| View previous topic :: View next topic |
| Author |
Message |
Buckie
Joined: 13 Feb 2008 Posts: 12 Location: Denmark
|
Posted: Tue Mar 04, 2008 12:02 am Post subject: Smart GUI - > Paypals |
|
|
I used smart GUI....It likes to send me to paypal, even when im not useing it...for some reason...I think, if you program free software you should not send peoples computers to places where they pay for stuff...I really think this program should be rewritten without this "feature" or banned from autohotkeys command refrence
 |
|
| Back to top |
|
 |
Lexikos
Joined: 17 Oct 2006 Posts: 2364 Location: Australia, Qld
|
Posted: Tue Mar 04, 2008 8:15 am Post subject: Re: Smart GUI - > Paypals |
|
|
| Buckie wrote: | | I used smart GUI....It likes to send me to paypal, | Smart GUI is open source, so you may see for yourself that it does no such thing. Either you are/were not using the genuine Smart GUI, or something else on your system is wreaking havoc. |
|
| Back to top |
|
 |
Rajat
Joined: 28 Mar 2004 Posts: 1715
|
Posted: Tue Mar 04, 2008 12:19 pm Post subject: |
|
|
lexiKos is right. SGUI doesn't contain anything that'd do that. Its open source and you can compile your own copy to be sure that you have a clean application. _________________
 |
|
| Back to top |
|
 |
Buckie
Joined: 13 Feb 2008 Posts: 12 Location: Denmark
|
Posted: Tue Mar 04, 2008 12:39 pm Post subject: |
|
|
I very strongly doubt that (#2). I have never had any Critical outgoing messages like this, I downloaded the software from "official" site, and even if it is possible to see the source code. Its not hard to add some extra lines to the compiled version, and not in the sourcecode. I think that even if I did a string search for "yahoo" or paypal in my SmartGUI.exe, and posted here, you state that it is my version (downloaded straight from http://www.autohotkey.net/~rajat/SGUI/index.html#Download) that might be "bugged"
I cant see why this file (smartgui.exe) should be attacked, it has never been "outsite" my computer since i downloaded it and why my firewall tells me that smartgui.exe is trying to launch mozilla to go to paypals or some wierd yahoo tool bar search.
Im really trying hard to understand, HOW this could happen |
|
| Back to top |
|
 |
SKAN
Joined: 26 Dec 2005 Posts: 5298
|
Posted: Tue Mar 04, 2008 1:07 pm Post subject: |
|
|
I downloaded a copy 3 days back and it does not do anything that you claim.
| Buckie wrote: | | Its not hard to add some extra lines to the compiled version, and not in the sourcecode. I think that even if I did a string search for "yahoo" or paypal in my SmartGUI.exe, and posted here, you state that it is my version (downloaded straight from http://www.autohotkey.net/~rajat/SGUI/index.html#Download) that might be "bugged |
You better upload and link your app before you make such allegations.
 |
|
| Back to top |
|
 |
Rajat
Joined: 28 Mar 2004 Posts: 1715
|
Posted: Tue Mar 04, 2008 1:23 pm Post subject: |
|
|
SGUI has a big userbase, and its just you who is facing that error… that should tell something. If my saying so means anything to you, I’ve not put in anything that could be said to be a malware in SGUI. Some hosting sites also tested for such things before hosting it.
And as SKAN said, you could upload your copy and have somebody (besides me) test it for you on another system. Maybe that app is clean and something else is the cause (and its just a hunch, but maybe you should read about process hijacking etc.), or maybe the copy you hold is tampered. _________________
 |
|
| Back to top |
|
 |
Rhys
Joined: 17 Apr 2007 Posts: 618 Location: Florida
|
Posted: Tue Mar 04, 2008 2:29 pm Post subject: |
|
|
Just wanted to add that I've never experienced a bit of trouble with SmartGUI. _________________
 |
|
| Back to top |
|
 |
Buckie
Joined: 13 Feb 2008 Posts: 12 Location: Denmark
|
Posted: Tue Mar 04, 2008 2:37 pm Post subject: |
|
|
Well, I might be the only one who noticed it yet. Im not saying that anyone put malware in anything. Im just wondering, Why it does that - because its not normal behavior ?
If my system was fubar, I would not notice something like this - I notice it because its something that never happend to me before (atleast in the last 5 years or so), anyone who would like to test the the exe file can download it at
http://w15.easy-share.com/1699762517.html |
|
| Back to top |
|
 |
Azerty
Joined: 19 Dec 2006 Posts: 58 Location: France
|
Posted: Tue Mar 04, 2008 2:38 pm Post subject: |
|
|
| Buckie wrote: | I very strongly doubt that (#2). I have never had any Critical outgoing messages like this, I downloaded the software from "official" site, and even if it is possible to see the source code. Its not hard to add some extra lines to the compiled version, and not in the sourcecode. I think that even if I did a string search for "yahoo" or paypal in my SmartGUI.exe, and posted here, you state that it is my version (downloaded straight from http://www.autohotkey.net/~rajat/SGUI/index.html#Download) that might be "bugged"
I cant see why this file (smartgui.exe) should be attacked, it has never been "outsite" my computer since i downloaded it and why my firewall tells me that smartgui.exe is trying to launch mozilla to go to paypals or some wierd yahoo tool bar search.
Im really trying hard to understand, HOW this could happen |
Hi Buckie
just download strings.exe and check the executable for yourself to make sure... Then CRC32 it to see if it's been tampered with (I'm sure old pals will be glad to give you their CRC32 result for the exe). If tampered, turn to your computer and scold it  |
|
| Back to top |
|
 |
Buckie
Joined: 13 Feb 2008 Posts: 12 Location: Denmark
|
Posted: Tue Mar 04, 2008 6:37 pm Post subject: |
|
|
Well I did scan the exe, it found no string in the file matching the links - I was mostly curious to as why it did it. It seems pretty weird, that a application start to launch firefox to get visit paypals. And since Autohotkeys have a rumor for containing virus, malware w/e. I wanted to post it inhere, so we could figure out why it did it ? (and ofc i was pissed after getting these outgoing msg from the program)
What bothers me about it is, I cant figure out "what" did it. What made it do this. I mean, how can a lets say, a virus (trojan or any other malware) contact SmartGui, and tell Smartgui.exe to launch my browser, and then go to paypal. Im sure its doable, but noone in their right mind would bother to write a virus/malware that does that.
the only other thing that can come into my mind would be a hacker attack.But a hacker with full access to my computer (in case he got in) would have no use of the SmartGui Application for his purposes.
So...why did SmartGui try to launch these pages ? WHY !?!!?
Rajat im sorry about being so fast on the trigger but I felt pretty sure that there was programmed some kind of malware into your software - I really like the program:P
Btw, that strings program is really hot little tool ill keep that one for later |
|
| Back to top |
|
 |
Rhys
Joined: 17 Apr 2007 Posts: 618 Location: Florida
|
Posted: Tue Mar 04, 2008 8:26 pm Post subject: |
|
|
Your exe: ED172301
My exe: ED172301 _________________
 |
|
| Back to top |
|
 |
Buckie
Joined: 13 Feb 2008 Posts: 12 Location: Denmark
|
Posted: Tue Mar 04, 2008 9:45 pm Post subject: |
|
|
| so its the same, the screen still speaks for itself - the remote mac adresse is the same, tbh im no network expert, but does this mean anything ? |
|
| Back to top |
|
 |
Rhys
Joined: 17 Apr 2007 Posts: 618 Location: Florida
|
Posted: Tue Mar 04, 2008 10:44 pm Post subject: |
|
|
Disclaimer: I'm no expert
It sounds to me like the issue is isolated to your machine - No one else seems to have experienced the problem and the app has been around the community for a while and (I think) is widely used. While it is closed source (right?) it is my opinion that Rajat would not provide anything close to malware. The message on your screen does not support my opinion, so maybe an expert can sort out what's really happening.
P.S. even though the CRC are the same, I just ran your executable to test - No issues noted. _________________
 |
|
| Back to top |
|
 |
Oberon
Joined: 18 Feb 2008 Posts: 408
|
Posted: Tue Mar 04, 2008 11:01 pm Post subject: |
|
|
| What's the email address of the PayPal account it sends you to? |
|
| Back to top |
|
 |
Lexikos
Joined: 17 Oct 2006 Posts: 2364 Location: Australia, Qld
|
Posted: Wed Mar 05, 2008 2:36 am Post subject: |
|
|
| Rhys wrote: | | it is closed source (right?) | I guess you didn't read the first reply in this thread...
| Buckie wrote: | | I mean, how can a lets say, a virus (trojan or any other malware) contact SmartGui, and tell Smartgui.exe to launch my browser, and then go to paypal. | It is relatively easy to inject code into a running process (at least if you are an administrator?), but like you said, why would anyone bother? Maybe the (hypothetical) virus hijacks a random process to disguise itself? |
|
| Back to top |
|
 |
|