New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 22)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 885
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
image vrs: Beware!: Swen Virus Continues To Fool Users image
Viruses
Swen Virus Continues To Fool Users
By Jay Wrolstad
Enterprise Windows IT
September 22, 2003

Swen sends a message that claims to contain a cumulative patch for several security vulnerabilities in Outlook, Outlook Express and Internet Explorer. Once a machine is infected, the worm distributes itself to addresses found in a user's system.

Swen, a mass e-mailing virus, continues to spread worldwide, adding yet another concern to a growing heap of problems that have plagued Windows customers in recent weeks.
The W32/Swen@MM worm, also known as a Gibe.F virus, initially was launched late last week. It arrives on PCs as a fraudulent Microsoft software-update message that easily can fool users who have been busy trying to keep up with patches issued by Microsoft for previous attacks.

Swen exploits a Microsoft Internet Explorer flaw revealed two years ago. The worm sends a message that claims to contain a cumulative patch for several security vulnerabilities in Outlook, Outlook Express and Internet Explorer. Once a machine is infected, the worm distributes itself to addresses found in a user's system.

The new bug also spreads through P2P and Internet Relay Chat (IRC) networks, and can copy itself across shared networks.

Number of Infections Rising

This is a very good social engineering attempt, says Bruce Hughes, malicious code authority with security firm TruSecure. He told NewsFactor that Swen spread rapidly on Friday, primarily affecting home computer users, who, unlike businesses, do not have e-mail attachment filters on their systems.

After briefly subsiding over the weekend, the number of Swen bug infections picked up on Monday, said David Loomstein of Symantec security response. The company has received 3,300 submissions regarding the virus, he told NewsFactor, with that number on pace to double, indicating that the infection rate is rising.

This is a very agressive virus using a lot of tools to deceive users, Loomstein said. Beyond causing odd behaviors on a PC, such as slow operation, Swen is sending dialogs to users telling them there is a problem with their e-mail system and requesting personal e-mail account information. It can even delete itself to cover its tracks once the damage has been done, and will install itself on a computer even if the user clicks the no dialogue box.

Consumers Take the Brunt
Of the machines infected, said Loomstein, just 10 percent are corporate computers, while the vast majority are consumer PCs.

Hughes described the worm as a variant of the Gibe virus strain that has previously spread as a disguised Microsoft update. He reinforced Microsoft's reminder that the company does not distribute patches via e-mail, and advised users to delete any such messages they receive.

Users are encouraged to update their antivirus software and to be particularly wary of all e-mail messages with attachments purporting to contain patches or other software-repair tools, Hughes said.

Those using Web-based e-mail should install a third-party firewall to help protect a computer from this worm. In addition to updating antivirus software with new virus definitions, users should scan their computer and follow the instructions from Microsoft for removing this worm.

NewsFactor
Posted on Tuesday, 23 September 2003 @ 10:57:38 EDT by phoenix22
image

 
Login
Nickname

Password

· New User? ·
Click here to create a registered account.
image
Related Links
· TrackBack (0)
· Microsoft
· Microsoft
· HotScripts
· W3 Consortium
· More about Viruses
· News by phoenix22


Most read story about Viruses:
Xupiter Virus!

image
Article Rating
Average Score: 4.33
Votes: 6


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


image
Options

Printer Friendly Page  Printer Friendly Page

image
"Login" | Login/Create an Account | 10 comments | _SEARCHDIS
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Swen Virus Continues To Fool Users (Score: 0)
by Anonymous  on Thursday, 25 September 2003 @ 10:22:26 EDT
if you use sendmail you can copy and paste the following section into your sendmail.cf. This will block the mail at the server, and hopefully slow the spread of the worm. on the lines such as the following:
R${MPat} $* $#error $: 553 ${MMsg}
should actully be tab delimited such ash

R${MPat} $*$#error$: 553 ${MMsg}

these filters also block the mellisa virus. The section can be up any where in the sendmail.cf but i recommend any section after the H sections

Drew decker
ddecker_AT_ezdn_dot_net

HSubject: $>Check_Subject
D{MPat}Next Critical Vulnerability Patch!
D{MMsg}This message may contain a virus, if you are trying to send a legitmate email, please change the subject
SCheck_Subject
R${MPat} $* $#error $: 553 ${MMsg}
RRe: ${MPat} $* $#error $: 553 ${MMsg}
RFW: ${MPat} $* $#error $: 553 ${MMsg}

HSubject: $>Check_Subject
D{MPat}last update
D{MMsg}This message may contain a virus, if you are trying to send a legitmate email, please change the subject
SCheck_Subject
R${MPat} $* $#error $: 553 ${MMsg}
RRe: ${MPat} $* $#error $: 553 ${MMsg}
RFW: ${MPat} $* $#error $: 553 ${MMsg}

HSubject: $>Check_Subject
D{MPat}net critical update
D{MMsg}This message may contain a virus, if you are trying to send a legitmate email, please change the subject
SCheck_Subject
R${MPat} $* $#error $: 553 ${MMsg}
RRe: ${MPat} $* $#error $: 553 ${MMsg}
RFW: ${MPat} $* $#error $: 553 ${MMsg}

HSubject: $>Check_Subject
D{MPat}microsoft security upgrade
D{MMsg}This message may contain a virus, if you are trying to send a legitmate email, please change the subject
SCheck_Subject
R${MPat} $* $#error $: 553 ${MMsg}
RRe: ${MPat} $* $#error $: 553 ${MMsg}
RFW: ${MPat} $* $#error $: 553 ${MMsg}

HSubject: $>Check_Subject
D{MPat}newest internet upgrade
D{MMsg}This message may contain a virus, if you are trying to send a legitmate email, please change the subject
SCheck_Subject
R${MPat} $* $#error $: 553 ${MMsg}
RRe: ${MPat} $* $#error $: 553 ${MMsg}
RFW: ${MPat} $* $#error $: 553 ${MMsg}

HSubject: $>Check_Subject
D{MPat}internet pack
D{MMsg}This message may contain a virus, if you are trying to send a legitmate email, please change the subject
SCheck_Subject
R${MPat} $* $#error $: 553 ${MMsg}
RRe: ${MPat} $* $#error $: 553 ${MMsg}
RFW: ${MPat} $* $#error $: 553 ${MMsg}



Re: Swen Virus Continues To Fool Users (Score: 0)
by Anonymous  on Friday, 03 October 2003 @ 13:57:41 EDT
Can someone offer some advice? I continue to clean SWEN off my computer with stinger.exe and McAfee [updated] virus scan/clean - but it just keeps coming back. What must I do to rid this thing completely from my system. Thanks