Home
Terms & Definitions
Parasites List
Categories
Threat Level
Contact Us
Spyware Information
Name: WurldMedia
Threat Level:
Category: Adware
Aliases: Morpheus Shopping Club, WURLD Shopping Community or BuyersPort

Variants: WurldMedia/bpboh: first variant released with early Preview Releases. You have this variant if there is a file called "bpboh.dll" in your Windows directory. Presumbly the name should have been 'bpbho' (Buyers' Port Browser Helper Object), but someone made a typo. There will also be a 'rdxrNNNN.de' file containing an encoded target list. (NNNN is some numbers, looks like a date.)

WurldMedia/mbho: installs 'mbho.dll' and the 'rdxr' data file in the System directory instead of the Windows directory. Installer is not so stealthy and includes an option to prompt the user before redirecting a merchant site. However, if "enable" (the default option) is chosen on any of these prompts, it will be silent again forever.

WurldMedia/MSCStat: in this variant you get a 'MSCStat.exe' system tray program in the System directory, with an 'msc(numbers).de' file and 'ad(numbers).de.xml' as well as the files from the mbho variant. WurldMedia/MSCStat2: the MSCStat.exe file is renamed MSCStat2, and there is finally an entry in Add/Remove Programs, which disables the software (though it leaves behind the files and some registry entries).

WurldMedia/MShop, WurldMedia/MPohs and WurldMedia/MDef have new IDs and filenames: m030106shop.dll, m030206pohs.dll and mdefshop.dll, respectively.

WurldMedia/Mo and WurldMedia/Moaa. The BHO is renamed mo030414s.dll or moaa030425s.dll and has new ID; the mscstat process is renamed mostat.exe and there is a configuration program called moconfig.exe.

WurldMedia/TChk is bundled with the Mo and Moaa variants. It checks for the existance of the WurldMedia BHO, and, if it finds it missing, it contacts its controlling server xnef.com which direct TChk to reinstall the software. WurldMedia/TChk tries to escape detection by using a completely random filename and ID


Spyware Characteristics
Description: An IE browser helper object that detects visits to known sites and redirects them through a third-party server in order to take the affiliate fees. WurldMedia even steals the fees from other webmasters when you use their own links.

Properties:
  • Stays resident in background.
  • Stealth: hides itself from user.
  • Show advertisements.
  • Makes changes to browser settings.

What it does?
Advertising: No.

Privacy violation: Yes, WurldMedia will be informed of visits to any of their targeted sites with referring site information and user-tracking through a unique ID built into the software.

Security issues: Yes, for MSCStat and later. These versions can connect to its controlling servers when IE is first run to download a new version of themselves, allowing arbitrary code to be executed.

Stability problems: The redirect mechanism used by this software breaks the web browser's 'back' button in some variants.

Method of infection
Bundled with Morpheus.

Removal Instructions
bulletproofsoft.com "Spyware Remover" is the best tool for the removal of this spyware.

Links
Site: http://www.wurldmedia.com/