Gnutella Forums  

Go Back   Gnutella Forums > Gnutella News and Gnutelliums Forums > General Gnutella / Gnutella Network Discussion
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

General Gnutella / Gnutella Network Discussion For general discussion about Gnutella and the Gnutella network.
For discussion about a specific Gnutella client program, please post in one of the client forums above.


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old June 12th, 2002
Novicius
 
Join Date: June 12th, 2002
Posts: 3
hunangarden is flying high
Exclamation Virus/trojan launched when playing .mpg file

I downloaded an .mpg file and when I double clicked it, it launched Windows Media Player and started to play.

Then a bunch of browser windows started opening, directed to porn sites. Then my anti-virus software said I had js/seeker virus/trojan.

Anyone know how the .mpg file was able to do this? Are the holes in Windows Media Player? Hidden File extension (not likely, since phex showed it as .mpg)?


Help.
Thanks.
Reply With Quote
  #2 (permalink)  
Old June 12th, 2002
Paradog's Avatar
Distinguished Member
 
Join Date: April 5th, 2002
Location: Germoney
Posts: 739
Paradog is flying high
Default

I bet it was a .asf file.
ASF files have to ability to direct you on a website
with the Internet Explorer. There he can use JavaScript
to do malicious things.

As far as I know there's nothing to do about the asf
files opening iexplore
Reply With Quote
  #3 (permalink)  
Old June 12th, 2002
Novicius
 
Join Date: June 12th, 2002
Posts: 3
hunangarden is flying high
Unhappy

Yeah, but...
I downloaded the .mpg using PHEX.
Phex prompts you for a file name when downloading, so I edited the filename which was quite long, and specifically entered the inocuous name "An.mpg".

So there was no hidden file extension, unless Phex is hidding those exentsions as well, which seems pretty weird since its java and all.

I'm fairly certain it was just a .mpg file without a hidden extension, I will do more research tonight.

Is there anyway a file with an extension of .mpg (without any hidden extension) can cause a trojan to be triggered? Are there some flaws in windows Media player that allow this?

Stumped.
Reply With Quote
  #4 (permalink)  
Old June 12th, 2002
Gnutella Veteran
 
Join Date: March 24th, 2002
Location: Virginia
Posts: 101
tshdos is flying high
Default

You can rename an asf file to mpg and it will still play, Windows Media Player just guesses what it is when it opens it. So it could have been ( and probably was ) really an asf file.
Reply With Quote
  #5 (permalink)  
Old June 12th, 2002
Unregistered
Guest
 
Posts: n/a
Default

or worse, it was a exe file and you renamed it
why are you all so happy when you run a lame OS and have problems like this?

Last edited by KathW; June 13th, 2002 at 12:29 PM.
Reply With Quote
  #6 (permalink)  
Old June 12th, 2002
Gnutella Veteran
 
Join Date: March 24th, 2002
Location: Virginia
Posts: 101
tshdos is flying high
Default

Quote:
Originally posted by Unregistered
or worse, it was a exe file and you renamed it
If it was an exe it wouldn't have played.

Quote:
Originally posted by Unregistered
why are you all so happy when you run a lame OS and have problems like this?
asf, another windows security hole, when are you people going to get a clue?
asf is not a security hole, it just allows for scripting like many other formats.
Reply With Quote
  #7 (permalink)  
Old June 12th, 2002
Gnutella Muse
 
Join Date: February 3rd, 2002
Posts: 186
mrgone4662 is flying high
Default

Quote:
Originally posted by Unregistered
why are you all so happy when you run a lame OS and have problems like this?
the driver support is nice
Reply With Quote
  #8 (permalink)  
Old June 12th, 2002
Novicius
 
Join Date: June 12th, 2002
Posts: 3
hunangarden is flying high
Talking Mystery Solved

Paradog and tshdos were correct.

The file was in fact a asf file with an mpg extension.
I had to download the Windows Media Resource kit to analyse the file.

The asf file contains a script command that causes IE to go to a URL. That page contains the evil JS/seeker code.

Thank you for all your help.

If you have any thoughts on how I can safely play mpeg/mpg files please let me know.
Reply With Quote
  #9 (permalink)  
Old June 12th, 2002
Gnutella Muse
 
Join Date: February 3rd, 2002
Posts: 186
mrgone4662 is flying high
Default

1) use a different browser (i recommend Opera)

2) set up a firewall and block Internet Explorer and Windows Media Player from connecting to the internet

(there are probably a million other solutions as well, but this is the first that came to mind. someone who watches more movies on their comp should be able to assist more.)
Reply With Quote
  #10 (permalink)  
Old June 13th, 2002
igalan's Avatar
Enthusiast
 
Join Date: November 27th, 2001
Location: Barcelona
Posts: 38
igalan is flying high
Default Re: Mystery Solved

Quote:
Originally posted by hunangarden
If you have any thoughts on how I can safely play mpeg/mpg files please let me know.
Use BSPlayer, it will play fine your ASF files and no scripts! (BSPlayer is like WinAmp but for video, you can even get new skins -the default is ugly - ). Also you can download ASFTools and remove any URL or convert the ASF into AVI (I prefer this).
__________________
| Israel Galan
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus File/Trojan warning Hatt Tips & Tricks 5 February 28th, 2007 10:25 AM
All movies have virus/trojan etc.... coastalpatrol Open Discussion topics 4 January 1st, 2007 12:31 PM
adware, trojan, virus, ect. dgrn Download/Upload Problems 1 January 12th, 2006 11:59 AM
VIRUS TROJAN Warning flymang1 General Gnutella / Gnutella Network Discussion 0 January 8th, 2005 07:23 PM
virus or trojan found on mac serevro Open Discussion topics 0 July 28th, 2004 02:41 PM


All times are GMT -7. The time now is 06:31 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.