Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Fake MP3s on various P2P networks

Notifications for Security Updates, as well as News and Information from across the web - mostly security minded.

Update Contributors: Members of the Malware Removal University.

Regular Members: Our Regular Members are invited to start and/or participate in all other topics. Join in and share the news that's important to you.

Fake MP3s on various P2P networks

Unread postby Dino » May 7th, 2008, 5:53 am

Detection of a trojan named Downloader-UA.h was added to the McAfee DAT files several days ago. Since that time more than 360,000 McAfee VirusScan Online users have reported detections, a whopping 32% of those reporting in the past 24 hours alone. Now Downloader-UA.h is not your everyday trojan, this detection covers fake music and video files associated with fastmp3player.com.

When a user attempts to load one of these MP3 and MPG files, they don’t get the music/video they were hoping for; instead they’re directed to download a file named PLAY_MP3.exe. In fact, the MP3/MPG file they downloaded was completely fake, playing no media clip what so ever.

Here are some of the samples names that we’ve seen. Many many other file names are surely floating around on P2P networks. File sizes vary as these files are padded with nulls.


http://www.avertlabs.com/research/blog/index.php/2008/05/06/fake-mp3s-running-rampant/
Dino
Regular Member
 
Posts: 93
Joined: April 22nd, 2008, 7:51 am
Advertisement
Register to Remove

Re: Fake MP3s on various P2P networks

Unread postby Dakeyras » May 7th, 2008, 6:08 am

Zero bump :).
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8804
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Fake MP3s on various P2P networks

Unread postby ndmmxiaomayi » May 7th, 2008, 9:27 am

http://vil.nai.com/images/AvertBlog_FastMP3EULA.gif

This screenshot is interesting. Wonders if installing crapware is compulsory when the user agrees to download the fake files.
ndmmxiaomayi
MRU Emeritus
MRU Emeritus
 
Posts: 9708
Joined: July 17th, 2006, 9:22 am

Re: Fake MP3s on various P2P networks

Unread postby ndmmxiaomayi » May 8th, 2008, 12:45 am

A little update - http://www.avertlabs.com/research/blog/ ... dia-files/

This comes with a video to show the infection process.

These "MP3" files are in fact ASF files that instruct media players such as Windows Media Player to navigate to a specified URL (via the default HTTP protocol handler - ie. default browser).


I don't know how is that an answer.

Do I understand that those ASF files are responsible for downloading those crapwares?
ndmmxiaomayi
MRU Emeritus
MRU Emeritus
 
Posts: 9708
Joined: July 17th, 2006, 9:22 am

Re: Fake MP3s on various P2P networks

Unread postby ndmmxiaomayi » May 8th, 2008, 1:21 am

ndmmxiaomayi wrote:http://vil.nai.com/images/AvertBlog_FastMP3EULA.gif

This screenshot is interesting. Wonders if installing crapware is compulsory when the user agrees to download the fake files.


Answer is in the video. :D
ndmmxiaomayi
MRU Emeritus
MRU Emeritus
 
Posts: 9708
Joined: July 17th, 2006, 9:22 am
Advertisement
Register to Remove


Return to News Desk



Who is online

Users browsing this forum: No registered users and 19 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware