Gnutella Forums  

Go Back   Gnutella Forums > Current Gnutella Client Forums > GnucDNA Based Clients > Morpheus (Windows)
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

Morpheus (Windows) For users of Morpheus to get assistance. Important link: Clean Updated Morpheus Installers available here!


 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old March 19th, 2002
Unregistered
Guest
 
Posts: n/a
Arrow New Morpheus Contains Spyware

Short story: I have found that Morpheus Preview Edition (the new version
of Morpheus) contains spyware which launches everytime Internet Explorer
is invoked.

Long story: I noticed that Internet Explorer was being very slow to
launch as of a few days ago. I also noticed that my computer's webserver
logs contained an odd line, which seemed to coincide with my Internet
Explorer launches:

05:05:40 127.0.0.1 HEAD /bpboh.dll - 404 162 150 0 HTTP/1.1
rdxrDLL;SID=b0000001;DllVers=1.0.0.0

I decided to a bit of digging. I first confirmed that this hit to my
local webserver does occur each time Internet Explorer is launched. Then, I launched File Monitor (free tool from www.sysinternals.com) to see
what files IE was launching at startup. Turns out it was running this
bpboh.dll file:

12:07:48 AM IEXPLORE.EXE:1208 IRP_MJ_CREATE
D:\WINDOWS\bpboh.dll SUCCESS Attributes: N Options: Open

Interesting. So I decided to rename the file to hide it. Launching
Internet Explorer again did not cause my webserver to log the "bpboh.dll"
hit.

Next I examined the bpboh.dll file, and found all sorts of curious
references in it: one to "BuyersPort" (the 'Shop' page on the new
Morpheus), a few to Barnes and Noble, Sephora, and two very curious ones:

www.rdxrp.com - visiting this site takes you to Morpheus' Homepage

"morph" - possible a reference to Morpheus?

I then went to the Morpheus directory, and saw that the installer log left this behind

RegDB Key: SOFTWARE\rdxr
RegDB Val: 1.3.3.1
RegDB Name: mv
RegDB Root: 2
RegDB Old: 1.3.3.1
Self-Register: D:\WINDOWS\bpboh.dll
User Rights: Admin

Clearly, this means that Morpheus is installing Spyware.

Please announce this on your website, and also tell people that they can delete the spyware simply by deleting the bpboh.dll. It may also be a good idea to search through the registry for references to bpboh.dll and delete them; though only experienced users should do that.
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Morpheus and Neonet suck... only Gnutella is the good thing of Morpheus Dark Guy Morpheus (Windows) 0 March 7th, 2007 05:50 PM
is morpheus 3.2 really free of ad&spyware ron wolpa Morpheus (Windows) 3 October 23rd, 2004 05:40 AM
Morpheus 4.0.1 Zaggar Morpheus (Windows) 9 March 17th, 2004 07:08 AM
Morpheus 4.0a backmann Morpheus (Windows) 0 November 27th, 2003 07:36 PM
Morpheus OS 1.8.2 Unregistered Open Discussion topics 4 June 24th, 2002 05:30 PM


All times are GMT -7. The time now is 12:21 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.