There is a Trojan Horse appearing on some websites that claims that it "needs an updated driver" to display a video or similar file. It won't let you back out from installing the "upgrade," opening the same window again and again. But it is no upgrade; it is a Trojan Horse designed to take over your computer.

I encountered several sites proffering Woodstock footage that set the trap, but there are others too. Once you enter the page, the trap is already sprung. The install window opens immediately.

Once you see the install window that won't let you refuse installation, the ONLY way to keep it from installing the malware is to Ctrl-Alt-Del and close your browser through the task manager. You will have to tell it you want to close it anyway when it says the browser is waiting for your input.

If you accidentally installed it, the Symantec antivirus program can remove it.

Dani AI

Generated

As found, some pages will present what looks like a legitimate “codec/driver” or video‑player upgrade and push an installer before you can do anything. That pattern — fake codec or update prompts that drop downloader/rogueware and fake security tools — is a well‑known social‑engineering vector used to get code running on a machine. ()

If a prompt has already run or you suspect the install started, treat the machine as compromised and don’t use it for sensitive tasks. First isolate it from the network (disconnect Ethernet or Wi‑Fi) and use a different, clean device to fetch removal tools. Boot the infected PC into an environment that limits active code (Safe Mode or an offline scanner) and run up‑to‑date, on‑demand scanners — reputable options include on‑demand tools from established vendors and portable removers that won’t rely on an in‑place installer. If basic removal fails, consider professional cleanup. (bitdefender.com)

After scanning, check for persistence and network tampering. Use a startup‑inspection tool to find/uncheck suspicious autorun entries, browser helper objects and codec installs; inspect the hosts file and adapter DNS settings; and verify your router’s DNS and admin settings (malware has historically altered router/DNS settings to keep victims directed to malicious sites). If router settings are altered, a factory reset and firmware update plus a new admin password are usually required. (learn.microsoft.com)

Prevention: run browsers with click‑to‑play for plugins, keep OS/browsers/firmware patched, browse as a limited user (not admin), avoid running executables from sites, and keep verified, offline backups so you can restore a clean image if needed. When in doubt — persistent or unusual behavior, changed DNS, or credential theft — reimage from a known good backup and change passwords from a clean device. Official vendor offline‑scan and rebuild guidance can help with the safest recovery steps. (learn.microsoft.com)

Recommended Answers

All 2 Replies

Good to know, i have encountered a similar trojan through plugin install. if a site needs a plugin find what it is and go to the manufacturer site to download. Thats what i always do and its worked so far.

Eh most of em are fake codecs and it usually turns out to be the zlob trojan. Nothing a scan with AVG cant handle. :)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.