📜 ⬆️ ⬇️

Following malware, Punto (Yandex) also decided to break the interface.

In recent days, probably, everyone using the Punto Switcher (starting with some, not very old version) and having access to the Internet, received the following message, as in the screenshot:
Punto Switcher: update available.

What is this criminal, the reader will ask?
The essence of the situation is suggested by the word “all” in the first sentence. “All” means “ even those who were not going to recognize and update ”. The illustration is explained in the following screenshot:


It shows that the only setting in the interface that indicates "Do not check for updates" is installed. But, following Google Chrome (or not, viruses did that first, then malware, and only after them Google Chrome) more than a year ago, and, after some puzzled pause, Firefox (in July 2012), the programs decide that they know better the needs of stupid users who need to install updates without any warning. But at the same time, they honestly do not say anything in the interface, do not mislead readers, and in the news warn that they will be updated without demand.

Yandex, the reader will say, gets softer: it only warns about the update. But at the same time, he himself is breaking his own interface: it is unlikely that the “Check for Updates” setting in the checked checkbox was unlikely to mean the opposite, was it “check for updates” (tested on 3 computers), or am I lagging behind life? Therefore, I assume that the messages received and those who have the checkbox installed, that is all.

(For more informational content: version 3.2.8 wants to be installed via the update button; the version that behaves this way - 3.2.6 of 10/21/2011 - or the installer has quietly entered the system in other ways (unlikely), or even then, almost a year ago, in version 3.2.6, they installed such an opportunity.) For information, I don’t have any software and bars from Yandex (except for one Punto Switcher) on any of the computers, as well as other caring guards, and Kaspersky Rescue checks all computers Disk with databases from September 22 held just yesterday.)
')
UPD : real specialists appeared - x0rHamster unearthed the reason:
# September 28 07:08
Taaaaaa. I dug a little before work, but I was satisfied with the result (because I didn’t check it more carefully). Judging by the logs from AppData, Punto was completely spit out that I had checked the “Check for updates” checkbox right from the time of installation - it checked and checked. This happened all through COM-calls to BITS (in fact, this output is taken from dllhost.exe, which appeared during updates, and morning-inattentive reading of logs), through which Windows Update and a couple of hellish ones are put (though it is for this reason that it was made), and it works through svchost.exe, which is probably enabled in firewalls (otherwise Windows itself will cough nervously). I learned how to manually trigger the check for updates, because they did not invent the a-la Fx buttons - reset the last and next check in the registry and restart the computer. And finally, he deleted the folder with the unambiguous name Updater from the Punto program directory - the message for the next reboot did not appear, the logs were not updated, the parameters in the registry did not change either (as they were zeros, they remained). So far, so, although my research is more like medieval doctors with a lobotomy.

Source: https://habr.com/ru/post/152509/


All Articles