Slashdot Mirror


Stealware: Kazaa et al Stealing Link Commissions

goombah99 writes "We all heard about spyware, well now Kazaa, Morpheus and LimeWire are sneaking a new type of nastiness onto your computer, software that - without you even knowing it - redirects commissions for online purchases you make from other vendors you make back to them. For example, if you buy a CD from an affiliate of Amazon.com, say some charity, the software fools Amazon into crediting the commission to Morpheus, not the charity! The story quotes a LimeWire Developer who admits 'While I agree that this is really a bit of a scam, it is a way for us to pay salaries while not adversely affecting our users.' The insidious part is the stealware program remains even if you delete the original P2P software. And you supposedly gave your permission when you clicked through the EULA."

23 of 654 comments (clear)

  1. Kazaa Lite by Gildenstern · · Score: 4, Informative

    That's why if your going to use Kazaa you should really use Kazaa Lite. It's Kazaa without all the spy stuff installed.

  2. Re:just great... by Jucius+Maximus · · Score: 2, Informative
    "i just installed Kazaa yesterday, having ignored p2p programs uptill now.. hopefully someoen will crack this.."

    It's already been done.

  3. Re:just great... (HOW TO REMOVE) by Christopher_G_Lewis · · Score: 5, Informative

    From the article's side-bar:

    A Software Cleanup

    Computer users who want to remove shopping software from their machines can do so in a few steps. Instructions for removing three of the most common programs:

    BUYERSPORT - The shopping software with Morpheus:

    Click the Start button.

    Click on Find.

    Click on Find Files or Folders.

    Type in mbho.dll. Click on find now. When the file appears in the directory window, drag mbho.dll into the trash.

    LIMESHOP - The software with LimeWire:

    Click the Start button.

    Click on Settings.

    Click Control Panel.

    Double-click Add/Remove Programs.

    Click LimeShop.

    Click Add/Remove.

    SAVENOW - The software used by Kazaa:

    Click on Start.

    Click Settings.

    Click on Control Panel.

    Double-click on Add/Remove Programs.

    Click SaveNow.

    Click on Add/Remove.

  4. Gnucleus by RailGunner · · Score: 5, Informative

    It might not be as fast as the other p2p networks, but Gnucleus is free, open source, and not subject to any malware like Kazaa is...

  5. You can beat them. by casio282 · · Score: 5, Informative

    This is more than "a bit of a scam" -- it's immoral and undoubtedly illegal. There are ways to get defeat all their little scams and still use the Fasttrack P2P network. You can try Kazaa Lite, which is Kazaa without the spy/scumware. I'd also recommend using AdAware, a great little program that scans your registry, memory, and hard drives for spy/scum/adware components and gives you the option to delete them.

    Using AdAware to delete cydoor.dll will likely leave your P2P client not working. That's where the dummy cydoor.dll comes in. It allows the client to start without providing any of the unwanted cydoor functionality.

    For more info on spyware and scumware in general, check out the quite wonderful Counterexploitation site...

    Hope this helps...

    --

    :wq
  6. Furthurnet.com by Bullschmidt · · Score: 5, Informative

    I'd like to point people's attention to furthurnet.com. I'm sure it won't have the popularity of the other sharing systems, but its a legit system and you get unique material.

    Furthurnet.com is a system where fans of bands which allow bootlegging of live concerts post full sets from those shows.

    Pros:
    *Free, no ads, no spyware, nothin
    *Legal - music is only by bands who approve
    *New stuff - you can get stuff no on CD's yet
    *Live stuff - could be a plus or minus depending on the artist, but its a new perspective.

    Cons:
    *Bigger - they're recorded in a non-lossy format shn, so a full concert is anywhere between 200-600 meg
    *Recording quality not as good - depending on the band, the recorder and show, the acoustics and equipment aren't as good as live CD's and certainly not as clean as studio.
    *Fewer artists

    I just discovered this a few days ago looking for Jack Johnson stuff. I love it. Take a look. Its on Win and linux (maybe Mac too, not sure)

    --
    "Of all days, the day on which one has not laughed is the most surely the one wasted." -Sebastian Roch Nicol
  7. Re:Suggestions for the not-so-techincally adept? by Bullschmidt · · Score: 3, Informative

    Try adaware by lavasoft. Think of it as a virus scanner for spy/ad/stealware. Not a bad product.

    --
    "Of all days, the day on which one has not laughed is the most surely the one wasted." -Sebastian Roch Nicol
  8. Use vmware by qarnage · · Score: 3, Informative

    For all the crapware i use vmware. Sure, you've got to pay for it, but then it'll save you lots of headaches dealing with this stuff. Just use a virtual machine for the crap, and the main one for the real stuff. Probably bochs would also do, though i didn't test it.

  9. Re:Fer Chrissake, it's FRAUD! by TekPolitik · · Score: 5, Informative
    Isn't Kazaa owned by a Sydney based company now? This is definitely illegal in Sydney under the Crimes Act 1900 (NSW). AustLII's misbehaving at the moment so I can't find the links online, but:

    s178BA - Obtaining money by deception - 5 years

    s178BB - Obtaining money etc by false or misleading statements (it doesn't require the statement to be in writing, false claim as to referrer will definitely count) - 5 years

    s180 - Causing payment etc by false pretence etc (the false referrer will count here too) - 5 years

    This could be prosecuted under any one of these.

  10. How to rid of it by yadayadayada · · Score: 2, Informative
    From an article at Speedy3D.com:
    1) First run a search on your C: drive for the file bpboh.dll after the search has completed it should return one result.
    2) Delete the file
    3) Next it's a good idea (but not necessary) to run a search through the registry for all references to Morpheus and bpboh.dll.
  11. It's against the affiliate agreement for amazon. by evil_one · · Score: 5, Informative

    Here's the link: http://associates.amazon.com/exec/panama/associate s/join/operating-agreement.html/104-2963693-286633 7

    Section 5, at the end:
    In addition, you may not: [snip] (b) read, intercept, record, redirect, interpret, or fill in the contents of any electronic form or other materials submitted to us by any person or entity;

    --
    Desperation is a stinky cologne
  12. Re:The price of freedom. by Codifex+Maximus · · Score: 3, Informative

    >What person out there would take a company to court
    >that is allowing them to distribute and download
    >music that a lot of the major companies don't want
    >you to do?

    Insightful.

    >I'm uneffected by this because i'm a happy WinMX
    >user. I've never had a problem whatsoever, unlike
    >AudioGalaxy and Bearshare (this is awhile ago) that
    >deleted some of my system files, thus making me
    >have to reformat!

    Yeah, isn't that something? It's faster to reformat a Window's partition than it is to deltree c:\windows and c:\progra~1. It takes hours to deltree and mere minutes (usually) to format.

    I just boot LOAF (Linux on a Floppy) if I have to rm -fR the windows and the program files dirs on a windows partition... much much faster.

    As for the stealing of commissions intended as charitable contributions, I have no first hand information on it but... if it is going on, it diminishes the spirit of charitable giving and probably breaks the law. Flame on!

    --
    Codifex Maximus ~ In search of... a shorter sig.
  13. Gnucleus by C4-GodH8sMe · · Score: 2, Informative

    Has nobody heard of Gnucleus?
    http://www.gnucleus.com/
    http://gnucleus.sourceforge.net/

    And it's Not Evil. :)
    Unlike many file sharing systems, Gnucleus is not run by a company. This project has been active for over a year and no one has made a dime of it. We do not want your money, we want your support in development and making this program something great. Few windows programs are open-source, this is one of the few, because of that it is impossible for us to ever charge you for this program or future versions. I make this program out of my need for a honest file sharing system.

    --
    We are all Gods unwanted children. Did you ever consider he may hate you too?
  14. Re:I guess Amazon will be changing their contract. by Koos · · Score: 4, Informative
    I'd imagine that Amazon et al will be chaning their contractual terms specifically preventing this sort of behavior. The whole 'affiliate' program is dependant upon the warm and fuzzy feeling one gets by helping out a site you use, giving additional sales to Amazon.
    I am in the amazon affiliate program with The Virtual Bookcase and I recently checked the whole operating agreement again. A search in that agreement gives:

    you may not: [..] read, intercept, record, redirect, interpret, or fill in the contents of any electronic form or other materials submitted to us by any person or entity;

    This should be enough to boot any account from amazon that has transactions coming from altering affiliate links. I'm starting to wonder how much my site 'lost' due to things like this.

  15. Re:Moral issues anyone? by MushMouth · · Score: 5, Informative

    I talked to Colin the head of the Amazon Associates program a few months ago, and they absolutely do not find this acceptable, however they have somehting on the order of 20,000 associates, so it takes a little while for them to see trends that would ferret this behaviour out. He said they had seen it before and told the companies to stop, or they would cancel their Associates account.

  16. Just use winMX by an_mo · · Score: 3, Informative

    www.winmx.com
    It's a much better client than morpheus/kazaa, its network size has passed the threshold to be useful.

  17. What it basically says... by Karhgath · · Score: 3, Informative

    It's totally illegal. What the EULA actually says is :

    "By signing this contract you allow us to steal from your neighbor."

    This is the same thing, period.

    First, it asks the permission to someone not related to the contract's target, which is illegal. (You cannot have a contract that says: By signing this, you agree that your friend X owes us XX bucks.)

    Second, stealing is illegal.

    So, it doubly illegal!

    This is just sick.

    1. Re:What it basically says... by loply · · Score: 2, Informative

      The EULA (presumeably) implies that "You grant permission for software to be installed which allows you to choose products from a range of websites and have them purchsed from the Kazaa website automatically, on your behalf".
      Fucking disgusting thing to do, but Im not convinced that its as clearly illegal as some people think. By aggreeing to the EULA, you agree to the installation and operation of this software and you know about its presence and function.

    2. Re:What it basically says... by epmos · · Score: 2, Informative

      I suspect that rather than Canada getting the concept from US law, both the US and Canada inherited the concept from English law.

  18. Removing spyware by fluor2 · · Score: 2, Informative
    Here are some links to programs that remove spyware like this:

    http://download.com.com/3120-20-0.html?qt=spyware& tg=dl-2001

    I would personally recommend Lavasoft Ad-Aware from Lavasoft.de. "Ad-aware is a free multi spyware removal utility that scans your memory, registry and hard drives for known spyware and scumware components and lets you remove them safely. It is updated frequently. If you are new to Ad-aware, we recommend you read the getting started tutorial."

    Don't forget to download the Reference file Updater v2.01 for Ad-aware.

  19. Re:Dancing with the devil by Sancho · · Score: 2, Informative

    But I use Kazaa to find songs from my favorite bands that /allow/ their songs to be shared. I'm using it legitimately. And they're stealing money that I pay amazon for the CDs of music I /don't/ steal!

    This is the problem.

  20. Re:Victimless crime? by JoeBuck · · Score: 4, Informative

    Their diversion of cash does hurt the customer.

    Many co-op preschools in my area, in order to be able to charge less tuition money, permit parents to agree to engage in a certain amount of fundraising. Among the options available is to sign up for Schoolpop, at which point the school gets a quite generous cut of commissions for purchases on Amazon and similar sites.

    However, if the KaZaa folks steal the commissions, the parent is liable, since the parent must raise some minimum amount (yes, Schoolpop provides the data to the school so the school knows who's raised the money for them). In cases like this, which are quite common, the KaZaa folks and their hitchhikers are directly stealing from their users, as well as from schools and charities.

  21. Re:What did you expect by arkane1234 · · Score: 2, Informative

    No... as has been reiterated ad nauseum and is legally correct, it is copyright infringement.

    Please, stop calling theft. When I walk up to you, snag the cd from your hand and walk away, that is theft. When I walk up to you, borrow your cd, put it into my handy-dandy portable TiBook and rip it to OGG or MP3 and walk away, now that is copyright infringement. One involves a tangible object, the other is dealing with a something more abstract than a physical object.

    --
    -- This space for lease, low setup fee, inquire within!