Virus scanner detects a threat in one thread

Anything to do with the running of the website. (e.g. Suggestions, bugs, etc)
Post Reply
Message
Author
User avatar
Prince George
Legendary Member!
Posts: 974
Joined: Wed Sep 10, 2008 11:02 pm
Location: Melrose Park

Virus scanner detects a threat in one thread

#1 Post by Prince George » Wed Dec 03, 2008 12:21 am

When I visit the Sturt Highway thread http://www.sensational-adelaide.com/for ... f=9&t=1567, my virus scan is giving me this notification:

The Actns/Swif.T was detected in ...\TEMPORARY INTERNET FILES\LOW\CONTENT.IE5\S2309FAL\L[1].SWF.
File Status: File was cured; system cure performed.

I'm typically getting this message twice when I go there - could it be those latest couple of pictures?

User avatar
Norman
Donating Member
Donating Member
Posts: 6392
Joined: Sun Mar 25, 2007 1:06 pm

Re: Virus scanner detects a threat in one thread

#2 Post by Norman » Wed Dec 03, 2008 12:33 am

the SWF indicates it's a Flash file... so it must be the videos... I don't see how they could be infected though, it's hosted on YouTube.

User avatar
Prince George
Legendary Member!
Posts: 974
Joined: Wed Sep 10, 2008 11:02 pm
Location: Melrose Park

Re: Virus scanner detects a threat in one thread

#3 Post by Prince George » Wed Dec 03, 2008 12:39 am

I can't find a specific advisory that explains this threat, but the closest may be this one for ActnS/Swif.O. Of course, every different company lists their threats under different names, so there's no easy way to corelate this with any of the other security companies' databases :(

User avatar
Prince George
Legendary Member!
Posts: 974
Joined: Wed Sep 10, 2008 11:02 pm
Location: Melrose Park

Re: Virus scanner detects a threat in one thread

#4 Post by Prince George » Wed Dec 03, 2008 12:51 am

Following Norman's suggestion that it could be the videos, I tried going to the Rundle Lantern thread and sure enough when I get to the section with the videos I get the message again. On the other hand, I can go to YouTube without any issues. The videos themselves may be hosted on YouTube, but what about the embedded player? Could it be coming from somewhere else?

User avatar
Howie
VIP Member
VIP Member
Posts: 4871
Joined: Mon Mar 21, 2005 3:55 pm
Location: Adelaide
Contact:

Re: Virus scanner detects a threat in one thread

#5 Post by Howie » Wed Dec 03, 2008 7:55 am

I see thing sort of thing quite often in my work. One of the possibilities is that the problem may lie in your virus scanner itself (either too sensitive to flash's getURL() command), or you've been infected by some sort of worm that's rewriting your swf files as you're browsing the net.

Anyhow, if you find out anything else let us know... i'll be watching this thread.

Btw, what version of IE are you running?

User avatar
Prince George
Legendary Member!
Posts: 974
Joined: Wed Sep 10, 2008 11:02 pm
Location: Melrose Park

Re: Virus scanner detects a threat in one thread

#6 Post by Prince George » Wed Dec 03, 2008 8:42 am

IE8 beta 2 in compatability mode. Virus scanner is CA eTrust. I've seen some email traffic that seems to show that other people have also gotten this message from other sites that I think have embedded youtube videos. I'll keep you posted.

muzzamo
Legendary Member!
Posts: 1026
Joined: Tue Aug 21, 2007 4:44 pm

Re: Virus scanner detects a threat in one thread

#7 Post by muzzamo » Wed Dec 03, 2008 9:14 am

Prince George wrote:IE8 beta 2 in compatability mode. Virus scanner is CA eTrust. I've seen some email traffic that seems to show that other people have also gotten this message from other sites that I think have embedded youtube videos. I'll keep you posted.
Just use firefox. Jeesus.

Edgar
Legendary Member!
Posts: 990
Joined: Tue Jun 27, 2006 10:20 pm
Location: Adelaide
Contact:

Re: Virus scanner detects a threat in one thread

#8 Post by Edgar » Wed Dec 03, 2008 10:36 am

muzzamo wrote:
Prince George wrote:IE8 beta 2 in compatability mode. Virus scanner is CA eTrust. I've seen some email traffic that seems to show that other people have also gotten this message from other sites that I think have embedded youtube videos. I'll keep you posted.
Just use firefox. Jeesus.
Each to their own preference muzzamo, there is no need for that last name calling.

Anyway to Prince George, see if you are getting the same report from using Firefox.

I have long ditched Microsoft Internet Explorer, it somehow doesn't quite work in my laptop which is pre-installed with Vista Home Premium. Every time I close the Internet Explorer Browser, it comes up with an error message saying "Internet Explorer Has Stopped Working" - and when I click "Checked Online for Solutions" it just sends the bug to the Microsoft team but nothing has been fixed yet.
Visit my website at http://www.edgarchieng.com for more photos of Adelaide and South Australia.

User avatar
Prince George
Legendary Member!
Posts: 974
Joined: Wed Sep 10, 2008 11:02 pm
Location: Melrose Park

Re: Virus scanner detects a threat in one thread

#9 Post by Prince George » Wed Dec 03, 2008 10:46 am

It appears that CA is the culprit - http://www.crunchgear.com/2008/12/02/ac ... tube-vids/ No official word on CA's site, nor on YouTube/Google. Might be time to check for updates - bah, and it's not even Patch Tuesday.

And sufficeth to say - one who lives in Seattle may have a good reason to be running explorer :)

User avatar
monotonehell
VIP Member
VIP Member
Posts: 5466
Joined: Fri Feb 01, 2008 12:10 am
Location: Adelaide, East End.
Contact:

Re: Virus scanner detects a threat in one thread

#10 Post by monotonehell » Wed Dec 03, 2008 6:29 pm

Prince George wrote:It appears that CA is the culprit - http://www.crunchgear.com/2008/12/02/ac ... tube-vids/ No official word on CA's site, nor on YouTube/Google. Might be time to check for updates - bah, and it's not even Patch Tuesday.

And sufficeth to say - one who lives in Seattle may have a good reason to be running explorer :)
Just run Linux -- that'll get up their noses. ;)

False positives are becoming more common as the number of viruses to detect increases. The "signature" that the virus checker is looking for is more likely found in another piece of code the bigger the virus checker's "brain file" gets. Firefox is a good option as you can get a flash blocker (I assume you can get one for IE as well) this allows you to only play the flash that you want to see, or trust. It's incredible the number of hidden Flash bugs that websites place on their pages to do evil. Flash is a big security hole, and it's best to refuse it unless you trust it.
Exit on the right in the direction of travel.

Post Reply

Who is online

Users browsing this forum: No registered users and 16 guests