bsinstall.exe

Free Peers Inc.

The application bsinstall.exe, “BearShare Installer” by Free Peers has been detected as a potentially unwanted program by 15 anti-malware scanners. The program is a setup application that uses the Wise Installer installer.
Publisher:
Free Peers, Inc.  (signed by Free Peers Inc.)

Description:
BearShare Installer

Version:
4.6.0.54

MD5:
74c5d63a4fd5d58196fa9a1c7e22d175

SHA-1:
b98943f67e4bf77a7a8f75d7b028ffde11605833

SHA-256:
b76f0e698968f9bcc686af7446eb8e3a9aad628dd4a2fb6dfb625f502b9b1c55

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 10:47:08 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Whenu.Weathercast.G
218

Avira AntiVirus
Adware/WhenU.3269640
7.11.179.120

avast!
Win32:Whenu-I [PUP]
2014.9-160630

Bitdefender
Application.Whenu.Weathercast.G
1.0.20.910

Comodo Security
ApplicUnwnt
19846

Dr.Web
Adware.SaveNow
9.0.1.0182

ESET NOD32
Win32/Adware.SaveNow
10.10584

Fortinet FortiGate
Adware/SaveNow
6/30/2016

F-Secure
Application.Whenu.Weathercast
11.2016-30-06_5

G Data
Application.Whenu.Weathercast
16.6.24

IKARUS anti.virus
not-a-virus:AdWare.Win32.SaveNow
t3scan.1.7.8.0

Kaspersky
not-a-virus:AdWare.Win32.SaveNow
14.0.0.-23

MicroWorld eScan
Application.Whenu.Weathercast.G
17.0.0.546

Qihoo 360 Security
Win32/Virus.Adware.2bf
1.0.0.1015

Vba32 AntiVirus
Adware.SaveNow
3.12.26.3

File size:
3.1 MB (3,269,640 bytes)

Copyright:
Copyright (C) 2001 Free Peers, Inc.

File type:
Executable application (Win32 EXE)

Installer:
Wise Installer

Language:
English (United States)

Common path:
C:\users\{user}\downloads\bsinstall.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
1/15/2004 5:43:19 AM

Valid to:
1/19/2005 8:12:22 AM

Subject:
CN=Free Peers Inc., OU=Corporate, O=Free Peers Inc., L=Miami Beach, S=Florida, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
3DAA91

File PE Metadata
Compilation timestamp:
4/8/1999 1:24:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:PxJ3Sw9xsBVzTiZNtwcwH6uWrLXr/qscK2/9Ujlb:PL3ZqlGZMcwlM/AVkb

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, 78, 05, 00, 00, 53, 56, BE, 04, 01, 00, 00, 57, 8D, 85, 94, FD, FF, FF, 56, 33, DB, 50, 53, FF, 15, 34, 20, 40, 00, 8D, 85, 94, FD, FF, FF, 56, 50, 8D, 85, 94, FD, FF, FF, 50, FF, 15, 30, 20, 40, 00, 8B, 3D, 2C, 20, 40, 00, 53, 53, 6A, 03, 53, 6A, 01, 8D, 85, 94, FD, FF, FF, 68, 00, 00, 00, 80, 50, FF, D7, 83, F8, FF, 89, 45, FC, 0F, 84, 7B, 01, 00, 00, 8D, 85, 90, FC, FF, FF, 50, 56, FF, 15, 28, 20, 40, 00, 8D, 85, 98, FE, FF, FF, 50, 53, 8D, 85, 90, FC, FF, FF, 68, 10, 30, 40, 00, 50...
 
[+]

Entropy:
7.9985

Packer / compiler:
Wise Installer Stub

Code size:
512 Bytes (512 bytes)

Remove bsinstall.exe - Powered by Reason Core Security