Gnutella Forums

Gnutella Forums (https://www.gnutellaforums.com/)
-   Download/Upload Problems (https://www.gnutellaforums.com/download-upload-problems/)
-   -   New Virus On Limewire (https://www.gnutellaforums.com/download-upload-problems/84503-new-virus-limewire.html)

BCOOL May 21st, 2008 01:54 AM

New Virus On Limewire
 
Hi Everybody.
Just to give you all a heads up there's a new virus on Limewire. :mad:
Trojan-Downloader.WMA.Wimad.n....It showed up April 7 2008.I picked it up yesterday.My ZoneAlarm zapped it. Lucky ya...Thing is,it looked like a normal MP3...BEWARE :eek:

ursula May 21st, 2008 10:30 AM

Thanks for the HU, but, PLEASE, remember... there are NO viruses on Limewire...

Limewire is simply one of numerous p2p 'clients' that work within the Gnutella Network...

The viruses that are out there are from US.

US meaning normal users.

Many 'normal users' do not know that they are sharing infected files.

This is because they are, first, victims of the idiocy and arrogance of the client developers and, further, because they are trying to run a marathon before they can even fantasize about crawling.

The above means that one should NEVER allow ANY sharing from the default DownLoads Folder...
NEVER allow 'Partial Filesharing'...
NEVER put any file into a Shared Folder until it has been checked for viruses, proper tagging and actually TESTED !
In simple words... If you do NOT know the quality of something, why should you share it with someone else ?
And, if one does share without first really checking the quality, than there is absolutely no grounds for complaint, right ???

Those who share sh¡t are THE PROBLEM.
Each and every one of us must use great discipline to be certain to NOT share sh¡t.
It's easy if you care.

Hey, BCOOL, the above isn't aimed AT you...
Just saw the soap-box you carried out here to the field and thought I climb on !!!

Ta !

p.s. As long as I am up here, on the box, could a request also be made to you fools that are sharing huge numbers of files to NEVER EVER be an Ultrapeer ?
You are wrecking the network with such stupidity. You're also limiting your own p2p activities !

BCOOL May 21st, 2008 09:17 PM

OK...Lets all give a big hand to ursula :xirokrotima: :xirokrotima: :xirokrotima:

I'm sad to say I got hit with that Trojan again today.Like before it looked like a legitimate MP3.Am I the only one? :pullinghair:

90hoursleep May 21st, 2008 09:55 PM

um il download something that looks like an mp3 , but it doesnt play music , and then il do a search for another mp3 and it says ive already downloaded it .... im guessing thats the virus ? ( im a n00b by the way )

BCOOL May 22nd, 2008 12:16 AM

Howz It 90hoursleep,

I'm not sure what you downloaded.Here is a little information on Trojan.Downloader.WMA.Wimad.N.


While accessing the ".wma" which is a media file extension the following behavior is noticed :

1. A browser page opens to a certain webpage ( fastmp3player.com )
2. It tries to download and execute (when the user hits run on IE ) a malware from the mentioned site.......

1. This adware usually disguises itself as an "codec" for viewing or listening to media files. It states that without this product the user can't access the wanted file. A sample of this kind of strategy of spreading is explained here : Trojan.Downloader.WMA.Wimad.N
2. A window pops up while the user tries to access a certain kind of exploited media file with the title "Play Free MP3s" . It has a checkbox to validate the users choice of the products EULA to a company named "Media Holding Enterprises" . The user has the predefined choice ( the checkbox is already checked ) to install another adware : Adware.Mirar.

.................................................. .................................................. .................................................. ..................


This is an disguised application meant to trick the user to download and execute a malware. Usually it states the false incapacity of your software configuration to view this kind of media. Due to the common misconception that malware or viruses are only in executables, the user could be lead to trust this strategy and install without his knowledge the downloaded threat.

The file could be saved with different names of various celebrities, usually events or generally appealing things to users. This makes the malware spread with the help of users.

First , the malware opens a browser window to fastmp3player.com where it gets a file , which is an installer signed with the name Adware.PlayMp3z.A ( a detailed description of this malware here : Adware.PlayMp3z.A ). The downloaded file is saved with the name "PLAY_MP3.exe" .


I hope this helps you or anyone else that runs in to this Trojan :)

Liberanos5 May 22nd, 2008 01:05 PM

Gotta love a soap box. May I have a turn?? It took me quite a while to undo "VUNDO" that I got through this "client" day one. I paid for PRO with my VISA on 05/07/08. I won't list all the hoops I had to jump through to get "clean" again but it included deleting everything and starting over....a couple a times. Now LIMEWIRE says my account has expired and wants me to pay AGAIN! Everyone that uses this computer has been given lessons on how to avoid a repeat performance....thank you URSULA for a concise and lucid description of how the virii/trojans/malware get spread around. I made both my kids read it. There's a special place in hell for writers of malicious code IMO. It keeps Bangalore busy for sure. Meanwile how do I dowload PRO again??? And yes it says LIMEWIRE LLC INTERNET NY on the transaction.

90hoursleep May 22nd, 2008 07:34 PM

Quote:

Originally Posted by BCOOL (Post 318083)
1. This adware usually disguises itself as an "codec" for viewing or listening to media files. It states that without this product the user can't access the wanted file. A sample of this kind of strategy of spreading is explained here : Trojan.Downloader.WMA.Wimad.N
2. A window pops up while the user tries to access a certain kind of exploited media file with the title "Play Free MP3s" . It has a checkbox to validate the users choice of the products EULA to a company named "Media Holding Enterprises" . The user has the predefined choice ( the checkbox is already checked ) to install another adware : Adware.Mirar.

yea i dont get that so im guessing im ok ? just kinda concerned when i go to delete a "blank" mp3 that wont play , and it says it wont let me because its "in use in an application , or being downloaded to"

frylock04 May 23rd, 2008 08:35 AM

Quote:

Originally Posted by BCOOL (Post 318083)
Howz It 90hoursleep,

I'm not sure what you downloaded.Here is a little information on Trojan.Downloader.WMA.Wimad.N.


While accessing the ".wma" which is a media file extension the following behavior is noticed :

1. A browser page opens to a certain webpage ( fastmp3player.com )
2. It tries to download and execute (when the user hits run on IE ) a malware from the mentioned site.......

1. This adware usually disguises itself as an "codec" for viewing or listening to media files. It states that without this product the user can't access the wanted file. A sample of this kind of strategy of spreading is explained here : Trojan.Downloader.WMA.Wimad.N
2. A window pops up while the user tries to access a certain kind of exploited media file with the title "Play Free MP3s" . It has a checkbox to validate the users choice of the products EULA to a company named "Media Holding Enterprises" . The user has the predefined choice ( the checkbox is already checked ) to install another adware : Adware.Mirar.

.................................................. .................................................. .................................................. ..................


This is an disguised application meant to trick the user to download and execute a malware. Usually it states the false incapacity of your software configuration to view this kind of media. Due to the common misconception that malware or viruses are only in executables, the user could be lead to trust this strategy and install without his knowledge the downloaded threat.

The file could be saved with different names of various celebrities, usually events or generally appealing things to users. This makes the malware spread with the help of users.

First , the malware opens a browser window to fastmp3player.com where it gets a file , which is an installer signed with the name Adware.PlayMp3z.A ( a detailed description of this malware here : Adware.PlayMp3z.A ). The downloaded file is saved with the name "PLAY_MP3.exe" .


I hope this helps you or anyone else that runs in to this Trojan :)

OMG I DOWNLOADED THAT FILE...
but no effects though 4 days passed already I have uninstalled it already and removed from the computer even at recycle bin so how will I play the songs I downloaded? pls answer BCOOL or usrula my pc might be in danger:yikes:

frylock04 May 23rd, 2008 08:48 AM

I HAVE DOWNLOADED THAT FILE BCOOL
but no effects though 4 days have past already, and I have Uninstalled it and removed programs it also so it not in my pc anymore :). So how do I play my downloaded songs? It still opens the browser so same things happen what now? Does re-installing nescessary? Or is their any way that I can play the file w/o making it open a browser? PLS REPLY GUYS NEED HELP FAST thak you in advance

jay736 May 24th, 2008 07:28 PM

i had a few trogans downloading video clips but ZA warned me before I tryed to watch them


All times are GMT -7. The time now is 09:13 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.