[Guide] Avoiding Adware in Installers


Recommended Posts

Avoiding Adware in Installers

About This Guide

This guide provides several real examples of installers which contain adware. The intent is to show you the tricks that they use to attempt to trick you into installing the adware in hopes that you can learn to avoid it.

Before you brush off this guide as common sense, it may be worth a look. The adware developers are getting very sneaky and I've almost been caught a few times myself. Recently, Foxit Reader modified their installer so that the adware was no longer optional but mandatory. This is a continuing trend and adware is only going to get worse, so it's important to learn how to avoid installing it... unless you like toolbars which track your browsing history.

Note: All of the installers have [#] in their titlebar because they were running in Sandboxie.

Accept or Decline? Agree or Disagree?

This is a common trick that they'll use. To avoid installing the adware, you must click Decline / Disagree rather than Accept / Agree.

post-57213-0-97313500-1307244464.png

This may catch some users because the text looks like the license agreement.

post-57213-0-75118600-1307244483.png


I agree to...

In these examples, you must uncheck the checkbox in order to avoid installing the adware.

I agree to the agreement :huh:

post-57213-0-54889700-1307244460.png

post-57213-0-30507300-1307244543.png


Custom Installation

For some installers, you must choose Custom installation if you want to opt out of the adware.

post-57213-0-01617000-1310709539.png


Post-Installation

This installer attempts to catch you after you've installed the program.

post-57213-0-76124000-1307244486.png


Distraction

Some installers may catch you by tricking you into clicking the wrong option. I'm not sure if these were designed to deceive, but I nearly clicked the wrong options for both installers, so I added them to the guide.

Here, my first reaction was to click Custom installation and uncheck the boxes below it.

It seems obvious, but the Custom installation is the first thing to grab your attention.

post-57213-0-63316500-1307244452.png

Once again, the Custom installation was the first thing to grab my attention.

post-57213-0-44441900-1310709537.png


Mandatory Installation

Recently, Foxit Reader didn't give you an option; You we're forced to install the adware if you wanted to install Foxit Reader. You may think that unchecking the two boxes was enough, but you have to read to understand there's no opting out.

Foxit Reader later updated their installer following several complaints, but this still stands as a solid example.

post-57213-0-38803100-1307244490.png


Websites Packaging Adware in Downloads

This is a new and worrying trend. Many websites, including the popular CNET, have started packaging several downloads in a custom web installer which includes adware, often without the permission of the original developers. The examples below are pretty obvious and easy to avoid, but it's a trend you should be aware of none the less.

CNET's download.com

post-57213-0-93104600-1323809688.png

Softonic.com

post-57213-0-45170600-1323809690.png

Tucows

post-57213-0-86509500-1328579848.png


Installers with Spyware

It was recently reported that DAEMON Tools, a popular CD-image mounting software, installed a spyware feature called MountSpace which reported every image you mounted to an online server. Even if you declined the feature, it was still active without your permission.

http://www.neowin.ne...ted-last-summer

Edited by Xinok
  • Like 7
Link to comment
https://www.neowin.net/forum/topic/1002608-guide-avoiding-adware-in-installers/
Share on other sites

Nice work Xinok, i recently installed Foxit 5 and like you mentioned unchecked the Ask toolbar boxes (as was the case in previous versions) then during install i was alerted to the AskToolbar checker making an outgoing connection. I knew something wasn`t right but carried on, i was like proper :angry: when the toolbar showed up in the browser.

Wasn`t a problem as i just re-imaged from a recent back up, but boy have i lost faith in Foxit. This is not something you should do to potential customers, fair enough if the option to not install is there (these companies pay big money to be included in installers, thus help with development hopefully!) but to downright trick people is out of order.

Needless to say i`m am trying out other pdf options...

Thanks for this. I script a lot of my installers in my custom XP source and one test run wound up with "Dealio Toolbar" installed. I was seeing red, half at myself for not having caught it and half for the marketroid bottom-feeders who buried that installer in there to begin with. I think it installed alongside a disc-burning tool but I'm not sure yet.

What ****es me off is that unattended installs offer no way that I know of to cut the worthlessware (hear me advertisers? You and everything you do are all worthless. Yes, you. And yes, everything, really. Go die.) out and just leave the core program itself. Makes it a lot harder to do up some effortless automated installs.

  • 3 weeks later...
  • 2 weeks later...
  • 4 months later...

So I recently came across an installer that was so bad, I felt the need to post it. I was looking for a desktop application for Facebook chat, so I wouldn't have to keep my web browser open. What resulted is the horror you see below.

Immediately after launching the installer, I'm greeted with the first box I must uncheck. Not only that, but if you read the text, it installs a mandatory background process which calls home.

post-57213-0-66413000-1321136836.png

Next, I had to choose custom installation and uncheck three boxes.

post-57213-0-35765700-1321136839.png

That isn't all! Next, I'm presented with this screen in which you must check Decline, not accept.

post-57213-0-67158200-1321136843.png

Now that I've avoided all that, I continue to install and launch the program. As if all the crap in the installer wasn't enough, they also implement an ad into the interface.

post-57213-0-01380200-1321136838.png

Okay... so I'll just login and see if this program was worth the trouble...

post-57213-0-17528800-1321136835.png

At this point, I stop, clear the sandbox, and check Facebook to make sure it hadn't made any changes to my account.

  • 3 weeks later...
  • 2 weeks later...
  • 1 year later...

Also avoid downloading anything from cnet :p

Lately, yes I'd have to agree, I hate that installer thing you need to have just to download something.

I always choose advanced when installing, to see what I have control over (in case of something I don't want installed) but even then, like OP pointed out you don't have a choice with some software

(usually I'll go find a rival product)

  • 10 months later...
  • 2 years later...

What I cannot understand is why some software developer has never created an app to circumvent these dirtbags. How difficult could it be to create something that would download from CNET into a safe containment (Virtualbox? Sandboxie?), allow one to open the archive, save the target file, and delete the malware? They can create Fraudfox to help juvies steal your credit card info, but not this!

16 minutes ago, Formido said:

What I cannot understand is why some software developer has never created an app to circumvent these dirtbags. How difficult could it be to create something that would download from CNET into a safe containment (Virtualbox? Sandboxie?), allow one to open the archive, save the target file, and delete the malware? They can create Fraudfox to help juvies steal your credit card info, but not this!

Dude this thread is so old, it is moldy. 

 

https://unchecky.com/

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • But the reality is it will work for people's needs, and they don't care about the technology that makes it. Clearly not everyone's needs, but that low end space where personal laptops were only used to type emails, watch content and browse websites, but they didn't want to do that on a small screen device. Heck, writing that out I can now see the connection and reason it'll do so well. Apple is about experience. If the experience is bad, they don't release it. Low end Windows laptop manufacturers up until this point have not taken that into consideration ever before, so slow laggy usage with brittle slimey plastic shells were common. I hope that the low end space at least creates better physical products that last a bit longer, and if Microsoft get their act together, they could also have a solid OS on such low end hardware that would actually make the experience work for what the hardware was intended for. The fact that the CPU is a "cellphone", sorry mobile phone processor is irrelevant. It's about the experience, and so far, that sounds quite solid.
    • Hello, Bonjour is Apple's implementation of a multicast-DNS service, which allows devices running Apple's software and/or hardware to find each other on your local network.  I believe the Windows version was last updated around 2010. If you do not need it, you can stop and disable the Bonjour service in the Services Control Manager (filename: SERVICES.MSC).  Once you have done that, the operating system will no longer attempt to load the service. Regards, Aryeh Goretsky  
    • This AMD RX 9070 16GB GPU that performs close to Nvidia 5070 is under $600 by Sayan Sen With the memory shortage that's prevalent nowadays, discounts are super-hard to get. As such we post good deals whenever they pop up. Recently, we covered a few great discounts on SSDs wherein you can get a 4TB TeamGroup NVMe PCIe Gen4 drive for just $400 thanks to a special coupon. If you want a faster product but don't need all that capacity, you can also opt for Samsung's 990 PRO 2TB that is on sale for its lowest price in over three months. Let's say though that you are on the hunt for a 1440p gaming card. In that case AMD's RX 9070 non-XT can help, and with its 16GB VRAM, you can also run AI models locally without worrying about bottlenecking (check out our recent 9070 GRE reviews for gaming and productivity to get an idea). The PowerColor Reaper variant of the RX 9070 is currently on sale for just $580 which is a very good price in the current state of affairs (purchase link under the specs table down below). The Reaper cooler on this 9070 uses a triple‑fan design with ring‑blade fans, paired with premium dual ball bearings to extend lifespan and reduce friction. "Intelligent" fan control allows the fans to remain idle at lower temperatures, only spinning up when the GPU is under load. A nickel‑plated copper base makes direct contact with both the GPU and memory modules, helping to spread heat evenly. PowerColor also applies Honeywell PTM7950 phase‑change thermal interface material (TIM), which fills microscopic gaps between the die and heatsink for more efficient thermal transfer. The fan shroud is shorter in height as the firm has made it such that it can be used in certain SFF (small form factor) cases. The technical specifications of the Reaper RX 9070 are given in the table below: Specification Value Stream Processors 3584 Units Video Memory 16GB GDDR6 Memory Speed 20.0 Gbps Memory Interface 256-bit Engine Clock Game Clock: up to 2070 MHz Boost Clock: up to 2520 MHz Bus Standard PCI Express 5.0 x16 Display Connectors 1 x HDMI 2.1b, 3 x DisplayPort 2.1a Maximum Resolution DisplayPort: 7680 × 4320 HDMI: 7680 × 4320 Board Dimensions 289mm × 111mm × 41mm 304mm × 127mm × 42mm (with bracket) Slot 2 Minimum System Power Requirement 600W Power Connectors Two 8-pin PCI Express Get the PowerColor Reaper RX 9070 at the links below (you get only a 90-day warranty on Woot): PowerColor Reaper Radeon RX 9070 16GB Graphics Card (RX9070 16G-A): $579.99 (Sold and Shipped by Amazon US) (Was: $700) PowerColor Reaper Radeon RX 9070 16GB Graphics Card (RX9070 16G-A): $559.99 (Sold and Shipped by Woot US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Are they marketed as an entry into astronomy or astrophotography? I do astrophotography. With big rigs, lots of computers, cables and headaches. I love it. And by learning this ridiculously complex hobby, I’ve learned about the objects I’m shooting. Astronomy followed from photography.
    • Microsoft confirms Recycle Bin bug across all versions of Windows by Usama Jawad A couple of days ago, we reported that the latest Patch Tuesday update has seemingly resulted in a lot of issues for many users, including OneDrive and Dropbox access problems, BitLocker recovery lockouts, and BSODs. Although Microsoft is yet to acknowledge these bugs, it has confirmed another, relatively smaller issue across all supported versions of Windows. In an update on its Windows Release Health Dashboard, Microsoft has confirmed that after installing June's Patch Tuesday update (KB5094126), you'll experience unexpected behavior when leveraging Recycle Bin. Basically, when you attempt to delete an item from the Recycle Bin, the confirm dialog will show you the internal file name of that content rather than the actual name. For example, the file may be named abc.png, but the confirm dialog will ask if you're sure that you want to permanently delete $Rxxxxx.png from the Recycle Bin. This is pretty much it for the scope of the bug itself; it just displays the wrong name in the confirm dialog. The correct name will be shown in the list view of the Recycle Bin and if you restore the file, it will return with the correct name as well. This issue affects pretty much all supported versions of Windows client and server, including: Client: Windows 11, version 26H1; Windows 11, version 25H2; Windows 11, version 24H2; Windows 11, version 23H2; Windows 10, version 22H2; Windows 10 Enterprise LTSC 2021; Windows 10 Enterprise LTSC 2019; Windows 10 Enterprise LTSB 2016 Server: Windows Server 2025; Windows Server 2022; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012 As things currently stand, Microsoft is working on a concrete solution that will be released in a "future" Windows update. It remains to be seen if the firm will wait till the next Patch Tuesday or roll out an out-of-band (OOB) fix. The good news is that commercial customers can deploy a workaround right now, but they will have to reach out to Microsoft Support for Business for additional details.
  • Recent Achievements

    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      578
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      72
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!