Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Nasty Worm Poses as MS Security Update
The Register ^ | 09/19/03 | John Leyden

Posted on 09/19/2003 10:03:08 AM PDT by Salo

Windows users were yesterday warned of the appearance of a worm that poses as a security update from Microsoft but actually causes all manner of mischief on infected PCs.

Swen-A (AKA Gibe-F) is a mass-mailing worm that also attempts to spread through file-sharing networks, such as KaZaA and IRC, and over local area network shares. The worm attempts to de-activate antivirus and personal firewall programs running on an infected computer.

AV vendors warn that the worm is spreading rapidly and that disinfection is difficult. As usual this is a Windows-only menace - Linux, Mac, OS/2 and Unix users are immune.

Managed services firm MessageLabs reports today that it has blocked copies of Swen-A 35,400 times since first intercepting it on September 14. Initial copies all originated from Slovakia, and some later copies originated from the Netherlands, the company reports, adding that MessageLabs' subscribers in the US, UK and the Netherlands have been most heavily targeted by the worm.

Swen-A uses a well known vulnerability in Internet Explorer to execute directly from e-mail. Windows users can also catch the pox by executing an infected email attachment.

Finnish AV firm F-Secure compares the worm to Gibe, and believes it is likely that the same author wrote both worms.

Swen-A (like Gibe and numerous other viruses before it) purports to be a security alert from Microsoft. This time around infectious messages come with a well-presented HTML message complete with graphics that are more likely to trip up the unwary.

The worm can also impersonate mail delivery failure notices, attaching itself as a randomly named executable.

Swen-A attempts to spread by emailing itself using its own SMTP client to addresses extracted from various sources on the victim's drives (e.g. MBX and DBX files). Periodically the worm presents users with a fake MAPI Exception error, prompting them to enter the details of their email account (name, user name, servers).

Sneaky.

Swen-A also makes modifications which make it hard to run Reg Edit, along with other changes to infected PCs explained in advisories from F-Secure and Symantec.

Windows users are advised to update the virus signature files on their AV scanners to defend themselves against the worm, which is all very well but the reason the virus got a hold in the first place is probably because of the shortcomings of the scanner model. ®


TOPICS: Business/Economy; Technical
KEYWORDS: lowqualitycrap; microsoft; security; virus; windows; worm
Navigation: use the links below to view more comments.
first 1-2021-35 next last
Terrorists, careful with those weapons! Also, I realize this was covered somewhat yesterday, but this is a new article.
1 posted on 09/19/2003 10:03:09 AM PDT by Salo
[ Post Reply | Private Reply | View Replies]

To: rdb3
Pinging the Penguin Pinger.
2 posted on 09/19/2003 10:03:34 AM PDT by Salo (Are you a man, or a mouse-user?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bush2000; Golden Eagle; Coral Snake; TheEngineer
We need an MS ping, too. :-)
3 posted on 09/19/2003 10:04:28 AM PDT by Salo (Are you a man, or a mouse-user?)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Salo
I talk to people until I am blue in the face and they still screw up. NEVER RUN ANYTHING YOU GET IN EMAIL. Do they listen? No.

And it doesn't help that our IT dept sent an email telling people to apply an update from their website. SHEESH!!

4 posted on 09/19/2003 10:05:05 AM PDT by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salo
I wonder how much of this is being created by Linux, Mac, OS/2 and Unix employees looking to get back into the market?
5 posted on 09/19/2003 10:05:34 AM PDT by A CA Guy (God Bless America, God bless and keep safe our fighting men and women.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: AppyPappy
Some of it also poses as a jpg or gif, so there is that issue as well.
6 posted on 09/19/2003 10:06:14 AM PDT by A CA Guy (God Bless America, God bless and keep safe our fighting men and women.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: A CA Guy
I tell them "If you don't know what it is, don't open it". I don't care if it came from the President.
7 posted on 09/19/2003 10:08:42 AM PDT by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: A CA Guy
And while I am ranting, why can't I talk people into NOT sending messages in Word Documents. Every baby shower comes in a Word document. You know, that application that can carry VBA viruses.

And don't get me started on Webshots. A freaking hole in the firewall.

8 posted on 09/19/2003 10:10:28 AM PDT by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Salo
Thanks for the update. This shows just how diabolical these hacker fanatics are. Anything to vandalize personal property, including masquerading as a security patch to sneak attack the helpless. They are gutless punks and should have to spend the rest of their lives on an disconnected pc running Windows 1.0.
9 posted on 09/19/2003 10:15:20 AM PDT by Golden Eagle
[ Post Reply | Private Reply | To 3 | View Replies]

To: A CA Guy
I would imagine none. Real companies don't pull crap like this because of what happens when they get caught. Think of that useless fatboy in Minnesota: he's more along the lines of what you are looking for. I'm hoping he becomes currency in the prison cigarette trade very soon.

I wonder how much of this is being created by Linux, Mac, OS/2 and Unix employees looking to get back into the market?

10 posted on 09/19/2003 10:17:59 AM PDT by Salo (Are you a man, or a mouse-user?)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Golden Eagle
Damn, dude, that's worse than the death penalty. :-)

They are gutless punks and should have to spend the rest of their lives on an disconnected pc running Windows 1.0.

11 posted on 09/19/2003 10:22:00 AM PDT by Salo (Are you a man, or a mouse-user?)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Salo
I've gotten 6 emails today, purporting to be from "Microsoft Security" which were infected with the Automat.H worm. Symantec deleted them.

Microsoft never sends patches through email. If you have "Automatic Updates" in Control Panel set to "Notification" an icon will appear in the system tray.

12 posted on 09/19/2003 10:23:55 AM PDT by Alouette (The bombing begins in five minutes.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Alouette
Correct. My Zone Alert firewall has stopped dozens of these over the past five days alone. Also glad I ditched McAffy and got Norton.
13 posted on 09/19/2003 10:27:30 AM PDT by Eric in the Ozarks
[ Post Reply | Private Reply | To 12 | View Replies]

To: Salo
a mass-mailing worm that also attempts to spread through file-sharing networks, such as KaZaA and IRC, and over local area network shares

Anyone who opens up his computer to hackers with Kazaa or some other file sharing program is asking for big trouble.

14 posted on 09/19/2003 10:29:13 AM PDT by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Salo
Good thing the Department of Homeland SECURITY!!! has gone with M$. Makes me feel really safe - Ugghhhhh!!!
15 posted on 09/19/2003 10:45:45 AM PDT by SengirV
[ Post Reply | Private Reply | To 1 | View Replies]

To: SengirV
Good thing the Department of Homeland SECURITY!!! has gone with M$. Makes me feel really safe - Ugghhhhh!!!

Let's blame MS. We wouldn't want to blame the bastard hackers that actually commit these crimes... /SARCASM
16 posted on 09/19/2003 10:54:07 AM PDT by Bush2000
[ Post Reply | Private Reply | To 15 | View Replies]

To: SengirV
Might as well learn to speak Farsi. :-)

Good thing the Department of Homeland SECURITY!!! has gone with M$. Makes me feel really safe - Ugghhhhh!!!

17 posted on 09/19/2003 11:04:26 AM PDT by Salo (Are you a man, or a mouse-user?)
[ Post Reply | Private Reply | To 15 | View Replies]

To: AppyPappy
"And don't get me started on Webshots. A freaking hole in the firewall."

Even worse, I think, is weatherbug. Man, I never had so many popups and viruses as I did when I had that thing installed. I took it out, and the popups STOPPED.

18 posted on 09/19/2003 11:10:12 AM PDT by redhead (Mom said you're not the boss of me)
[ Post Reply | Private Reply | To 8 | View Replies]

To: redhead
I did a webapp(php/Access...thanx for asking) for the school and went to test it. The person fired up the URL and a FREAKING POPUP jumped in. I almost had a coronary. Why is my webapp throwing out popups for a drug company?!! The person said "Oh that's because I have Webshots". I could have shot her.
19 posted on 09/19/2003 11:20:14 AM PDT by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 18 | View Replies]

To: Cicero
This is what the e-mail looks like. I got it today by e-mail, and I never file swap.(Image is from symantec).


20 posted on 09/19/2003 11:58:05 AM PDT by ThreeYearLurker
[ Post Reply | Private Reply | To 14 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-35 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson