Pornoplayer installed from fake Windows Codec

There are several ways modern spyware is infecting unsuspecting systems these days. The most common is still the method of bundling malware into trojans so that the user has as little to do with the installation process as possible. Downloader-ADV is a very large series of Trojan downloaders designed to cripple a machine with adware, password crackers, spyware, and other malware. One instance of Downloader-ADV, innocently named loader.exe, drops a pornography media player under the guise of a perfectly legitimate Windows codec. The name of this player is appropriately named, Pornoplayer.

Upon installing loader.exe, it will phone home to You may recognize this site for such infamous hits as PWS-Pinch and Agent-ECM. You are then directed to a pornography site called


This site pushes on the user a seemingly legitimate codec from Microsoft.


This is actually an installer for Pornoplayer!


Other files are also installed along with the Downloader-ADV/Pornoplayer combo. Research also points to installing another part of the Trojan downloader as well as being redirected to This site is a warehouse for pornography that installs ICOO products.

