Fake music, video files spread malware on P2P, says McAfee

By Ed Oswald | Published May 7, 2008, 5:24 PM

McAfee is warning file-sharers that they may be at risk due to a Trojan horse posing as an MP3 or MPEG file.

The security firm said Tuesday that it had detected a half million instances of the malware since Friday, dubbed "Downloader-UA.h." It is calling the incident the most significant malware outbreak in three years.

A check of McAfee's virus map showed the majority of infections have occurred in the US during the past 24 hours, although high rates of infection are being reported in Mexico, Venezuela, Brazil, Australia, and much of Western Europe.

It appears as if the files are located on Gnutella and Limewire under a variety of names. When loaded, the file redirects through the player to a download of a file called PLAY_MP3.exe.

Once this file loads, it shows up a EULA, and if accepted, the files "FBrowsingAdvisor" and "SurfingEnhancer" are installed. The file PlayMP3.exe is also installed, but instead of it being an actual local MP3 player, the application loads up a webpage with the Wimpy Flash MP3 player with several dozen songs available.

The two previous files are believed to load some type of adware, which instead of blocking popups like the EULA claims deliver them to the end user.

McAfee rated the issue a "medium" risk, the first time its given any piece of malware such a high rating since 2005.

Comments

Who even uses McAfee? Its just as bad as Nortan...

Score: 0

|

oooooooooooooooo

I'm shakin' in my boots... hahahaha

Score: 0

|

How come an MP3 file can start another process to download and install something?

Score: 0

|

Read the article, Joco.

PLAY_MP3.exe

Score: 0

|

So glib PC, jebus.

Joco in reference to "When loaded, the file redirects through the player to a download of a file called PLAY_MP3.exe"

The file is fake as the article mentions, so it's probably coded through script to load a webpage and download that file when the file is 'played'. It's not a real mp3 at all so obviously you don't hear anything when you 'play' it.

Score: 0

|

Thanks for your reply. You would be surprise that I did read the article.

It is confusing. And I honestly wonder if you had read and understood the article. It said "It appears as if the files are located on Gnutella and Limewire under a variety of names. When loaded, the file redirects through the player to a download of a file called PLAY_MP3.exe."

The song I wanted is, let's say "Hotel California.mp3". That would be exactly that file that I would download. Even if it's fake, then that would play some gibberish sounds within Foobar. What I don't understand is that the PLAY_MP3.exe got into the computer when the media player plays the mp3.

Score: 0

|

Ya got me.

I skimmed and got "download of a file called PLAY_MP3.exe."

;)

Regardless, it would have to be an executable or script file (not a .mp3/.wma) file as I understand it. AFAIK, .com, .exe, and certain script extensions (none of which are .mp3, or .wma) can actually execute code.

Now...

...if a malformed audio file (say, with bad metadata?) ran in a player that for some asinine reason ran scripts, or took cues from the Metadata, it could wreak havok with the player, but even then, that'd be pretty hard to accomplish.

If Ed could have given an example or two of the names in questionm we would not only have something to watch out for it would clear up a lot of this confusion.

Score: 0

|

Don't blame jebus, he had nothing to do with it. 100% on me, man. ;)

Score: 0

|

Like DUR the MPAA and RIAA and other people that wish users harm has been doing this very thing for years already. lol Ahh well Not that it matters much anymore anyway.

I know so few people getting things this way now, it almost seems as obsolete as Napster is... There are so many better ways now to get music and TV Show files to keep legal or not, that are still under the radar, and lots more Secure packet wise... The MPAA RIAA is still playing catchup. like a big wack a mole game...

People that appricate the content Buy it when it becomes available in an acceptable medium (alla DVD CD whatever). If they do not they never will. thats just the way it is. and always will be.

Score: 0

|

LOL. This is proof that McAfee sucks. They're just learning that now???? WTF.

Score: 0

|

Christ.
This sort of thing has been happening since 2003, if not earlier.

Basically, if you're a complete computer n00b, be afraid; if not, as we here at BetaNews aren't, this is old and repetative news.

Score: 0

|

No kidding....

THIS JUST IN!!!

Betanews has just learned that the "lost" dead relative in Nigeria, is not real!!!

Score: 0

|

Seriously.

I half expected the story to being with:

Dateline: 1996.

Score: 0

|

Wait a second!!! You mean last nights episode of Lost in HD thats only 278kb is malware???

Crazy times we live in!

Score: 0

|

lmao...

That's nothing. I found a pre-air copy of next week's in 1080p that was only 36k. I'm sure it's just a link-file telling me how to download the rest of it...

...right?

Score: 0

|

lol...

You know as much as we get a kick out of it, there are people that just don't know. To us it probably is like saying the sky is blu, but I guess we're not everybody.

Score: 0

|

The world would definitely be an interesting place if they were. ;)

Score: 0

|

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Why would Windows 7 customers spend $120 more for BitLocker?

For pre-orders from now until July 11, Microsoft is offering the Windows 7 Professional SKU for a very steep discount. So why invest in Ultimate?

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

SMS could be a critical iPhone vulnerability, says white-hat hacker

Mac hacker Charlie Miller knows how to get into your iPhone.

Will Oracle's Java-based Fusion middleware 'fuse' with Java?

Now that Oracle has acquired Sun Microsystems, Java developers and supporters are wondering when Oracle will formally welcome Java into the family.

All together now: iPhone and Palm Pre, likely to both grace O2's UK portfolio

European wireless network operator O2 has reportedly reached a deal to exclusively carry the Palm Pre in the UK. O2,...

Vista's dead: Microsoft kills an OS and no one cares

Carmi Levy: Wide Angle Zoom Can you kill an operating system? Microsoft is about to find out.

Kantaris Media Player 0.5.7

July 3 - 5:34 PM ET

Wine 1.1.25

July 3 - 5:30 PM ET

ChrisTV Online! Free 4.00

July 3 - 5:22 PM ET

glu 1.0.19 RC1

July 3 - 5:11 PM ET

Website-Watcher 5.1.0 Beta 10

July 3 - 1:20 PM ET