Skip to main content

Trojan.asf.gen

Classification

Category:

Malware

Type:

Trojan

Aliases:

  • Trojan.asf.gen

Summary

This detection identifies video files that have been intentionally corrupted. When launched, instead of displaying the video, a message is displayed that prompts the user to download an additional file to "resolve video playback issues". If the user does so, a malicious file is downloaded.

Removal

Technical Details

The video files identified by this detection are typically in the WMV video format and are distributed in ZIP archive files. The videos themselves appear to be pirated copies of current popular movies or television series, with their filenames indicating the movie or series.

Downloading malware

When the file is launched using Windows Media Player, an image of a message box entitled "Media Usage Rights Acquisition" is displayed. Note that it is not an actual message box - it is an image with two buttons, "Download Fix" and "Web Help".

The text shown in the image is designed to make the user believe that a codec is missing from their machine, and that the necessary file must be downloaded to "resolve video playback issues". If the "Download Fix" button is clicked, a file is downloaded from a remote server. The downloaded file is malware, typically a trojan.

Social engineering

This tactic of using a desirable file that appears to require an "additional component" in order to be properly viewed is an old but effective social engineering ploy to trick users into unwittingly downloading malware onto their own machines.

An example of an older malware that uses the same technique is Trojan-Downloader:OSX/DNSChanger.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.