It was originally introduced by Microsoft as an ActiveX object
in Internet Explorer 4 and later adopted by other browsers as XMLHttpRequest.
Users surfing these sites are asked to download a "missing Video ActiveX Object
" but are sent a virus instead.
Once clicked, the documents open a familiar ActiveX object
on the screen, allowing the code to send stolen data to another Web address for the cybercriminals to utilise.
As with the RSPlug.D Trojan horse, when a user visits an infected site, and attempts to view a video, they are alerted that there is a "Video ActiveX Object
Error" and is told that their "Browser cannot play this video file." The alert instructs the user to download the "missing Video ActiveX Object
If you do click one of the links you'll get a CNN-branded video player and an error message with a notice: "Video ActiveX Object
Georgia SoftWorks, Dawsonville, Ga., has developed RF FormMaker, an ActiveX Object
that allows Visual Basic developers to easily create forms and controls for RF Devices with all programming performed on the server.