SHARE
THIS ON

Facebook Twitter Google Plus

Trojan.HTML.Zlob

LOW
VERY LOW
5kB - 30kB
(JS/Zlob!tr.dldr, TrojanDownloader:JS/Zlob, Trojan.HTML.Agent)

Symptoms

While browsing the Internet a message in your browser appears with a text similar to:

Video ActiveX Object Error. Your browser cannot play this video file.Click 'OK' to download and install missing Video ActiveX Object.

or

ActiveX Object Error:
Your browser cannot display this video/image file.

You need to download new version of Video
ActiveX Object to play this video file.

Even if you click the Cancel button a popup will appear telling you again that "Your browser cannot play this image file." You may need to check a button in your browser to stop executing that script and to be able to close the webpage.

Removal instructions:

Please let BitDefender disinfect your files.

Analyzed By

Andrei DAMIAN-FEKETE, virus researcher

Technical Description:

This malware is part of a web page that asks the user to download a certain codec or ActiveX component that supposedly helps viewing the content of an (inexistent) video file embedded in the page.

The malware is not capable installing itself on the user's computer. It has to do this by tricking the user into believing it has to install the "codec" and by showing the message over and over again, even if the user tries to close the page.

It has the following behaviour :
  1. Receiving messages from the browser : "Video ActiveX Object Error. Your browser cannot play this video file.Click 'OK' to download and install missing Video ActiveX Object." when the user accesses some webpage. If the user cancels the request then he receives, in a loop, this message : "Please install new version of Video ActiveX Object."
  2. Then it will give the user an executable to install on the computer. Usually this is "ActiveX" related or "video codecs" related.
  3. The pages change rapidly and they usually contain reference to codecs : VideoAccessCodec, VideoSoftOnline, CodecPro, VipCodecVip, IXCodec, MoonCodec , or to video enhancers: VideoAdaptation, SoftWebVideo.
  4. When given the approval and getting installed the malware takes these steps ( http://www.bitdefender.com/VIRUS-1000125-en--Trojan.Zlob.2.Gen.html )