Sysinternals Homepage
Forum Home Forum Home > Windows Discussions > Malware
  New Posts New Posts RSS Feed: Ultra Surf : is NOT malware, I think ! ...
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

Topic ClosedUltra Surf : is NOT malware, I think ! ...

 Post Reply Post Reply Page  <123>
Author
Message Reverse Sort Order
onionbubs View Drop Down
Newbie
Newbie


Joined: 11 October 2009
Online Status: Offline
Posts: 6
Direct Link To This Post Topic: Ultra Surf : is NOT malware, I think ! ...
    Posted: 11 October 2009 at 4:31pm
From http://www.threatexpert.com/report.aspx?md5=bb97cf958f1d383e1316a0db06202e22:

* The newly created Registry Values are:
  o [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    + Lwzihkjv = 0x00000617
  o [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
    + CurrentLevel = 00 00 00 00
    + 1C00 = 00 00 00 00

* The following Registry Value was deleted:
  o [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
    + CurrentLevel = 0x00000000
    + 1C00 = 0x00010000

---

Aha... this piece of software messes with your security settings. That should raise a red flag immediately.
Back to Top
onionbubs View Drop Down
Newbie
Newbie


Joined: 11 October 2009
Online Status: Offline
Posts: 6
Direct Link To This Post Posted: 11 October 2009 at 4:26pm
Like I'll ever trust advice from dot info domains... Tongue
Back to Top
ntunldr View Drop Down
Senior Member
Senior Member
Avatar

Joined: 05 July 2009
Online Status: Offline
Posts: 229
Direct Link To This Post Posted: 11 October 2009 at 3:52pm
http://www.how-to-hide-ip.info/2009/01/12/is-ultrasurf-a-trojan



Back to Top
onionbubs View Drop Down
Newbie
Newbie


Joined: 11 October 2009
Online Status: Offline
Posts: 6
Direct Link To This Post Posted: 11 October 2009 at 2:32pm
If you wanna prove that Ultrasurf is not malware, download Wireshark and do some serious packet analysis. Until then, I'd rather believe a man that spoke at Blackhat who did say it's malware.
Back to Top
PROROOTECT View Drop Down
Senior Member
Senior Member
Avatar

Joined: 06 April 2008
Location: Fort Lee, NJ ..
Online Status: Offline
Posts: 559
Direct Link To This Post Posted: 07 October 2009 at 9:26pm
Yes, in Chinese: UltraSurf site is called wujie.net: http://www.wujie.net/ 
 
Today - English version has a problem of domains, server ... And NOW - it's OK!
 
""""""""""""""""""""""""""
 
THE reality is as follows: the millions of happy users of UltraSurf perfectly legal and safe to use.
Thank you nullptr, Spynet, Gemmashaw and others, I'm with you all.Smile
 
I have compassion for those who want to promote its software - by the denigration of all other solutions that do not come from them ... Many speculation - you are right, Redhawk.
 
But you dsilvers, you have every right to have another opinion, I would call you instead of someone wandering ... Checkmate.
Well, stay cool, if we could all enjoy a drink, you'll quickly agree with me!Tongue
 
Some links for you:
 
* VirusTotal UltraSurf results from February, 2009: http://jonsnetwork.com/2009/02/virustotal-ultrasurf-results/ 
 
 
* Ultra Surf - World's best proxy surfing technology: http://rajeshrana.net/2007/08/08/ultra-surf-worlds-best-proxy-surfing-technology/ 
 
 
Stay cool.
 
P.


Edited by PROROOTECT - 07 October 2009 at 11:18pm
I remember:GMER 1.0.15.15281|XueTr 0.32|Kernel Detective 1.3.1|RootRepeal 1.3.5|..Sarah ah! He remembers me:AntiVir|I'm a stranger HERE ..
Back to Top
redhawk View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 14 September 2005
Location: United Kingdom
Online Status: Offline
Posts: 1220
Direct Link To This Post Posted: 07 October 2009 at 4:53pm
UltraSurf does work as claimed however like all proxies there's no such thing as safe and secure browsing since you are borrowing access from an unknown network.
As for the malware claim who can tell, proxies tend to get a bad name so it's no surprise many AV products are flagging this as bad.
I've read the arguments put forward about UltraSurf but to be honest I haven't seen anything conclusive yet just speculation.

Richard S.

Edited by redhawk - 07 October 2009 at 6:03pm
Back to Top
PROROOTECT View Drop Down
Senior Member
Senior Member
Avatar

Joined: 06 April 2008
Location: Fort Lee, NJ ..
Online Status: Offline
Posts: 559
Direct Link To This Post Posted: 07 October 2009 at 8:08am
Cool, some drinks, this evening dsilvers ...Wink
 
P.
I remember:GMER 1.0.15.15281|XueTr 0.32|Kernel Detective 1.3.1|RootRepeal 1.3.5|..Sarah ah! He remembers me:AntiVir|I'm a stranger HERE ..
Back to Top
dsilvers View Drop Down
Groupie
Groupie


Joined: 22 January 2008
Online Status: Offline
Posts: 45
Direct Link To This Post Posted: 07 October 2009 at 12:50am
Originally posted by PROROOTECT

It is not evidence ...


It is enough to make a reasonable man pause.  Here, drink some kool aid.  Wink
Back to Top
PROROOTECT View Drop Down
Senior Member
Senior Member
Avatar

Joined: 06 April 2008
Location: Fort Lee, NJ ..
Online Status: Offline
Posts: 559
Direct Link To This Post Posted: 06 October 2009 at 10:20pm
It is not evidence ...
I remember:GMER 1.0.15.15281|XueTr 0.32|Kernel Detective 1.3.1|RootRepeal 1.3.5|..Sarah ah! He remembers me:AntiVir|I'm a stranger HERE ..
Back to Top
dsilvers View Drop Down
Groupie
Groupie


Joined: 22 January 2008
Online Status: Offline
Posts: 45
Direct Link To This Post Posted: 06 October 2009 at 9:47pm
It's a one hop proxy that turns off SSL and contacts banks, financial institutions and government agencies supposedly to confuse a Chinese firewall.  The only conclusion I can come to for turning off SSL and contacting a bank or a government agency is a man in the middle.  Tracing a one hop proxy would be insignificant compared to the competition.    A one hop proxy is probably why it is fast.  Setting up the necessary servers might be time consuming and expensive.  I have no interest in confusing a Chinese firewall.

I don't run a proxy so I don't have a horse in this race.  If you can read and comprehend those threads and still believe it's safe, knock yourself out.  AVG, Previx and I forgot the other one, are flagging it as malware. 

Posting in a security forum that Ultrasoft is safe seems irresponsible.  At best it is controversial.  At the worst it is malware.  There are better and safer choices.
Back to Top
 Post Reply Post Reply Page  <123>

Forum Jump Forum Permissions View Drop Down