So this morning, I navigated to this page to see what lovely comments had been left by my threes of readers, and I got a popup warning from my virus scanner that two instances of the actns/swif.t virus had been detected and deleted.
Naturally, I crapped my pants. After that was cleaned up, I poked around looking for information on this virus. Unfortunately, it's a relatively new thing and there's not much out there. I suspect it was just added to the virus definition files on the last update.
The problem was a couple of videos that I had embedded from Youtube. The videos themselves weren't infected. It was just the HTML code that was being flagged and deleted every time the page was loaded.
I finally found this info on the actns/swif.t virus on AntivirusConnection.com:
The Actns/Swif.T has been a tricky one. It seems this virus has just recently spawned, causing computers to show a embedded shockwave/flashplayer file within IE/Firefox browser. Inside the embedded swf, it features a redirect to a phishing website that I advise everyone NOT to click on! So if you see this embedded vicious file pop up, Do Not Click It! It will install another virus called Antivirus 2009, which those of you who know this virus already, it’s a pest to get rid of.
Now, based on this, I'm suspecting my detections were false positives. Since the virus definitions were just added, I think my virus scanner saw the embedded videos in my browswer and just assumed they were placed there maliciously. The videos themselves don't appear to be infected, and I've never been redirected to the phishing site.
But I'm hardly an expert, and I don't want to take any chances until I know for certain. So I've deleted the embedded videos until I can get a little more information. If any of you out there are smarter about this kind of thing than me, I'd love to hear from you.
Update: After all the ballyhoo, it turns out it was just a false positive from CA Antivirus. Apparently they've fixed the problem and I'm off to download the updated files. I feel pretty goddamn smart for having figured it out myself FOURTEEN HOURS AGO!
Also, I had a LOT of hits on the blog today. I was apparently one of the first people to post anything about the virus online, so for a few hours my blog was showing up on Google near the top of the list for searches on "actns swif.t" or variations thereof. Ordinarily, I get 20 to 30 hits a day. Today, I got 600+.
Of course, Google's brilliant algorithm eventually kicked in and decided that link farms and sites devoted to 80s heavy metal were FAR more relevant than my blog, so now I've dropped down several pages. But that's okay. Fame would have only changed me.