uTorrent and WinZip New Targets of BitTorrent Malware

Written by enigmax on August 07, 2007 

The best torrent software clients like uTorrent or Azureus are free, no strings attached. However, some companies are making money tricking novice users into installing bad clients, bad media players and even bad Winzip-like software. We expose them and their badware and show you how to block them.

All the best BitTorrent clients (like uTorrent) are free and when you install them they don’t install extra stuff on your PC like adverts, annoying popups or spyware.

However, there are companies out there who give you ‘free’ software (like a torrent client) but at the same time install some of that extra stuff you don’t want too. We have regularly reported on BitTorrent clients which also install this malware such as Torrent101, BitRoll, TorrentQ and GetTorrent. These are just a handful of bad clients currently available online.

It didn’t take much research to discover that a Swedish company called Wakenet is behind the enterprise, a company that made news on lots of spyware sites due to its Anti-Leech plugin.

Wakenet has a new domain called uvTorrent.com (currently diverting to their Cash4Downloads site) - no prizes for guessing the planned confusion with novices and the official ‘uTorrent’ client. They also have a new (fake) ‘compression’ utility called Winzix, obviously named to be confused with Winzip. Unfortunate downloaders will download something from BitTorrent, only to learn that it needs to ‘decompressed’ with Winzix in order to work. Installing Winzix again results in malware getting onto the host PC.

Our investigations revealed two major servers carrying the malware-ridden clients, media players, compression utilities and other sites supporting the enterprise:

IP: 69.72.144.122

1. netpumper.com (there’s even a link to this from Wakenet’s homepage)
2. bitgrabber.com
3. bitroll.com
4. c4dl.com
5. cash4downloads.com
6. download.play3w.com
7. get-torrent.com
8. playon.play3w.com
9. winzix.com (additional information from Symantec)
10. bitdownload.org
11. divoplayer.com
12. plugindl.com
13. torrent101.com
14. torrentq.com
15. torrentsoftware.org

IP: 207.44.244.86

1. bitroll.com
2. c4dl.com
3. cash4downloads.com (Click here for removal instructions)
4. download.netpumper.com
5. Uvtorrent.com
6. playon.play3w.com
7. wakenet.se (WakeNet’s own homepage is on the same server)
8. bitsofporn.com
9. domplayer.com
10. gamingtorrent.com
11. kitplayer.com
12. torrentmusic.org
13. torrentgamers.com
14. Torrentspeeder.com (different server currently)

We suggest that everyone stays well away from every site on the above lists. Use uTorrent or Azureus to download and if you ever download anything that requires anything other than a standard media player or WinRAR in order to play, be a little suspicious. Checking the comments to the torrent you plan to download is always a good idea.

For the little more adventurous reader, it’s possible to use the Windows HOSTS file to block the activity caused not only by the malware listed above but also that from hundreds of other sources. We recommend the excellent guide from MVPS, “Blocking Unwanted Parasites with a Hosts File

UPDATE: Reports suggest that software is now available to play 3WPlayer (and possibly DomPlayer) files without getting either player. This software is untested by TorrentFreak.

UPDATE 2: Software to crack 3WPlayer, WinZix can also be found here. Click here for the .torrent.

If you don't like torrents try MP3 Fiesta. They hold nearly 67,000 albums from nearly 17,000 artists. Prices are around the $0.10 mark for single tracks with full albums coming in at roughly $1.00. Tracks are available from 192kbps and they take major credit cards and PayPal

Previously: Use uTorrent to Organize Your BitTorrent Downloads

Next: Television Studios Embrace BitTorrent

63 Responses (Add yours or TrackBack)

1 Aug 07, 2007 at 15:46 by The Yunvus

It’s usually only noobs who download stuff from shady websites like that… gotta go for the official websites. But it’s unlikely that those noobs would be reading this site either, so this doesn’t really do any good for the potential downloaders of those…
Oh well.

2 Aug 07, 2007 at 18:49 by Jalla

The guy behind wakenet

Johan Anders Christian Wennberg
Birthday: 1981-04-16

Address
Tjustgatan 3 6 TR
11827 Stockholm
SWEDEN

Cellphone: +46 76-3385430
Home: +46 8-6434227
E-mail: johan@wakenet.se

3 Aug 07, 2007 at 22:05 by Hey You!

Johan Anders Christian Wennberg is the retarded fucker doing all that shit? He want to get rich dirty & quickly! Why that scammer stay so long in business? Nobody wanna to sue for damages that dude do? He is also involved in porn business and drug traffic right?

4 Aug 07, 2007 at 23:42 by That Guy

Wakenet seems to use ZoneEdit instead of hosting their own DNS-server.

Spamming etc, seems to violate ZoneEdits policy
http://zoneedit.com/doc/policy.html

If someone took the time to contact zoneedit, and they choose to terminate wakenets account, all of wakenets sites would go down. Of course, he can always switch to a new DNS-server, but hey, it will disrupt his business.

5 Aug 08, 2007 at 05:28 by Yatti

I use HostsMan… Works great.. Also … WOT Firfox extension also highly recommended!!

6 Aug 29, 2007 at 00:44 by Hari

So if im download bittorrent movie files. after i download them do i use winzip or winzix to decompress the files. im a “noob” but i understand abit about this computer shit but i still duno how to unzip all these torrent files and i no you have to pay for winzip… please help!

7 Sep 17, 2007 at 19:14 by ipswichross

decompression tool=winrar

watch your movies with either..VLC…Media Player Classic or get FFDshow codec pack and use media player.

For virtual drives use Daemon tools (for mounting ISO’s)

These are the basic essentials for all you n00bs out there….Pirates FTW….me hearties..!!

8 Sep 28, 2007 at 17:05 by Tom

Aliens versus predators requiem on isoHunt is one of these files, running on vlc claims it needs domplayer to run. Also pretending to be an aXXo download.

9 Oct 05, 2007 at 20:31 by CiD

Good luck Chuck DVD Rip is one of that movies. Even if archieved with RAR, inside you will find a Zix file in wich you finnaly find the avi file next to a codec.exe, off course, another virus.

10 Oct 12, 2007 at 23:30 by jason

we have got to stop these assholes what sad lives they must be living alien versus predator what a load of crap me like a mug fell for it as well beware we will find you who ever you sados are !!!!!!!!

11 Oct 15, 2007 at 15:07 by Anonymous

[quote comment="154443"]So if im download bittorrent movie files. after i download them do i use winzip or winzix to decompress the files. im a “noob” but i understand abit about this computer shit but i still duno how to unzip all these torrent files and i no you have to pay for winzip… please help![/quote]
http://www.7-zip.org/

12 Oct 17, 2007 at 14:01 by RDS

I downloaded a file (TV show) that said it was an AVI file but it had XRO at the end. When I opened it with the VLC player it said that I had to to have the Domplayer, but I see that this is on the list above.Are all XRO files linked to this Domplayer–how can I know? Is there any way to open this file?
Thanks for any help

13 Oct 17, 2007 at 22:50 by still learning

Bionic.Woman.S01E04.HDTV.XviD-XORx
Downloaded from ‘PLUBE’
Needs Winzix to be instaled first.
I didn’t.
Thanks for the posts.

14 Oct 22, 2007 at 22:02 by Anonymous

Isohunt.com

The.Game.Plan[2007]DvDrip[Eng]-aXXo.avi

Need domplayer to run.
Yet another scam…

15 Oct 29, 2007 at 02:09 by Dan

Just downloaded Iron Man (axxo) and it says I need domplayer… so this is like that 3wplayer? Just malware and shit? Bastards! I read on another site that there’s a way to get the 3wplayer files to play in mediaplayer by deleting a bunch of code. Haven’t tried it yet… heard that when the files are played it’s usually another movie altogether: sometimes porn or could end up being a good movie. Just not the 1 you thought. Has anyone figured out a way to do this with dom player?
For now.. i just comment that its a dom or 3w and let it seed… If more people rated and commented, would be save alot of fustration.

16 Nov 01, 2007 at 20:09 by Jay

I just downloaded 30 days of night and yes I got the same - apparently it needs domplayer - I’m no noob but I was still caught out as i ALWAYS check that the bittorent movies I download aren’t rar or zip files (for the obvious reason that 9 times outta 10 you’re required to visit some bullshit site to get a password to decompress the file), and this showed as an avi file
At the end of the day, are we sure this swedish company etc are in business and being a pain in the ass on their own volition? Remember piracy IS illegal (not that many of us give a damn lol), so it could be that these companies are just a front for the authorities who are obviously trying their hardest to stamp out piracy……
but yes I feel the same as the rest of you - goddamn sick and tired of all these bogus downloads that you have to just delete(if you have any sense) after spending days downloading them

And yes Dan I agree - PEOPLE LEAVE COMMENTS ON BOGUS DOWNLOAD TORRENTS!!!

17 Nov 01, 2007 at 20:13 by Jay

on the subject of passworde rar files though - If any of you know of a free rar password cracker that ISNT a trial version and DOESNT consume shedloads of ram - post a link to it on here please - would save us all a lot of frustration

OR

if you have a rar password cracker with a crack so you dont need to pay to ugrade it to full version - make it into a torrent and again post the link on here…..

18 Nov 03, 2007 at 21:38 by tenacious

I have just downloaded Stardust using the following tracker.
http://tpb.tracker.thepiratebay
.org:80/announce. If your using utorrent
go to the general tag and look at the tracker section. If you see the above tracker stop the download as it requires
dom player.
Don’t get mad, get even.
Find the cracks and post the links here.

19 Nov 08, 2007 at 06:00 by Anonymous

[quote comment="188923"]I downloaded a file (TV show) that said it was an AVI file but it had XRO at the end. When I opened it with the VLC player it said that I had to to have the Domplayer, but I see that this is on the list above.Are all XRO files linked to this Domplayer–how can I know? Is there any way to open this file?
Thanks for any help[/quote]

20 Nov 13, 2007 at 02:50 by sand

yep i got fucked too with that dom shit… well i think i should be happly its not the latest virus on the web.

21 Nov 20, 2007 at 01:44 by rojoman

are all torrent shit how do you know al say download dom

22 Nov 20, 2007 at 22:53 by smoke

i have download a movie from isohunt [isoHunt] Southland.Tales.2007.Eng.DivX-PCR.avi.torrent
it is the same creap shit… it needs domplayer to play so be aware of this fake malewared dirty torrents read the comments and remove that shit from the pc

23 Nov 23, 2007 at 08:43 by haha

dadadaddddddddddddddddddddaaaaaaaaaaaa

24 Nov 25, 2007 at 02:14 by Squire

Its just the authories messing with torrents , fakes, player scams and password scams who else would want to do a thing like that ? We need database or some thing where we could check to see what was clean or not?

25 Nov 26, 2007 at 23:04 by bouncer86

use 3wdecoder to convert domplayer files but dont be suprised if it aint wot it sez it iz

26 Nov 28, 2007 at 00:08 by JakeBlake

No.Country.for.Old.Men.2007.English.TS.DivX-LTT,
this was some Transgaysporn.

domDexter.S02E09.HDTV.XviD.XOR.[eztv].avi,
was an episode from Heroes.

Bouth asked for this crappy domplayer.

“eBomb that Wakenet”

27 Nov 30, 2007 at 09:49 by sam1441

When it ask you for domplayer just pick up and dumb it in the Recycle Bin and do not forget to Empty the Recycle Bin

28 Dec 05, 2007 at 00:22 by kes47

domplayer what is it this site is a load off rubish cant download NOWT

29 Dec 05, 2007 at 20:21 by Anonymous

from bigmack goldin compas dom shit to

30 Dec 07, 2007 at 03:02 by metal6

thanks glad to see this is all bullshit. hopefully i haven’t downloaded some virus.basically we can’t download shit anymore

31 Dec 07, 2007 at 03:03 by metal6

the assholes win for now

32 Dec 08, 2007 at 06:35 by shamshu

i want free don load dom player

33 Dec 08, 2007 at 13:45 by lokey

the mudder fooker who set that domplayer shite up needs to have his bollox slammed repeatedly in a car door, his parents should be raped in front of him and his whole family should be burned alive, what a PRICK! there is no need for it, if you want to send uh-hum, movies across the net for people to download, do it. dont fuck people over. YOU WANKER.

34 Dec 09, 2007 at 12:30 by kingjim

i have downloaded golden compass.3 times. one needs this dompayer shit.the other two require a codec for windows media player.does any one know what this codec is .or am i wasting my time?thank for any coment.

35 Dec 09, 2007 at 15:17 by wayne norman

i have downloaded golden compass TOO
AND GOT THE DOMPLAYER SHIT
quite a lot of the stuff from iso hunt
via azurius needs a secondary [pay for code] or player.
how are they doing it once ya know that
it should be stoppable..
bring on the geeks.
in the mean time it looks like we just gotta delete
wayne

36 Dec 13, 2007 at 16:23 by Anonymous

[quote comment="176112"]Aliens versus predators requiem on isoHunt is one of these files, running on vlc claims it needs domplayer to run. Also pretending to be an aXXo download.[/quote]

37 Dec 18, 2007 at 02:41 by jeff

people have nothing better to do then piss us off we just want to watch a fucking movie the downloads woeked fine before and now they all need this stupid fucking retarded domplater like wtf!!!

38 Dec 18, 2007 at 10:56 by Chargy

Fukin nightmare dwnloadin movies frm u torrent knw. Dwnloaded 2 “i am legends” lst nite as its a film i really wann c but both came up as fakes. wen r those pricks guna find sumfin beta 2 do with their time!!

39 Dec 18, 2007 at 17:01 by ?TF

bit torrent junkie theres a i am legend on there that works ok look for the posts in comments that say something about a guys head being in the way, it is for the first few minues its an ok cam flick if you stay with it for 5 mins

40 Dec 22, 2007 at 20:24 by 2pac

its fucked up

41 Dec 23, 2007 at 17:49 by Anonymous

[quote comment="154443"]So if im download bittorrent movie files. after i download them do i use winzip or winzix to decompress the files. im a “noob” but i understand abit about this computer shit but i still duno how to unzip all these torrent files and i no you have to pay for winzip… please help![/quote]

42 Jan 02, 2008 at 02:54 by golfingmechanic

This is from a newby. Why doesn’t someone figure out how we can recognize a phony. By the way many thanks to AXXO great stuff. It’s a shame some assholes need to screw with his stuff.

43 Jan 07, 2008 at 00:53 by nimd4

@Jalla, hopefully you’ve supplied the right info there. Wouldn’t want someone else getting these text messages..:)

44 Jan 09, 2008 at 22:12 by bloodseeker

man….nice, i’m seek of that f_ing abuser-tards.

45 Jan 12, 2008 at 18:27 by Joni

I guess I am what would be concidered a “noob”, but I have been downloading bunches of movies that are all this STUPID Domplayer. I recently found a forum and they gave a link to somewhere that can fix them.
It says… that basically the ‘header information is off and that there are two tracks for video in an AVI file and this picks up the other one… or something, like I said, I know very little about this stuff, but I am willing to try it. IT’s free! And I’m so tired of trying to find an actual copy of JUNO that I am about willing to try anything. It says that you can download a utility from Wildman Productions that will remove the crap and let you watch the video normally. The website I found it on is
http://www.goitexpert.com/entry.cfm?entry=DomPlayer-3wPlayer-Fix and they also give a link to Wildman Productions. I hope it works. Just wanted to leave it here, maybe it can help someone else too.

46 Jan 21, 2008 at 08:10 by jay1967

just downloaded hitman.2007.dvdrip.english.[divx]-[neo]avi from seedpeer. asked me to download domplayer after what i have just read about malware there is no chance of me downloading this. wou;d rather wait until a good copy appears on one of the better download sites. domplayer also asks for money so you can download it. BE WARNED. DO NOT DOWNLOAD UNLESS YOU LIKE SHIT GETTING ON YOUR PC.

47 Jan 28, 2008 at 05:23 by wyrm

Ditto for Cloverfield - downloaded 2 pass-protected rars (no pass provided in comments), and 1 Domplayer version. I used the 3wdecoder on it, and it then told me I had to dl the 3wd player. Used the decoder again, and the movie turned out to be a sped-up “Hipster Olympics” from Eastern Europe.

48 Jan 30, 2008 at 09:46 by non noob

You n00bs. It’s not that hard.

49 Jan 30, 2008 at 09:57 by non noob

“I guess I am what would be concidered a ‘noob,’ but I have been downloading bunches of movies that are all this STUPID Domplayer.”

::Sigh:: I guess. :\ Go to mininova.org for a legitimate copy of The Golden Compass. READ COMMENTS FIRST to see which one is the best quality.

50 Feb 09, 2008 at 03:08 by cough cough

to n00bs - just look at the comments, its not hard to find a legit copy of a film, plus most people will say what the quality is. there’s plenty of fake stuff knocking around, just be patient and something legit always turns up. i sat on my arse for 2 weeks waiting for avp2, then i got a great R3 copy. you might want to stick to sites like mininova.org and the pirate bay, they both get their fair share of fakes from what i see but the moderators take them off most of the time and users leave comments.

my daily searches are - R3, R5 and DVDSCR. these will bring up the new film releases, but don’t forget to check the comments, if there aren’t any yet you might want to wait and see, or take a chance and d/l. either way though if it doesn’t open in vlc player chances are its a fake

good luck folks

51 Feb 15, 2008 at 16:50 by kuma

Hell yeah just makin sure the info was out and btw sent the dom player a nice present to their server

52 Feb 22, 2008 at 22:28 by sdfsdf

sdfsdfsdfsd

53 Mar 04, 2008 at 07:50 by Death Fairy

I use my windows media player with a thing called combined community codec and have never had problems playing anything really. Course I also get avi and nothing else.easier and hassle free. If its not on avi I wait. patience is a virtue.

54 Mar 20, 2008 at 05:29 by Chandler

basically every fuckin’ dl of Never Back Down is this bullshit… anyone got a clean dl?

55 Apr 17, 2008 at 09:37 by Controlfreq

I have just been introduced to the torrent phenominom about 3 days ago..i have been learning as i go, but i am in fear of getting my comp messed up. I continuisly read threads to get my knowledge up. From what i have learned is the aXXo has some good movies, so what i did was use mininova and used his name in the user search. so now i only download from his torrents. Is what im doing stupid, or over cautios??

56 Jul 18, 2008 at 08:01 by these bozos

I am an owner of a well known torrent site that has been around for 5+ years now. C4DL Media contacted me to try to get me to show banner ads for their torrent client, and media player on my site. I would of course never do this as we don’t do ads, especially with crooks like this bunch, but watch out as the new crop of untrustworthy and greedy torrent site owners may take up their offers, at their members expense.

57 Jul 18, 2008 at 18:59 by Dramacydal

hi, AM a noob at the torrent thing,am using utorrent, i download a movie hancock and it dosent play (use vlc player)its say rar file,
plz help some one. dont no how 2 decompress files, nothing,
can some1 help step by stef plzzz

send me at player384@hotmail.com
ty :)

Add your response

It takes approximately 1 minute for your comment to appear on TorrentFreak after it's posted.