Main Menu
Home
Bookmark
Contact Us



 
SWScript.LF Viruses Information

Name: SWScript.LF
Category: Viruses
Description: Details
SWScript.LFM
text written by Costin Raiu, Kaspersky Labs, Romania
This is the first virus known to infect Macromedia Shockwave (.SWF) files, which are commonly used for various kinds of animations on the World Wide Web; for instance in animated e-cards or e-greetings. The virus does not work if an infected Shockwave .SWF file is loaded in the player plugin distributed with most newer versions of the Netscape and Internet Explorer browsers - it will only execute and replicate if the user manually loads infected animation into the stand-alone Shockwave Flash Player application, which greatly limits the danger posed by the virus to most computer users. At this time, there have not been any reports of this virus "in-the-wild," and we do not expect it to ever become widespread.
Technical details
The virus works by taking advantage of the scripting language available in Shockwave animations - it is itself stored as a Shockwave script that further drops a DOS .COM executable named "V.COM" that is 926 bytes long. The DOS executable is dropped to disk through a standard DEBUG script, but this will only work on Windows NT, 2000 and XP systems, because the dropper script attempts to call the command line preprocessor as "cmd.exe", which is not available on Win9X/ME installations. When executed, the V.COM program will search for all the *.SWF files in the current directory, make sure they are not read-only, hidden or system, so they can be written to, and it will attempt to infect them. First, it will check whether they have the standard "FWSx99" signature, and if so, the virus will proceed to create a new Shockwave script dropper similar to the one used to initially drop the "V.COM" executable to disk. The Shockwave script dropper is created in a piece of dynamically allocated memory, and is written at the beginning of the target Shockwave file.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Voronezh Famil
MzBoot.46
MD Famil
USTC.91
Win32.HLLC.Sulpex.
Keydro
Win32.Sin
Win32.Positon.466
Predator.107
Flowers.168


 


© 2006-2008 spyware32.com - Privacy Policy