CDROM-Guide forums  

PDA

View Full Version : first flash virus


   
cyrus-troy
Jan 08, 2002, 11:39 AM
Description:

SWF/LFM-926 is the first virus which is capable of infecting
Shockwave Flash (.SWF) files, commonly used for animation and
special effects on websites.

When an SWF file is played the virus displays the message
"Loading.Flash.Movie..." and then it infects other SWF files in
the current directory.

The virus makes use of the ability of Shockwave files to run
scripts. In this case it causes the command line interpreter to
run a debug script which produces a file called V.COM. This file
is then automatically run by the virus infecting all other SWF
files in the current directory.

In testing we confirmed the Shockwave element of the
virus works when the SWF file is downloaded from an affected
website and opened using the Shockwave player.

we recommend webmasters put in place procedures and
policies to ensure the integrity of the code they place on their
websites, whether it be obviously executable (in the case of,
for instance, EXE and COM files) or Shockwave Flash movies.

hammy18_99
Jan 08, 2002, 11:41 PM
I was wondering when u were gonna post in here :D thx for the heads up.

Paul_H
Jan 09, 2002, 10:05 AM
At present, many anti-virus software programs do not by default scan files ending in .SWF. Sophos advises its customers to add .SWF to the list of file extensions which Sophos Anti-Virus scans.

"At the moment, this isn't Armageddon. But it should serve as a further reminder that users should always be wary about unsolicited files you receive or download from the Internet," said Cluley

Sophos's description of the Flash virus is at http://www.sophos.com/virusinfo/analyses/swflfm926.html .