Playback Problems (1 Viewer)

Dunk_R

New Member
August 24, 2008
2
0
Wellington
Home Country
New Zealand New Zealand
When you figure out the cause please post it,,,

The problem that you have described is exactly the same symptoms that I am experiencing.
I am beginning to dispair of ever finding out what is causing it.........
Anybody that has managed to find out what is causing the "Bass.dll" file to disapear please advise.
I have the added issue that I cannot stard the configuration tool, it just crashes every time, I assume that this is related to the same issue, as it happens at the same time as I lose the ability to view any movies, recorded TV, timeshifting ect, ect, ect,,,,,,,,
Thanks to anybody that can help.
 

Paranoid Delusion

Moderation Manager
  • Premium Supporter
  • June 13, 2005
    13,052
    2,978
    Cheshire
    Home Country
    United Kingdom United Kingdom
    Has anyone got antivirus\antispyware that may be thinking this BASS.dll is a threat to there systems.

    Cannot think of any other way this may be getting deleted.

    Regards
     

    luther1978

    New Member
    April 30, 2008
    1
    0
    Home Country
    United Kingdom United Kingdom
    Well done Paranoid, fixed my problem too, now to see what is removing it!!!

    meant to say thank you, just over excited at resolving the problem, thanks paranoid.
     

    RichieB

    MP Donator
  • Premium Supporter
  • May 9, 2008
    22
    0
    Adelaide
    Home Country
    Update on Playback Problems

    Hi Guys,

    Just a quick update: Since replacing the missing bass.dll file as per my last post, MP has been fine. Like Paranoid says, it must have something to do with the virus scanner that decided it didn't like the file. Funny thing is it hasn't happened again? I'm using ZoneAlarm, if that's any help.

    Cheers for now......
     

    RichieB

    MP Donator
  • Premium Supporter
  • May 9, 2008
    22
    0
    Adelaide
    Home Country
    Update on Playback Problems

    Hi all,

    Found the problem - It WAS the Virus Scanner (see the attached screen dump). I've now set it to "Ignore Always". I hope this solves the problem others are having with bass.dll being deleted.

    Once again, thanks to all for your help and advice.

    :D
     

    Attachments

    • bass_dll.JPG
      bass_dll.JPG
      65.9 KB

    MPKeith

    Portal Member
    September 21, 2008
    16
    2
    Home Country
    Hello,
    I have been using MP for a year or so now without problems (great program guys, thanks!). A seemingly unrelated spyware problem and long exhaustive search and process of elimination has led me to this thread - but I have something new to add to the discussion so far.

    My problem was the same as has been described above by others in this thread: For many months and seemingly randomly, the ZoneAlarm Spyware scanner would pick up bass.dll as spyware.
    My next steps were to:
    - update to latest svn snapshots, make sure that MP installation files+bass.dll were not infected before being installed.
    - triple check that bass.dll was the original that came with MP,
    - Complete in-depth Scans of whole system with multiple spyware systems and over multiple days turned up nothing - my system appeared clean (woohoo!)

    This process leans towards the conclusions that bass.dll was either A) a false positive in ZA, or B) infected after MediaPortal install. Not finding any other infections for many weeks of searching, I decided it was all a false positive, and so did the same as RichieB above; setting bass.dll to be ignored always by ZA. All seemed well and good.... but then the problems begun

    My machine would seemingly randomly start trying to contact 888.com. Looking up that domain quickly shows it to be a well known location for the CasinoOnNet spyware. ZA spy site blocking would quickly pick it up and block the attempt, blink and you would miss the warning. Intrigued and alarmed that something was directing my Firefox browser to contact a known spyware supplier, I set out to track the problem down... which has led me back to bass.dll.

    Starting from a clean install of MP, clean sweep(s) of system to determine there is no Virus/Spyware and running machine and no attempts to connect to any known spyware sites from my machine for a month or so. I fire up MP and use internet radio:

    - bass.dll appears to "activate". ZoneAlarm suddenly picks it up as spyware where there was none before.
    - I hardly ever use internet radio in MP, but now I had solved the "seemingly randomly" part of my problem - it's not random, its when I actually use the internet radio.
    - Shortly after (usually the day later for me), my machine attempts to connect to 888.com. Other registry keys seem to be being set. This rules out that it is a false positive - this is a real spyware problem. (I quickly removed the "ignore always" option of ZA)
    - Researching, and Mediaportal is not the only one effected. Kantaris www.kantaris.org • View topic - Adware found and a few other people around the net are discussing the same thing from different angles and combination's of these topics: 888.com, bass.dll, spyware, zonealarm. I have not yet found anything to the level of detail being discussed here though.
    - I research bass.dll, who's behind it, what exactly is it and where does it come from? Turn up next to nothing. All I can find so far is what it does: BASS . Its not open source I cannot check the source code. Un4seen alright, looks very suspicious so far.

    Two conclusions I am drawing towards from all this:
    1) bass.dll could still possibly somehow be infected after it is being activated for use streaming internet radio. However I am finding this explanation increasingly unlikely after hours of repeating the above process, pouring through security task manager/whats running logs and file access stats to figure out whats going on here. It appears to be coming from the file itself and only after it connects to a radio station.
    OR
    2) bass.dll IS a backdoor that is activating when it connects to any internet radio station.

    In either case, for now I have no choice but to consider it real spyware. Either indirectly or directly bass.dll is allowing something/someone to enter into my machines, setup 888.com (known), do other damage (unknown).

    Does anybody know more about bass.dll and un4seen and how trustworthy is it from this communities point of view? How likely could it be that this closed source library from unknown programmers is a clever front for a backdoor into every machine it is installed on?

    Sorry for the long post, all comments and suggestion very welcome, thanks!

    Keith.
     

    Paranoid Delusion

    Moderation Manager
  • Premium Supporter
  • June 13, 2005
    13,052
    2,978
    Cheshire
    Home Country
    United Kingdom United Kingdom
    Does anybody know more about bass.dll

    Why is it no other AV\Spyware program picks this up, mine nor any of the other team members does and we all have antivirus\antispyware installed.

    I think you have a trojan on your pc which is piggybacking by using this dll or any other for its purposes, make sure you delete all your temporary files including internet ones, then try another online antivirus scanner maybe.

    And we would not supply a dll from a unknown\unreputable source.
     

    MPKeith

    Portal Member
    September 21, 2008
    16
    2
    Home Country
    Hi Ray,

    Why is it no other AV\Spyware program picks this up, mine nor any of the other team members does and we all have antivirus\antispyware installed.

    Note that ZA does not pick it up either, at least until internet radio/bass.dll is used and even then it is not an immediate change to malware - there seems to be a delay or it needs a reset or some other step to be performed. Using the popular web based VirusTotal.com service, only 3 of 36 current uptodate virus checkers think that https://svn.sourceforge.net/svnroot/mediaportal/trunk/mediaportal/MediaPortal.Base/bass.dll is suspect. Report for base.dll (before it converts into ZA-identifiable malware):
    Virustotal. Suspicious File VIPRE.Suspicious Win32.Malware.gen (suspicious)
    Note that ZA does not detect anything unusual at this stage.

    I would normally consider this a false positive, and just move on.... but since I know its not and digging a little deeper:
    "W32.Malware.Gen
    6 Sep
    W32.Malware.Gen is a generic detection for files or threats that are part of the Malware Group which has the capability to download and execute additional threat by exploiting software vulnerabilities.
    http://www.precisesecurity.com/blogs/2007/09/06/w32malwaregen/"

    So bass.dll has the capability to to download and execute additional threats. I agree it still does not mean much, many "respectable" programs can turn up this warning.

    I think you have a trojan on your pc which is piggybacking by using this dll or any other for its purposes, make sure you delete all your temporary files including internet ones, then try another online antivirus scanner maybe.

    I agree that this is usually the most common explanation and I have taken as many steps as I can under various conditions on different machines to try and rule this out. Used new clean machines, safe modes w/wo networking, cleared windows restore archives and the all usual steps when tracking down these types of problems. Fortunately (or unfortunately :) as a computer scientist I have had a lot of experience in this area for many years now, so I am as confident as you can be with windows boxes that I am running tight security ship. That still does not mean I rule it out though - it is the most common cause especially if the infected dll/program can be guaranteed not to contain malware, backdoor and/or remote security vulnerability - which is why I raised the question of integrity.

    If it is a trojan piggybacking on base.dll, then it is highly specialised and/or bass.dll has something it really likes unlike all other files on the infected machines. Assuming its a piggybacking trojan, then it is not infecting any other dll's or files over at least a 7 month window that this problem has been reoccurring. How about with other MP users who have experienced this security breach? It all started the same time that I started dabbling with MP's internet radio functions, how about others? If it is infecting other dll's on my machines then ZA can only detect it in base.dll but I consider this is highly unlikely. As a piggybacking trojan, it is not readily visible in the specialised thread/process list security monitors I have tried at the time base.dll is active, and no direct file modify access is being made to base.dll while its in use that I can find or see. For me at least, the full malware detection only strikes sometime after base.dll has been used in internet radio operations, and as mentioned a few time now it needs some other intermediate step - most likely MP release control of base.dll so it can be modified and/or a system reset but I have been so far unable to conclusively confirm what exactly. These points in combination were enough for me to stop and start asking harder questions about base.dll... even if this security breach does turn out to be a separate trojan infection of some sort only not detectable by any spyware scanner.

    There are two other possibilities that have to seriously consider now (which is why I posted really):
    1) base.dll or some nearby closely related code is somehow remotely exploitable, contains buffer overrun vulnerabilities or something similar while there is remote internet radio access. Possible initiated externally by visiting a rouge a radio link or some other external to the machine means. I have only used internet radio to access radioparadise.com a well known widely used and "respected" station, and I have only ever used one of four access urls that they provided me (posted at end):
    OR
    2) base.dll or related code is of malicious intent, and initiates malware installation over the top of itself by itself. This really need's some time consuming packet sniffing to confirm/rule this out, and I am not very experienced in this area of security.

    And we would not supply a dll from a unknown\unreputable source.

    I do not doubt Team-MP is not all above board or would do such a thing knowingly, otherwise I would not even be bothering to post or use MP. What I am saying is that I can't delve (easily) into bass.dll and related code to see what is going on to solve this problem, and I assume that Team Mediaportal developers cannot, either? The best programmers in the world have been known to accidently introduce security vulrabilities into their code. Even if bass.dll is rock solid, respectable and has secure code, there appears to be a good deal of other apparently proprietary and closed source code that could also be responsible:

    Code:
    File                             Company
    bass.dll                       Un4seen Developments
    Bass.Net.DLL            TEN53
    bassasio.dll                 Un4seen Developments
    bassmix.dll                  Un4seen Developments
    BassRegistration.DLL
    bass_fx.dll                  (: JOBnik! :)[Arthur Aminovm ISRAEL]
    bass_vis.dll                 BrewIdeas@Emil Weiss
    bass_vst.dll
    bass_wadsp.dll           TEN53
    any others?

    Malicious intent by proprietary code suppliers cannot be ruled out. A quick search for online casino affiliate referrals show sizable revenue share offers: "We offer a genuine 25 - 35% of net revenue of any players you refer to us" etc. That's a big incentive for any struggling shareware shop to make some money on the side, especially in this economic climate. In this unlikely and unfortunate case, and if they are half decent programmers then they probably would use the common affiliate tactic of targeting markets by time, country/region and IP address ranges. Not everyone would get the problem showing up, and of those that do, not all of the time. Only one thing is certain so far: bass.dll is implicated either indirectly or directly in infecting some of our machines with malware, and (fortunately!) it does not appear to be a Mediaportal specific security vulnerability.

    Four Radio Paradise access urls mentioned above:
    http://64.236.34.97:80/stream/1048
    http://scfire-dll0l-1.stream.aol.com:80/stream/1048
    http://scfire-chi0l-1.stream.aol.com:80/stream/1048
    http://scfire-nyk0l-1.stream.aol.com:80/stream/1048
     

    Users who are viewing this thread

    Top Bottom