Downloader.Swif.C

When your computer is compromised with Downloader.Swif.C, you may follow the procedure on this page to contain this threat. Remove the Trojan at once before it can further harm the system.

Downloader.Swif.C is a Trojan that can download more threats and execute in the infected computer. It will take advantage of the Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability to run the code without user’s intervention. Once the Trojan loads, it may carry out harmful task on the compromised PC. The Trojan can also redirect Internet browser to a web site where malicious SWF file is located.

Alias: Trojan-Downloader.SWF.Small.ag, Troj/SWFdlr-Gen, SWF_DLOADER.ZTS, SWF_DLOADER.YVN, SWF_DLOADER.YVM

Damage Level: Low

Systems Affected: Windows 9x, 2000, XP, Windows Vista

Characteristics
When the Trojan executes, it opens an instance of Flash Player simultaneous with Internet Explorer and redirect victims to a malicious web address. This may lead to exploitation of Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability that causes the affected system to download additional threats from a predefined location.

Downloaded threat is saved under Windows Temporary folder as ORZ.EXE, identified as a Trojan Horse.

Distribution
Downloader.Swif.C may arrive on a computer as a downloaded file from a remote site that disguises as useful application. An especially designed .SWF file checks Flash Player version installed on target computer. It access various web address depending on detected Flash Player version. If it detects that system has version, 9.0.115.0, it tries to visit the following address:

http://www.{BLOCKED}nie.com/pcd/topics/ff11us/20080311cPxl31/WIN%209.0.115.0ff.swf
http://www.{BLOCKED}nie.com/pcd/topics/ff11us/20080311cPxl31/WIN%209.0.115.0ie.swf

Both URL’s displayed above are not available as of this writing.

1 Response

  1. juan colon estrada says:

    Downloader.Swif.C this virus is attacking my computer and my antivirus is not working properly, I mean don’t clean it, I do a scan and it don’t report the virus, but when I used my browser it show up a report that there’s a virus. please I need to know what to do, this is the notification that show my antivirus Symantec.
    Scan type: Real time Protection Scan
    Event: Virus Found!
    Virus name: Downloader.Swif.C
    File: C:\Documents and Settings\josue\Local Settings\Temporary Internet Files\Content.IE5\JOLNFQHJ\i115[1].SWF
    Location: C:\Documents and Settings\josue\Local Settings\Temporary Internet Files\Content.IE5\JOLNFQHJ
    Computer: JUAN-DA62A64E3C
    User: josue
    Action taken: Delete succeeded : Access denied
    Date found: Thursday, September 18, 2008 7:49:41 AM

Leave a Reply

Your email address will not be published. Required fields are marked *