Virus in BSPlayer ?

Hey all…

Hope someone can help me with an answer…

I just installed the new version of BS-Player Free edition 2.33
http://bsplayer.com

Now my Avast Home edition comes up with an Virus detection - installdata358.tmp.exe infected - Win32:Trojan-gen {Other}

To explain the installation…

I installed BS-Player free edition, Deselected everything from the install except the program itself and the shortcut to menu start… at the auto codecs download/install i cancelled. an thats it…
Avast detected a Virus in C:\Windows\System32\installdata358.tmp.exe…

i can see installdata358.tmp.exe in the task manager, terminated it an found the file in system32, the file is hidden… (nothing happens when i click the .exe, other than it places itself in the taskmanager again…

Does anyone know what the file does, ?

Hope someone can give me an answer…

thanks allot.

BSPlayer is adware:

http://news.softpedia.com/news/Safe-To-Install-Version-Of-BS-Player-Is-Out-And-About-92721.shtml

yea so far so good, but i deselected all the files which should make it a clean media player…

anyways Avast detects it as Win32:Trojan-gen ? ? that doesn’t seem like ad-aware more like a virus ? or am i wrong ?

It’s a fairly generic detection.

You need to report the detection to avast! if you think it’s wrong.

There should be a option to do this at the bottom right of the detection screen, I think, or follow the advice here:

http://forum.avast.com/index.php?board=2;action=display;threadid=7779

C:\Windows\System32\installdata358.tmp.exe looks quite fishy… it is autorunned, contains encrypted data, refers to C:\Log.log… we’ll do further analysis…

Maxx_original…

where did u get the installdata358.tmp.exe from ? the BS.Player installation ?
i posted on BS.Players Official Forum, and send them the file to, but they deny that it should come from their installer…

this is their reply

Ok, you sent us the infected file itself and not the BS.Player installation file (btw. our antivirus reports it as WORM/Kolabc.fat), but the problem is that BS.Player does not have anything to do with this infected file. Like stated before - BS.Player does not write anything in System32 folder.

BS.Player installation does not include any viruses, worms, trojans…

Your entire system may be infected (but not because of BS.Player) and now with every installation, virus copies itself over and over again. I suggest you run full computer antivirus scan and delete/quarantine all infected files and then install BS.Player.

the file from european mirror is hijacked by a virus… its size is bigger than the file downloaded from US mirror… also the original file is Nullsoft installer, the hijacked is CAB self-extract with the virus and the original installer included…

ok thanks alot…

Can u tell me exactly what the virus does ?

I deleted the file as soon as i noticed it, running comodo firewall and defense+ (HIPS) could see the file tried to do some DNS lookups or something like that…

it’s a spying trojan most probably… anyway - regarding the non-detection by some engines there could be “few” affected users… let’s see what will the BSPlayer developers do…

yea, was only because of HIPS protection that i noticed the file so.
(an short after that avast detected it to)

But anyways thanks for the support, and help on the BS.Player forum (don’t think they belived me)
I’m reinstalling my two systems with the virus on as we speak…

Ill write back when i am up an running again…

Thanks for freaking great service Avast…
Special thanks to Maxx_original

Ps.
Just checked the post at BS.Player forum, they say its fixed now.

yes… fixed and the official note is available…

http://www.bsplayer.org/forum/viewtopic.php?p=42275&sid=1e9e4917d56f056dc8948c2f5dd936d7&BSPLAYER=bbefb59fae434a5d4c31aea665630fb5

As I’m sure you’ve noticed, these changes to your system are not mandatory and, therefore, BS.Player cannot be considered spyware but, certainly, neither can it be said to be 100% clean. And so, although [b]marked as adware[/b], BS.Player is once again safe to install and back on Softpedia.

By Stefan Fintea, Software News Editor

2nd of September 2008, 20:41 GMT

NO Adware bundled in BS.Player FREE anymore!

Mat2000, BSPlayer team member

PostPosted: Mon Aug 11, 2008 7:28 pm

I don’t see a problem here Frank. There is an option to not install BS.Player ControlBar … Even if you do i still don’t consider it adware.

Im up an running again on a reinstalled system…

once again thanks for the great service Avast / Maxx_original
(one thing is for sure… im sticking with avast.)

Nothing to do with you or me. Softpedia marks it adware because “it offers to install a third-party application”; BSPlayer says there’s no adware bundled with the player.

I thought avast! might be detecting the toolbar add-on, which is why I mentioned it. If you object to the adware description, you’ll really need to take it up with Softpedia, or ask BSPlayer to clarify whether they mean there is no adware bundled with the player, or there is adware bundled with the player, but it’s not a mandatory install.

I know i know, i just hate how everything is “adware” for them.
They had CCleaner listed as adware aswell Frank, apparently anything that includes a toolbar(even if you can opt-out in the installation) is considered adware by them. It’s just not fair IMHO. By that logic Nero and a alot of other good and trusted programs are also adware. What a load of crap.

EDIT: Fixed a typo …

http://www.softpedia.com/get/CD-DVD-Tools/Data-CD-DVD-Burning/Nero-8.shtml

Reasons why this program is marked as adware:

· Adware included … Ask Toolbar… However you can uncheck this at installation.
· The software is trying to change your Default Search Engine.

http://www.softpedia.com/get/Security/Firewall/Comodo-Personal-Firewall.shtml

Reasons why this program is marked as adware:

· (1) Attempts to change the homepage for web browsers installed on the system |
· (2) Attempts to change the default search engine for web browsers installed on the system |
· (3) Offers to download or install software or components (such as browser toolbars) that the program does not require to fully function

http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/Spyware-Terminator.shtml

Reasons why this program is marked as adware:

· ADWARE INCLUDED - you can, however, UNCHECK that ADWARE at installation: Web Security Guard Toolbar

http://www.softpedia.com/get/Internet/Other-Internet-Related/IE7pro.shtml

Reasons why this program is marked as adware:

· The software is trying to change your default homepage. However, you can uncheck this option during the program’s installation process.

http://forum.piriform.com/lofiversion/index.php/t4157.html

See what i mean ?

EDIT: Added a few more examples …

EDIT2: Sorry for hijacking your thread Mr_llama but i had to get this off my chest, been bothering me for a long time now. Wonder how many regular users steered clear of the above programs because they saw them listed as adware on the softpedia page. ::slight_smile:

I just got an account on avast, and here I see something about this virus TODAY. It seems like you can get this thing from more than what i got it from… I got it from a popup on myspace.com!

This sucks, right now Ive got very low protection, my system restore is corrupt and my firewall settings have been remotely tampered with. I was attacked by this thing you are talking about but was also attacked by another thing that was like AIDS to my computer called “WIN32.Spybot.Worm” that my norton antivirus decided to just remove repetitively.

This piece of trash kept coming back like fleas on my dog, and went straight to c:\ProgramFiles\Symantec\ and got blocked by norton right there first time and killed. an hour later it showed its ugly face again and took a different approach which did damage…
c:\WINDOWS\system32\systemrestore_settings\I01779G3%4692 and did something to that. now I cant open system restore!

Please post a new topic.