Sponsor for PC Pals Forum

Author Topic: Fake MP3s pose 'signifcant threat'  (Read 1216 times)

Offline Clive

  • Administrator
  • *****
  • Posts: 75153
  • Won Quiz of the Year 2015,2016,2017, 2020, 2021
Fake MP3s pose 'signifcant threat'
« on: May 07, 2008, 16:39 »
A new computer Trojan disguised as a media file has been described by security experts as the most significant malware outbreak in three years.

McAfee Avert Labs has discovered more than 360,000 detections of a Trojan horse which hides behind fake music and video files on P2P networks such as Limewire and eDonkey.

When someone attempts to load one of these MP3 and MPG files, they don't get the music or video they were hoping for but are instead instructed to download a file named PLAY_MP3.exe. If you agree to download and run PLAY_MP3.exw, it serves the computer with adware.

Craig Schmugar, a researcher with McAfee, said: "This is one of the most prevalent pieces of malware in the last three years. We have never before had a threat this significant that arrives as a media file."

"In the end you're left with a fake MP3 file taking up space, a worthless MP3 player, adware that claims not only to not display pop-ups but also to block them, and more adware that successfully displays pop-up and pop-under ads."

According to McAfee, it has rated the threat "medium" risk, the highest risk rating given to a threat since 2005.


www.mcafee.com/uk/



Offline sam

  • Administrator
  • *****
  • Posts: 19977
Re: Fake MP3s pose 'signifcant threat'
« Reply #1 on: May 07, 2008, 17:27 »
this is a new thing??
- sam | @starrydude --

Offline Rik

  • Former Admin
  • *****
  • Posts: 26506
  • Ceud mille failte
Re: Fake MP3s pose 'signifcant threat'
« Reply #2 on: May 07, 2008, 18:14 »
Well, Clive's only just got rid of his wind up gramophone... ;D :scoot:
Slainthe!

Rik

Offline Clive

  • Administrator
  • *****
  • Posts: 75153
  • Won Quiz of the Year 2015,2016,2017, 2020, 2021
Re: Fake MP3s pose 'signifcant threat'
« Reply #3 on: May 07, 2008, 19:55 »
Well, Clive's only just got rid of his wind up gramophone... ;D :scoot:

Over my dead body! 

Offline Reno

  • Established Member
  • ****
  • Posts: 1286
  • ø¤º° bob °º¤ø
Re: Fake MP3s pose 'signifcant threat'
« Reply #4 on: May 07, 2008, 21:28 »
The latest generation of malware has gotten down right nasty. I worked on a machine awhile back who's owner :o: had downloaded an updated xp activation registry crack. Testing it installed a rootkit version of vundo which cratered the installation over three days. With so many variants popping up these days its getting practically impossible to recover an installation once a machine get infested.

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
Re: Fake MP3s pose 'signifcant threat'
« Reply #5 on: May 09, 2008, 14:29 »
this is a new thing??

I doubt anyone here would know Sam.  :o:
Those who can make you believe absurdities,
can make you commit atrocities.

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
Re: Fake MP3s pose 'signifcant threat'
« Reply #6 on: May 21, 2008, 12:06 »
This happened to me this afternoon, when I tried to delete it, a little Comodo warning popped up, Installer.exe asking permission to access the internet.
I have just finished 2 hours of scans, which found nothing but cookies, except this, "There were problems in the include file C:\Program Files\Spybot - Search_Destroy\Includes\TrojansC.sbi" See 'Include errors.log' for details.

I can find the first file, but I don't know where the Include errors.log is.  :dunno:

And I don't know where the Installer.exe file is either, I did a search, including hidden files, and nothing.  :dunno:
Those who can make you believe absurdities,
can make you commit atrocities.

Offline Simon

  • Administrator
  • *****
  • Posts: 77923
  • First to score 7/7 in Quiz of The Week's News 2017
Re: Fake MP3s pose 'signifcant threat'
« Reply #7 on: May 21, 2008, 12:33 »
If you've deleted the rogue file, and blocked it with Comodo, I would think it fairly safe to assume the threat has gone, Kate.  I had one myself the other day, and F-Secure dealt with it.
Many thanks to all our members, who have made PC Pals such an outstanding success!   :thumb:

Offline mistybear

  • Forum Fanatic
  • ******
  • Posts: 7656
Re: Fake MP3s pose 'signifcant threat'
« Reply #8 on: May 21, 2008, 12:40 »
Thanks Simon, I get a little paranoid about these things, as I do my banking on this computer.  :)

Maybe I should leave the other things to Michael, couldn't find what I wanted either, to top things off.  ::)
Those who can make you believe absurdities,
can make you commit atrocities.

Offline Clive

  • Administrator
  • *****
  • Posts: 75153
  • Won Quiz of the Year 2015,2016,2017, 2020, 2021
Re: Fake MP3s pose 'signifcant threat'
« Reply #9 on: May 21, 2008, 18:53 »
The main thing is that you didn't give it permission to access the internet.  Glad you managed to sort it out MB.


Show unread posts since last visit.
Sponsor for PC Pals Forum