Skip to comments.
Nasty Worm Poses as MS Security Update
The Register ^
| 09/19/03
| John Leyden
Posted on 09/19/2003 10:03:08 AM PDT by Salo
Windows users were yesterday warned of the appearance of a worm that poses as a security update from Microsoft but actually causes all manner of mischief on infected PCs.
Swen-A (AKA Gibe-F) is a mass-mailing worm that also attempts to spread through file-sharing networks, such as KaZaA and IRC, and over local area network shares. The worm attempts to de-activate antivirus and personal firewall programs running on an infected computer.
AV vendors warn that the worm is spreading rapidly and that disinfection is difficult. As usual this is a Windows-only menace - Linux, Mac, OS/2 and Unix users are immune.
Managed services firm MessageLabs reports today that it has blocked copies of Swen-A 35,400 times since first intercepting it on September 14. Initial copies all originated from Slovakia, and some later copies originated from the Netherlands, the company reports, adding that MessageLabs' subscribers in the US, UK and the Netherlands have been most heavily targeted by the worm.
Swen-A uses a well known vulnerability in Internet Explorer to execute directly from e-mail. Windows users can also catch the pox by executing an infected email attachment.
Finnish AV firm F-Secure compares the worm to Gibe, and believes it is likely that the same author wrote both worms.
Swen-A (like Gibe and numerous other viruses before it) purports to be a security alert from Microsoft. This time around infectious messages come with a well-presented HTML message complete with graphics that are more likely to trip up the unwary.
The worm can also impersonate mail delivery failure notices, attaching itself as a randomly named executable.
Swen-A attempts to spread by emailing itself using its own SMTP client to addresses extracted from various sources on the victim's drives (e.g. MBX and DBX files). Periodically the worm presents users with a fake MAPI Exception error, prompting them to enter the details of their email account (name, user name, servers).
Sneaky.
Swen-A also makes modifications which make it hard to run Reg Edit, along with other changes to infected PCs explained in advisories from F-Secure and Symantec.
Windows users are advised to update the virus signature files on their AV scanners to defend themselves against the worm, which is all very well but the reason the virus got a hold in the first place is probably because of the shortcomings of the scanner model. ®
TOPICS: Business/Economy; Technical
KEYWORDS: lowqualitycrap; microsoft; security; virus; windows; worm
Navigation: use the links below to view more comments.
first 1-20, 21-35 next last
Terrorists, careful with those weapons! Also, I realize this was covered somewhat yesterday, but this is a new article.
1
posted on
09/19/2003 10:03:09 AM PDT
by
Salo
To: rdb3
Pinging the Penguin Pinger.
2
posted on
09/19/2003 10:03:34 AM PDT
by
Salo
(Are you a man, or a mouse-user?)
To: Bush2000; Golden Eagle; Coral Snake; TheEngineer
We need an MS ping, too. :-)
3
posted on
09/19/2003 10:04:28 AM PDT
by
Salo
(Are you a man, or a mouse-user?)
To: Salo
I talk to people until I am blue in the face and they still screw up. NEVER RUN ANYTHING YOU GET IN EMAIL. Do they listen? No.
And it doesn't help that our IT dept sent an email telling people to apply an update from their website. SHEESH!!
4
posted on
09/19/2003 10:05:05 AM PDT
by
AppyPappy
(If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
To: Salo
I wonder how much of this is being created by Linux, Mac, OS/2 and Unix employees looking to get back into the market?
5
posted on
09/19/2003 10:05:34 AM PDT
by
A CA Guy
(God Bless America, God bless and keep safe our fighting men and women.)
To: AppyPappy
Some of it also poses as a jpg or gif, so there is that issue as well.
6
posted on
09/19/2003 10:06:14 AM PDT
by
A CA Guy
(God Bless America, God bless and keep safe our fighting men and women.)
To: A CA Guy
I tell them "If you don't know what it is, don't open it". I don't care if it came from the President.
7
posted on
09/19/2003 10:08:42 AM PDT
by
AppyPappy
(If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
To: A CA Guy
And while I am ranting, why can't I talk people into NOT sending messages in Word Documents. Every baby shower comes in a Word document. You know, that application that can carry VBA viruses.
And don't get me started on Webshots. A freaking hole in the firewall.
8
posted on
09/19/2003 10:10:28 AM PDT
by
AppyPappy
(If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
To: Salo
Thanks for the update. This shows just how diabolical these hacker fanatics are. Anything to vandalize personal property, including masquerading as a security patch to sneak attack the helpless. They are gutless punks and should have to spend the rest of their lives on an disconnected pc running Windows 1.0.
To: A CA Guy
I would imagine none. Real companies don't pull crap like this because of what happens when they get caught. Think of that useless fatboy in Minnesota: he's more along the lines of what you are looking for. I'm hoping he becomes currency in the prison cigarette trade very soon.
I wonder how much of this is being created by Linux, Mac, OS/2 and Unix employees looking to get back into the market?
10
posted on
09/19/2003 10:17:59 AM PDT
by
Salo
(Are you a man, or a mouse-user?)
To: Golden Eagle
Damn, dude, that's worse than the death penalty. :-)
They are gutless punks and should have to spend the rest of their lives on an disconnected pc running Windows 1.0.
11
posted on
09/19/2003 10:22:00 AM PDT
by
Salo
(Are you a man, or a mouse-user?)
To: Salo
I've gotten 6 emails today, purporting to be from "Microsoft Security" which were infected with the Automat.H worm. Symantec deleted them.
Microsoft never sends patches through email. If you have "Automatic Updates" in Control Panel set to "Notification" an icon will appear in the system tray.
12
posted on
09/19/2003 10:23:55 AM PDT
by
Alouette
(The bombing begins in five minutes.)
To: Alouette
Correct. My Zone Alert firewall has stopped dozens of these over the past five days alone. Also glad I ditched McAffy and got Norton.
To: Salo
a mass-mailing worm that also attempts to spread through file-sharing networks, such as KaZaA and IRC, and over local area network shares Anyone who opens up his computer to hackers with Kazaa or some other file sharing program is asking for big trouble.
14
posted on
09/19/2003 10:29:13 AM PDT
by
Cicero
(Marcus Tullius)
To: Salo
Good thing the Department of Homeland SECURITY!!! has gone with M$. Makes me feel really safe - Ugghhhhh!!!
15
posted on
09/19/2003 10:45:45 AM PDT
by
SengirV
To: SengirV
Good thing the Department of Homeland SECURITY!!! has gone with M$. Makes me feel really safe - Ugghhhhh!!!
Let's blame MS. We wouldn't want to blame the bastard hackers that actually commit these crimes... /SARCASM
16
posted on
09/19/2003 10:54:07 AM PDT
by
Bush2000
To: SengirV
Might as well learn to speak Farsi. :-)
Good thing the Department of Homeland SECURITY!!! has gone with M$. Makes me feel really safe - Ugghhhhh!!!
17
posted on
09/19/2003 11:04:26 AM PDT
by
Salo
(Are you a man, or a mouse-user?)
To: AppyPappy
"And don't get me started on Webshots. A freaking hole in the firewall."Even worse, I think, is weatherbug. Man, I never had so many popups and viruses as I did when I had that thing installed. I took it out, and the popups STOPPED.
18
posted on
09/19/2003 11:10:12 AM PDT
by
redhead
(Mom said you're not the boss of me)
To: redhead
I did a webapp(php/Access...thanx for asking) for the school and went to test it. The person fired up the URL and a FREAKING POPUP jumped in. I almost had a coronary. Why is my webapp throwing out popups for a drug company?!! The person said "Oh that's because I have Webshots". I could have shot her.
19
posted on
09/19/2003 11:20:14 AM PDT
by
AppyPappy
(If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
To: Cicero
This is what the e-mail looks like. I got it today by e-mail, and I never file swap.(Image is from symantec).
Navigation: use the links below to view more comments.
first 1-20, 21-35 next last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson