bsplayer-setup.exe

The application bsplayer-setup.exe has been detected as a potentially unwanted program by 13 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.slunecnice.cz and multiple other hosts.
MD5:
454cde5bfbea744ec7fc418bb5c816d5

SHA-1:
bf2c09b95f414d54028bdea70676b2601a8a62e9

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/18/2024 12:44:25 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Conduit
4.0.3.1551

Bkav FE
W32.Clod00e.Trojan
1.3.0.4959

Dr.Web
Adware.Conduit.6
9.0.1.0121

ESET NOD32
9.9614

K7 AntiVirus
Trojan
13.176.11595

Malwarebytes
PUP.Optional.Conduit
v2015.05.01.11

McAfee
Artemis!454CDE5BFBEA
5600.6779

NANO AntiVirus
Trojan.Win32.Conduit.cmhvsi
0.28.0.58720

Panda Antivirus
PUP/Conduit.A
15.05.01.11

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
23.00.65.15429

Trend Micro House Call
TROJ_GEN.F47V1111
7.2.121

Trend Micro
PAK_Generic.005
10.465.01

VIPRE Antivirus
Conduit
27868

File size:
7.2 MB (7,533,546 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\documents and settings\user\plocha\bsplayer-setup.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:4iHom1IOESuF2t2ZbUeoipa9kG+irJ7cs:4itUSuF+2owsWGf79

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file bsplayer-setup.exe has been seen being distributed by the following 2 URLs.

http://www.slunecnice.cz/sw/bsplayer/stahnout/.../?m=abf448395350c8ef14d107a45d41ba40&t=52ed1f8f

Remove bsplayer-setup.exe - Powered by Reason Core Security