|
 |
|
Remove Trojan Downloader.ASX.Wimad.BD
TrojanDownloader:ASX/Wimad.BD
Name: TrojanDownloader:ASX/Wimad.BD
Aliases:
Trojan-Downloader.WMA.GetCodec.c (Kaspersky)
Troj/Wimad-E (Sophos)
ASF/Wimad!generic (CA)
Downloader-UA.h (McAfee)
Trojan.Wimad (Symantec)
TrojanDownloader:ASX/Wimad.BD is a detection for malicious Windows media files that are used in order to encourage users to download and execute arbitrary files on an affected machine. When opened with Windows Media Player, these malicious files open a particular URL in a web browser. The sites contacted, and files downloaded by TrojanDownloader:ASX/Wimad are variable, and may change over time and from instance to instance of this trojan downloader.
How do I know if my computer is infected?
There are no obvious symptoms that indicate the presence of this malware on an affected machine.
Technical information for more advanced users
TrojanDownloader:ASX/Wimad.BD is a detection for malicious Windows media files that are used in order to encourage users to download and execute arbitrary files on an affected machine. When opened with Windows Media Player, these malicious files open a particular URL in a web browser. The sites contacted, and files downloaded by TrojanDownloader:ASX/Wimad are variable, and may change over time and from instance to instance of this trojan downloader.
Installation
TrojanDownloader:ASX/Wimad.BD is a malicious Advanced Streaming Format (ASF) file, which when opened by Windows Media Player, urges a user to download and execute an arbitrary file,
At the time of writing the file downloaded may be detected as "Adware:Win32/PlayMp3z".
We strongly suggest that users avoid downloading and executing any files when prompted by Windows Media Player upon opening streaming format files.
Additional Information
Some reports suggest that the trojan file is distributed as a malicious MP3 file type.
This shouldn't be viewed as a characteristic of the trojan, the extension can be changed and the trojan will still try to perform its action as long as an extension of the trojan file is registered with the media player (for instance .avi, .asf, .mpg). In case of the mp3 extension the format of the trojan file does not follow the mp3 file format convention. This might prompt a media player to issue a warning:
If answered the trojan file will be processed by the media player. Performing this action the media player will try to open internet explorer and prompt a user to download a file which masquerades as an mp3 player.
Recovery Instructions
Manual removal is not recommended for this threat.
TO REMOVE THIS THREAT FROM YOUR PC, DOWNLOAD MICROSOFT MALICIOUS SOFTWARE REMOVAL TOOL
 download microsoft malicious software removal tool
|
| | |
 |
|
|