Page 3 of 3
Posted: 2007-08-01 15:02
by Hitperson
but wait we have just been told it is malware...

Posted: 2007-08-01 16:25
by Hx.Clavdivs
just stay away from the file.
By the way, any other file we might try instead?
Posted: 2007-08-01 16:59
by sofad
hey, this file cant be a malware. seriuosly, it comes directly from the creative developer site. do you really think such a global player like creative will risk his reputation by let ppl download malware??
Posted: 2007-08-01 17:02
by Hx.Clavdivs
Yes. Considering I've used another software to confirm it as a malware and a fast google confirms multiple sites warning that this is a nasty little trojan.
Posted: 2007-08-01 17:07
by GeZe
Yeah, my F-Secure deleted a trojon. This is the only thing that I recently installed, so I assume it's it. It may be a false positive.. don't know.
Posted: 2007-08-01 17:15
by Hx.Clavdivs
I can also confirm, that was the only software that I have added in the last timeframe.
Posted: 2007-08-01 17:33
by pureperversions
or if you look at the bottom were it says Other versions of OALINST.EXE and links to
http://spywarefiles.prevx.com/ssJFGD511031/OALImore.html
and scroll through that, notice the green circle for good, orange for undetermined and red for bad then look at the file instal locations you will see the creative labs install locations are marked as green
what you will find is that most likely there is a viral/trojan with the same installer name, its a common tactic for viral creaters to name the files after legit program/installs to try and trick people into installing. As much as i dont trust there ability to write decent drivers i dont belive they would host a trojan, ive scanned the file with AVG paid edition, trend micro, spybot s&d and ad aware and seems clean
also looked at
http://www.spywaredata.com/spyware/malware/oalinst.exe.php
and it comes up clean
Posted: 2007-08-01 18:30
by R@ge
'[R-DEV wrote:sofad']hey, this file cant be a malware. seriuosly, it comes directly from the creative developer site. do you really think such a global player like creative will risk his reputation by let ppl download malware??
Even the president of the USA have done something wrong
pureperversions wrote:or if you look at the bottom were it says Other versions of OALINST.EXE and links to
http://spywarefiles.prevx.com/ssJFGD511031/OALImore.html
and scroll through that, notice the green circle for good, orange for undetermined and red for bad then look at the file instal locations you will see the creative labs install locations are marked as green
This list shows the determination of prevx software on different locations on your computer and has nothing to do where you get the file......
The other list is another thing, I’m not sure what to say about it…
But i would NOT recommend anyone to even download this software at all...
Several people have got their computer infected with Trojans when they installed this, so how safe is that is that???
I hope first post get changed and remove link to this garbage!!
Posted: 2007-08-01 18:41
by Hx.Clavdivs
Not to worry R@ge.
Cleaned up my PC nice and tidy.
Installed fresh. Use it per usuall for 24 hours.
Run the Prevx once more and say if it frets.

I laugh at my own insanity.
And I might add that prevx also says this
COVERT ANALYSIS OF: OALINST.EXE
* File Names Used: 515
* Paths Used: 312
* Common File Name: OALINST.EXE
* Common Path: %programfiles%\adobe\acrobat 7.0\reader\data\resources\
* Vendor Information: No Vendor details specified
* Version Information: 0.0.0.0
* OALINST.EXE may use 515 or more path and file names, these are the most common:
* 1 :%commonfiles%\adobe\calibration\data\resources\ADOBE GAMMA LOADER.EXE
* 2 :%commonfiles%\microsoft shared\dw\data\resources\DW20.EXE
* 3 :%honeypotroot%\backdoors\backdoor.msil.agent.b\D6DEF837.EXE
* 4 :%prevxhome%\data\resources\SDBCONVERT.EXE
* 5 :%prevxhome%\data\resources\UPDATESILENT.PREVX2.1.0.2.53.....EXE
* 6 :%programfiles%\adobe\adob... center\data\resources\AHC.EXE
* 7 :%programfiles%\asus\asus chkmail\data\resources\CHKMAIL.EXE
* 8 :%programfiles%\autopatche...c_files\data\resources\WINDOWSXP-KB917344-X86-ENU.EXE
* 9 :%programfiles%\bethesda s...blivion\data\resources\OBLIVIONLAUNCHER.EXE
* 10:%programfiles%\bitcomet\data\resources\BITCOMET.EXE
* 11:%programfiles%\ccp\eve\cache\data\resources\EVEPATCH4557-4561.EXE
* 12:%programfiles%\creative\m...source5\data\resources\CTCMSU.EXE
* 13:%programfiles%\creative\
* File Name Structure: Normal
* File and Path Structure: Suspicious, unusually high number of file and path combinations
Note the file names use are 515
Posted: 2007-08-02 00:22
by hx.bjoffe
Hm, you guys scared me.
I never got a warning of my AVG Antivirus, and Prevx didnt come up with shit. Can anyone confirm the speculation, atleast it didnt contaminate my system?
Anyhow, that file is only for Creative chipsets, right? Tried them on for fun on my onboard Realtek, but sound wouldnt work ingame at all. Purchasing a X-Fi one of the next days, so not embarrasing my brand new headphones.
Posted: 2007-08-02 00:52
by sofad
the openAl update isnt only for creative cards.
its for all openAl games (update to openAl 1.1) and BF2/PR (when copy and rename the openAL wrapper to the battlefield2 folder) when using software in soundsettings and EAX enabled.
Posted: 2007-08-02 04:49
by Hx.Clavdivs
hx.bjoffe wrote:Hm, you guys scared me.
I never got a warning of my AVG Antivirus, and Prevx didnt come up with shit. Can anyone confirm the speculation, atleast it didnt contaminate my system?
Anyhow, that file is only for Creative chipsets, right? Tried them on for fun on my onboard Realtek, but sound wouldnt work ingame at all. Purchasing a X-Fi one of the next days, so not embarrasing my brand new headphones.
Norwegian superhero? Please ...

Just do as I say.
Posted: 2007-08-02 04:55
by Hx.Clavdivs
'[R-DEV wrote:sofad']the openAl update isnt only for creative cards.
its for all openAl games (update to openAl 1.1) and BF2/PR (when copy and rename the openAL wrapper to the battlefield2 folder) when using software in soundsettings and EAX enabled.
Not to burst you bubble or anything, but it worked just great on my system. And I don't have any soundcard at all. Then again, it did suddenly did show up as a trojan on my Prvx.
Posted: 2007-08-02 10:48
by sofad
kaspersky, one of the best AV software out there, didnt find anything. not in the installer, nor the installed files.
is it possible that you have got the real oalinst.exe trojan from somwhere else?
the oalinst.exe from the creative developer site is 100% clean!
Posted: 2007-08-02 11:44
by Jaymz
well Calvidvs, I guess as usual the lady is wrong. OH YES, I WENT THERE, OH YES!!!!

Posted: 2007-08-02 12:03
by BlakeJr
I don't know what to say... I've downloaded the oalinstaller as well.
It has not turned up in any of my antivirus or antispyware detection software.
I even downloaded PrevX and guess what. Negative.
So I pointed PrevX right at the offending file and scanned it. Still negative, NO infection detected...
So if y'all pardon me I'm keeping this baby installed.

Posted: 2007-08-02 15:11
by R@ge
[R-DEV]Jaymz wrote:well Calvidvs, I guess as usual the lady is wrong. OH YES, I WENT THERE, OH YES!!!!
You don't want to get this woman mad....
Consider you’re self warned
Posted: 2007-08-02 17:03
by Nitrius
Question, i'am running vista x64 with creative x-fi xtrememusic, will this work with PR and BF2? or do i have to download any extra to get the best sound?
of course i use the latest driver for the soundcard.
Posted: 2007-08-02 20:10
by sofad
as X-FI has native support in BF2 (make sure to choose the X-FI in your sound options, set sound to ultra high and enable EAX), there is no need for an extra action.
im running vista 32bit with X-FI xtrememusic fine with an autstanding sound experience!
