Mal/ASFDldr-A

Category: Viruses and Spyware Protection available since:27 Apr 2009 07:55:38 (GMT)
Type: Malicious behavior Last Updated:03 Dec 2010 20:09:36 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Mal/ASFDldr-A detects malicious media files with the .asf (Advanced Streaming Format) extension.

 

The malicious files use Microsoft Media Player's scripting capability to open a web browser to an infected site instead of playing the video the user was hoping for.

 

Microsoft has issued an update for this vulnerability:

http://support.microsoft.com/kb/828026

 

Most of the files detected as Mal/ASFDldr-A do not contain any video or audio content. They are several megabytes in size due to null padding.

 

Mal/ASFDldr-A tries to pass itself off as media coming from artists such as:

Lady Gaga

ABBA

Taio Cruz

Madoona (sic)

Examples of Mal/ASFDldr-A include:

Example 1

File Information

Size
3.3M
SHA-1
00dae3cf8cfe83108922efad0bc4e7963a8abd25
MD5
386e554040706f3dd0d7e831e3839b62
CRC-32
13667dc8
File type
video/x-ms-asf
First seen
2010-10-05

Example 2

File Information

Size
3.6M
SHA-1
00ea34a19ecd0571233c6475fcee2af564c3fb75
MD5
02356173e3ebfb4431e62f61b0452f62
CRC-32
f7f0d771
File type
video/x-ms-asf
First seen
2010-11-07

Example 3

File Information

Size
3.3M
SHA-1
01311441bf8112add337a1448c59c698c941c2b6
MD5
3f206a2373ae5e987939ac7a38885ed3
CRC-32
9ba5a4fe
File type
video/x-ms-asf
First seen
2011-01-29

download Try Sophos products for free
Download now