PDA

View Full Version : DivX Pro Ad - Nasty Web3000 Spyware


skyout
6th March 2002, 08:24
For those of you who have installed the DivX Pro Ad version, be very careful about trying to disable 'Gain'. It's really Web3000 which doesn't always go away and may alter some Windows system files.

You can also corrupt your system if you don't know what you are doing. And guess what, if you uninstall DivX Pro Ad, Gain/Web3000 does not go away!

If you don't believe me, download Ad-aware and run a scan. Also search the web for Web3000 and check out some of the response sites.

http://www.lsfileserv.com/index.html

http://www.accs-net.com/smallfish/web3000.htm

I for one feel a bit betrayed with this Ad version. Not from the standpoint of the ads but from being misled into downloading a nasty spyware program that I'm still not sure is totally gone.

I had all the intentions of buying the Pro version after checking it out with the Ad version and determinining if I really needed it. I support software development (AVI_IO, Zoom Player, etc.) and don't object to the $30, but after being burned with this spyware, I'm having second thoughts about supporting DivX.

Too bad the developers didn't choose a trialware model where you would get x number of encodes before you have to purchase it. I think everyone would have accepted that much better than a spyware version.

Disappointed,

Mark.

Minako
6th March 2002, 09:44
You can remove everything except the two gator-reg-keys with AdAware (including gain tickler) and it still works, at least here :-)

skyout
6th March 2002, 09:55
Here are the reg keys that Ad-aware found. I'm using the latest reference and signature files.

Gator key:HKEY_CLASSES_ROOT\clsid\{21ffb6c0-0da1-11d5-a9d5-00500413153c}\
Gator key:HKEY_LOCAL_MACHINE\software\gator.com\
Web3000 key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\stashedgef
Web3000 key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\stashedgmg
Web3000 key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\trickler

I'm just a bit nervous just having this crap around, especially since it is claimed that Web3000 dinks around with Windows.

What is rather interesting is that I've been a huge fan of DivX and have never even considered using anything else. However now I'm thinking seriously about trying out Xvid and seeing how it compares to my existing encodes (I capture and encode home videos).

Vinaren
6th March 2002, 10:07
I tried to remove everything with Ad-Aware yesterday and that worked fine but I had a nasty drawback. Unfortunately I couldn't encode after that. Divxcodec gave me a message that it couldn't find the Adware program and quit.

I'm also very unpleased with adware since it collects information like your real emailadress and sends it to some kind of database. I have enough spam mail as it is.

It would be fine se figure out what files or registry entries the codec looks for before it actually encode and save those "triggers" and get rid of the rest.

On the other hand.. It's allready cracked. Havn't found a working crack yet but that is just a matter of time.

Hanty
6th March 2002, 10:21
Hey guys, this whining about the ads has been done unto death.
Especially when it has been pointed out a number of times in the forums, and Doom9 even put it on the frontpage inthe news, how to disable the ad program.

Mystion
6th March 2002, 13:32
Well, there is another detail regarding the adware... The whole thing is being controlled by the gain_trickler_3102.exe found in the installation directory... Dor you that haven't noticed this little crappy shit loads itself on startup and ad-aware 5.6 Plus (the one I 've been using...) has removed successfully all reg entires and files, but did not alter the startup of this proggie... I assume (waiting to finish the encoding in order to test it out...) that the program must resident in order for the codec to function properly... In the best case it should find itself in the intstall dir, so delete the gain/gator/web3000/cydoor entries but do not delete this file from the install directory... As long as I find out I shall let you all know...

tripnotik
6th March 2002, 16:01
Instead of using ad-aware, just go in the registry and remove the key that tells windows to start the program. Any computer user should know this in order to control which program load at startup.

The key is in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and there you should see your the gain_trickler_3102.exe entry. Just delete it. And no, the program must not be resident for the codec to function properly (I just tested it). Also, if you not want to play with your registry, you could just rename the gain_trickler_3102.exe to something else, so windows won't find it and won't be able to start it.

MaTTeR
6th March 2002, 16:38
I can definitely confirm that after uninstalling Divx 5 Pro/Ad Version that Gator is still alive and kicking.

AdAware Plus is showing it(Gator) modifying registry keys in real-time. Argh...never again. I have to question either the ethics of the company that makes Gator or a company that would bundle this with there software. Please don't give me the speech that another solution doesn't exist. Take a look at NetZero and AT&T dialup free software. They do not use Gator, it's simply a popup add that gets cached.

My assumption was that everyone was fully aware of how evil Gator has been for some time. A quick search over the web will tell you this. So why not look at a better solution? Sorry for the rant folks, you better download AdAware plus if you truly want to get rid of the Gator soft.

kastro68
6th March 2002, 16:38
Start>Accesories>System Tools>System Restore


Need i say more?

skyout
7th March 2002, 04:18
An excerpt from http://www.accs-net.com/smallfish/web3000.htm

"Warning: Registering software embedded with Web3000 does not ensure the software will stop transmitting information. If programs containing Web3000 are uninstalled incorrectly, severe problems may occur. Web3000 replaces wsock32.dll and possibly other Windows system files. To remove Web3000, see "Removing Web3000" (below)."

I'm not too sure how true this is but it definitely is scarry.

Yeah kastro68, a system restore is sounding more and more appealing. Thanks a whole bunch DARC!

theReal
7th March 2002, 06:12
Web3000 replaces winsock32.dll and possibly other Windows system files. These will not be restored if AD-aware is used first.

Oh really, thank you very much!!!
Of course I uninstalled Web 3000 with Ad-Aware BEFORE I uninstalled the codec!
Good that my current Win 98 is at it's end anyways and I'm going to format and install Win2k in a few days...

ThePanda
7th March 2002, 06:25
hmm, i've got the ZoneAlarm program on and I still just saw a Gain/Gator ad

grug2k
7th March 2002, 06:33
You're a follower of Steve Gibson, aren't you? :p

Doom9
7th March 2002, 13:19
"Warning: Registering software embedded with Web3000 does not ensure the software will stop transmitting information. If programs containing Web3000 are uninstalled incorrectly, severe problems may occur. Web3000 replaces wsock32.dll and possibly other Windows system files. To remove Web3000, see "Removing Web3000" (below)."
For a sec that scared me but then I thought it's impossible. WinNT, W2K and XP would raise hell if some app tries to overwrite their winsock dlls, especially while the PC is running (and I never rebooted after installing DivX5 pro.. just killed the process, prevented autostart and generally blocked the adware from ever accessing the net). But.. just to be sure I compared both winsock.dll and wsock32.dll on a clean WinXP installation with one that has DivX5 Pro.. and found no difference. So, all I have are 5 useless registry keys, one of which ensures that the codec still works and the other 4 eating up a little HD space, plus the 200k app in the divx codec folder.. that's worth 30$ for me

theReal
7th March 2002, 13:49
you don't even need four reg keys and the .exe
It works like Chibi Jasmin said: remove anything except the gator reg-keys. That means only two reg-keys are left, that's ok!