Fake music, video files spread malware on P2P, says McAfee

By Ed Oswald | Published May 7, 2008, 5:24 PM

McAfee is warning file-sharers that they may be at risk due to a Trojan horse posing as an MP3 or MPEG file.

The security firm said Tuesday that it had detected a half million instances of the malware since Friday, dubbed "Downloader-UA.h." It is calling the incident the most significant malware outbreak in three years.

A check of McAfee's virus map showed the majority of infections have occurred in the US during the past 24 hours, although high rates of infection are being reported in Mexico, Venezuela, Brazil, Australia, and much of Western Europe.

It appears as if the files are located on Gnutella and Limewire under a variety of names. When loaded, the file redirects through the player to a download of a file called PLAY_MP3.exe.

Once this file loads, it shows up a EULA, and if accepted, the files "FBrowsingAdvisor" and "SurfingEnhancer" are installed. The file PlayMP3.exe is also installed, but instead of it being an actual local MP3 player, the application loads up a webpage with the Wimpy Flash MP3 player with several dozen songs available.

The two previous files are believed to load some type of adware, which instead of blocking popups like the EULA claims deliver them to the end user.

McAfee rated the issue a "medium" risk, the first time its given any piece of malware such a high rating since 2005.

Comments

View comments by with a score of at least

Who even uses McAfee? Its just as bad as Nortan...

Score: 0

|

oooooooooooooooo

I'm shakin' in my boots... hahahaha

Score: 0

|

How come an MP3 file can start another process to download and install something?

Score: 0

|

Read the article, Joco.

PLAY_MP3.exe

Score: 0

|

So glib PC, jebus.

Joco in reference to "When loaded, the file redirects through the player to a download of a file called PLAY_MP3.exe"

The file is fake as the article mentions, so it's probably coded through script to load a webpage and download that file when the file is 'played'. It's not a real mp3 at all so obviously you don't hear anything when you 'play' it.

Score: 0

|

Thanks for your reply. You would be surprise that I did read the article.

It is confusing. And I honestly wonder if you had read and understood the article. It said "It appears as if the files are located on Gnutella and Limewire under a variety of names. When loaded, the file redirects through the player to a download of a file called PLAY_MP3.exe."

The song I wanted is, let's say "Hotel California.mp3". That would be exactly that file that I would download. Even if it's fake, then that would play some gibberish sounds within Foobar. What I don't understand is that the PLAY_MP3.exe got into the computer when the media player plays the mp3.

Score: 0

|

Ya got me.

I skimmed and got "download of a file called PLAY_MP3.exe."

;)

Regardless, it would have to be an executable or script file (not a .mp3/.wma) file as I understand it. AFAIK, .com, .exe, and certain script extensions (none of which are .mp3, or .wma) can actually execute code.

Now...

...if a malformed audio file (say, with bad metadata?) ran in a player that for some asinine reason ran scripts, or took cues from the Metadata, it could wreak havok with the player, but even then, that'd be pretty hard to accomplish.

If Ed could have given an example or two of the names in questionm we would not only have something to watch out for it would clear up a lot of this confusion.

Score: 0

|

Don't blame jebus, he had nothing to do with it. 100% on me, man. ;)

Score: 0

|

Like DUR the MPAA and RIAA and other people that wish users harm has been doing this very thing for years already. lol Ahh well Not that it matters much anymore anyway.

I know so few people getting things this way now, it almost seems as obsolete as Napster is... There are so many better ways now to get music and TV Show files to keep legal or not, that are still under the radar, and lots more Secure packet wise... The MPAA RIAA is still playing catchup. like a big wack a mole game...

People that appricate the content Buy it when it becomes available in an acceptable medium (alla DVD CD whatever). If they do not they never will. thats just the way it is. and always will be.

Score: 0

|

LOL. This is proof that McAfee sucks. They're just learning that now???? WTF.

Score: 0

|

Christ.
This sort of thing has been happening since 2003, if not earlier.

Basically, if you're a complete computer n00b, be afraid; if not, as we here at BetaNews aren't, this is old and repetative news.

Score: 0

|

No kidding....

THIS JUST IN!!!

Betanews has just learned that the "lost" dead relative in Nigeria, is not real!!!

Score: 0

|

Seriously.

I half expected the story to being with:

Dateline: 1996.

Score: 0

|

Wait a second!!! You mean last nights episode of Lost in HD thats only 278kb is malware???

Crazy times we live in!

Score: 0

|

lmao...

That's nothing. I found a pre-air copy of next week's in 1080p that was only 36k. I'm sure it's just a link-file telling me how to download the rest of it...

...right?

Score: 0

|

lol...

You know as much as we get a kick out of it, there are people that just don't know. To us it probably is like saying the sky is blu, but I guess we're not everybody.

Score: 0

|

The world would definitely be an interesting place if they were. ;)

Score: 0

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."