Pornoplayer installed from fake Windows Codec

| | Comments (0)

There are several ways modern spyware is infecting unsuspecting systems these days. The most common is still the method of bundling malware into trojans so that the user has as little to do with the installation process as possible. Downloader-ADV is a very large series of Trojan downloaders designed to cripple a machine with adware, password crackers, spyware, and other malware. One instance of Downloader-ADV, innocently named loader.exe, drops a pornography media player under the guise of a perfectly legitimate Windows codec. The name of this player is appropriately named, Pornoplayer.

Upon installing loader.exe, it will phone home to You may recognize this site for such infamous hits as PWS-Pinch and Agent-ECM. You are then directed to a pornography site called


This site pushes on the user a seemingly legitimate codec from Microsoft.


This is actually an installer for Pornoplayer!


Other files are also installed along with the Downloader-ADV/Pornoplayer combo. Research also points to installing another part of the Trojan downloader as well as being redirected to This site is a warehouse for pornography that installs ICOO products.

Leave a comment

About this Entry

This page contains a single entry by Chris Mannon published on June 22, 2007 11:18 AM.

Problem With Windows Live ID Fixed was the previous entry in this blog.

GTA: Hoodlife - Virus Attack is a Public Enemy is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.