+ Reply to Thread + Post New Thread
Page 3 of 5 FirstFirst 12345 LastLast
Results 21 to 30 of 47

Thread: Warning about SpinnerChief !!!

  1. #21
    Senior SEO Specialist
    Join Date
    Apr 2008
    Posts
    881
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    Please PM me the names of the forums if you recall which ones they are.
    If we receive a positive, there's no need to leave them in the dark about this situation.

  2. Shorten URL    SEO Services    Buy Xrumer

    Sponsored Links

  3. #22
    Noobie
    Join Date
    Apr 2008
    Posts
    664
    Thanks
    0
    Thanked 1 Time in 1 Post

    Default

    Yes . . . Better safe than sorry.

    PS: I have temporarily made this thread a Sticky.

  4. #23
    Noobie
    Join Date
    Apr 2008
    Posts
    437
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    ok, give me a few minutes

  5. #24
    Noobie
    Join Date
    Apr 2008
    Posts
    301
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    Awesome catch. Thanks for sharing!

  6. #25
    Noobie
    Join Date
    Jun 2008
    Posts
    5
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    I just looked at the cookies in Firefox, the browser I use & do not see them there? I can't find the AppData/Microsoft/Cookies/ folder.

    Is making sure they aren't listed in the browser cookies file enough?

    Thanks!

  7. #26
    Noobie
    Join Date
    Apr 2008
    Posts
    103
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    I have to say I think it is kind of weird that his software is actually really good if he was trying to infect our computers; why would he go to the trouble?

    Anyway I ran Hitman Pro: no infection
    SpyBot: nothing unusual

    But when I tried to install Spinner Chief I don't think it fully installed.

  8. #27
    Noobie
    Join Date
    Apr 2008
    Posts
    42
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    I'm a .NET developer so I tried using a reverse engineering tool to take a peek at the source code to see if I could see anything untoward going on it there. Unfortunately it's been obfuscated which means I'm not getting anything useful back. One thing I am left wondering though is although protecting your application from being reverse engineered is good practice for a paid product why on earth would you need to do it for something you're giving away for free?

  9. #28
    Noobie
    Join Date
    Aug 2008
    Posts
    19
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    I think the file footprint may be ordinary explorer behaviour. Remains the question why a window is created and instantly hidden, and what the excess registry entries do. The following are unique to SpinnerChief:

    Code:
    > > Sandbox_Riedel_Spinner (sandbox container name)
    > > Micr
    > > Wind
    > > Curr
    > > MountPoints2
    > > BitB
    > > Brow
    > > Moun
    > > {073d9fb8-3ed6-11de-810c-806e6f6e6963}
    > > _CommentFromDesktopINI
    > > Expl
    > > Inte
    > > Expl
    > > Inte
    > > Tracing
    > > COM3`
    > > Trac
    > > Wind
    > > wind
    > > SpinnerChief_RASAPI32
    > > EnableFileTracing
    > > EnableConsoleTracing
    > > FileTracingMask
    > > ConsoleTracingMask
    > > Cach
    > > MaxFileSize
    > > FileDirectory
    > > SpinnerChief_RASMANCS
    > > EnableFileTracing
    > > EnableConsoleTracing
    > > DOMS
    > > Cook
    > > Intehbin
    > > FileTracingMask
    > > ConsoleTracingMask
    > > MaxFileSize
    > > FileDirectory
    > > Connections
    > > Connections
    > > Microsoft
    > > Windows
    > > CurrentVersion
    > > Internet Settings
    > > GDIPlus
    > > GDIP
    > > Wind
    > > Update_RASAPI32
    > > Spin
    > > Spin
    > > Upda
    > > Upda
    > > EnableFileTracing
    > > EnableConsoleTracing
    > > FileTracingMask
    > > ConsoleTracingMask
    > > Cont
    > > Cook
    > > MaxFileSize
    > > FileDirectory
    > > Update_RASMANCS
    > > EnableFileTracing
    > > EnableConsoleTracing
    > > FileTracingMask
    > > ConsoleTracingMask
    > > MaxFileSize
    > > FileDirectory
    > > Conn
    > > Conn8
    > > Zone 0
    > > Zone
    > > Cont
    > > Cook
    > > Exte
    > > Cont0*
    > > edProxyEnable
    > > ietl
    > > DOMS,
    > > feed
    > > ietlp-
    > > Zones
    Can someone figure out exactly what registry queries are performed?

  10. #29
    Noobie
    Join Date
    Aug 2008
    Posts
    12
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    Excellent work omgnames. Thanks for the hint!

  11. #30
    Noobie
    Join Date
    May 2008
    Posts
    14
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    I have downloaded and ran the program under free mode as well... as of right now i'm glad i had a chance to come to bhw today as it's almost time for a good labor day weekend.

    until we figure out whats going on with this program, i think it's safe to say not to go to any important websites.

+ Reply to Thread
Page 3 of 5 FirstFirst 12345 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts