
origin:       AS4837
mnt-by:       MAINT-CNCGROUP-RR
changed:      abuse@cnc-noc.net 20060118
source:       APNIC

person:       huang zheng
nic-hdl:      HZ19-AP
e-mail:       ipaddr@ywb.online.tj.cn
address:      76 NO, ShiZiLin Street ,HeBei district of Tianjin,China
phone:        +86-22-24459190
fax-no:       +86-22-24454499
country:      CN
changed:      ipaddr@ywb.online.tj.cn 20050721
mnt-by:       MAINT-CNCGROUP-TJ
source:       APNIC


Does anyone know which version of FlashGet is safe to use? The newest version is this one that connects to these sites, and the really older versions used to have spyware, but I am not sure which version do and do not.

Also do you think these connections are just because of the emule/BT features, are they harmless or less t han benign?
Moore
Hey dude. smile.gif

I use Flashget 1.3 at the moment, and have used 1.4 ... If it's not a registered copy then it would display ads from cydoor but it doesnt "install" any spyware onto your system.

I have read comments that newer versions sucked compared to older ones so I never bothered to upgrade it and 1.3 does what I want.

There are options in Flashget to check mirrors for the file you are downloading, make sure you have that turned off so it doesnt go looking for stuff on its own ..

Edit : check out the comments here biggrin.gif :
http://www.neowin.net/index.php?act=view&id=40333
dr_Ibanez
I spent my whole day reinstalling win2k3 on my laptop, and when installed flashget i saw netstat s shown some connections owned by flashget process. First of all I disabled all bonus features from GUI, like eMule protocol support etc. And it definitely wasnt a solution. So I spend two minutes analyzing my config file. To disable unattended connections attempts, just modify your core.cfg configuration file, which you can find somewhere in FlashGet directory. So I must claim that FlashGet is the best, ive been using it from few years without any problem so far.
Quite easy thing, included my diff dump below (changes between my config and the original one - with disabled share-url, eMule and BT features in GUI):

#diff core.cfg core.old
16c16
< UPnP.Enable=0
---
> UPnP.Enable=1
20c20
< ED2K.Enable=0
---
> ED2K.Enable=1
22c22
< ED2K.Server.AutoConnect=0
---
> ED2K.Server.AutoConnect=1
26,28c26,28
< ED2K.Search.SearchInServers=0
< ED2K.Search.SearchInKADNetwork=0
< ED2K.KAD.Enable=0
---
> ED2K.Search.SearchInServers=1
> ED2K.Search.SearchInKADNetwork=1
> ED2K.KAD.Enable=1
33,34c33,34
< ED2K.WebSvr.MaxConnection=0
< BT.Enable=0
---
> ED2K.WebSvr.MaxConnection=8
> BT.Enable=1
39c39
< BT.DHT.Enable=0
---
> BT.DHT.Enable=1

I hope you find it information pretty useful.

regards,
Lucas
Moore
Thanks dr Ibanez smile.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.