Does anyone here know how to block spyware?...... especially OpenCandy

True Colors

New member
Local time
12:02 PM
Messages
16
I just imaged a new drive on my PC. I downloaded a lot of the tools that I have been using for years.... VLC player, MPC-HC, Media Info, handbrake, imgburn, stream transport, etc. etc. Most of this stuff is freeware/shareware type stuff.

To my surprise, there is a new form of spyware which seems be running rampant everywhere called "OpenCandy." It installs itself on your computer without your knowledge..... sometimes it even comes embedded into software without any mention that it is there.

Of course, this p1sses me off to no end.

I have no problem with software developers including extraware as long as they are open about it. For example, virtually everyone now offers to install some sort of special toolbar in your browser. It is up to you to make a conscious decision if you want it or not.

I have removed OpenCandy from my computer multiple times already by using MalwareBytes. However, I am looking for a way to take this a step further. How can I stop OpenCandy from ever even installing on my computer in the first place?

I saw the comments below....... I am not knowledgeable enough in this area, so can someone please educate me on whether or not this will work......or if you have any other recommendations that you can make about what can be done.

Thanks,

TC

Controversial Advertising Program Now Being Embedded in More Software

There are 2 things one should do to install a OpenCandy program.

1. Block OpenCandy servers in the windows host file.

You do not want OpenCandy to spy on you.

Click on your start button, go to programs, accessories, right click on notepad and run as administrator.

Click on file, open.
Go to C:\Windows\System32\drivers\etc
type *.* and click on host

Add this to the host file

127.0.0.1 tracking.opencandy.com.s3.amazonaws.com
127.0.0.1 media.opencandy.com
127.0.0.1 cdn.opencandy.com
127.0.0.1 tracking.opencandy.com
127.0.0.1 api.opencandy.com

And click save.

2. Now go to the command line and enter:

"ProgamName /NOCANDY"

The program will now install with no chance of installing third party software & no chance of spying on you by communicating with the OpenCandy servers.
 

My Computer My Computer

Computer Manufacturer/Model Number
Dell
OS
Windows 7 professional 64 bit
CPU
Intel E8400
Memory
8 gig DDR2
Hard Drives
320 gig Western Digital
I have Malwarebytes Premium (real-time) and have it set to treat PUPs as malware.
It has auto blocked and quarantined OpenCandy in installers for me.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
CPU
AMD Athlon II x4 620
Motherboard
Gigabyte GA-MA785G-UD3H
Memory
6GB GSkill DDR2 800
Graphics Card(s)
AMD 4670 GPU + AMD 4200 IGP
Sound Card
on board Realtek ALC889A
Monitor(s) Displays
RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor
Screen Resolution
1680 x 1050
Hard Drives
OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ...
PSU
Corsair 500 W
Case
Rosewill mid tower
Cooling
CM 90mm rifle
Keyboard
Gyration wireless, Logitech wireless, Dell USB wired
Mouse
Gyration wireless, Logitech wireless, V7 USB wired
Internet Speed
Spectrum - 100Mbps D / 10Mbps U
Antivirus
Avast, MBAM3, EMET, WinPatrol
Browser
Pale Moon, Firefox, IE
Other Info
2 multi-boot PC's
Mainly HTPC/Office/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.

Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.

Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner.

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 10 Pro
CPU
AMD Ryzen 5 2400G Processor with Radeon RX Vega 11 Graphics
Motherboard
ASRock X470 Master SLI/AC AM4 AMD Promontory X470 SATA 6Gb/s
Memory
G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-Pin DDR4 SDRAM D
Graphics Card(s)
2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Sound Card
Motherboard Built in
Monitor(s) Displays
Acer R240HY bidx 23.8-Inch IPS HDMI DVI VGA (1920 x 1080) Wi
Screen Resolution
1920 x 1080
Hard Drives
1TB Sandisk SSD PLUS (Main drive)
500 GB Seagate 7200 RPM (Games)
500 GB Western Digital 7200 RPM (Virtual Machines)
PSU
CORSAIR TX Series TX650M 650W 80+ Gold Modular Power Supply
Case
CORSAIR CARBIDE SPEC-02 Mid-Tower Gaming Case, Red LED Fan
Cooling
220mm, two 120mm, and four 60mm fans
Keyboard
Wired Dell keyboard
Mouse
Wireless Logitech mouse
Internet Speed
250mb down, 30mb up
Antivirus
Panda Cloud Antivirus
Browser
Chrome-ish x64
Other Info
Your awesome for reading this.
this was suggested to me by GREGROCKER, I bet its gonaa solve your problem
SUPERantispyware
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
toshiba
OS
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
CPU
2.4 core i 3
Motherboard
TOSHIBA PWWAA
Memory
2.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel(R) HD Graphics
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
465.76 GB
Internet Speed
4mbps
Antivirus
baidu
Browser
chrome
Block Open Candy like this

Please read this post:

http://www.sevenforums.com/system-s...ell-means-your-system-danger.html#post2774859

It explains how to block Open Candy when the installer is bundled with freeware program installers or set up files. The first method works well - the second method is for more advanced users and registry entries created will need to be excluded from any auto registry cleaners (if installed).

Also if the Open Candy executable file name shown in the above post is changed it will need to be added via either or both methods in the above article.

Hosts file is all good but will not prevent installation.
 
Last edited:

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Check downoads before you run them

Also see:

How to check downloads

Explains how to scan a file either before you've actually downloaded it or before you attempt to run it.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
The main thing you can do is watch your installs like a hawk so that nothing sneaks in hidden in tricky checkbox choices or the License Agreement of freeware or other programs or apps.

If something gets in and is listed in your Control Panel>Programs or your browsers' Add-Ons under Extensions or Search, uninstall it in both places and run a full MBAM and SuperAntiSpyware scan. Decline their trial when you first install but later if you get regularly infected I would buy MBAM's Real Time protection at $29 for life, which will block all such infection.
 
From what I've found, some installers are installing OpenCandy BEFORE any installation Window is displayed.
So, there is no chance to opt-out BEFORE the installation begins.
That's what I'm seeing, as MBAM quarantines the file before the I see any Window...
I've seen this recently with Foxit Reader, ImgBurn, and CDBurnerXP.
With ImgBurn, MBAM quarantined the installation file, so ImgBurn did not install.
With the other two, the OpenCandy file was quarantined, and the installation proceeded.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
CPU
AMD Athlon II x4 620
Motherboard
Gigabyte GA-MA785G-UD3H
Memory
6GB GSkill DDR2 800
Graphics Card(s)
AMD 4670 GPU + AMD 4200 IGP
Sound Card
on board Realtek ALC889A
Monitor(s) Displays
RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor
Screen Resolution
1680 x 1050
Hard Drives
OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ...
PSU
Corsair 500 W
Case
Rosewill mid tower
Cooling
CM 90mm rifle
Keyboard
Gyration wireless, Logitech wireless, Dell USB wired
Mouse
Gyration wireless, Logitech wireless, V7 USB wired
Internet Speed
Spectrum - 100Mbps D / 10Mbps U
Antivirus
Avast, MBAM3, EMET, WinPatrol
Browser
Pale Moon, Firefox, IE
Other Info
2 multi-boot PC's
Mainly HTPC/Office/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.

Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.

Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner.
From what I've found, some installers are installing OpenCandy BEFORE any installation Window is displayed.


That's just unforgivable!! If you don't even have an "opt out", then it's plain and simply an unmitigated 'Hijack' of your system ...
e073.gif
:mad:
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Yeah, unfortunately I have seen those as well. Usually virus total will flag it as a bad installer in that case.

I upload everything I download to virus total in a virtual machine before running it on my own pc.

Crazy, I know. But I have never gotten infected yet. As far as I know anyway.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 10 Pro
CPU
AMD Ryzen 5 2400G Processor with Radeon RX Vega 11 Graphics
Motherboard
ASRock X470 Master SLI/AC AM4 AMD Promontory X470 SATA 6Gb/s
Memory
G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-Pin DDR4 SDRAM D
Graphics Card(s)
2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Sound Card
Motherboard Built in
Monitor(s) Displays
Acer R240HY bidx 23.8-Inch IPS HDMI DVI VGA (1920 x 1080) Wi
Screen Resolution
1920 x 1080
Hard Drives
1TB Sandisk SSD PLUS (Main drive)
500 GB Seagate 7200 RPM (Games)
500 GB Western Digital 7200 RPM (Virtual Machines)
PSU
CORSAIR TX Series TX650M 650W 80+ Gold Modular Power Supply
Case
CORSAIR CARBIDE SPEC-02 Mid-Tower Gaming Case, Red LED Fan
Cooling
220mm, two 120mm, and four 60mm fans
Keyboard
Wired Dell keyboard
Mouse
Wireless Logitech mouse
Internet Speed
250mb down, 30mb up
Antivirus
Panda Cloud Antivirus
Browser
Chrome-ish x64
Other Info
Your awesome for reading this.
The best thing to do find another download site which you haven't posted where you download from :(

The file you posted blocks outward communication not installing opencandy or anything else,

Superantispyware and mabm I doubt would block the install either,
Reading the terms of a download would most likely show the extras,
Clicking on download usually means you accepted those terms,
Cheers.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
I have removed OpenCandy from my computer multiple times already by using MalwareBytes. However, I am looking for a way to take this a step further. How can I stop OpenCandy from ever even installing on my computer in the first place?

Controversial Advertising Program Now Being Embedded in More Software

From the article you linked:

They also claim that OC installs nothing permanently on your computer should you choose not to accept any OC download recommendations.

So, how is it you're always needing to uninstall the thing?
 

My Computer My Computer

Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
Open Candy Installs

I have removed OpenCandy from my computer multiple times already by using MalwareBytes. However, I am looking for a way to take this a step further. How can I stop OpenCandy from ever even installing on my computer in the first place?

Controversial Advertising Program Now Being Embedded in More Software

From the article you linked:

They also claim that OC installs nothing permanently on your computer should you choose not to accept any OC download recommendations.

So, how is it you're always needing to uninstall the thing?


Hi,

It seems that OC is currently being bundled with some software installers with no chance to opt out of installation anywhere. One example is GOM Media Player (I tried it). I've seen other software do the same thing with other toolbars, like Photofiltre - that will install Ask toolbar whether you like it or not!
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
I have Malwarebytes Premium (real-time) and have it set to treat PUPs as malware.
It has auto blocked and quarantined OpenCandy in installers for me.

I run Malwarebytes antimaleware pro (Paid version ) real time protection too and it stops it from being installed to
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Compac
OS
Microsoft Windows 7 Ultimate 32-bit 7601
CPU
Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz
Motherboard
MSI Boston
Memory
4.00 GB
Graphics Card(s)
(1) VNC Mirror Driver (2) Intel(R) G33/G31 Express Chipset
Sound Card
Disabled
Monitor(s) Displays
Headless
Screen Resolution
1280 x 960 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST3320820AS ATA Device
Keyboard
Headless
Mouse
Headless
Antivirus
Malwarebytes pro
Other Info
Also
Windows 8.1 Laptop and Desktop both Acer
Back
Top