Quick Links: SpywareGuide Greynets Blog | SpywareGuide Product Database | SpywareGuide Company Database | SpywareGuide Categories
SpywareGuide powered by FaceTime Security Labs
Search SpywareGuide Greynets Database & Site
Security Email Alerts & Updates
Search the Blog
 
Recent Posts
Categories
Monthly Blog Archives
Links
Subscribe
Subscribe to this blog's feed
About the Blog
About SpywareGuide Greynets Blog
Link to Us
Link to SpywareGuide.com

« Skype Phish? | Main | The Pooo Hijack, and an Empty Sweetbox... »

  • A Korean Trick or Treat?

Here's a weird one - there are hints and suggestions that some sort of advertising mechanism is in place, but with the program being from Korea it's vaguely tricky to know exactly what is going on. Let's take a look anyway...

http://blog.spywareguide.com/upload/2007/05/da0-thumb.jpg
Click to Enlarge

Of course, the site is in Korean and the EULA isn't exactly easy to understand which doesn't really help:

http://blog.spywareguide.com/upload/2007/05/da1-thumb.jpg
Click to Enlarge

In fact, the installer is so fiddly it took a good five minutes to work out what buttons to press to get it to run in the first place! After everything is up and running on the PC, this is what we're left with:

da2.jpg

...and now, it's time to run this thing and see what it does! An icon is dumped onto your Taskbar and into IE itself, and when you click either you see this:

http://blog.spywareguide.com/upload/2007/05/da3-thumb.jpg
Click to Enlarge

......yeah, I have no clue either. If you click into the other tab, things look a little more useful:

http://blog.spywareguide.com/upload/2007/05/da4-thumb.jpg
Click to Enlarge

From the looks of it, one of the primary functions of this program is to store basic "notes" about the sites you visit in the interface. Beyond that, I have no idea if you can do more with the data you input, or if the program has any other "features". Here's where it gets interesting - from the translated page:

To case of the keyword which the user does not register with the site which generally is useful movement
- Ex) Seoul watching -> seoul.go.kr/ and pcfree -> pcfree.co.kr
- -> With www automatic conversion function.
- In compliance with the malignant cord or other Hangul (Korean alphabet) keyword program the function which intercepts the part which is rightly connected with an advertisement characteristic site in the dictionary.
- The user wants search engine configuration feature.
- Up-to-date version connection (DirectConnector) it maintains rightly the automatic update function for. (Default)

Allowing for a hopeless translation, this is effectively saying it grabs keywords and relates them to advertisements in the "dictionary". Of course, I don't know what "dictionary" they speak of. Built in word-list to pop relevant adverts? Or something else altogether? Who knows, but I couldn't get it to pop anything while running it so a final decision on this thing is still pending.

...don't you just hate it when that happens?

Summary Write-Up: Chris Boyd, Director of Malware Research
File Discovery: Chris Mannon, FSL Senior Threat Researcher

  • TrackBack

TrackBack URL for this entry:
http://blog.spywareguide.com/mt/mt-tb.cgi/174

Listed below are links to weblogs that reference A Korean Trick or Treat?:

» Tramadol side effects. from Tramadol side effects.
Tramadol for dogs side effects. Tramadol side effects. [Read More]

» Ambien buy ambien online starting from per. from Buy ambien online cod.
Buy ambien online wholesale prices save up to no. [Read More]

» united life insurance from united life insurance
zero?Victorians sweating Hattizes ugliness [Read More]


Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)


Site EULA | Site Map | Contact Us | About Us | Site and Spyware FAQ | Advertise | RSS Feeds  | Link To Us | SpywareGuide JapanJapanese

© Copyright 2006, FaceTime Communications, Inc. All rights reserved.