Old Trick New Dog...
Posted: Mon Apr 11, 2005 2:35 pm
Okay I know that this is a virus thats been around a long time but there seems to be two changes lately.
One is it caught my attention with all the searching I've been doing recently, and..
Two is that it has the names of not only porn type files (supply and demand), but many of the artists that are being flooded right now by the RIAA.
So I felt it was fitting to warn folks about this little nasty and I felt that the most appropriate place was the WinMX section.
I have seen it several times in searches I have been doing on WinMX.
So you may wonder now why I am bringing this up in a new post. The reason is because of the way this file is being circulated on WinMX.
Its quite strange to me that "All of a Sudden" .. the names on the files come up in searches for flooded artists that i do...
This has RIAA written all over it if you ask me.
One of the Hash numbers is
HASH>6735343b0d7fba50937affaafc80b113-22975
The File size is always 22,975 bytes.
If you download this file, and try to play it in your Windows Media Player, it trys to connect to a outside website called:
h.t.t.p.:././.w.w.w...inet4you.com/cgi-bin/license.cgi that is hidden in the code of this beast.
Once it connects its allows other little nastys in, that strike havoc on your machine. Opens up a porthole so to speak to allow its little trojans in, or to allow someone access to your machine.
Now who can I think of that would want to have access to your machine because your on WinMX?..
If you see a file like the one below in someone's shares or in a search beware.. and please try to pass on this information.
Be warned there is some not nice words in this.. I felt it necessary not to edit it so that you could see what they look like..

Notice the names of different mp3's
One is it caught my attention with all the searching I've been doing recently, and..
Two is that it has the names of not only porn type files (supply and demand), but many of the artists that are being flooded right now by the RIAA.
So I felt it was fitting to warn folks about this little nasty and I felt that the most appropriate place was the WinMX section.
I have seen it several times in searches I have been doing on WinMX.
http://support.microsoft.com/?kbid=308567Advanced Streaming Format (ASF) is one of the streaming media formats that is supported by Windows Media Player. A security vulnerability occurs in Windows Media Player 6.4 because the code that processes ASF files contains an unchecked buffer.
By creating a specially-malformed ASF file and inducing a user to play it, an attacker could overrun the buffer, with two possible results. In the simplest case, Windows Media Player 6.4 would stop working, and in the more complex case, code that was chosen by the attacker could be made to run on the user's computer, with the privileges of the user. The scope of this vulnerability is rather limited. It affects only Windows Media Player 6.4, and can only be exploited by the user opening and deliberately playing an ASF file. There is no capability to exploit this vulnerability by using e-mail messages or a Web page.
In addition, some of affected components of Windows Media Player 6.4 (for purposes of backward compatibility) are included with Windows Media Player 7 and 7.1.
Windows Media Player for Windows XP includes components of Windows Media Player 6.4, but they are not affected by the ASF buffer overrun or by any of the other vulnerabilities that are described in the preceding security bulletins. However, the version 6.4 components that are included with Windows Media Player for Windows XP are affected by some of the newly-discovered variants of these vulnerabilities.
So you may wonder now why I am bringing this up in a new post. The reason is because of the way this file is being circulated on WinMX.
Its quite strange to me that "All of a Sudden" .. the names on the files come up in searches for flooded artists that i do...
This has RIAA written all over it if you ask me.
One of the Hash numbers is
HASH>6735343b0d7fba50937affaafc80b113-22975
The File size is always 22,975 bytes.
If you download this file, and try to play it in your Windows Media Player, it trys to connect to a outside website called:
h.t.t.p.:././.w.w.w...inet4you.com/cgi-bin/license.cgi that is hidden in the code of this beast.
Once it connects its allows other little nastys in, that strike havoc on your machine. Opens up a porthole so to speak to allow its little trojans in, or to allow someone access to your machine.
Now who can I think of that would want to have access to your machine because your on WinMX?..
If you see a file like the one below in someone's shares or in a search beware.. and please try to pass on this information.
Be warned there is some not nice words in this.. I felt it necessary not to edit it so that you could see what they look like..

Notice the names of different mp3's