Tech ARP Forums

Go Back   Tech ARP Forums > Software Discussion > General Software
Register
FAQ Members List Calendar Arcade Mark Forums Read

Google Web www.techarp.com forums.techarp.com

General Software This is the forum for general discussions about software.

Reply
 
LinkBack Thread Tools
Old 12th Jan 2005, 01:24 AM   #1 (permalink)
Super Active
 
Join Date: 13 Oct 2004
Posts: 2,356
Reputation: 197
SAMSAMHA has a spectacular aura aboutSAMSAMHA has a spectacular aura about
Rep Power: 9
Default Video files appear that download malicious application when they are run

MS is apparently helping spyware (well they are not at fault, rather their buggy software.

Quote:
These files are .wmv files infected by Trj/WmvDownloader.A and Trj/WmvDownloader.B, two Trojans that take advantage of a new technology incorporated in Microsoft Windows Media player to install spyware, adware and dialers, as well as computer viruses.

PandaLabs has detected the appearance of two new Trojans, Trj/WmvDownloader.A and Trj/WmvDownloader.B, which are spreading through P2P networks in video files. These Trojans take advantage of the new technology incorporated in Microsoft Windows Media player called Windows Media Digital Rights Management (DRM), designed to protect the intellectual property rights of multimedia content. When a user tries to play a protected Windows media file, this technology demands a valid license. If the license is not stored on the computer, the application will look for it on the Internet, so that the user can acquire it directly or buy it. This new technology is incorporated through the Windows XP Service Pack 2 + Windows Media Player 10 update.



The video files infected by these Trojans have a .wmv extension and are protected by licenses, supposedly issued by the companies overpeer (for Trj/WmvDownloader.A), or protectedmedia (for Trj/WmvDownloader.B). If the user runs a video file that is infected by one of these Trojans, they pretend to download the corresponding license from certain web pages. However, what they actually do is redirect the user to other Internet addresses from which they download a large number adware (programs that display advertisements on screen), spyware, dialers (applications that dial-up high rate toll numbers) and other viruses. Below are some examples of the malicious programs and viruses these Trojans download:

Adware/Funweb

Adware/MydailyHoroscope

Adware/MyWay

Adware/MyWebSearch

Adware/Nsupdate

Adware/PowerScan

Adware/Twain-Tech

Dialer Generic

Dialer.NO

Spyware.AdClicker

Spyware/BetterInet

Spyware/ISTbar

Trj/Downloader.GK

Even though these Trojans have been detected in video files with extremely variable names which can be downloaded through P2P networks like KaZaA or eMule, bear in mind that they can also be distributed through other means, such as files attached to email messages, FTP or Internet downloads, floppy disks, CD-ROM, etc. Panda Software has made the corresponding updates to its anti-malware solutions available to its clients to detect and disinfect any video file protected by the licenses used by Trj/WmvDownloader.A and Trj/WmvDownloader.B to carry out their malicious actions. Similarly, the Panda Software solutions protect users against the malware that these Trojans try to install on computers.
SAMSAMHA is offline   Reply With Quote
SPONSOR
Old 25th Apr 2006, 06:00 PM   #2 (permalink)
Getting there
 
Join Date: 18 Aug 2004
Location: Ex-Tokyo shoebox renter
Posts: 230
Reputation: 28
b104 is on a distinguished road
Rep Power: 6
Default

For DRM to work properly does it need both SP2&WMP10 together or is it installed with just one of the updates ?
Even bloody Creative has got in on the act,where for further updates for Audigy2 &the like ,you have to install DRM as part of one of the updates. Dont like being held to ransom!
Hope some other soundcard manufacturer can start making some decent cards so we have an alternative to compulsory software installs!
__________________
B104
b104 is offline   Reply With Quote
Old 26th Apr 2006, 05:51 PM   #3 (permalink)
Warming up
 
Join Date: 24 Apr 2006
Posts: 118
Reputation: 15
Kalo is on a distinguished road
Rep Power: 4
Angry

DRM is in WMP9, but I think it was cracked...and the WMP10 release, the DRM has not been cracked. It does not require SP2 to be installed. I also couldn't agree with you more on the problem with Creative...
Kalo is offline   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
The Video BIOS Flashing Guide! Adrian Wong Reviews & Articles 10 14th Apr 2004 09:07 AM


All times are GMT +8. The time now is 12:35 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Copyright © 1998-2009 Tech ARP. All rights reserved.