This is an old revision of the document!

OpenCandy

WinSCP uses OpenCandy advertising module in its installation program.

OpenCandy is advertising application. It is similar to Google AdSense, except it displays advertisements in installation program instead of websites. These advertisements promote another software packages. The advertisements are selected by providers of software being installed (in case of WinSCP it means WinSCP developers). When user installing a software (WinSCP) chooses to install promoted package, revenue is generated and shared between OpenCandy and software providers (WinSCP developers).

Advertisement

s

HACKED BY DONTLAUGHMEPLEASE

What does an OpenCandy recommendation look like?

Below it an example of OpenCandy recommendation screen in WinSCP installation program. Use the Install … button (or similar) to choose to install the recommended application. Use the Do not install … button (or similar) to continue installing WinSCP without installing the recommended application.

Adware Alerts

Occasionally you may receive alert from your antivirus or other security application regarding the WinSCP installer/OpenCandy.

Most notably, Microsoft Windows Defender has started recently to trigger WinSCP installer. See corresponding entry on Adware:Win32/OpenCandy on Microsoft security site. The article correctly describes OpenCandy functionality in a similar way as this page. And correspondingly it states that security threat from OpenCandy is low.

Last modified: by 202.162.10.9