Hav0c Posted August 1, 2014 Share Posted August 1, 2014 So I download some software from Sourceforge and my AV (ESET) gos mad and warns me about some variant of Win32/InstallCore.PO. I also noticed the file icon from Sourceforge is "SF".Downloaded the software from the site itself and nothing, no warnings and the icon is the standard windows application icon.Uploaded both files to VirusTotal and here is the results Sourceforge filehttps://www.virustotal.com/en/file/710d348f260148dbec289a1afa13fc4f81c563d19cd274c472cd9427546516cd/analysis/1406930031/ Direct Link filehttps://www.virustotal.com/en/file/d7de4affcf24c5025a3526bcff94f595d7af361e4b2ef848331eafd37e927f4a/analysis/1406928539/ Anyone else noticed this ? Every line of code written by man can be undone by man . "A loser in the real world is still a loser in the net!" - .hack//SIGN . Getting old is inevitable, growing up is optional !! Link to comment Share on other sites More sharing options...
Winapp2.ini Posted August 1, 2014 Share Posted August 1, 2014 I believe SF has been doing this for some time. I think there was a topic about it previously winapp2.ini additions thread winapp2.ini github Link to comment Share on other sites More sharing options...
Moderators Andavari Posted August 2, 2014 Moderators Share Posted August 2, 2014 There was a topic about it before, lost in the multitude of posts after it though. SF including adware has been going on for sometime now. At least your antivirus warned you! An easy solution is to only download archived versions (7z, ZIP, RAR) of software from SF (found in the Files link on their pages) and completely avoid the installers (EXE, MSI). Link to comment Share on other sites More sharing options...
Moderators hazelnut Posted August 2, 2014 Moderators Share Posted August 2, 2014 The bundling started quite a while ago. Here is a thread I made about it http://forum.piriform.com/index.php?showtopic=39831 Support contact https://support.ccleaner.com/s/contact-form?language=en_US&form=general or support@ccleaner.com Link to comment Share on other sites More sharing options...
Hav0c Posted August 2, 2014 Author Share Posted August 2, 2014 The bundling started quite a while ago. Here is a thread I made about it http://forum.piriform.com/index.php?showtopic=39831 Thanks Haz, looks like it's one of the posts I missed . Found it strange as I have downloaded a couple of things from SF lately but never ran in to this one before until now. Looks like times are getting tough if most of the portals are including adware. Every line of code written by man can be undone by man . "A loser in the real world is still a loser in the net!" - .hack//SIGN . Getting old is inevitable, growing up is optional !! Link to comment Share on other sites More sharing options...
Moderators Andavari Posted August 2, 2014 Moderators Share Posted August 2, 2014 Looks like times are getting tough if most of the portals are including adware. SF was bought though, then came the adware. The reason some of your installations didn't have is the refusal of those developers to use it, and/or SF hasn't got around to repackaging that setup file being that they have so many to go through. I can't remember what developer it was (some popular program) that left SF over the adware bundling, damn can't remember the name of it but it was on allot of tech related sites as "big news." Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now