[Guide] Avoiding Adware in Installers


Recommended Posts

Avoiding Adware in Installers

About This Guide

This guide provides several real examples of installers which contain adware. The intent is to show you the tricks that they use to attempt to trick you into installing the adware in hopes that you can learn to avoid it.

Before you brush off this guide as common sense, it may be worth a look. The adware developers are getting very sneaky and I've almost been caught a few times myself. Recently, Foxit Reader modified their installer so that the adware was no longer optional but mandatory. This is a continuing trend and adware is only going to get worse, so it's important to learn how to avoid installing it... unless you like toolbars which track your browsing history.

Note: All of the installers have [#] in their titlebar because they were running in Sandboxie.

Accept or Decline? Agree or Disagree?

This is a common trick that they'll use. To avoid installing the adware, you must click Decline / Disagree rather than Accept / Agree.

post-57213-0-97313500-1307244464.png

This may catch some users because the text looks like the license agreement.

post-57213-0-75118600-1307244483.png


I agree to...

In these examples, you must uncheck the checkbox in order to avoid installing the adware.

I agree to the agreement :huh:

post-57213-0-54889700-1307244460.png

post-57213-0-30507300-1307244543.png


Custom Installation

For some installers, you must choose Custom installation if you want to opt out of the adware.

post-57213-0-01617000-1310709539.png


Post-Installation

This installer attempts to catch you after you've installed the program.

post-57213-0-76124000-1307244486.png


Distraction

Some installers may catch you by tricking you into clicking the wrong option. I'm not sure if these were designed to deceive, but I nearly clicked the wrong options for both installers, so I added them to the guide.

Here, my first reaction was to click Custom installation and uncheck the boxes below it.

It seems obvious, but the Custom installation is the first thing to grab your attention.

post-57213-0-63316500-1307244452.png

Once again, the Custom installation was the first thing to grab my attention.

post-57213-0-44441900-1310709537.png


Mandatory Installation

Recently, Foxit Reader didn't give you an option; You we're forced to install the adware if you wanted to install Foxit Reader. You may think that unchecking the two boxes was enough, but you have to read to understand there's no opting out.

Foxit Reader later updated their installer following several complaints, but this still stands as a solid example.

post-57213-0-38803100-1307244490.png


Websites Packaging Adware in Downloads

This is a new and worrying trend. Many websites, including the popular CNET, have started packaging several downloads in a custom web installer which includes adware, often without the permission of the original developers. The examples below are pretty obvious and easy to avoid, but it's a trend you should be aware of none the less.

CNET's download.com

post-57213-0-93104600-1323809688.png

Softonic.com

post-57213-0-45170600-1323809690.png

Tucows

post-57213-0-86509500-1328579848.png


Installers with Spyware

It was recently reported that DAEMON Tools, a popular CD-image mounting software, installed a spyware feature called MountSpace which reported every image you mounted to an online server. Even if you declined the feature, it was still active without your permission.

http://www.neowin.ne...ted-last-summer

Edited by Xinok
  • Like 7
Link to comment
https://www.neowin.net/forum/topic/1002608-guide-avoiding-adware-in-installers/
Share on other sites

Nice work Xinok, i recently installed Foxit 5 and like you mentioned unchecked the Ask toolbar boxes (as was the case in previous versions) then during install i was alerted to the AskToolbar checker making an outgoing connection. I knew something wasn`t right but carried on, i was like proper :angry: when the toolbar showed up in the browser.

Wasn`t a problem as i just re-imaged from a recent back up, but boy have i lost faith in Foxit. This is not something you should do to potential customers, fair enough if the option to not install is there (these companies pay big money to be included in installers, thus help with development hopefully!) but to downright trick people is out of order.

Needless to say i`m am trying out other pdf options...

Thanks for this. I script a lot of my installers in my custom XP source and one test run wound up with "Dealio Toolbar" installed. I was seeing red, half at myself for not having caught it and half for the marketroid bottom-feeders who buried that installer in there to begin with. I think it installed alongside a disc-burning tool but I'm not sure yet.

What ****es me off is that unattended installs offer no way that I know of to cut the worthlessware (hear me advertisers? You and everything you do are all worthless. Yes, you. And yes, everything, really. Go die.) out and just leave the core program itself. Makes it a lot harder to do up some effortless automated installs.

  • 3 weeks later...
  • 2 weeks later...
  • 4 months later...

So I recently came across an installer that was so bad, I felt the need to post it. I was looking for a desktop application for Facebook chat, so I wouldn't have to keep my web browser open. What resulted is the horror you see below.

Immediately after launching the installer, I'm greeted with the first box I must uncheck. Not only that, but if you read the text, it installs a mandatory background process which calls home.

post-57213-0-66413000-1321136836.png

Next, I had to choose custom installation and uncheck three boxes.

post-57213-0-35765700-1321136839.png

That isn't all! Next, I'm presented with this screen in which you must check Decline, not accept.

post-57213-0-67158200-1321136843.png

Now that I've avoided all that, I continue to install and launch the program. As if all the crap in the installer wasn't enough, they also implement an ad into the interface.

post-57213-0-01380200-1321136838.png

Okay... so I'll just login and see if this program was worth the trouble...

post-57213-0-17528800-1321136835.png

At this point, I stop, clear the sandbox, and check Facebook to make sure it hadn't made any changes to my account.

  • 3 weeks later...
  • 2 weeks later...
  • 1 year later...

Also avoid downloading anything from cnet :p

Lately, yes I'd have to agree, I hate that installer thing you need to have just to download something.

I always choose advanced when installing, to see what I have control over (in case of something I don't want installed) but even then, like OP pointed out you don't have a choice with some software

(usually I'll go find a rival product)

  • 10 months later...
  • 2 years later...

What I cannot understand is why some software developer has never created an app to circumvent these dirtbags. How difficult could it be to create something that would download from CNET into a safe containment (Virtualbox? Sandboxie?), allow one to open the archive, save the target file, and delete the malware? They can create Fraudfox to help juvies steal your credit card info, but not this!

16 minutes ago, Formido said:

What I cannot understand is why some software developer has never created an app to circumvent these dirtbags. How difficult could it be to create something that would download from CNET into a safe containment (Virtualbox? Sandboxie?), allow one to open the archive, save the target file, and delete the malware? They can create Fraudfox to help juvies steal your credit card info, but not this!

Dude this thread is so old, it is moldy. 

 

https://unchecky.com/

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • They aren't going to want to. Most would just go with the 17 Pro and save money. Why would they want to spend $300 for basically the same thing? It's not worth it if there are hardly any changes from year to year.
    • 24H2 rolled out to the Release Preview Channel in early June 2024, so this coming a bit later in the Experimental Channel (formerly Dev) doesn't really say much more than earlier H2 releases that came out in October. I am not sure what the thinking is here by putting it in Experimental, one would think that the 26H2 stamp means features are locked down and it's now bug tested until October? I don't even pretend to understand Microsoft's strategy for Windows Insider Program though
    • Nothing Ear (a) and CMF Buds Pro 2 with active noise cancellation drop to lowest price ever by Fiza Ali With Prime Day 2026 scheduled to run from Tuesday 23 to Friday 26 June, Amazon has already begun rolling out early access offers ahead of the main event. Particularly, Nothing Ear (a) and CMF Buds Pro 2 wireless earbuds have dropped to their lowest price ever with limited Prime deal offering 33% and 24% discounts, respectively. Nothing Ear (a) are equipped with 11mm dynamic drivers featuring a PM1 + TPU diaphragm. For noise control, the earbuds offer active noise cancellation (ANC) of up to 45dB across frequencies reaching 5,000Hz. The smart ANC algorithm adapts to surrounding noise levels, while a Transparency Mode allows users to remain aware of their environment when needed. Connectivity is handled via Bluetooth 5.3, with support for AAC, SBC, and LDAC audio codecs. Additional features include IP54-rated earbuds for dust and splash resistance, paired with an IPX2-rated charging case. Furthermore, users also benefit from pinch controls, in-ear detection, Google Fast Pair, Microsoft Swift Pair, dual-device connectivity, and a low-latency mode designed for gaming and video playback. The Nothing X app unlocks a range of customisation options, including a personalised equaliser, bass enhancement, control remapping, ear tip fit testing, firmware updates, dual-device management, a Find My Earbuds feature, and low-latency mode settings. When it comes to the battery, the earbuds house a 46mAh lithium-ion battery, while the charging case contains a 500mAh cell. With ANC disabled, users can expect up to 9.5 hours of playback from the earbuds and up to 42.5 hours in total with the charging case. With ANC enabled, battery life is rated at up to 5.5 hours per charge and up to 24.5 hours combined with the case. Finally, fast charging is also supported that should provide up to 10 hours of playback from a 10-minute charge with ANC turned off. Nothing Ear (a) Wireless Earbuds (Black): $53.20 (Amazon US) - 33% The CMF Buds Pro 2 feature a dual-driver audio system consisting of an 11mm bass driver and a 6mm micro-planar tweeter. The earbuds use PU (polyurethane) and PET (polyethylene terephthalate) titanium-coated diaphragms and are tuned by Nothing to deliver balanced audio performance. They further support active noise cancellation of up to 50dB across a frequency range of up to 5,000Hz, and noise control features include a Smart ANC algorithm, Adaptive ANC, Transparency Mode, and Clear Voice Technology 2.0. For calls, the CMF Buds Pro 2 use a total of six microphones and feature an environmental noise-cancelling algorithm, Clear Voice Technology 3.0, and Wind Noise Reduction 3.0 that should improve voice clarity during conversations. Furthermore, when it comes to the connectivity, it is provided through Bluetooth 5.4. Additional features include an IP55 rating for dust and water resistance, Google Fast Pair, Microsoft Swift Pair, in-ear detection, a low-latency mode, and a Find My Earbuds function. Moreover, through the Nothing X app for Android and iOS, users can access custom EQ settings, a bass enhancement algorithm, customisable controls, Find My Earbuds, low-latency mode, dual-device connectivity, an ear tip fit test, and firmware updates. The earbuds contain a 60mAh rechargeable lithium-ion battery, while the charging case houses a 460mAh battery. A full charge of the earbuds and case via USB-C should take approximately 85 minutes, while the earbuds alone should be fully recharged in the case in around 60 minutes. Battery life is rated at up to 11 hours of playback on a single charge and up to 43 hours with the charging case when ANC is turned off. With ANC enabled, playback time is reduced to up to 6.5 hours on the earbuds and up to 26 hours with the charging case. Talk time is rated at up to 6 hours on the earbuds and 25 hours with the case with ANC disabled, or up to 4.8 hours and 18.6 hours, respectively, with ANC enabled. CMF Buds Pro 2 Wireless Earbuds (Dark Grey): $37.05 (Amazon US) - 24% Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • The entire world moved to the vastly superior and now universally supported Dolby Atmos technology a very long time ago, mate.
  • Recent Achievements

    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      544
    2. 2
      +Edouard
      187
    3. 3
      Michael Scrip
      77
    4. 4
      PsYcHoKiLLa
      75
    5. 5
      Steven P.
      71
  • Tell a friend

    Love Neowin? Tell a friend!