allentech.net

Limited Time - 25% Off!
Find your geek at
Slaphappy Geeks!
SlapHappyGeeks! SlapHappyGeeks!

Parasite: BDE

This record last updated Tue Sep 20 2005 00:34:14

PLEASE NOTE: Due to the overwhelming extent of this problem and the unbelievable volume of email we have received, we regret that we cannot respond to questions about browser parasites at this time. If you have attempted to contact us about this parasite please accept our apology for not responding. "Thank you's" are always appreciated ;-)

Description

A player for ‘rich media’ advertising. Similar to Onflow.

Also known as

Brilliant Digital (company name), B3D Projector (application name).

Distribution

Apart from being downloadable from Brilliant’s own legitimate-looking site, it is also stealth-installed by newer versions of KaZaA and other free applications.

What it does

Advertising

Minor. It allows sites to use ‘rich’ (ie. annoying) advertising with 3D effects, sound, and so on. However, it does not add its own advertising to other sites.

Privacy violation

None known.

Security issues

Yes. The Projector downloads new components and updates silently. Code-signing seems to be used, to ensure only Brilliant Digital can write code to be executed by the software.

Stability problems

Some reports of crashes and slowdown whilst using the software. This is not wholly surprising: the Projector has 3D functions, which are always liable to cause problems with dodgy graphics cards and driver versions.

Removal

You can use ‘Add/Remove Programs’ for ‘B3d Projector’. It does leaves a lot of files behind, though, and an unholy mess in the registry. It is perhaps possible that a site could re-install BDE using some of the leftover stubs.

You will want to delete the directory ‘BDE’ inside your Windows directory, and the files ‘bdeinstall.exe’, ‘bdeinsta2.dll’, ‘bdefdi.dll’, ‘bdedata2.dll’, ‘bdedownloader.dll’, ‘bdeverify.dll’, ‘bdesecureinstall.exe’ and ‘bdesecureinstall.cab’ inside your System directory (which is ‘WINDOWS\SYSTEM’ under Windows 95/98/Me, and ‘WINNT\System32’ under Windows NT/2000/XP).

Next, run regedit and remove the ‘b3dUpdate’ value from key ‘Software\Microsoft\Windows\CurrentVersion\Run\’ in HKEY_LOCAL_MACHINE. You can also remove ‘Software\ZUpdate’, and in HKEY_CLASSES_ROOT the keys: ‘b3d’, ‘b3ds’, ‘s3d_auto_file’, ‘b3dini_auto_file’, ‘BDEPLAYER.BDEPlayerCtrl[.1]’, ‘BDESmartInstaller.BDESmartInstallerCtrl[.1]’, ‘.b3dini’.

Links

  • BrilliantDigital site (warning: if you go there with BDE installed it will try to install more components and updates automatically).
  • The CNet article which was the first to outline AltNet, an application that may be installed by BDE.

* Parasite information and detection script by Andrew Clover - www.doxdesk.com, used with permission.

For more information about Scumware, Spyware and Parasites, their sources and their cure, visit our About Parasites page and related Tech Links.

Visit our new services portal at Allen One for a completely new parasite database format, comming November 2005!

Top