Trojan adware hiding in MP3s, McAfee says
Peer-to-peer networks vector of latest infections
May 7, 2008 12:00 PM ETIDG News Service - Adware pushers have found a new way to trick you into downloading their annoying products: fake MP3 files.
On Tuesday, security vendor McAfee Inc. reported that it has seen a huge spike in fake MP3 files spreading on peer-to-peer networks. Although the files have names that make them look like audio recordings, they're really Trojan horse programs that try to install a shoddy media player and adware on your computer, said Craig Schmugar, a researcher at McAfee.
"Once you run it, there is no content. You're taken to this site to install this player which you don't really need," he said.
Fake file names include: preview-t-3545425-changing times earth wind .mp3 and t-3545425-just got lucky.mp3. Schmugar listed more filenames, as well as details on the adware, in a Tuesday blog post.
Ironically, while the Mirar software tells users that it doesn't display popups, NetNucleus does deliver popup ads, so users who do not realize that they are installing two programs might feel tricked, Schmugar said. "You have a Window telling you that there are no popups and right behind it is a popup."
Although McAfee has seen some nasty software disguising itself as media files in the past, it has never seen anything on this scale, Schmugar said. Over the past 24 hours, nearly a third of the McAfee customers who reported data back to the security company have detected these files, he said.
In the past few days, McAfee has spotted the files on more than 360,000 users' desktops.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
adware
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Network Security Overwatch Layer: Smarter Protection For the Enterprise
Download this whitepaper now!
Best Practices for Log Monitoring
Watch Now!
Endpoint Security: When Encryption Isn't Enough
Over 60% of data breaches are caused by careless employees or insider theft.
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
3 Tips for Faster File System Auditing
Download this White Paper Now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Network-Optimized, Secure Replication for Enterprise-Class Disaster Recovery
Download this resource now!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Interactive Brochure: iPhone in the Enterprise
Download This Resource Today!
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

