Jump to content
Beenthere

Potplayer adware FusionCore

Recommended Posts

Posted (edited)

Hi

Potplayer autoupdated itself few days ago.

I now did a scan with Malwarebytes and it found this (it was in temp folder but I transferred it to another folder so i can copy on a virtual machine)

image.thumb.png.3ce5091c7812d2c04edbf7dfff5a6f78.png

https://www.virustotal.com/gui/file/07834aec356f5ae44357b41d231f19345e315b629c7767b6d23f8e4a0cb60f4f/detection

I did a full scan with Malwarebytes, it found nothing.

Then, tried installing the above mentioned .exe (thought that the adware skipped my system because it was an autoupdate), on a virtual machine and there was no adware in the installer for checking/unchecking except for the last step shown below

image.png.9fec4f4b49a768e31caf3c86464f5e56.png

 

Now this OpenCodec has been with PotPlayer for a while, and I don't think that's the culprit.

I read this but while installing I wasn't asked for McAfee webadvisor or any other similar thing.

I did a fullscan on the virtual machine, Malwarebytes found nothing.

 

Edited by Beenthere

Share this post


Link to post
Share on other sites

Hi,

My MalwareBytes client also just warned me about this same thing too. I've been using PotPlayer for years and first time getting any issues from it. My PotPlayer also updated a day or two ago.

Share this post


Link to post
Share on other sites

This doesn't appear to be a false positive. We detect this installer because it is bundled with a .DLL that belongs to an Adware family known as FusionCore ->  hYEBnFBwH.dll MD5: EDDA84B853315B732C1B26F1D9E042A4

I believe it is the "Install Additional Codec" option you have selected. We might lower the detection to PUP.Optional instead of Adware though after I have a chance to confer with my colleagues.

Thanks for your report

Share this post


Link to post
Share on other sites
5 hours ago, thisisu said:

Thanks for your report

Thanks for taking a look into it.

Share this post


Link to post
Share on other sites

No problem. We're going to keep it listed as Adware.FusionCore

Share this post


Link to post
Share on other sites

My Malwarebyte Premium report Adware.FusionCore in the C:\users\username\appdata\local\temp\potupdate\potplayersetup64_104-exe too after auto scan when starting machine few minute ago.

I have rich experience with AdwancedCystemCare where MBM found 6 threats like PUP (all modules).

Also after installation Duplicate File Finder dffsetupsbg_sysblog-best10duplicatefinder.exe

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.