Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Malicious Trojan infects Windows Media Player
vnunet ^ | 11 Jan 2005 | Robert Jaques

Posted on 01/11/2005 7:32:42 AM PST by holymoly

Downloads malicious application when video files are run

Security experts have intercepted two malicious Trojans hidden in video files that download and install spyware, diallers and computer viruses when played in Microsoft Windows Media player.

PandaLabs warned that Trj/WmvDownloader.A and Trj/WmvDownloader.B, are spreading through P2P networks hidden in video files. These Trojans take advantage of technology incorporated in Microsoft Windows Media player called Windows Media Digital Rights Management (DRM), designed to protect the intellectual property rights of multimedia content.

When a user tries to play a protected Windows media file, this technology demands a valid licence. If the license is not stored on the computer, the application will look for it on the internet, so that the user can acquire it directly or buy it. This technology is incorporated through the Windows XP Service Pack 2 + Windows Media Player 10 update.

The video files infected by these Trojans have a .wmv extension and are protected by licences, supposedly issued by the companies overpeer (for Trj/WmvDownloader.A), or protectedmedia (for Trj/WmvDownloader.B).

If the user runs a video file that is infected by one of these Trojans, the files pretend to download the corresponding licence. However, what they actually do is redirect the user to other internet addresses from which they download adware, spyware, diallers (applications that dial-up high rate toll numbers) and viruses, security experts at PandaLabs said.

Below are some examples of the malicious programs and viruses these Trojans download:

Adware/Funweb
Adware/MydailyHoroscope
Adware/MyWay
Adware/MyWebSearch
Adware/Nsupdate
Adware/PowerScan
Adware/Twain-Tech
Dialler Generic
Dialer.NO
Spyware.AdClicker
Spyware/BetterInet
Spyware/ISTbar
Trj/Downloader.GK

"Even though these Trojans have been detected in video files with extremely variable names which can be downloaded through P2P networks like KaZaA or eMule, bear in mind that they can also be distributed through other means, such as files attached to email messages, FTP or Internet downloads, floppy disks, CD-ROM, etc," PandaLabs warned.

For further information about Trj/WmvDownloader.A, Trj/WmvDownloader.B or the malicious programs and viruses these Trojans try to download, click here


TOPICS: News/Current Events
KEYWORDS: computersecurity; exploit; gatesofhell; getamac; infect; infects; internetexploiter; lowqualitycrap; malicious; media; microsoft; patch; player; securityflaw; spyware; trojan; virus; windows; wmv; worm
Navigation: use the links below to view more comments.
first 1-2021-4041 next last
1.) Don't download pirated videos, warez, etc.
2.) Don't play WMV files.
3.) Problem solved. ;)
1 posted on 01/11/2005 7:32:42 AM PST by holymoly
[ Post Reply | Private Reply | View Replies]

To: ShadowAce

Security Ping!


2 posted on 01/11/2005 7:33:19 AM PST by KoRn
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Run ZoneAlarm and force it to always alert you when a program seeks to connect to the net.


3 posted on 01/11/2005 7:35:20 AM PST by snarks_when_bored
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

`` 2.) Don't play WMV files.``

Most of my porn is WMV. What do I do? I knew this was going to be a bad day.


4 posted on 01/11/2005 7:37:52 AM PST by mlbford2 ("Never wrestle with a pig; you can't win, you just get filthy, and the pig loves it...")
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly
The most malicious Trojan of em all:


5 posted on 01/11/2005 7:39:57 AM PST by The G Man (The Red States ... the world's only hope for survival.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

http://housecall.trendmicro.com/

Ease your mind and scan your PC for viruses.


6 posted on 01/11/2005 7:40:18 AM PST by TheForceOfOne
[ Post Reply | Private Reply | To 1 | View Replies]

To: snarks_when_bored
Run ZoneAlarm and force it to always alert you when a program seeks to connect to the net.

Excellent recommendation. And, with the explosion of spyware, trojans & diallers, even people on dial-up should use a firewall.

For those not currently running a firewall:
Zone Labs Free Downloads
(At the very bottom is the free version of ZoneAlarm.)

Some may also find this useful:
PCWorld: How to Install a Firewall

7 posted on 01/11/2005 7:41:18 AM PST by holymoly (I'm not a Tyrant, but I play one on Free Republic.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: holymoly

A better solution is to turn off the "acquire licences automatically" option (under the Privacy tab in Tools -> Options).


8 posted on 01/11/2005 7:43:01 AM PST by NonValueAdded ("We're going to take things away from you on behalf of the common good" HRC 6/28/2004)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

WINDOWS MEDIA PLAYER
TOOLS>OPTIONS>PRIVACY
Uncheck ACQUIRES LICENSES AUTOMATICALLY
You are now immune to that attack. While you are at uncheck all of the boxes on the privacy tab and you will be better off.


9 posted on 01/11/2005 7:43:30 AM PST by azcap
[ Post Reply | Private Reply | To 1 | View Replies]

To: The G Man

Wow. A canadian address with no postal code.

Must be old.


10 posted on 01/11/2005 7:43:51 AM PST by texas booster (Bless the legal immigrants!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: holymoly

I thought Trojans PREVENTED the spread of viruses.


11 posted on 01/11/2005 7:46:58 AM PST by sportutegrl
[ Post Reply | Private Reply | To 1 | View Replies]

To: azcap

Azcap, thanks for the tech tip. I just followed your instructions.

madison


12 posted on 01/11/2005 7:47:12 AM PST by madison10
[ Post Reply | Private Reply | To 9 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

"This is getting pretty old" ping


13 posted on 01/11/2005 7:48:15 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 2 | View Replies]

To: holymoly

bttt


14 posted on 01/11/2005 7:50:12 AM PST by Born Conservative (Those who hate you don't win unless you hate them. And then you destroy yourself." Richard Nixon)
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe

Windows security ping


15 posted on 01/11/2005 7:50:47 AM PST by Born Conservative (Those who hate you don't win unless you hate them. And then you destroy yourself." Richard Nixon)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
I never use Windows Media Player, partly because of issues like this. I just hate it when they have to embed their bundled programs so deep into the OS. When something goes wrong, or there is a security hole, it hoses up the entire system.


16 posted on 01/11/2005 7:54:27 AM PST by KoRn
[ Post Reply | Private Reply | To 13 | View Replies]

To: mlbford2

You owe me one keyboard. There's coffee everywhere!


17 posted on 01/11/2005 7:55:19 AM PST by kaboom
[ Post Reply | Private Reply | To 4 | View Replies]

To: TheForceOfOne
Yeah, I'm really going to trust something that tells me I need to download an EXE file to plug in to my NETSCAPE Browser, just so I can execute their virus-scanner.

Seeing how I'm running a Safari browser on Mac OS X, their code is just a bit shaky...

18 posted on 01/11/2005 8:06:15 AM PST by Izzy Dunne (Hello, I'm a TAGLINE virus. Please help me spread by copying me into YOUR tag line.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: snarks_when_bored

"Run ZoneAlarm and force it to always alert you when a program seeks to connect to the net."

Worth repeating, it's FREE. works great...

www.zonelabs.com


19 posted on 01/11/2005 8:16:54 AM PST by RS
[ Post Reply | Private Reply | To 3 | View Replies]

To: RhoTheta

Ping!


20 posted on 01/11/2005 8:36:01 AM PST by Egon (Government is a guard-dog to be fed, not a cow to be milked.)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson