|
|
Earlier we blogged about Fake MP3s Running Rampant, mostly on P2P networks, such as Gnutella used by Limewire. I took some time to create a video clip showing what the infection process looks like. In doing so, hundreds of additional media files were uncovered. Most leading to the aforementioned site, freemp3player.com, but others leads to different sites distributing adware and others still pose as codec installers that when run, display fake error messages and download and silently install tons of files, including many different adware packages, such as:
Adware-BB
Adware-Beginto
Adware-Isearch
Adware-Mirar
Adware-SrchExplorer
Adware-Zeno
Domains linked to from the media files include:
mediaprovider . info
missing-codecs . com
seonomad . com
vidscentral . net
While this demo below shows that user’s must accept a EULA before proceeding, others contain no EULA.
– Update May 7 –
Adding some answers for questions that we’ve received.
These “MP3″ files are in fact ASF files that instruct media players such as Windows Media Player to navigate to a specified URL (via the default HTTP protocol handler – ie. default browser). Not all media players support this functionality.
Our detection rates are based on a segment of VirusScan consumers who have opted-in to reporting their detections to McAfee. Approximately 500,000 unique systems have reported having these Trojan media files on their PCs over the last few days. However, the number of those systems that have downloaded the adware installer from fastmp3player.com during this period is less than 10% (< 50,000).
|
|
We are only looking for the facts on this virus. No one needs to slam others who are less experienced (i.e. “.. tards get what they deserve..”).
I actually laughed when I saw that video, it was the most obvious invasion I’ve ever seen… I agree; If people are going to go through all those steps even after downloading a 77kb “movie” (!!!!!) then they deserve to get infected. Treat downloading files as you would treat taking candy from strangers, honestly… And Matt is correct, they’ve been around for ages, so just use your common sense. And FYI people, LimeWire in and of itself isn’t dangerous (although it’s often illegally used), it’s how you USE it that can be dangerous. Only download files of a reasonable size for their extension, and DON’T USE WMP!!!
Hi, I am Daniel Boyd with bnr associates –we have suspended SEONomad.com from our network and forwarded the real owners information to ICANN.
Daniel
i got hit i know i dumb, but how do i remove this virus (fake media file). can someone help me
LMFAO idiots these days…why dont they just go download SpyFalcon?
Those size files have been around for years. Can’t believe this is anything new.
Submit your own comments / message for this post