Industry


Ads by TechWords

See your link here


Michael Horowitz's picture
Michael Horowitz

Defensive Computing

IObit accused of stealing from Malwarebytes

Marcin Kleczynski is the  President and CEO of Malwarebytes, the company behind the popular anti-malware program. In a forum posting on their website, Kleczynski today accused IObit of stealing their software.

He writes:

"Malwarebytes has recently uncovered evidence that a company called IOBit based in China is stealing and incorporating our proprietary database and intellectual property into their software. We know this will sound hard to believe, because it was hard for us to believe at first too. But after an in-depth investigation, we became convinced it was true ... They are using both our database and our database format exactly."

In a later comment on the forum posting, Doug Swanson, Malwarebytes VP of Development, wrote:

"We conducted this investigation thoroughly over a period of weeks until we were 100% sure of everything we wrote above. These were not statements we made lightly."

Their proof is phony malware. Again quoting Kleczynski:

"The final confirmation of IOBit's theft occurred when we added fake definitions to our database for a fake rogue application ... This "malware" does not actually exist: we made it up. We even manufactured fake files to match the fake definitions. Within two weeks IOBit was detecting these fake files under almost exactly these fake names."

As further proof Malwarebytes offers a safe, non-malicious executable program, dummy.exe, that was tweaked to match a signature in their database.

I downloaded dummy.exe and scanned it at VirusTotal which gave it a clean bill of health. I also scanned it with MBAM and, as shown below, it was flagged it as Don't.Steal.Our.Software.A.

 

MBAM detecting dummy.exe as malware

 

Lo and behold, IObit Security 360 also detects it as malware, even using the same phony "Don't.Steal.Our.Software.A" name. You can see this in a screen shot posted by Malwarebytes.

And it gets worse.

Kleczynski concludes his forum posting with:

"During the course of our investigation, we uncovered additional evidence that IOBit may have stolen the proprietary databases of other security vendors as well. We are in the process of contacting these vendors."

Over at download.com, CNET editors gave IObit Security 360 version 1.10 five stars out of five. Ironically, they gave Malwarebytes Anti-Malware only 4.5 stars. Here's hoping that CNET, Majorgeeks and other software repositories remove IObit Security 360 from their systems. 

Web of Trust (WOT) currently rates the IObit website positively. WOT, however, does not have a central ruler, their ratings come from their customers, many of whom have started  commenting on the ethical issues involving IObit. The website rating will probably fall shortly.

A commenter at CNET pointed out something else interesting. The web page for IObit Security 360 claims the software was "featured" at places that have no information about it at all. Sure enough, a search for IObit at Forbes.com, bizjournals.com, reuters.com and hoovers.com came up empty at each site.

At this point, I wouldn't touch any software from IObit with a ten foot pole. But, that's just me.



NOTE: The forum posting is duplicated on the Malwarebytes blog posting:  IOBit Steals Malwarebytes’ Intellectual Property.

Update November 15, 2009: Iobit initialy denied the charge from MalwareBytes but their denial seems to have been removed from their website. MalwareBytes replied that IOBit’s Denial of Theft Unconvincing.

 

 

What People Are Saying

IObit may have stolen the malware database of others

Malwarebytes is also claiming that IObit may have stolen the malware database of other security vendors as well. More info at: http://malwarebytes.besttechie.net/2009/11/03/iobits-denial-of-theft-unconvincing

IoBit is the chinese sby

The chinese government has paid them millions of money as prize for IoBit as Iobit help them to control so many PCs in the west.

I'm fairly shocked that no

I'm fairly shocked that no one else is concerned that basically anyone, at any time, can accuse someone of "stealing" and the internet convicts them as guilty with no more than the accuser's word!

Think about the ramifications of this for a minute - I could easily say that I wrote Michael's article, not him. Post it on my blog with a few bits of "evidence" and bam! Michael Horowitz is guilty of plagurism! We can drag it out for years in court, but the immediate damage is staggering.

If IObit did the crime, then they should pay the price. But we can't allow bold accusations to ruin ANYONE's reputation without due process. For those of you bashing the Chinese, shame on you for overlooking one of our most fundamentally American rights - the presumption of innocence until guilt is proven.

IoBit is controled the China goverment.

I have to tell all of you the truth all I know.

This company is invested by some guy from the chinese "FBI". they want to have as many netbot in the west as they can. They already made millions of users and controled these computers in the west. The can do any thing when they want.

This is the strategy from their leader. they made all their products free and spread them in the west.

There are many popular "chinese" product in download.com from china. from their website, you can never know where they come from.

Interesting? If you want to know more, I can tell you more.

IoBit deleted all the comments

Why they deleted all the comments in their blog?
Why they stop others to "help" them in their forums?

They are guilty and they know they steal many things.

I never how cheeky one chinese company can be, but now I finally know that!

IoBit products

Apparently Gizmo's has removed IoBit products from it's recommendation lists, MajorGeeks on the other hand is dragging it's feet on removing them from it's list (other than 360 appears to be blocked). It's time to remove all IoBit products from all the download sites, and yes I mean all of their products not just a selected one. The evidence appears to be very compelling for this drastic an action to be taken. IoBits response to this whole thing on it's forum, IMHO was a feeble tap dance attempt, and not believable.

Thanks
Wildman

Reddit

Let people know about this:
http://www.reddit.com/r/WTF/comments/a0zuh/wtf_iobit_stealing_malwarebytes_database/

1. Of the commenters who

1. Of the commenters who cry out about IObit's alleged criminal act of stealing code and data, how many steal by downloading copyrighted music, DVDs, videos, etc. or steal by using pirated software, copying original software, etc.?

2. For the commenter who asks us to "think reasonably now," it is incredibly strange that Malwarebytes starts with a forum warning rather than immediately filing a lawsuit. If there is wrongdoing and a truly colorable case, no self-respecting business would phart around before suing the bastirds; it's the American way.

3. One understandable position is the one taken by the "poor old man" who commented, "free and powerful" is good and saves the poor a few pennies. In any event, Sinophobia is uncalled for because the Chinese just happen to make the best knockoffs, copies, etc. Other countries can't compete--that's not to say Chinese copies are good copies; just that their copies are the best out there and they have cornered the market. Go buy an Australian knockoff if it'll make one feel better, mate.

4. BTW if you judge authenticity by grammar and correct writing, only 2 of the 7 posts prior to this post are genuine and not fabricated.

5. IMHO IObit has a product that might be remarkably similar to Malwarebytes, but as a layman I have not seen it do the same thing that the original would under specified circumstances. Kleczynski should stop bellyaching, file suit and and let a jury decide already.

"1. Of the commenters who

"1. Of the commenters who cry out about IObit's alleged criminal act of stealing code and data, how many steal by downloading copyrighted music, DVDs, videos, etc. or steal by using pirated software, copying original software, etc.?"

Of the top anti-malware companies in the world, how many steal by downloading copyrighted music, DVDs, videos, etc. or steal by using pirated software, copying original software, etc.? None but IObit

2. "For the commenter who asks us to "think reasonably now," it is incredibly strange that Malwarebytes starts with a forum warning rather than immediately filing a lawsuit."

They are filing a lawsuit you dummy. The reason they posted this warning to users was to tell them that you guys were software pirates, and that we should refrain from using their stolen software. Telling people directly about this issue is the most effective way to get the info across.

3. "Other countries can't compete--that's not to say Chinese copies are good copies; just that their copies are the best out there and they have cornered the market. Go buy an Australian knockoff if it'll make one feel better, mate."

And that somehow justifies a major company stealing software?

4. "BTW if you judge authenticity by grammar and correct writing, only 2 of the 7 posts prior to this post are genuine and not fabricated."

No, we judge authenticity by testable evidence, something that any user, and malwarebytes can reproduce with little effort.

5. "IMHO IObit has a product that might be remarkably similar to Malwarebytes, but as a layman I have not seen it do the same thing that the original would under specified circumstances. Kleczynski should stop bellyaching, file suit and and let a jury decide already."

His bellyaching is very effective, and the news has spread across the web, and many people are now taking the time in removing this illegal software from their systems. The evidence is overwhelming, and their is no denying that malwarebyte's code is being stolen.

Refund my money, IoBit

The IoBit guys, please refund my money, I should never use any of your product again.

You are a stupid chinese thief! I would never buy any thing from a thief.