The Register® — Biting the hand that feeds IT

Feeds

Trojans exploit Windows DRM loophole

Dirty tricks

  • print
  • alert

Agentless Backup is Not a Myth

Virus writers have subverted digital rights management features in Windows Media Player to spread Trojans and other malware. License-protected movie (.wmv) files infected with the WmvDownloader-A or WmvDownloader-B Trojans have entered circulation on P2P networks, reports Madrid-based antivirus firm Panda Software.

Normally when a user tries to play a protected Windows media file, and a valid license is not stored on a computer, the application will look for it on the internet, so that the user buy access to copyright-protected content. This new technology is incorporated in the latest Windows Media Player 10 update as well as XP SP2.

If the user runs a video file that is infected by one of the "DRM Trojans", they pretend to download the corresponding license from the net. In reality users are redirected to sites that take advantage of Windows vulnerabilities to download spyware, adware, premium-rate diallers and other viruses onto victim's machines.

The Trojans have been detected in video files with extremely variable names circulating across P2P networks such as KaZaA or eMule. File traders beware.

The video files infected by these Trojans have a .wmv extension and are protected by licenses, supposedly issued by the companies overpeer (in the case of WmvDownloader-A) or protected media (for WmvDownloader-B), Panda reports. Overpeer was previously hired by the recording industry to dump fake versions of songs on file sharing networks. Later it lobed pop-ups and adware at users. Loudeye - overpeer's parent company - told PC World last December that P2P users are getting what they deserve.

Whether overpeer has begun using more aggressive tactics is unclear, the evidence against it is circumstantial and it could be other parties have used its name as a convenient smokescreen. ®

Related stories

Firm gives P2P networks adware infection
Fizzer stealth worm spreads via KaZaA
P2P virus fakes nude Zeta Jones pics

Steps to Take Before Choosing a Business Continuity Partner

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?