R E L A T E D   C O N T E N T
ADVERTISEMENT

Malicious Trojan infects Windows Media Player

Downloads malicious application when video files are run

Robert Jaques, vnunet.com 11 Jan 2005
ADVERTISEMENT

Security experts have intercepted two malicious Trojans hidden in video files that download and install spyware, diallers and computer viruses when played in Microsoft Windows Media player.

PandaLabs warned that Trj/WmvDownloader.A and Trj/WmvDownloader.B, are spreading through P2P networks hidden in video files. These Trojans take advantage of technology incorporated in Microsoft Windows Media player called Windows Media Digital Rights Management (DRM), designed to protect the intellectual property rights of multimedia content.

When a user tries to play a protected Windows media file, this technology demands a valid licence. If the license is not stored on the computer, the application will look for it on the internet, so that the user can acquire it directly or buy it. This technology is incorporated through the Windows XP Service Pack 2 + Windows Media Player 10 update.

The video files infected by these Trojans have a .wmv extension and are protected by licences, supposedly issued by the companies overpeer (for Trj/WmvDownloader.A), or protectedmedia (for Trj/WmvDownloader.B).

If the user runs a video file that is infected by one of these Trojans, the files pretend to download the corresponding licence. However, what they actually do is redirect the user to other internet addresses from which they download adware, spyware, diallers (applications that dial-up high rate toll numbers) and viruses, security experts at PandaLabs said.

Below are some examples of the malicious programs and viruses these Trojans download:

Adware/Funweb
Adware/MydailyHoroscope
Adware/MyWay
Adware/MyWebSearch
Adware/Nsupdate
Adware/PowerScan

Adware/Twain-Tech
Dialler Generic
Dialer.NO
Spyware.AdClicker
Spyware/BetterInet
Spyware/ISTbar
Trj/Downloader.GK

"Even though these Trojans have been detected in video files with extremely variable names which can be downloaded through P2P networks like KaZaA or eMule, bear in mind that they can also be distributed through other means, such as files attached to email messages, FTP or Internet downloads, floppy disks, CD-ROM, etc," PandaLabs warned.

For further information about Trj/WmvDownloader.A, Trj/WmvDownloader.B or the malicious programs and viruses these Trojans try to download, click here

See also:

Virus attempts to steal login detailsMalicious code steals passwords and logins  26 Jan 2005
Trojan allowed hacker to spy through webcamsSpanish Civil Guard nabs alleged virus writer  19 Jan 2005
Flaws could allow hackers to take remote controlTime to get patching  12 Jan 2005
Virus writers are not yet targeting mobile platforms, but is this the calm before the storm?  03 Feb 2003
Following the recent outbreak of the Love Bug on PCs, a new virus that sends unwanted text messages to mobile phones has been reported in Europe.  20 Jul 2000
A computer virus that sends unwanted text messages to mobile phones has been reported in Europe today.  06 Jun 2000

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Analyst Programmer - HP Service Center - Competitive Salary - Reading Foster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil & ... more >
Solihull, United Kingdom | Enzen Global Limited
 Business Consultant - £35,000 - £40,000 - Solihull We are in need of a Business Consultant with strong analytical skills and a penchant for learning the domain knowledge of the Utilities sector (Gas industry in ... more >
Durham, United Kingdom | Durham University
Durham University Shaped by the past, creating the future Ocean-Bottom Instrumentation Consortium Software Developer £25,888 - £33,780 per annum Applications are invited for a software developer to join the Ocean-Bottom Instrumentation Consortium (http://www.obs.ac.uk/), who provide ... more >
United Kingdom | MI5 Security Services
UNIX and Database Technology Team Manager - Competitive + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and ... more >
More job opportunities