1

I downloaded a .wmv file (supposedly the new movie War Dogs) from thepiratebay.org, and when I tried to play it using VLC, a dialog box popped up, indicating some error. Information about this error kept on being written to this box so VLC was looping and I quit it by right-click -> quit.

The readme file associated with the .wmv file said to use windows media player, but here is where I got suspicious and shift+del both the readme file and the .wmv file. After some searching, I came across the following reddit post: https://www.reddit.com/r/Piracy/comments/4g3b8f/psa_codecfixexe_virus_appearing_in_certain_video/

This led to me to these two stackexchange posts: 1. Can a rogue .wmv file "hijack" Windows Media Player? 2. Is VLC on Linux vulnerable to an attack from .wmv files designed to install viruses?

Based on the reddit post and the readme file, I'm pretty sure that I downloaded the same malicious file as the guy from the first stackexchange post. So my question is: Is my computer infected?

Based on the second stackexchange post, the answer appears to be no, but that question was about VLC on Linux, while I am on Windows 7. My computer has been behaving completely normally, but I don't have an antivirus installed. However, I did do a quick scan using the Microsoft's August 2016 malicious software removal tool, and it couldn't find any infected files. Anyways, I'm still a bit worried so can anybody confirm that this virus doesn't work with VLC?

By the way, when I went back to the pirate bay to check out this torrent, it was gone, but now, there's another War Dogs torrent that has about 17000 seeders and 800 leechers; I suspect it's the same malicious file: hxxxs://thepiratebay.org/torrent/15555357/War_Dogs_2016_720p_BrRip_x264_-_SPARKS

Steffen Ullrich
  • 184,332
  • 29
  • 363
  • 424
Carl
  • 11
  • 1
  • 2
  • The readme file tells you to use WMP to open the file, so there's a good chance the exploit only works against that player (otherwise why would they tell you to use it?). Since you didn't open it you are safe. – André Borie Aug 13 '16 at 03:01
  • Micrisoft scanner won't detect such malware. It has very low detection ratio and I am not sure if it scans wmv files at all. – Aria Aug 13 '16 at 14:19
  • @Aria if the malware is the same as in the linked question them the video file does not contain it - it just contains an URL and hopes to social-engineer the user to make them install the "codecs" located at that URL. It's only once they try to download it that antimalware would (hopefully) catch the malicious .exe. – André Borie Aug 13 '16 at 20:31
  • I'm not sure how we could possibly determine if your computer is infected. I'd assume that you are, and move forward from that assumption. – schroeder Aug 15 '16 at 07:17

1 Answers1

0

I run this myself and what it did it created some files:

  • c:\users\me\Temp\LH4P238G44.exe
  • c:\drive_c\users\me\Temp\1AI9XBO4U6\bureautique.exe
  • c:\onespd\otutnetwork.exe and config.ini
  • c:\Program Files (x86)\onespd

In config.ini there's maji=tytyuaaua

Here are the scans results: https://virustotal.com/en/file/f67590816306117e88ef6c67c6f5d6d1453ddfa1460c4dab846b86184982dec9/analysis/1471121151/

https://virustotal.com/en/file/d129792d6afa7b2cf1bfb86f225822cb941c99e30ce264026963aaf56a3e2e93/analysis/1471121206/

https://virustotal.com/en/file/21c68d4b6914bc1e185c03c632d6f2eaf779ea9e8ebe4075a45015733edd41fe/analysis/1471121316/

https://virustotal.com/en/file/807878a330893176423d8567d8fe0a091d41c11f3fe410ad18a10cb93d349263/analysis/1471121259/

https://virustotal.com/en/file/7322c3fefd8c25de5df9c5d4251aa157632f80126b9adf5810999a268f9aa52b/analysis/1471121330/

You get free panda now and get rid of it ASAP.

Here is the scan of original file:

https://virustotal.com/en/file/c9c4c39a294cbf3b62fc11376101d2d78201da4da066509d67892b698d201720/analysis/1471121592/

Aria
  • 2,706
  • 11
  • 19
  • I downloaded malwarebytes yesterday and ran a full scan; it only found some PUP files. I tried opening the .wmv file with VLC, not WMP, so I was never confronted with the prompt to download any malicious .exe. I also don't have any of the files mentioned above in my C:\ directory. I'll still download panda antivirus to see if it'll pick up anything malwarebytes missed. Thank you for your help! – Carl Aug 13 '16 at 23:28