allentech.net

Limited Time!
Totally FREE Web Design!
Click here!

Blue Host

Parasite: FavoriteMan

This record last updated Tue Sep 20 2005 00:34:15

PLEASE NOTE: Due to the overwhelming extent of this problem and the unbelievable volume of email we have received, we regret that we cannot respond to questions about browser parasites at this time. If you have attempted to contact us about this parasite please accept our apology for not responding. "Thank you's" are always appreciated ;-)

Description

FavoriteMan is a backdoor downloader implemented as an Internet Explorer Browser Helper Object (BHO) stored in the System32 folder. It periodically connects to its controlling server to download a control text file, which instructs it what software to install and where to download the control file from next.

It also has the facility to add web links to the desktop background and IE Favorites menu as directed by the control file.

FavoriteMan is unusual in that its various variants are used simultaneously by two different groups of companies:

  • Razor Media LLC (razormedia.net, n-lite.com), a US marketing company (not known to have anything to do with the ‘Razor Media LLC’ that run US men’s magazine Razor). Razor Media are also reponsible for the DailyWinner, WhileYouSurf and ClickTheButton parasites.
  • Vista Interactive Media (vistainteractivemedia.com, mindsetinteractive.com), who are also responsible for the VistaBar and NetPal parasites, and used to control Transponder.

Variants

VariantBHO file Data file Server Found (approx)
Razor variants
FavoriteMan/Ofrg ofrg.dll favboot.dllwww.yourspecialoffers.comJan 2002
FavoriteMan/Favorite Favorite.dll favboot.dllwww.yourspecialoffers.comJul 2002
FavoriteMan/Ss32 ss32.dll sysfile.dllwww.r-vision.org Jun 2003
FavoriteMan/MMView mmviewer_10(n).dllsysfile.dllwww.mmviewer.com Nov 2004
Vista variants
FavoriteMan/F1 F1.dll SysLdr.dll www.prize4all.com Sep 2002
FavoriteMan/Lwz lwz.dll SysLdr.dll www.f1organizer.com Dec 2002
FavoriteMan/FOne FOne.dll SysLdr.dll www.f1organizer.com Dec 2002
FavoriteMan/ZZ ZZ.dll SysLdr.dll www.f1organizer.com Dec 2002
FavoriteMan/IMZ (random).dll SysLdr.dll www.f1organizer.com Feb 2003
FavoriteMan/Mpz mpz300.dll mbr32.dll www.f1organizer.com Mar 2003
FavoriteMan/Trk trk.dll mbr32.dll www.f1organizer.com Apr 2003
FavoriteMan/Gr02 Gr02.dll im64.dll www.f1organizer.com Jun 2003
FavoriteMan/Gig gig.dll mbr32.dll www.f1organizer.com Jul 2003
FavoriteMan/EMesX emesx.dll dlh0st.dll www.f1organizer.com Jul 2003
FavoriteMan/Aess aess2.dll im64.dll www.f1organizer.com Oct 2003
FavoriteMan/YsUp ysup01.dll im64.dll www.f1organizer.com Nov 2003
FavoriteMan/Gnt GrlNt0i.dll im64.dll www.f1organizer.com Nov 2003
FavoriteMan/Td1 td1.dll mbr32.dll www.f1organizer.com Nov 2003
FavoriteMan/On On01.dll im64.dll www.f1organizer.com Nov 2003
FavoriteMan/N3t n3tpa1p.dll im64.dll www.f1organizer.com Dec 2003
FavoriteMan/Icm IAicm.dll im64.dll www.f1organizer.com Dec 2003
FavoriteMan/Int IAint.dll im64.dll www.f1organizer.com Mar 2004
FavoriteMan/Cal calsdr.dll im64.dll www.f1organizer.com Mar 2004
FavoriteMan/Benceed Benceed.dll im64.dll www.f1organizer.com Mar 2004
FavoriteMan/ATPartnersATPartners.dll im64.dll www.f1organizer.com May 2004

The filename for FavoriteMan/MMView may be mmviewer_101.dll or mmviewer_102.dll. The filename for FavoriteMan/IMZ is one of the nonsense names associated with lop, such as eelykofrllfrpr.dll.

FavoriteMan DLL files are typically around 100K long, except for the EMesX and Gig variants which are compressed to around 50K using the UPX executable file packer.

The ATPartners variant comprises many minor variations (one for each distributor) which differ only in the name of the control file fetched from f1organizer.

Also known as

NetPal. Mindset Interactive (now Vista) used to call all its software ‘NetPal’, including the NetPal parasite and Transponder, which they previously controlled.

Distribution

The Ss32 variant is installed by SpyAssault, a supposed spyware scanner from Razor Media. The MMView variant is installed by ActiveX drive-by downloads in pop-ups sourced from Mamma Media Solutions (targetnet.com).

The Favorite, F1 and Mpz variants have been bundled with iMesh. The ZZ and Gr02 variants were bunded with Grokster around January and June 2003.

The IMZ variant is installed by the lop/IMZ parasite. The Gig variant is installed by software from TwistedHumor.com. (’Gig’ refers to Gigatech Software, producers of the SuperBar parasite.)

The YsUp variant is installed by ActiveX drive-by download in pop-up adverts served by YesUp Ecommerce Solutions (yesup.net, popinads.com), who also operate the Pugi/WhyPPC parasite.

The Int, Icm and ATPartners variants are installed by downloads from affiliates of addictivetechnologies.com/addictivetechnologies.net/at-games.com, including Vista’s own sites such as 1000funnyvideos.com, screensthemesandmore.com and at-offers.com, and others such as free-windows-games.com.

The ATPartners variant is additionally installed by bundling with other parasites and from affiliate sites using ActiveX drive-by downloads, ‘aggressive’ downloader scripts and IE security hole exploits.

What it does

Advertising

No pop-ups, but adds advertising links to the Desktop background and IE Favorites menu.

Privacy violation

In the Razor Media variants, no.

The Vista variants contain vestigial code that appears to want to read the user e-mail adress stored in Outlook and Outlook Express settings. However this has not been observed to actually work.

Security issues

Yes. The software can and does execute arbitrary unsigned code as directed by its controlling server. FavoriteMan’s aim is to install as much unsolicited commercial software as possible in order to earn commission fees from other parasite vendors.

Unsolicited commercial software seen to be installed by the early Razor Media variants of FavoriteMan (Ofrg, Favorite) includes:

Software installed by the later Razor Media variants of FavoriteMan (Ss32, MMView) includes:

Software installed by the Vista variants of FavoriteMan includes at least:

Stability problems

Yes. FavoriteMan sometimes causes IE to lock up for a variable period of time, occasionally indefinitely, when a new browser process is started. This may be something to do with its trying to contact its servers on startup. Also crashes may occur when very long URLs are used.

Removal

FavoriteMan/F1, ZZ, IMZ, Icm/Int and ATPartners may offer a removal feature: go to Add/Remove Programs in the Control Panel, choose ‘F1’, ‘ZZ’, ‘IMZ’, ‘Netpal Games’ or ‘ATP’ and click ‘Remove’.

Manual removal

The DLL file with the name from the table above can be found in the System32 folder, which is inside the Windows folder, and called just ‘System’ on Windows 95/98/Me. In the case of the IMZ version, look for the nonsense name; if you sort the files to show the newest version it should be reasonably obvious.

Before you can delete the program file, you must deregister it. Open a DOS command prompt window (under Accessories in the [All] Programs menu on the Start button) and enter the commands:

cd "%WinDir%\System"
regsvr32 /u favorite.dll

Change the filename ‘favorite.dll’ to match the filename.

After doing this and restarting the computer you can delete the file. You can also delete the data file named in the table above, which should be found in the same folder.

To clean up, you can also open the registry (click ‘Start’ choose ‘Run’, enter ‘regedit’) and select the key HKEY_CURRENT_USER\Software\Microsoft\Windows, then delete the entries named ‘Counter’, ‘Server’ and ‘Object’. on the right.

* Parasite information and detection script by Andrew Clover - www.doxdesk.com, used with permission.

For more information about Scumware, Spyware and Parasites, their sources and their cure, visit our About Parasites page and related Tech Links.

Visit our new services portal at Allen One for a completely new parasite database format, comming November 2005!

Top