"This is one of the most prevalent pieces of malware in the last three years," said Craig Schmugar, a McAfee Avert Labs researcher, in an e-mailed statement. "We have never before had a threat this significant that arrives as a media file."
The malware does not affect computers running Mac OS X.
The malicious media files appear to be either MP3 audio files or MPEG video files and can be found on file-sharing services like LimeWire and eDonkey. McAfee believes they were placed there by cybercriminals.
When a user tries to play one of the infected media files, he or she is prompted to download a file called PLAY_MP3.exe, Schmugar explained in a blog post. The file does not contain music or video as advertised. Rather, the Trojan program -- Downloader-UA.h -- presents users with an end-user license agreement. If the user agrees to the terms set forth in the 4,800-word EULA, he or she consents to the installation of NetNucleus' Mirar Toolbar adware, and the Trojan downloads the adware "FBrowsingAdvisor" and "SurfingEnhancer," which serve pop-up and pop-under ads.
"In the end you're left with a fake MP3 file taking up space, a worthless MP3 player, adware that claims not only to not display popups, but also to block them, and more adware that successfully displays popup and popunder ads," Schmugar wrote.
In December 2006, NetNucleus threatened to sue security company Sunbelt Software for categorizing its Mirar software as adware. Mirar, the company insisted in a letter, "is a bona fide search tool that collects keywords from Web sites to direct users towards similarly themed sites." A month later, Sunbelt's attorney responded, insisting in a letter that Mirar's designation as adware was accurate.
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.